The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Irfaan Santoe -- The Power of Strategy in AppSec
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Irfaan Santoe joins us for an in-depth discussion on the power of strategy in Application Security. We delve into measuring AppSec maturity, return on investment, and communicating technical needs to business leaders. Irfaan shares his unique journey from consulting to becoming an AppSec professional, and addresses the gaps between CISOs and AppSec knowledge. Irfaan shares valuable insights for scaling AppSec programs and aligning them with business objectives. Irfaan Santoe joins us to discuss the power of strategy in AppSec. We go deep on this one, on AppSec program maturity, how we can measure maturity, and even some tips for success. We talk about measuring return on investment and how to speak the language of the business as a technical person.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
We provide diverse training content and easy-to-digest lessons to meet individual learner needs.
→ Learn more about Security Journey
Connect with Irfaan Santoe:
→ OWASP SAMM
→ OWASP Security Champions Guide
Mentioned in this episode:
→ OWASP SAMM
→ OWASP Security Champions Guide
→ BSIMM
→ Jim Routh on Twitter
→ OWASP Netherlands Chapter
→ OWASP SAMM
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Irfaan Santoe: The Power of Strategy in AppSec
03:12 That's kind of the— it's almost the opposite of what a
06:35 A little bit about maturity. So, what is maturity within an
09:30 We think about measuring maturity then, so let me read back
12:20 Yeah. So, what is a part of that link then
17:16 Okay. So, we talked a little bit about, you know, how
20:59 I think there's a real disconnect between the business side and
27:03 Because that seems like, I mean, that's return on investment to
29:39 I've been waiting to ask this next question for a long
31:49 Yeah. And, if we use your car example and if I
33:51 Let's pull all this together. How do we scale an AppSec
38:12 All right. So, we have 3 questions that we usually ask
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo