The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Devin Rudnicki -- Expanding AppSec
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Devon Rudnicki, the Chief Information Security Officer at Fitch Group, shares her journey of developing an application security program from scratch and advancing to the CISO role. She emphasizes the importance of collaboration, understanding the organization's business, and using metrics to drive positive change in the security program. Devin Rudnicki, the Chief Information Security Officer at Fitch Group, developed an application security program and advanced to the CISO role after years in security governance. She holds a BS in mathematics from DePaul University and multiple certifications, including CISSP, GSTRT, GSEC, and GCSA. Outside work, she enjoys group fitness, global travel, and mentoring in cybersecurity.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term measurable results.
→ Learn more about Security Journey
Connect with Devin Rudnicki:
→ Alice and Bob Learn Application Security
→ RSA Conference
Mentioned in this episode:
→ Alice and Bob Learn Application Security
→ RSA Conference
→ Black Hat
→ Walter Isaacson
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Devin Rudnicki: Expanding AppSec
03:05 Very cool. So the internship, security and governance, does that lead
05:03 Is that What's that approval look like as far as, is
07:28 What's the first thing that you focus on with this program
10:17 You're kind of, you're learning a little bit about the personalities
11:41 Yes, I think that's an important tactical thing that we can
14:54 Yeah. Okay. So when we, if we break the program, then
17:54 Okay. So, that's the vulnerability management side. How about developer education
20:23 In the past, I would say no to that question, and
21:18 That's, you know, you can minimize. But yeah, I mean, pen
24:49 Tracking the work. What metrics and KPIs did you use to
27:05 Yeah, and I had a similar situation in my previous time
30:03 Devin, we have 3 questions that we typically ask in the
32:59 The gene splicing therapy. We'll find it and put it in
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo