Ofer Maor -- A Pen Testers Transition to #AppSec: #VoteForOfer episode artwork

EPISODE · Sep 4, 2018 · 26 MIN

Ofer Maor -- A Pen Testers Transition to #AppSec: #VoteForOfer

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Finding vulnerabilities is only part of improving software security; the harder work is changing how people build and operate applications. Ofer Maor shares his transition from penetration testing into application security and the lessons he learned through security startups. He and Chris discuss culture, genuine risk management, and the industry’s attraction to offensive work. They explore delivering findings inside developers’ tools, the limits of dumping issues into a backlog, and the roles of interactive testing and runtime protection. Ofer explains how compensating controls can buy time without replacing the need to fix code. The episode closes with his OWASP involvement and board candidacy at the time of recording, connecting technical progress with the community needed to support it.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Ofer Maor:→ Ofer Maor on LinkedInMentioned in this episode:→ OWASP Israel community→ OWASP Top 10Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 From penetration testing to AppSec with Ofer Maor01:08 Ofer’s security origin story03:04 Why secure development is hard03:46 Culture and risk management06:30 Balancing offensive and defensive work07:37 Persistent vulnerabilities and framework defenses11:52 Making security actionable for developers14:11 Delivering findings in the IDE14:36 Why thousands of backlog tickets do not help18:54 IAST, RASP, and the risk of overreliance21:44 Using runtime protection while fixing the code22:18 OWASP involvement and the historical board campaign23:19 OWASP Israel and growing new leaders

Episode metadata supplied by the publisher feed · Published Sep 4, 2018

Embed this episode

Finding vulnerabilities is only part of improving software security; the harder work is changing how people build and operate applications. Ofer Maor shares his transition from penetration testing into application security and the lessons he learned through security startups. He and Chris discuss culture, genuine risk management, and the industry’s attraction to offensive work. They explore delivering findings inside developers’ tools, the limits of dumping issues into a backlog, and the role...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Ofer Maor -- A Pen Testers Transition to #AppSec: #VoteForOfer

0:00 26:55

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 26 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on September 4, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!