The Elephant in AppSec

The Elephant in AppSec
Podcast Description
Time to discuss AppSec issues no one talks about.
Podcast Insights
Content Themes
The podcast covers a wide range of application security topics, including measuring AppSec ROI, API security, threat modeling, and the integration of security with product management. For example, episodes like 'Can You Really Quantify AppSec ROI?' challenge listeners to think critically about how security initiatives are evaluated, while 'How to Fix API Security Before It's Too Late' dives deep into proactive measures for securing APIs.

Time to discuss AppSec issues no one talks about.
Today, I'm joined by Jamie Scott, a recovering cybersecurity practitioner turned founding product manager at Endor Labs. Previously, Jamie served as Product Manager of Security at Redis, where he was an active open-source contributor, and as DevSecOps Manager at Cygna Healthcare.
Jamie is also a Certified Information Systems & Cloud Security Professional and continues to contribute to the cybersecurity community. He co-authored several benchmarks and volunteers as a consultant for the Center for Internet Security.
In this episode, we dive into the topic of IDE plugins: Do they help you boost your coding security or just hopeful? Jamie has firsthand experience trying to roll out an IDE security program in his career and shares his perspective, leaning more towards the “hopium” side of things. He’s observed that developers often don't proactively use them, which raises the question—are these tools really effective?
Dive right in!
Connect with Jamie: https://www.linkedin.com/in/james-m-scott-iii/
Connect with Alexandra: https://www.linkedin.com/in/alexandra-charikova/
This podcast is brought to you by Escape: https://escape.tech — Modern DAST built to test for business logic instead of missing headers
Mentioned
CIS Benchmark for NGINX: https://www.cisecurity.org/benchmark/nginx
The Challenger Sale: Taking Control of the Customer Conversation: https://www.amazon.com/Challenger-Sale-Control-Customer-Conversation/dp/1591844355
Shannon Lietz (DevSecOps Lead at Intuit) Keynote in 2016 https://www.youtube.com/watch?v=ru11MSYPBBQ

Disclaimer
This podcast’s information is provided for general reference and was obtained from publicly accessible sources. The Podcast Collaborative neither produces nor verifies the content, accuracy, or suitability of this podcast. Views and opinions belong solely to the podcast creators and guests.
For a complete disclaimer, please see our Full Disclaimer on the archive page. The Podcast Collaborative bears no responsibility for the podcast’s themes, language, or overall content. Listener discretion is advised. Read our Terms of Use and Privacy Policy for more details.