EPISODE · Sep 4, 2018 · 26 MIN
Ofer Maor -- A Pen Testers Transition to #AppSec: #VoteForOfer
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Finding vulnerabilities is only part of improving software security; the harder work is changing how people build and operate applications. Ofer Maor shares his transition from penetration testing into application security and the lessons he learned through security startups. He and Chris discuss culture, genuine risk management, and the industry’s attraction to offensive work. They explore delivering findings inside developers’ tools, the limits of dumping issues into a backlog, and the roles of interactive testing and runtime protection. Ofer explains how compensating controls can buy time without replacing the need to fix code. The episode closes with his OWASP involvement and board candidacy at the time of recording, connecting technical progress with the community needed to support it.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Ofer Maor:→ Ofer Maor on LinkedInMentioned in this episode:→ OWASP Israel community→ OWASP Top 10Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 From penetration testing to AppSec with Ofer Maor01:08 Ofer’s security origin story03:04 Why secure development is hard03:46 Culture and risk management06:30 Balancing offensive and defensive work07:37 Persistent vulnerabilities and framework defenses11:52 Making security actionable for developers14:11 Delivering findings in the IDE14:36 Why thousands of backlog tickets do not help18:54 IAST, RASP, and the risk of overreliance21:44 Using runtime protection while fixing the code22:18 OWASP involvement and the historical board campaign23:19 OWASP Israel and growing new leaders
Embed this episode
What this episode covers
Finding vulnerabilities is only part of improving software security; the harder work is changing how people build and operate applications. Ofer Maor shares his transition from penetration testing into application security and the lessons he learned through security startups. He and Chris discuss culture, genuine risk management, and the industry’s attraction to offensive work. They explore delivering findings inside developers’ tools, the limits of dumping issues into a backlog, and the role...
Ready to play
Ofer Maor -- A Pen Testers Transition to #AppSec: #VoteForOfer
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.