Training Security Champions With Brendan Dibbell
In episode 79 of The Secure Developer, Guy Podjarny is joined by Brendan Dibbell, Application Security Engineer Team Lead at Toast, a restaurant technology company based in Boston, Massachusetts. Brendan shares how they manage cloud security at Toast and what the interaction between the AppSec and the engineering team looks like, and discusses their security champion program, how it differs from the security training for regular developers, and the benefits of having created their own curriculum. Hear how Brendan and his team measure the success of their programs, focusing on the progress rather than on a set of objectives, and talks about what metrics have and have not worked along the way.
Episode 79 of the The Secure Developer podcast, hosted by Brendan Dibbell, Guy Podjarny, titled "Training Security Champions With Brendan Dibbell" was published on October 15, 2020 and runs 36 minutes.
October 15, 2020 ·36m · The Secure Developer
Summary
In episode 79 of The Secure Developer, Guy Podjarny is joined by Brendan Dibbell, Application Security Engineer Team Lead at Toast, a restaurant technology company based in Boston, Massachusetts. Brendan shares how they manage cloud security at Toast and what the interaction between the AppSec and the engineering team looks like, and discusses their security champion program, how it differs from the security training for regular developers, and the benefits of having created their own curriculum. Hear how Brendan and his team measure the success of their programs, focusing on the progress rather than on a set of objectives, and talks about what metrics have and have not worked along the way.
Episode Description
In today’s episode, Guy Podjarny talks to Brendan Dibbell, the application security engineer team lead at Toast, a restaurant technology company based in Boston, Massachusetts. Before moving into security, he spent years as a software developer, building mission-critical systems such as identity management, payment processing, and healthcare platforms, but has always been a vocal advocate for security. Brendan shares how they manage cloud security at Toast and what the interaction between the AppSec and the engineering team looks like, and discusses their security champion program, how it differs from the security training for regular developers, and the benefits of having created their own curriculum. Tuning in, listeners will hear how Brendan and his team measure the success of their programs, focusing on the progress rather than on a set of objectives, and talks about what metrics have and have not worked along the way. Later on, our guest explains why interrupting your workflow to solve every little risk that pops up is problematic and why it is far more important to stay focused on the bigger picture while not neglecting to address the smaller issues as you go.
Follow Us
Similar Episodes
Apr 9, 2026 ·17m
Apr 6, 2026 ·51m
Mar 26, 2026 ·25m
Mar 25, 2026 ·62m
Mar 22, 2026 ·32m
Mar 17, 2026 ·30m