
Jim Routh — Secure software pipelines
Om avsnittet
A secure software pipeline is more than a collection of scanners. Jim Routh joins Chris and Robert to explain how organizations can build repeatable controls into delivery systems while preserving the speed engineering teams need. From a CISO’s perspective, Jim describes the organizational and funding decisions behind pipeline transformation, the role of threat modeling, and the difference between application security, software security, and broader cyber risk. The discussion focuses on making controls consistent, measuring the value of automation, and structuring teams so secure delivery becomes a shared capability. Jim closes with lessons leaders can use when turning isolated security activities into an enterprise software assurance program.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Jim Routh:
→ Jim Routh on LinkedIn
Mentioned in this episode:
→ Threat Modeling Manifesto
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Building secure software pipelines
02:00 Jim Routh’s software security work
07:00 From DevSecOps activities to pipeline capabilities
13:00 The CISO perspective on software delivery
16:00 Embedding security controls in the pipeline
27:00 Application security, software security, and cyber risk
30:00 Organizational models for secure delivery
31:00 Funding a pipeline transformation
38:00 Practical takeaways for security leaders
43:00 Closing thoughts
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.