
Hillel Solow -- How to do AppSec without a security team
Om avsnittet
How can a startup build meaningful AppSec when it cannot hire a dedicated security specialist? Hillel Solow, a longtime security product builder and former ProtectOnce chairman, joins Chris and Robert to frame an application security program around what matters most: protecting availability, confidentiality, and integrity without crippling the product. They break the work into before, during, and after deployment; compare the constraints facing startups, midsize companies, and large enterprises; and explain why tools only help when developers understand their purpose. Hillel also argues that small companies need an incident plan, basic security architecture, and shared ownership early—not after the first enterprise security questionnaire arrives. The practical takeaway is simple: use what already exists, prioritize by risk, and make security part of everyone’s job.
You are now listening to the Application Security Podcast, brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Hillel Solow:
→ Hillel Solow on LinkedIn
Mentioned in this episode:
→ OWASP DevSecOps Guideline
→ AICPA SOC for Service Organizations overview
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Hillel Solow: AppSec Without a Security Team
03:03 From junior developer to security engineering
05:44 The building blocks of an AppSec program
10:28 Defense in depth across the application lifecycle
12:48 Why security tools need developer education
13:31 AppSec at startup, midsize, and enterprise scale
18:09 Advice for companies without a security specialist
23:41 A one-page incident response plan beats panic
27:01 Why small companies are still attractive targets
29:49 Making security everyone’s responsibility
30:33 Hillel’s practical call to action
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.