Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Ofer Maor -- A Pen Testers Transition to #AppSec: #VoteForOfer

27 min4 september 2018

Om avsnittet

Finding vulnerabilities is only part of improving software security; the harder work is changing how people build and operate applications. Ofer Maor shares his transition from penetration testing into application security and the lessons he learned through security startups. He and Chris discuss culture, genuine risk management, and the industry’s attraction to offensive work. They explore delivering findings inside developers’ tools, the limits of dumping issues into a backlog, and the roles of interactive testing and runtime protection. Ofer explains how compensating controls can buy time without replacing the need to fix code. The episode closes with his OWASP involvement and board candidacy at the time of recording, connecting technical progress with the community needed to support it.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Ofer Maor:
Ofer Maor on LinkedIn

Mentioned in this episode:
OWASP Israel community
OWASP Top 10

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 From penetration testing to AppSec with Ofer Maor
01:08 Ofer’s security origin story
03:04 Why secure development is hard
03:46 Culture and risk management
06:30 Balancing offensive and defensive work
07:37 Persistent vulnerabilities and framework defenses
11:52 Making security actionable for developers
14:11 Delivering findings in the IDE
14:36 Why thousands of backlog tickets do not help
18:54 IAST, RASP, and the risk of overreliance
21:44 Using runtime protection while fixing the code
22:18 OWASP involvement and the historical board campaign
23:19 OWASP Israel and growing new leaders

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.