The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Jeff Williams -- The History of OWASP
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
OWASP became a reference point for software security, but it began with people sharing knowledge and trying to solve problems together. Jeff Williams joins Chris to trace that early history, from their consulting roots to the first Top 10, the Foundation, and the growth of community events. He explains the tradeoffs behind an awareness list, the importance of independence, and why recognition alone does not make software safer. Their conversation also examines open-source project visibility, participation, and the difficulty of turning useful work into something more developers can discover and adopt. Jeff’s firsthand account offers both a history lesson and a challenge to the community: simplify security, communicate the value of its tools, and keep expanding who can contribute.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Jeff Williams:
→ Jeff Williams on LinkedIn
→ Contrast Security
Mentioned in this episode:
→ OWASP Foundation
→ OWASP Top 10
→ OWASP WebGoat
→ OWASP DefectDojo
→ OWASP Dependency-Check
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 OWASP’s history with Jeff Williams
01:39 Shared roots in security consulting
07:47 The early days of OWASP
11:13 Creating the first OWASP Top 10
14:22 Evidence, judgment, and the Top 10
17:48 Independence and outside interests
18:12 The Top 10’s growing influence
20:27 Simplifying the work of fixing vulnerabilities
23:15 Forming the Foundation and early conferences
29:46 Helping people discover OWASP projects
30:33 DefectDojo and communicating project value
33:20 Dependency-Check and broader adoption
35:49 Improving OWASP through participation
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
AI Security Table
Izar Tarandach, Matt Coles, and Chris Romeo