The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Kayra Otaner -- DevSecOps
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Kayra Otaner joins the podcast today to discuss DevSecOps and answer the question, is it dead? Kayra is the Director of DevSecOps at Roche and is highly involved in the DevSecOps community. Kayra states that DevSecOps in its traditional form is “dead” and that each organization should approach its needs based on their size. Otaner introduces the concept of "security as code" and "policy as code" as more effective approaches, where security functions are codified rather than relying on traditional documentation and checklists. Finally, they discuss the emergence of Application Security Posture Management (ASPM) tools as the "SIM for AppSec," suggesting these tools, especially when enhanced with AI, could help manage the overwhelming number of security alerts and issues that currently plague development teams.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
We provide diverse training content and easy-to-digest lessons to meet individual learner needs.
→ Learn more about Security Journey
Connect with Kayra Otaner:
→ Books by Yuval Noah Harari
→ Roche
Mentioned in this episode:
→ Books by Yuval Noah Harari
→ Roche
→ CISA Zero Trust Maturity Model
→ The Phoenix Project
→ OWASP DefectDojo
→ OWASP Dependency-Track
→ Phoenix Security
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Kayra Otaner: DevSecOps
01:47 I like to be controversial about our discipline. And there was
03:59 All right. Well, Kayra, I think we're going to dive right
09:28 Right
12:29 No, I agree with you there. I mean, there's definitely not
16:17 Can you gimme an example of a problem in which security
19:58 Makes sense. So what about zero trust
23:12 Yeah, so lightning round are 3 questions that we typically ask
25:34 Kero, what would be a key takeaway or a call to
27:09 Yeah. And Defect Dojo is a commercial entity now. So I
30:32 I'm going to disagree with you to some regard. I'm an
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo