Ray Espinoza -- The AppSec CISO, Vendor Relationships, and Mentoring episode artwork

EPISODE · Nov 15, 2023 · 50 MIN

Ray Espinoza -- The AppSec CISO, Vendor Relationships, and Mentoring

from The Application Security Podcast · host Chris Romeo

What does an application security leader need to know before stepping into the CISO role? Ray Espinoza joins Chris and Robert to share lessons from becoming a first-time CISO, aligning security work with business priorities, and building a culture where developers take pride in secure craftsmanship. Ray explains how he evaluates tools without confusing activity for impact, what good vendor relationships look like from the buyer’s side, and why empathy and credibility matter when security teams ask engineering teams to change. The conversation closes with practical advice on mentorship, leadership, and measuring whether an AppSec program is actually helping the business.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Ray Espinoza:→ Ray Espinoza on LinkedInMentioned in this episode:→ Extreme OwnershipFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Ray Espinoza and the AppSec CISO01:54 From eBay to security leadership04:59 Lessons from becoming a first-time CISO08:26 Learning from failure without repeating it11:29 How much security knowledge a CISO needs15:57 Leading security in a smaller company20:49 Aligning AppSec with business priorities26:45 Choosing tools and evaluating vendors30:44 Measuring security outcomes instead of activity38:54 Building productive vendor relationships42:13 Mentorship and growing security leaders47:34 The leadership lightning round

Episode metadata supplied by the publisher feed · Published Nov 15, 2023

Embed this episode

What does an application security leader need to know before stepping into the CISO role? Ray Espinoza joins Chris and Robert to share lessons from becoming a first-time CISO, aligning security work with business priorities, and building a culture where developers take pride in secure craftsmanship. Ray explains how he evaluates tools without confusing activity for impact, what good vendor relationships look like from the buyer’s side, and why empathy and credibility matter when security team...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Ray Espinoza -- The AppSec CISO, Vendor Relationships, and Mentoring

0:00 50:37

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 50 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on November 15, 2023.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!