Matt Rose -- Software Supply Chain Security Means Many Different Things to Different People episode artwork

EPISODE · Jun 11, 2024 · 46 MIN

Matt Rose -- Software Supply Chain Security Means Many Different Things to Different People

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Matt Rose, an experienced technical AppSec testing leader discusses his career journey and significant contributions in AppSec. The conversation delves into the nuances of software supply chain security and exploring how different perceptions affect its understanding. Matt provides insights into the XZ compromise, critiques the buzzword 'shift left,' and discusses the role of digital twins and AI in enhancing the supply chain security. He emphasizes the need for a comprehensive approach beyond SCA, the relevance of threat modeling, and the potential risks and benefits of AI in security. Matt Rose is a technical AppSec testing leader with consistent accomplishments in sales and sales engineering management roles with more than 20 years of experience.The Application Security Podcast is brought to you by Security Journey.About Security JourneyOur training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization.→ Learn more about Security JourneyConnect with Matt Rose:→ LinkedIn→ The Application Security Program Handbook by Derek FisherMentioned in this episode:→ The Application Security Program Handbook by Derek Fisher→ ReversingLabs→ YouTube video→ Stephen E Ambrose→ Mark Frost→ Fortify (OpenText)→ ChatGPT→ Pixee→ LinkedInFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Matt Rose: Software Supply Chain Security Means Many Different Things to Different People03:53 Let me ask you this question. How good are you at04:45 That's true. That is so true. That's, that's a good way11:33 Yeah, 100%. And I like to think of weaknesses in the14:56 You're, you just made me think of something. About when you17:12 Yeah, it seems like, it seems like there's a perfect storm19:09 I want to double-click on something that you mentioned earlier. And22:10 I mean, I think that's more of a startup growth problem24:55 It the first, is it the first thing you would like28:15 Yeah, I've never actually seen anybody do it. I've heard DJ30:38 About, uh, AI34:39 Yeah, I'm not, I'm not ready to embrace auto-remediation at this37:32 Yeah. And we're starting to see a whole cottage industry of40:14 Absolutely. The second question is, what would it say if you41:54 Our 3rd question is, uh, what's your top book recommendation and

Episode metadata supplied by the publisher feed · Published Jun 11, 2024

Embed this episode

Matt Rose, an experienced technical AppSec testing leader discusses his career journey and significant contributions in AppSec. The conversation delves into the nuances of software supply chain security and exploring how different perceptions affect its understanding. Matt provides insights into the XZ compromise, critiques the buzzword 'shift left,' and discusses the role of digital twins and AI in enhancing the supply chain security. He emphasizes the need for a comprehensive approach beyon...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Matt Rose -- Software Supply Chain Security Means Many Different Things to Different People

0:00 46:14

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 46 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on June 11, 2024.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!