EPISODE · Sep 7, 2026 · 48 MIN
Your AppSec Bottleneck Is a People Problem
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Most security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product security, which means she has argued both sides of this from inside the trenches. Drawing on the talk she and Mireia Cano gave at OWASP Global AppSec EU 2026, Lisi walks us through the four things that actually make these programs work: psychological safety first, then cognitive load, then influence when you hold no formal authority, then a champions community so the whole thing doesn't stall the week security goes on vacation. We also get into cutting security wait times, winning organizational support, what AI does and doesn't change here, and why she will tell you never to record the champions meeting.This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.About CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.→ Learn more about CorgeaConnect with Lisi Hocke:→ Lisi Hocke on LinkedIn→ A Tester's Journey — Lisi's blogMentioned in this episode:→ Slides: Security Champions — Lessons from Opposite Trenches (with Mireia Cano)→ OWASP Juice ShopFollow the Application Security Podcast:➜ Home: appsecpodcast.com➜ X: @AppSecPodcast➜ LinkedIn: The Application Security Podcast➜ YouTube: @ApplicationSecurityPodcast➜ Instagram: @appsecpodcast➜ Facebook: Application Security PodcastChapters:00:00 Cold open — what psychological safety actually means00:56 Meet Lisi Hocke02:25 Lisi's security origin story05:42 "That place was taken" — becoming a champion anyway07:39 Moving into a full-time product security role08:39 Meeting Björn Kimminich, the Juice Shop project lead09:23 Why role play instead of a normal conference talk12:27 Security and development, disconnected14:19 The first full-time security role15:14 Making people wait is the real damage17:10 Cutting the backlog and the turnaround time19:31 What Lisi got dead wrong20:08 What testing and quality work taught her21:31 The four things that make champions programs work22:07 One: fostering psychological safety24:50 Champions without their manager's blessing28:45 Two: managing cognitive load29:46 Three kinds of load, and which one to cut31:21 Three: power sources when you have no formal authority33:03 Four: build a champions community34:38 Keeping security people from burning out36:37 How AI changes who you recruit and what you need39:32 Should AI change champions programs at all?40:33 Psychological safety when a bot joins the meeting42:25 Don't record the champions meetings43:26 Programs that outlive the person who started them45:59 Key takeaway and homework47:21 Closing thoughts
Embed this episode
What this episode covers
Most security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product security, which means she has argued both sides of this from inside the trenches. Drawing on the talk she and Mireia Cano gave at OWASP Global AppSec EU 2026, Lisi walks us through the four things that actually make these programs work: psychological safety first, then cognitive load, then influence when you hold no formal authority, then a ...
Ready to play
Your AppSec Bottleneck Is a People Problem
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.