Secure by Design: The Agentic AppSec Podcast

PODCAST · technology

Secure by Design: The Agentic AppSec Podcast

Secure by Design explores how AI-powered, agentic application security is transforming the way software gets built and protected. Each episode dives into real-world strategies for embedding security across the agentic development lifecycle, from code to cloud without slowing innovation. Hear from industry leaders, practitioners, and pioneers shaping the future of secure software in the age of AI.

  1. 2

    The Hidden Blind Spots of AI: A CTO's Perspective

    As AI accelerates software development, security can no longer operate as a gate at the end of the pipeline. In this episode of Secure by Design, Bill Weinberg sits down with Adi Kavaler to explore how AI is fundamentally changing engineering velocity and why security must evolve alongside it.The conversation dives into the real‑world impact of AI‑first development: faster time to market, cross‑functional feature teams, and the breakdown of long‑standing friction between builders, developers, and security. Rather than slowing innovation, embedded security and intelligent triage enable teams to ship faster and safer.This session also examines the limits of today’s AI tools: from missing context to production blind spots, and why human oversight, guardrails, and multi‑model validation remain essential. The result is a pragmatic look at how modern organizations can balance speed, quality, and trust while navigating AI‑generated code at scale.Key TakeawaysAI dramatically increases engineering velocity, but only when security is embedded from day oneFriction between development and security disappears when teams operate as a single feature unitAI‑assisted triage helps eliminate noise and prioritize the vulnerabilities that truly matterConsolidated, normalized data is essential for effective AI‑driven security decisionsAI‑generated code still requires human context, validation, and accountabilityUsing multiple AI models and guardrails improves confidence—but comes with cost tradeoffsAI excels at pre‑production security, while post‑production reasoning still needs careful oversight

  2. 1

    Shift Left, Stay Secure: AI's Impact on the Development Lifecycle

    How security and development teams are partnering to manage AI-generated code risk.As AI pushes development teams to ship faster and write more code, security can no longer live at the end of the pipeline. This session explores practical strategies for embedding security earlier and smarter into the modern development lifecycle. Key Takeaways:Shifting security left means catching vulnerabilities before code ever leaves the developer's machineAI-generated code still requires developer ownership, approving it means owning itContext and guardrails make AI tools more consistent and compliance friendlyAutomated pipeline scanning turns security from a bottleneck into a built in safeguardCISO and CTO alignment is critical to making secure development a shared company goalFeaturing Bill Weinberg (VP of Solution Engineering, Checkmarx), Victor Cortes (CISO, Trans Network), and David Dewaele(Director of Product, Checkmarx)  recorded live at RSA.

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

Secure by Design explores how AI-powered, agentic application security is transforming the way software gets built and protected. Each episode dives into real-world strategies for embedding security across the agentic development lifecycle, from code to cloud without slowing innovation. Hear from industry leaders, practitioners, and pioneers shaping the future of secure software in the age of AI.

HOSTED BY

Checkmarx

CATEGORIES

URL copied to clipboard!