Your AppSec Bottleneck Is a People Problem episode artwork

EPISODE · Sep 7, 2026 · 48 MIN

Your AppSec Bottleneck Is a People Problem

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Most security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product security, which means she has argued both sides of this from inside the trenches. Drawing on the talk she and Mireia Cano gave at OWASP Global AppSec EU 2026, Lisi walks us through the four things that actually make these programs work: psychological safety first, then cognitive load, then influence when you hold no formal authority, then a champions community so the whole thing doesn't stall the week security goes on vacation. We also get into cutting security wait times, winning organizational support, what AI does and doesn't change here, and why she will tell you never to record the champions meeting.This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.About CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.→ Learn more about CorgeaConnect with Lisi Hocke:→ Lisi Hocke on LinkedIn→ A Tester's Journey — Lisi's blogMentioned in this episode:→ Slides: Security Champions — Lessons from Opposite Trenches (with Mireia Cano)→ OWASP Juice ShopFollow the Application Security Podcast:➜ Home: appsecpodcast.com➜ X: @AppSecPodcast➜ LinkedIn: The Application Security Podcast➜ YouTube: @ApplicationSecurityPodcast➜ Instagram: @appsecpodcast➜ Facebook: Application Security PodcastChapters:00:00 Cold open — what psychological safety actually means00:56 Meet Lisi Hocke02:25 Lisi's security origin story05:42 "That place was taken" — becoming a champion anyway07:39 Moving into a full-time product security role08:39 Meeting Björn Kimminich, the Juice Shop project lead09:23 Why role play instead of a normal conference talk12:27 Security and development, disconnected14:19 The first full-time security role15:14 Making people wait is the real damage17:10 Cutting the backlog and the turnaround time19:31 What Lisi got dead wrong20:08 What testing and quality work taught her21:31 The four things that make champions programs work22:07 One: fostering psychological safety24:50 Champions without their manager's blessing28:45 Two: managing cognitive load29:46 Three kinds of load, and which one to cut31:21 Three: power sources when you have no formal authority33:03 Four: build a champions community34:38 Keeping security people from burning out36:37 How AI changes who you recruit and what you need39:32 Should AI change champions programs at all?40:33 Psychological safety when a bot joins the meeting42:25 Don't record the champions meetings43:26 Programs that outlive the person who started them45:59 Key takeaway and homework47:21 Closing thoughts

Episode metadata supplied by the publisher feed · Published Sep 7, 2026

Embed this episode

Most security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product security, which means she has argued both sides of this from inside the trenches. Drawing on the talk she and Mireia Cano gave at OWASP Global AppSec EU 2026, Lisi walks us through the four things that actually make these programs work: psychological safety first, then cognitive load, then influence when you hold no formal authority, then a ...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Your AppSec Bottleneck Is a People Problem

0:00 48:03

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 48 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on September 7, 2026.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!