Ronnie Flathers — Security programs big and small episode artwork

EPISODE · Sep 28, 2019 · 37 MIN

Ronnie Flathers — Security programs big and small

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Which parts of an AppSec program should change as a company grows, and which should stay the same? Ronnie Flathers joins Chris and Robert to compare security work in a fast-moving smaller company with the challenges of a large enterprise. He explains the advantages of a consistent technology stack and close developer relationships, then explores what breaks when one team can no longer know every application or manager. The discussion covers developing security champions, meeting teams where they work, and making incremental improvements instead of chasing an overnight transformation. Ronnie grounds the comparison in four principles: visibility and transparency, enabling rather than hindering, iterative progress, and management through metrics. The starting point is understanding what exists before deciding how to secure it.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Ronnie Flathers:→ LinkedIn→ Ronnie's blogMentioned in this episode:→ Darknet Diaries→ OWASP Juice Shop→ Agile ManifestoFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introduction01:59 Xbox hacking and Ronnie's security beginnings04:50 Consulting and early mentorship08:44 Security catching up with software delivery11:54 Growing security skills in developers13:11 Champions who want to participate16:52 Embedding security with engineering teams18:37 Advantages of a smaller company's technology stack22:52 Why large-company security cannot do everything24:25 Working with development processes25:47 First priorities in a smaller company29:04 Making progress with resistant teams30:55 Enterprise visibility and management through metrics33:24 Four foundations of an AppSec program

Episode metadata supplied by the publisher feed · Published Sep 28, 2019

Embed this episode

Which parts of an AppSec program should change as a company grows, and which should stay the same? Ronnie Flathers joins Chris and Robert to compare security work in a fast-moving smaller company with the challenges of a large enterprise. He explains the advantages of a consistent technology stack and close developer relationships, then explores what breaks when one team can no longer know every application or manager. The discussion covers developing security champions, meeting teams where t...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Ronnie Flathers — Security programs big and small

0:00 37:53

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 37 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on September 28, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!