Rephonic
Artwork for The Application Security Podcast

The Application Security Podcast

Chris Romeo and Robert Hurlbut
Application Security
Cybersecurity
Threat Modeling
OWASP
Artificial Intelligence
Vulnerability Management
Education
Devsecops
Secure Guardrails
Software Development
API Security
Penetration Testing
EU Cyber Resilience Act
Security Champions
Product Security
Devops
Startups
Gaming
Local Chapters
Funding Models

Chris Romeo and Robert Hurlbut dig into the tips, tricks, projects, and tactics that make various application security professionals successful. They cover all facets of application security, from threat modeling and OWASP to DevOps+security and security champions. They approach these stories in an educational light, explaining the details in a way those new to the discipline can understand. Chris... more

PublishesTwice monthlyEpisodes304Founded10 years ago
Number of ListenersCategories
Tech NewsTechnologyNews

Listen to this Podcast

Artwork for The Application Security Podcast

Latest Episodes

Send us Fan Mail

In this episode, we sit down with Isaac Evans, co-founder and CEO of Semgrep, to talk about how AI is reshaping application security faster than almost anyone expected. Isaac walks us through why CI is losing its place as the centra... more

Send us Fan Mail

In this episode, we sit down with Jose Carlos Chavez from Okta to break down the OWASP Top 10 for 2025 and what actually changed since 2021. We trace Jose's path from software engineering and observability into security, dig into wh... more

Send us Fan Mail

AI adoption is accelerating faster than most organizations know how to handle it, and the gap between curiosity and confident use is where things go wrong. Michael Burch, VP of AI Enablement and Acceleration, joins to break down wha... more

Send us Fan Mail

AI coding tools are accelerating development fast, but they’re also exposing the limits of traditional AppSec tooling. Josh Grossman, CTO of Bounce Security and longtime AppSec consultant, joins the podcast to break down AGHAST, his... more

Key Facts

Accepts Guests
Accepts Sponsors
Contact Information
Podcast Host
Number of Listeners
Find out how many people listen to this podcast per episode and each month.

Similar Podcasts

People also subscribe to these shows.

CyberWire Daily
CyberWire DailyN2K Networks
Risky Bulletin
Risky BulletinRisky Business Media
Smashing Security
Smashing SecurityGraham Cluley

Recent Guests

Michael Burch
VP of AI Enablement and Acceleration at Security Journey
Security Journey
Episode: Michael Burch - AI-Enabled Citizen Developers
Josh Grossman
CTO of Bounce Security
Bounce Security
Episode: Josh Grossman--AI & SAST: Is it a match?
Dwayne McDaniel
Principal developer advocate focused on secret security and non-human identity governance at GitGuardian
GitGuardian
Episode: Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets
Caroline Wong
Author and Chief Strategy Officer at Axari
Axari
Episode: Caroline Wong--The AI Cybersecurity Handbook
Brad Geesaman
Principal security engineer at Ghost
Ghost
Episode: Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows
Francesco Cipollone
Seasoned entrepreneur and CEO of Phoenix Security, a contextual-based vulnerability management platform
Phoenix Security
Episode: Francesco Cipollone - Agentic AI Manifesto
Akansha Shukla
An information security professional with over 10 years of experience in application security, DevSecOps, and API security.
Women4Cyber
Episode: Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps
Nariman Aga-Tagiyev
An application security expert with over two decades of software development experience
Episode: Getting Ready for the EU CRA
Marisa Fagan
Head of product at Katilyst, a security champions as a service startup
Katilyst
Episode: Marisa Fagan - Measuring Security Culture

Hosts

Chris Romeo
Host of The Application Security Podcast; CEO/General Partner with several security and venture-focused roles.
Robert Hurlbut
Co-host / Principal Threat Modeling Architect; focused on threat modeling and product security.

Reviews

4.9 out of 5 stars from 73 ratings
  • Empowering, insightful and actionable! 🔥

    Whether you’re well established as an AppSec innovator, or just getting started as a catalyst for change - this is a must-listen podcast for you! Chris and Robert do an incredible job leading conversations that cover a huge breadth of topics related to the ins and outs of staying on the cutting edge of data security and privacy - with leaders who’ve actually experienced success themselves. Highly recommend listening and subscribing!

    Apple Podcasts
    5
    JoshCrist
    United States5 years ago
  • Best AppSec Podcast

    Interesting subjects and interviews. These guys know their stuff. Aren’t afraid to admit when they don’t know a lot about a topic. Just like me we are all here to learn from experts in the field of AppSec. They ask the most interesting and relevant questions of their guests.

    Keep up the great work!!

    Apple Podcasts
    5
    mjdecap
    United States7 years ago
  • awesome and very informative!

    Proud to give you a 5-star review! Well worth it!

    Apple Podcasts
    5
    holysheetman
    United States8 years ago
  • For developers and testers

    Best podcast for web application developers and testers. Vulnerabilities and controls in the same place.

    Apple Podcasts
    5
    Eepica
    United Kingdom9 years ago

Listeners Say

Key themes from listener reviews, highlighting what works and what could be improved about the show.

Audience appreciates honest discussions and clarity on complex security topics.
Listeners praise practical, actionable insights and thoughtful guest selections.
Fans value deep dives into AppSec topics with leaders who have real-world success stories.

Chart Rankings

How this podcast ranks in the Apple Podcasts, Spotify and YouTube charts.

Apple Podcasts
#178
South Africa/Technology
Apple Podcasts
#235
Finland/Technology

Talking Points

Recent interactions between the hosts and their guests.

Michael Burch - AI-Enabled Citizen Developers
Q: What should organizations do next for citizen developers?
Start with a defined reason and plan, ensure readiness before granting access, create a safe environment with dedicated tooling and an overseer, and build a supportive community. Emphasize enabling the right people, not just issuing licenses, and establish guardrails and processes that scale with the organization's needs.
Michael Burch - AI-Enabled Citizen Developers
Q: What is a citizen developer?
A citizen developer is someone who wants to build applications using AI-enabled tools with much broader access than traditional developers, but without the same coding background. The conversation emphasizes that the role is evolving beyond low-code/no-code to include AI-assisted creation, which requires new guardrails and enablement approaches rather than forcing everyone into a coder path.
Josh Grossman--AI & SAST: Is it a match?
Q: What are the future directions for Aghast in terms of integration and languages supported?
Plans include a diff-aware mode to focus on changed code, exploring additional discovery methods beyond SemGrep, and potentially broader language support while maintaining strong static-discovery foundations. The project aims to fit into OWASP ecosystems and community-driven development.
Josh Grossman--AI & SAST: Is it a match?
Q: How does Aghast handle false positives and token costs in practice?
By focusing AI analysis on specific problem areas flagged by static rules and offering a SARIF-based second pass, Aghast narrows the AI workload, improving precision. Token costs are managed by shaping workflows for CI, allowing static rules to run by default and AI-enabled checks only on targeted scenarios or diffs.
Josh Grossman--AI & SAST: Is it a match?
Q: What does Aghast do that traditional tools can't, and how does the hybrid mode work?
Aghast preserves the usefulness of static rules while layering AI analysis on targeted code regions to confirm or deny issues, delivering deterministic, actionable results without the AI wandering aimlessly through large codebases. This hybrid approach balances precision with the flexibility of AI, reducing false positives and enabling actionable SARIF outputs.

Audience Metrics

Listeners, social reach, demographics and more for this podcast.

Listeners per Episode
Gender Skew
Location
Interests
Professions
Age Range
Household Income
Social Media Reach

Frequently Asked Questions About The Application Security Podcast

What is The Application Security Podcast about and what kind of topics does it cover?

The show consistently packs practical, strategy-forward conversations around application security, DevSecOps, threat modeling, and AI's impact on secure software development. Episodes frequently spotlight real-world adoption, governance, and tooling choices—from AI-assisted security and secure coding to security culture and developer enablement—with guests who blend hands-on engineering experience with leadership in security strategy. Its strengths lie in actionable takeaways, thoughtful questions, and guests who bridge technical depth with business outcomes, making it useful for listeners aiming to modernize AppSec programs, build security-conscious teams, or sponsor thoughtful security conversations.

Noteworthy is the recurring emphasis ... more

Where can I find podcast stats for The Application Security Podcast?

Rephonic provides a wide range of podcast stats for The Application Security Podcast. We scanned the web and collated all of the information that we could find in our comprehensive podcast database. See how many people listen to The Application Security Podcast and access YouTube viewership numbers, download stats, audience demographics, chart rankings, ratings, reviews and more.

How many listeners does The Application Security Podcast get?

Rephonic provides a full set of podcast information for three million podcasts, including the number of listeners. View further listenership figures for The Application Security Podcast, including podcast download numbers and subscriber numbers, so you can make better decisions about which podcasts to sponsor or be a guest on. You will need to upgrade your account to access this premium data.

What are the audience demographics for The Application Security Podcast?

Rephonic provides comprehensive predictive audience data for The Application Security Podcast, including gender skew, age, country, political leaning, income, professions, education level, and interests. You can access these listener demographics by upgrading your account.

How many subscribers and views does The Application Security Podcast have?

To see how many followers or subscribers The Application Security Podcast has on Spotify and other platforms such as Castbox and Podcast Addict, simply upgrade your account. You'll also find viewership figures for their YouTube channel if they have one.

Which podcasts are similar to The Application Security Podcast?

These podcasts share a similar audience with The Application Security Podcast:

1. CyberWire Daily
2. Cybersecurity Headlines
3. Risky Bulletin
4. Cybersecurity Today
5. Smashing Security

How many episodes of The Application Security Podcast are there?

The Application Security Podcast launched 10 years ago and published 304 episodes to date. You can find more information about this podcast including rankings, audience demographics and engagement in our podcast database.

How do I contact The Application Security Podcast?

Our systems regularly scour the web to find email addresses and social media links for this podcast. We scanned the web and collated all of the contact information that we could find in our podcast database. But in the unlikely event that you can't find what you're looking for, our concierge service lets you request our research team to source better contacts for you.

Where can I see ratings and reviews for The Application Security Podcast?

Rephonic pulls ratings and reviews for The Application Security Podcast from multiple sources, including Spotify, Apple Podcasts, Castbox, and Podcast Addict.

View all the reviews in one place instead of visiting each platform individually and use this information to decide if a show is worth pitching or not.

How do I access podcast episode transcripts for The Application Security Podcast?

Rephonic provides full transcripts for episodes of The Application Security Podcast. Search within each transcript for your keywords, whether they be topics, brands or people, and figure out if it's worth pitching as a guest or sponsor. You can even set-up alerts to get notified when your keywords are mentioned.

What guests have appeared on The Application Security Podcast?

Recent guests on The Application Security Podcast include:

1. Michael Burch
2. Josh Grossman
3. Dwayne McDaniel
4. Caroline Wong
5. Brad Geesaman
6. Francesco Cipollone
7. Akansha Shukla
8. Nariman Aga-Tagiyev

To view more recent guests and their details, simply upgrade your Rephonic account. You'll also get access to a typical guest profile to help you decide if the show is worth pitching.

Find and pitch the right podcasts

We help savvy brands, marketers and PR professionals to find the right podcasts for any topic or niche. Get the data and contacts you need to pitch podcasts at scale and turn listeners into customers.
Try it free for 7 days