Listen "Your First 90 Days in a New AppSec Role"
Episode Synopsis
📋 Show NotesSecrets of AppSec Champions: Laying the Foundation of Application SecurityIn the inaugural episode of the multi-part series 'Decoding Application Security,' host Chris Lindsey and guest Anthony Israel-Davis, Product Security Manager at Fortra, dive into the fundamentals of building a successful application security program for large teams. They discuss essential first steps when starting at a new company, the importance of understanding the company culture, and the critical role of security champions. The conversation covers various aspects of application security, including the implementation of SCA, SAST, and DAST tools, the nuances of API and container security, and the importance of building strong relationships with developers and QA teams. Ultimately, the episode emphasizes the incremental and strategic approach necessary for managing and mitigating risks effectively in a complex software development environment. ❇️ Key Topics with Timestamps00:00 Introduction to Software Building 00:59 Meet the Expert: Anthony Israel Davis 01:08 First Steps in a New Company 02:57 Understanding the Application Environment 04:54 Building a Solid Security Foundation 11:29 The Role of Static Analysis (SAST) 17:12 Empowering Teams with Security Mindset 22:07 Collaboration with QA for Security 24:47 Ensuring a Clean Build: Developer and QA Collaboration 26:17 Dynamic Scanning Explained 27:32 Regression Testing and DAST 28:05 Understanding DAST Results and Fuzzing 33:24 API Testing: A Critical Component 37:02 Containerization and Security 42:12 Building a Secure Development Process 46:39 Final Thoughts and Key Takeaways
More episodes of the podcast Secrets of AppSec Champions
Building Security Programs That Actually Scale – with Bonnie Viteri | Secrets of AppSec Champions 🎙️
31/07/2025
Risk Mitigation and Cybersecurity Strategy with Samuel Brown | Secrets of AppSec Champions Podcast🎙️
17/07/2025
From Developer to Cybersecurity Without Certs – Ed Urbasius' Story | Secrets of AppSec Champions 🎙️
03/07/2025
Supply Chain Security with Cassie Crossley
07/01/2025
Bounty Programs with Michael Vance
26/11/2024
Auditing Your Security Program
12/11/2024
Penetration Testing - Nathaniel Shere
29/10/2024
Working with your CISO - Yaron Levi
15/10/2024
ZARZA We are Zarza, the prestigious firm behind major projects in information technology.