Seeding AppSec

Bumps, Bruises, & Wins in Building AppSec from Scratch


Listen Later

Embark on an enthralling journey through the captivating world of secure software development with Seeding AppSec's inaugural episode!


Join seasoned security executive and CISO at The Aaron's Company, David Nolan, as he spills the beans on building robust software systems while host Simon Wenet and Arnica Nir Valtman, CEO at Arnica, engage in an enlightening dialogue exploring the evolving landscape of application security. The discussion uncovers the role of automation in managing risk, emphasizing the balance between human ingenuity and automated processes. David highlights two key components of a successful application security program – quick response for high-risk findings and ownership by development teams. He emphasizes the significance of relationships, trust, and adaptability in modern AppSec practices. Looking into the future, David envisions a developer-centric approach, AI integration, and supply chain protection as key trends in the next five years.


What we cover on the episode:

[00:00 - 15:24] Building an Effective AppSec Program

  • Building an effective AppSec program starts with understanding how development works and forming strong relationships with development teams.
  • Prioritize targeted security outcomes over tools and requirements to align with business goals.
  • Be intellectually curious and engage with business leaders, developers, and security champions to identify critical applications and business priorities.
  • [15:24 - 33:54] Driving Success in Application Security

    • Integrations and dependencies of critical apps are often overlooked, leading to potential business disruptions.
    • Successful AppSec programs focus on collaboration and partnership with development teams.
    • Automation is crucial for managing risk, but human creativity and ownership remain essential in application security.
    • [33:54 - 41:35] The Evolving Landscape of AppSec

      • The evolution of security tools, especially open-source ones, can significantly improve cybersecurity capabilities.
      • AppSec professionals should focus on becoming trusted risk advisors and communicating security in business terms.
      • Building a strong community of peers and mentors through conferences and networking is valuable for career growth and knowledge sharing in the security industry.

      • Connect with David!

        LinkedIn: David Nolan

        Check out The Aaron’s Company


        We hope you enjoyed this edition of Seeding AppSec! Check out the latest trends in application security discussed with our esteemed guests from around the globe. Don't miss any future episodes; subscribe to Seeding AppSec on Spotify, YouTube, or Apple Podcasts.

        This podcast is proudly brought to you by Arnica, a revolutionary application security solution reshaping how AppSec teams tackle risk identification and mitigation. Explore Arnica.io for detailed information about their cutting-edge security solution, featuring real-time pipelineless risk identification and git posture management. Protect your developers, code, and products without compromising development velocity.

        Stay connected and informed by following Arnica.io on LinkedIn and Twitter for the latest updates and insights on application security.

        Thank you for joining us on this enlightening journey into the world of Application Security! Remember to prioritize security and continue seeding AppSec in your organizations. Until next time, stay secure and keep innovating!


        Key Quotes

        "I encourage all of my teams [AppSec professionals] to get out there, go to... targeted conferences... where you'll meet your peers and develop those relationships. We're all fighting the same criminal, the same evil. And so, we should be able to work together.” – David Nolan

        "Don't just start with tools when beginning an AppSec program. Instead, focus on learning, understanding, and building relationships. Identify champions and let them pave the way for success as you grow the program.” – David Nolan

        ...more
        View all episodesView all episodes
        Download on the App Store

        Seeding AppSecBy Arnica IO