EPISODE · Jun 11, 2024 · 46 MIN
Matt Rose -- Software Supply Chain Security Means Many Different Things to Different People
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Matt Rose, an experienced technical AppSec testing leader discusses his career journey and significant contributions in AppSec. The conversation delves into the nuances of software supply chain security and exploring how different perceptions affect its understanding. Matt provides insights into the XZ compromise, critiques the buzzword 'shift left,' and discusses the role of digital twins and AI in enhancing the supply chain security. He emphasizes the need for a comprehensive approach beyond SCA, the relevance of threat modeling, and the potential risks and benefits of AI in security. Matt Rose is a technical AppSec testing leader with consistent accomplishments in sales and sales engineering management roles with more than 20 years of experience.The Application Security Podcast is brought to you by Security Journey.About Security JourneyOur training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization.→ Learn more about Security JourneyConnect with Matt Rose:→ LinkedIn→ The Application Security Program Handbook by Derek FisherMentioned in this episode:→ The Application Security Program Handbook by Derek Fisher→ ReversingLabs→ YouTube video→ Stephen E Ambrose→ Mark Frost→ Fortify (OpenText)→ ChatGPT→ Pixee→ LinkedInFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Matt Rose: Software Supply Chain Security Means Many Different Things to Different People03:53 Let me ask you this question. How good are you at04:45 That's true. That is so true. That's, that's a good way11:33 Yeah, 100%. And I like to think of weaknesses in the14:56 You're, you just made me think of something. About when you17:12 Yeah, it seems like, it seems like there's a perfect storm19:09 I want to double-click on something that you mentioned earlier. And22:10 I mean, I think that's more of a startup growth problem24:55 It the first, is it the first thing you would like28:15 Yeah, I've never actually seen anybody do it. I've heard DJ30:38 About, uh, AI34:39 Yeah, I'm not, I'm not ready to embrace auto-remediation at this37:32 Yeah. And we're starting to see a whole cottage industry of40:14 Absolutely. The second question is, what would it say if you41:54 Our 3rd question is, uh, what's your top book recommendation and
Embed this episode
What this episode covers
Matt Rose, an experienced technical AppSec testing leader discusses his career journey and significant contributions in AppSec. The conversation delves into the nuances of software supply chain security and exploring how different perceptions affect its understanding. Matt provides insights into the XZ compromise, critiques the buzzword 'shift left,' and discusses the role of digital twins and AI in enhancing the supply chain security. He emphasizes the need for a comprehensive approach beyon...
Ready to play
Matt Rose -- Software Supply Chain Security Means Many Different Things to Different People
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.