The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Tanya Janca -- Secure Guardrails
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Tanya Janka, also known as SheHacksPurple, discusses secure guardrails, the difference between guardrails and paved roads, and how to implement both in application security. Tanya is an award-winning public speaker and head of education at SEMGREP and the best-selling author of ‘Alice and Bob Learn Application Security’. Tanya shares her insights on creating secure software and teaching developers in this episode. Tanya Jenka, also known as She Hacks Purple, is the bestselling author of Alice and Bob Learn Application Security. She's also the head of education and community at Semgrep, sharing content and training around teaching everyone to create secure software. Tanya's been coding and working in IT for over 25 years.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
We help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC.
→ Learn more about Security Journey
Connect with Tanya Janca:
→ Tanya Janca on LinkedIn
→ Alice and Bob Learn Application Security
Mentioned in this episode:
→ Alice and Bob Learn Application Security
→ Semgrep
→ Tanya Janca – What Secure Coding Really Means
→ The Expanse Series
→ Alice and Bob Learn Application Security
→ Tanya Janca (SheHacksPurple)
→ Azure DevOps
→ Microsoft Security Response Center (MSRC)
→ Microsoft Defender for Cloud
→ Content-Security-Policy (MDN)
→ Scott Helme
→ Kim Wuyts
→ Executive Order 14028
→ OWASP SAMM
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Tanya Janca: Secure Guardrails
05:09 Oh, that's so cool. So what, what are you excited about
06:49 Oh, that's great. That's, yeah, it's a, that's a fun thing
10:05 I was like, no, no, I'm good. And it was like
12:05 So based on the example that you just shared there, Now
15:55 Would you like to use the wrapper library
17:36 Am I willing to break the build
19:41 Oh, actually, you know what
22:39 What's the role of making it easy with the paved road
24:58 Right
26:53 Makes sense. Makes sense. That's, that's, uh, it's helpful just to
30:18 I have to go rotate the secret, yada, yada, yada, right
32:58 Like, because getting into buildings when you should not is a
34:18 No, no, it's good. It's good. So I guess one more
37:48 Someone else told me she did that and it said, this
40:19 All right. One more guardrail topic. And this is one that
43:05 Right
46:24 It's time for her to come back again. She has been
47:38 No
50:13 We've all gotten those though for, for plenty of times in
53:34 Um, and so then we talked about it and I'm like
57:14 So I'm going to do the top programming frameworks as well
61:11 Oh, nice. Very cool. Very cool. So, just to kind of
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo