Welcome to the Elephant in AppSec, the podcast to explore, challenge, and boldly face the AppSec Elephants in the room.
Today, we have an amazing guest, Chris Romeo, joining us.
Chris has 26 years of experience in cybersecurity, having worked for 11 years at CISCO, founded his own security education company, Security Journey, and now Devici, an AI-infused collaborative threat modeling tool.
Chris is a sought-after speaker at numerous global application security conferences.
He is also the author of a weekly newsletter, The Reasonable AppSec, where he shares the top 5 security articles worth your time.
Chris hosts not one but three security podcasts: the Threat Modeling Podcast, @SecTablePodcast and my personal favorite, @ApplicationSecurityPodcast I appreciate how he freely expresses his opinions, sometimes quite strong ones, like "DAST is dead". I was very eager to discuss his opinions with him!
We also talked about whether "shift left" is just a marketing term, how AppSec professionals should first educate themselves to understand all the tools and messaging thrown at them, and shared some Threat Modeling stories.