
MO Sadek -- Building an AppSec Program from Scratch
Om avsnittet
Mo Sadek shares his unique journey of building an Application Security program from scratch at Roblox. Mo discusses his unconventional path, including temporarily joining the infrastructure team to truly understand engineering challenges. He emphasizes that security isn't about mandating rules, but about making processes easier and more secure by default. Mo shares his insights on how to build effective cross-team security relationships and approaches for gaining leadership buy-in. Mo Sadek is a security transformation leader, passionate about staying ahead of emerging threats. He's built and fine-tuned vulnerability programs, customized solutions through hands-on coding, and driven security-first approaches in AI initiatives. Known for translating complex security metrics into actionable insights, Mo excels at uniting engineers, executives, and cross-functional teams.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
We help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC.
→ Learn more about Security Journey
Connect with MO Sadek:
→ Roblox
→ I Have No Mouth and I Must Scream
Mentioned in this episode:
→ Roblox
→ I Have No Mouth and I Must Scream
→ Metasploit
→ GitHub Dependabot
→ Robert Hurlbut
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet MO Sadek: Building an AppSec Program from Scratch
01:33 I can see the snow in your background there from the
06:02 Way back to the beginning of the story. So, so, so
07:18 Very cool. So jumping into the AppSec program at Roblox, you
12:41 Then, how does that, your experience working on those different disciplines
14:18 What, what, quick refine the question. Were you dotted line to
20:39 Security. And now you mentioned incident response. Did you security engineering
21:46 Mo, when you talk about, you know, the different approaches in
25:16 You talked about the importance of partnership and, you know, listening
29:35 How, how do you communicate this with senior leadership
31:47 There metrics
36:38 You mentioned, you use the term security partnership. And we certainly
38:37 There's multiple partners then in the way that you think about
44:24 All right. So lightning round, we have 3 questions that we
47:15 All right, I'm going to check that one out. That's good
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.