The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
James Berthoty -- Is DAST Dead? And the future of API security
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
James Berthoty, a cloud security engineer with a diverse IT background, discusses his journey into application and product security. James highlights his career trajectory from IT operations to cloud security, his experiences with security tools like Snyk and StackHawk, and the evolving landscape of Dynamic Application Security Testing (DAST) and API security. They delve into the practical challenges of CVEs, reachability analysis, and the complexities of patching in mid-sized companies. James shares his views on the often misunderstood role of WAF and the importance of fixing issues over merely identifying them. James Berthoty has been in technology for over 10 years in engineering and security roles.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
We provide application security training for not just your developers, but for all roles in your SDLC.
→ Learn more about Security Journey
Connect with James Berthoty:
→ AppSec Kool-Aid Statements I Disagree With
→ What is Art by Leo Tolstoy
Mentioned in this episode:
→ AppSec Kool-Aid Statements I Disagree With
→ What is Art by Leo Tolstoy
→ Snyk
→ StackHawk
→ AppSec Kool-Aid Statements I Disagree With
→ National Vulnerability Database (NVD)
→ eBPF
→ Kubernetes
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet James Berthoty: Is DAST Dead? And the future of API security
04:11 Mm-hmm. So when I think about your trajectory here, so you've
06:48 Let's start with this idea of DAST. And so anyone who's
10:02 So when you, when you're seeing these API scanners these days
13:07 You still using the term DAST or have you replaced it
14:49 What's your, what, what are your thoughts on this
16:42 Okay. That's helpful. What about reachability analysis
19:22 Patching really still that hard
22:43 The million dollar question then, is AI going to solve the
28:04 Yeah. I mean, fix it yourself and generate a PR, submit
32:22 I'm, I mean, let's, let's just talk about WAF and, and
36:12 Yeah, I think that's, uh, that's definitely true. Well, you got
38:01 Okay. Next. Like, celebration time. Yep. We passed. All right. So
41:29 Yeah. Yeah, definitely. So, all right, let's do a couple of
42:29 Question is, if you could have display a single message on
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
AI Security Table
Izar Tarandach, Matt Coles, and Chris Romeo