EPISODE · Nov 15, 2023 · 50 MIN
Ray Espinoza -- The AppSec CISO, Vendor Relationships, and Mentoring
from The Application Security Podcast · host Chris Romeo
What does an application security leader need to know before stepping into the CISO role? Ray Espinoza joins Chris and Robert to share lessons from becoming a first-time CISO, aligning security work with business priorities, and building a culture where developers take pride in secure craftsmanship. Ray explains how he evaluates tools without confusing activity for impact, what good vendor relationships look like from the buyer’s side, and why empathy and credibility matter when security teams ask engineering teams to change. The conversation closes with practical advice on mentorship, leadership, and measuring whether an AppSec program is actually helping the business.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Ray Espinoza:→ Ray Espinoza on LinkedInMentioned in this episode:→ Extreme OwnershipFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Ray Espinoza and the AppSec CISO01:54 From eBay to security leadership04:59 Lessons from becoming a first-time CISO08:26 Learning from failure without repeating it11:29 How much security knowledge a CISO needs15:57 Leading security in a smaller company20:49 Aligning AppSec with business priorities26:45 Choosing tools and evaluating vendors30:44 Measuring security outcomes instead of activity38:54 Building productive vendor relationships42:13 Mentorship and growing security leaders47:34 The leadership lightning round
Embed this episode
What this episode covers
What does an application security leader need to know before stepping into the CISO role? Ray Espinoza joins Chris and Robert to share lessons from becoming a first-time CISO, aligning security work with business priorities, and building a culture where developers take pride in secure craftsmanship. Ray explains how he evaluates tools without confusing activity for impact, what good vendor relationships look like from the buyer’s side, and why empathy and credibility matter when security team...
Ready to play
Ray Espinoza -- The AppSec CISO, Vendor Relationships, and Mentoring
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.