Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Ray Espinoza -- The AppSec CISO, Vendor Relationships, and Mentoring

51 min15 november 2023

Om avsnittet

What does an application security leader need to know before stepping into the CISO role? Ray Espinoza joins Chris and Robert to share lessons from becoming a first-time CISO, aligning security work with business priorities, and building a culture where developers take pride in secure craftsmanship. Ray explains how he evaluates tools without confusing activity for impact, what good vendor relationships look like from the buyer’s side, and why empathy and credibility matter when security teams ask engineering teams to change. The conversation closes with practical advice on mentorship, leadership, and measuring whether an AppSec program is actually helping the business.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Ray Espinoza:
Ray Espinoza on LinkedIn

Mentioned in this episode:
Extreme Ownership

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Ray Espinoza and the AppSec CISO
01:54 From eBay to security leadership
04:59 Lessons from becoming a first-time CISO
08:26 Learning from failure without repeating it
11:29 How much security knowledge a CISO needs
15:57 Leading security in a smaller company
20:49 Aligning AppSec with business priorities
26:45 Choosing tools and evaluating vendors
30:44 Measuring security outcomes instead of activity
38:54 Building productive vendor relationships
42:13 Mentorship and growing security leaders
47:34 The leadership lightning round

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.