The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Derek Fisher -- Hiring in Cyber/AppSec
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Derek Fisher, an expert in hardware, software, and cybersecurity with over 25 years of experience is back on the podcast. Derek shares his advice on cybersecurity hiring, specifically in application security, and dives into the challenges of entry-level roles in the industry. We discuss the value of certifications, the necessity of lifelong learning, and the importance of networking. Listen along for good advice on getting noticed in cybersecurity, resume tips, and the evolving landscape of AppSec careers. Mentioned in this episode: The Application Security Handbook by Derek Fisher Derek Fisher brings over 25 years of hardware, software, and cybersecurity expertise across multiple industries, including healthcare and finance.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
We provide application security training for not just your developers, but for all roles in your SDLC.
→ Learn more about Security Journey
Connect with Derek Fisher:
→ The Application Security Handbook by Derek Fisher
→ Cyber for Builders by Ross Haleliuk
Mentioned in this episode:
→ The Application Security Handbook by Derek Fisher
→ Cyber for Builders by Ross Haleliuk
→ Effective Vulnerability Management by Chris Hughes
→ With the Old Breed by E.B. Sledge
→ Derek Fisher – The Application Security Handbook
→ WiCyS (Women in Cybersecurity)
→ CISSP
→ BSides
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Derek Fisher: Hiring in Cyber/AppSec
01:35 Yeah, we're joined by someone who's been on the podcast before
03:48 What's your favorite thing to grow
06:21 It's the, as you said, it's the therapeutic value of getting
11:05 Which to your point, mid to senior level people are 100%
13:15 With that in mind, I mean, how are people getting into
17:32 I mean, if anything, it's the patterns, kind of the try
20:03 Reminds me of something about Billy the Kid. Like, do you
21:58 You mentioned resume reviews. I'm always curious. I've never participated in
26:18 The last, you know, 5, 7 years, all the hiring I've
33:16 I would say, you know, that's one way to stand out
35:43 One of the we got to blame the hiring companies though
37:00 You can apply something, yourself to something. And so that, I
39:57 That, that I look back and say, I didn't necessarily use
47:59 By doing a pen testing class and doing a forensics class
52:17 All right. So yeah, 3 questions that we have. First of
55:34 Makes sense. So number 3, what's your Top book recommendation and
57:24 Yeah, he just wrote a new book on, yeah, it's the
58:49 Excellent. Derek, what about a key takeaway or a call to
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
AI Security Table
Izar Tarandach, Matt Coles, and Chris Romeo