The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
David Quisenberry -- Building Security, People, and Programs
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
David Quisenberry shares about his journey into the security world, insights on building AppSec programs in small to mid-sized companies, and the importance of data-driven decision-making. The conversation delves into the value of mentoring and why it's important to build real relationships with the people you work with, the vital role of trust with engineering teams, and the significance of mental health and community in the industry. David Quisenberry leads security teams at Capri Health, where he's the senior manager of information security. He's a lifetime OWASP member, former chapter president of the Portland, Oregon OWASP chapter, and co-founder of the OWASP AppSec Days PNW.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
We provide diverse training content and easy-to-digest lessons to meet individual learner needs.
→ Learn more about Security Journey
Connect with David Quisenberry:
→ SRE Engineering
→ The Phoenix Project
Mentioned in this episode:
→ SRE Engineering
→ The Phoenix Project
→ Security Chaos Engineering
→ Wiring the Winning Organization
→ The Body Keeps the Score
→ Never Eat Alone
→ How Leaders Create and Use Networks
→ CISO Desk Reference Guide
→ Intelligence Driven Incident Response
→ Thinking Fast and Slow
→ Do Hard Things
→ BSIMM
→ OWASP Application Security Verification Standard (ASVS)
→ BSides
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet David Quisenberry: Building Security, People, and Programs
01:44 That's, uh, that's a t-shirt, t-shirt idea. I wish I had
04:45 Yeah. It's, it's one of those things where we're never going
06:56 Um, and I love that illustration you just made about comparing
12:43 In your experience then doing this a couple of times, do
17:28 I want to, I want to just acknowledge, I want to
19:42 That's just me. I, I, uh, yeah, I had, I had
22:52 Yeah. And I want to go there next. Um, I guess
24:08 This idea of trust with the engineering teams, because it seems
35:21 Let me, uh, let me, let me just summarize a couple
38:17 I never hear from him again. He's like, this was kind
40:54 About, let's just touch on this mental health point and just
44:29 I was just going to bring that up because it's something
47:30 We got to deal with this last one. Um, cause this
48:53 So I just kind of, the sociologist in me, this happens
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo