The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Matt Rose -- Software Supply Chain Security Means Many Different Things to Different People
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Matt Rose, an experienced technical AppSec testing leader discusses his career journey and significant contributions in AppSec. The conversation delves into the nuances of software supply chain security and exploring how different perceptions affect its understanding. Matt provides insights into the XZ compromise, critiques the buzzword 'shift left,' and discusses the role of digital twins and AI in enhancing the supply chain security. He emphasizes the need for a comprehensive approach beyond SCA, the relevance of threat modeling, and the potential risks and benefits of AI in security. Matt Rose is a technical AppSec testing leader with consistent accomplishments in sales and sales engineering management roles with more than 20 years of experience.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Our training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization.
→ Learn more about Security Journey
Connect with Matt Rose:
→ LinkedIn
→ The Application Security Program Handbook by Derek Fisher
Mentioned in this episode:
→ The Application Security Program Handbook by Derek Fisher
→ ReversingLabs
→ YouTube video
→ Stephen E Ambrose
→ Mark Frost
→ Fortify (OpenText)
→ ChatGPT
→ Pixee
→ LinkedIn
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Matt Rose: Software Supply Chain Security Means Many Different Things to Different People
03:53 Let me ask you this question. How good are you at
04:45 That's true. That is so true. That's, that's a good way
11:33 Yeah, 100%. And I like to think of weaknesses in the
14:56 You're, you just made me think of something. About when you
17:12 Yeah, it seems like, it seems like there's a perfect storm
19:09 I want to double-click on something that you mentioned earlier. And
22:10 I mean, I think that's more of a startup growth problem
24:55 It the first, is it the first thing you would like
28:15 Yeah, I've never actually seen anybody do it. I've heard DJ
30:38 About, uh, AI
34:39 Yeah, I'm not, I'm not ready to embrace auto-remediation at this
37:32 Yeah. And we're starting to see a whole cottage industry of
40:14 Absolutely. The second question is, what would it say if you
41:54 Our 3rd question is, uh, what's your top book recommendation and
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo