The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Jeff Williams -- Application Detection & Response (ADR)
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Jeff Williams, a renowned pioneer in the field of application security is with us to discuss Application Detection and Response (ADR), detailing its potential to revolutionize security in production environments. Jeff shares stories from his career, including the founding of OWASP, and his take on security assurance. We cover many topics including; security assurance, life, basketball and plenty of AppSec as well. Jeff Williams is a veteran application security expert who founded and led OWASP, Aspect Security, and Contrast Security. Jeff also created several highly successful open source projects, including JBomb, JOT, OWASP Top 10, WebGoat, ESAPI, ASVS, and more. Jeff serves as an advisor to NIST, CISA, PCI Council, Oasis Seraph, OWASP CycloneDX, OWASP Foundation, Eclipse Foundation, and advises many companies and agencies on AppSec.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
We help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC.
→ Learn more about Security Journey
Connect with Jeff Williams:
→ Jeff Williams on LinkedIn
→ The Tech of Runtime Security
Mentioned in this episode:
→ Jeff Williams on LinkedIn
→ The Tech of Runtime Security
→ Contrast Security
→ Log4j
→ OWASP ESAPI
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Jeff Williams: Application Detection & Response (ADR)
01:45 I mean, what's to talk about
05:18 Does the competitive firework when you're in a, like in a
13:12 You, has your thinking or your approach changed over the decades
16:05 I'm curious now, the comment you made about vulnerability scans and
17:39 Now to, to completely overturn the apple cart here, does AI
20:45 Yeah. I've had the same, I've drawn the same conclusion as
29:30 You're describing a world where the, the, what I would think
31:33 We think about the now classic technologies in a company's AppSec
34:59 There any, um, in terms of, you know, business problems, uh
38:56 Jeff, where do you see ADR going into the future
42:13 All right. Yeah. So, uh, first question is, um, shift left
46:23 Okay. Second question is a conference talk, or is there a
49:44 Very cool. Thanks for sharing that pointer. Definitely look Naomi up
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo