
David Kosorok — The Three Pillars of an AppSec Program: Prevent, Detect, and React
Om avsnittet
Where should a small application security team begin when it cannot do everything? David Kosorok joins Chris and Robert with a practical framework: prevent, detect, and react. Drawing on his background in software testing, he maps the pillars to requirements and design, coding and testing, and deployment and feedback. These are parallel areas to develop, not three stages to finish in order. David explains how relationships with security champions make prevention possible, how testing expertise strengthens detection, and why external findings can make risk tangible for developers. The conversation also explores bug bounties, feedback loops, and meaningful recognition. His emphasis is on building a supportive security culture through partnerships and small, useful controls rather than overwhelming teams with a complete program at once.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with David Kosorok:
→ LinkedIn
Mentioned in this episode:
→ OWASP Triangle
→ SSL Labs Server Test
→ Hacker101
→ HackerOne
→ Bugcrowd
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Introduction
02:33 From software testing to application security
03:56 What testers bring to security
07:07 Quality and security share a purpose
08:39 Prevent, detect, and react
09:56 Prevention through requirements and design
12:46 Partnerships and security champions
16:24 Detection during coding and testing
18:59 Working with quality engineers
20:36 Reacting to risk in deployed applications
23:49 Making external findings useful feedback
28:42 Recognition that encourages participation
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.