
Isaac Evans - AppSec in the Age of AI
Om avsnittet
AI is moving AppSec's control point out of CI and directly into the coding agent—but what happens when the model writing the code is also expected to secure it? Semgrep co-founder and CEO Isaac Evans explains why deep background analysis and real-time agent plugins may replace universal rule sets with organization-specific security controls. He and Chris explore how security engineering roles will change, why independent verification still matters, and where business-logic flaws may become the next major battleground. The conversation also covers vibe coding at enterprise scale, the limits of reasoning about model behavior, open source in an agent-built world, and why Isaac sees more opportunity than threat even as AI creates a fresh wave of vulnerabilities and cleanup work.
Connect with Isaac Evans:
→ Isaac Evans on LinkedIn
→ Semgrep
Mentioned in this episode:
→ Semgrep
→ DeepSeek
→ Cursor
→ OpenAI Codex
→ Claude Code
→ Boston Dynamics
→ DARPA Robotics Challenge
→ Reflections on Trusting Trust
→ uutils/coreutils
→ Rust
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Isaac Evans
01:11 From cryptography to the DARPA Robotics Challenge
03:43 Founding Semgrep
04:05 How AI is reshaping AppSec
06:15 Attackers, defenders, and model choice
08:02 Regenerating code until it clears the security bar
10:30 Organization-specific rules beat universal rules
14:18 The changing role of the security engineer
17:53 Career advice for security practitioners
19:47 Will foundation models absorb security vendors?
24:18 Getting secure changes across an enterprise
26:40 Trusting Trust becomes the easy problem
27:41 How much should we trust agent-generated code?
29:38 Independent verification and competing models
34:50 Business logic flaws after SQL injection
36:56 Protecting the new wave of citizen developers
39:40 Vibe coding and disposable software
42:05 Open source in an agent-built world
44:10 Can the exponential pace continue?
44:41 Key takeaways and calls to action
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.