The Application Security Podcast

Devin Rudnicki -- Expanding AppSec

Chris Romeo and Robert Hurlbut Season 11 Episode 11

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 35:57

Devon Rudnicki, the Chief Information Security Officer at Fitch Group, shares her journey of developing an application security program from scratch and advancing to the CISO role. She emphasizes the importance of collaboration, understanding the organization's business, and using metrics to drive positive change in the security program. Devin Rudnicki, the Chief Information Security Officer at Fitch Group, developed an application security program and advanced to the CISO role after years in security governance. She holds a BS in mathematics from DePaul University and multiple certifications, including CISSP, GSTRT, GSEC, and GCSA. Outside work, she enjoys group fitness, global travel, and mentoring in cybersecurity.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term measurable results.
Learn more about Security Journey

Connect with Devin Rudnicki:
Alice and Bob Learn Application Security
RSA Conference

Mentioned in this episode:
Alice and Bob Learn Application Security
RSA Conference
Black Hat
Walter Isaacson

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Devin Rudnicki: Expanding AppSec
03:05 Very cool. So the internship, security and governance, does that lead
05:03 Is that What's that approval look like as far as, is
07:28 What's the first thing that you focus on with this program
10:17 You're kind of, you're learning a little bit about the personalities
11:41 Yes, I think that's an important tactical thing that we can
14:54 Yeah. Okay. So when we, if we break the program, then
17:54 Okay. So, that's the vulnerability management side. How about developer education
20:23 In the past, I would say no to that question, and
21:18 That's, you know, you can minimize. But yeah, I mean, pen
24:49 Tracking the work. What metrics and KPIs did you use to
27:05 Yeah, and I had a similar situation in my previous time
30:03 Devin, we have 3 questions that we typically ask in the
32:59 The gene splicing therapy. We'll find it and put it in

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

The Security Table Artwork

The Security Table

Izar Tarandach, Matt Coles, and Chris Romeo