The Application Security Podcast

Jahanzeb Farooq -- Launching and executing an AppSec program

• Chris Romeo and Robert Hurlbut • Season 11 • Episode 16

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 49:44

Jahanzeb Farooq discusses his journey in cybersecurity and the challenges of building AppSec programs from scratch. Jahanzeb shares his experience working in various industries, including Siemens, Novo Nordisk, and Danske Bank, highlighting the importance of understanding developer needs and implementing the right tools. The conversation covers the complexities of cybersecurity in the pharmaceutical and financial sectors, shedding light on regulatory requirements and the role of software in critical industries. Learn about prioritizing security education, threat modeling, and navigating digital transformation. Jan Zeb Farouk currently serves as the head of application security at Danske Bank, the largest bank in Denmark. Before this, he was with Novo Nordisk, where he played a key role in building their application security program from scratch and in securing their digital health solutions.

Today's episode is brought to you by Security Journey.

About Security Journey
Our education platform teaches valuable secure coding skills based on real-world vulnerabilities and threats, including OWASP Top 10.
→ Learn more about Security Journey

Connect with Jahanzeb Farooq:
→ The Power of Habit by Charles Duhigg
→ BSIMM

Mentioned in this episode:
→ The Power of Habit by Charles Duhigg
→ BSIMM
→ OWASP SAMM

Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook

Chapters:
00:00 Meet Jahanzeb Farooq: Launching and executing an AppSec program
01:57 You could have told me that you painted it. I would
07:12 From that perspective. So how do you get to AppSec then
09:08 AppSec
12:55 I have a question. I have a question about having never
15:57 There's no central, so like they don't share services or share
17:27 You're starting with these businesses that were non-IT. They made their
25:46 Do you, what are you, what's the equation you're using to
28:18 You mentioned maturity. Is that something that is based on, Are
29:20 A little question about some of the experiences that you've had
40:06 If I, if I kind of read that back to you
42:58 Yeah, I think a well-tuned SAST tool is a good assessment
45:29 Question 2, if you could display a single message on a
47:14 Yeah, I think really cool. We'll put a link to that

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

The Security Table Artwork

The Security Table

Izar Tarandach, Matt Coles, and Chris Romeo