
Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps
Om avsnittet
APIs power modern applications, yet many AppSec programs still cannot reliably inventory them, model their threats, or enforce authorization. Akansha Shukla draws on more than a decade in application security and DevSecOps to explain why API security remains immature and what practitioners can do about it. She and the hosts examine the OWASP API Security Top 10, broken object-level authorization, API-specific threat modeling, and the role of posture management. The conversation also asks why foundational controls such as input validation remain difficult despite strong framework support, and whether declarations that shift left is dead reflect reality or marketing. Akansha closes with practical guidance for building developer understanding, integrating security throughout delivery, and treating APIs as first-class elements of architecture rather than invisible plumbing.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
We provide diverse training content and easy-to-digest lessons to meet individual learner needs. Learners report improving their knowledge as much as 85% on AppSec topics.
→ Learn more about Security Journey
Connect with Akansha Shukla:
→ Akansha Shukla on LinkedIn
→ Women4Cyber Mentorship Programme
Mentioned in this episode:
→ OWASP API Security Top 10
→ Burp Suite Professional
→ Women4Cyber Mentorship Programme
→ OAuth 2.0
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Akansha Shukla
03:11 Moving from engineering into security
06:13 Why development knowledge matters
09:09 Using the OWASP API Security Top 10
11:55 Authorization and API guardrails
14:46 Threat modeling APIs
17:26 Why teams skip API threat models
18:49 Is the barrier knowledge or process?
21:15 The role of API security posture management
22:25 Why API inventory is still difficult
24:41 Framework support versus real adoption
27:43 Did security make the paved road too hard?
28:14 Why input validation remains unsolved
29:39 Is shift left dead?
33:04 Akansha's key takeaway
34:55 Closing thoughts
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.