Tanya Janca - Secure Vibe Coding episode artwork

EPISODE · Apr 30, 2026 · 47 MIN

Tanya Janca - Secure Vibe Coding

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

If AI writes all the code and the developer barely reads it, where does AppSec fit? Tanya Janca returns to define vibe coding and explain why models trained on insecure public code do not understand secure design by default. She and the hosts build a practical secure-vibe-coding framework: explicit requirements, human-led threat modeling, reusable security prompts, iterative review, SAST, and independent testing. Tanya shares hard-earned examples of Claude removing error handling, models confidently reviewing their own insecure output, and developers accepting enormous finding backlogs for code they did not enjoy writing. The discussion also examines whether security tooling will consolidate into AI platforms, how AppSec must be reimagined, and why continuous, embedded guidance matters more than occasional training. Tanya closes by introducing her DevSecStation podcast.Connect with Tanya Janca:→ Tanya Janca on LinkedIn→ SecureMyVibe→ DevSecStationMentioned in this episode:→ SecureMyVibe→ OWASP Top 10→ Burp Suite→ OWASP ZAP→ DevSecStation→ Tanya Janca (SheHacksPurple)→ ChatGPT→ Stack Overflow→ The Security Table podcastFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Tanya Janca returns02:10 What vibe coding actually means04:03 AI adoption and how developers prompt05:57 Treating AI like an intern07:28 Do AI systems need parental controls?09:34 Security prompts for everyday development11:47 Models, memory, and protecting sensitive data14:11 What happens when Claude goes away?16:02 The most dangerous vibe-coding misconception18:06 Threat modeling before AI writes the code22:48 Using AI throughout the development lifecycle25:32 A reusable secure-prompt framework29:09 Expose security assumptions and challenge flattery32:30 Reviewing an AI-generated codebase36:09 Will AI platforms absorb security tooling?37:39 Five million findings for code nobody wrote42:19 The remaining pieces of secure vibe coding43:52 Reimagining AppSec45:25 Continuous guidance beats occasional training46:05 Introducing DevSecStation47:12 Closing thoughts

Episode metadata supplied by the publisher feed · Published Apr 30, 2026

Embed this episode

If AI writes all the code and the developer barely reads it, where does AppSec fit? Tanya Janca returns to define vibe coding and explain why models trained on insecure public code do not understand secure design by default. She and the hosts build a practical secure-vibe-coding framework: explicit requirements, human-led threat modeling, reusable security prompts, iterative review, SAST, and independent testing. Tanya shares hard-earned examples of Claude removing error handling, models conf...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Tanya Janca - Secure Vibe Coding

0:00 47:57

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 47 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on April 30, 2026.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!