
Vulnerability Jail and the AI-Era AppSec Engineer
Om avsnittet
Three years ago, Jeevan Singh mapped out what an application security engineer needed to know. AI has rewritten the job since. Jeevan, Director of Security Engineering at Rippling, returns to unpack how his team polices thousands of engineers shipping 10x more code: a "vulnerability jail" that locks non-compliant teams out of the main branch, AI-reviewed extension requests, and homegrown agents that hunt for entire classes of vulnerabilities instead of one bug at a time. He and Chris debate whether AI has killed classic SAST and DAST, whether code review still needs a human in the loop, and whether bug bounty programs still make sense when the researchers on both sides are running the same models. Plus: one concrete move every AppSec leader can make this quarter.
This episode is sponsored by Security Compass. Make modern software development secure, consistent, and provable.
About Security Compass
AI writes code faster than anyone reviews the design. Threats do not wait for an annual assessment. Security Compass models threats continuously and turns them into requirements developers act on, not a report read after ship.
→ Learn more about securing the AI-DLC with Security Compass
This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
About Corgea
Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
→ Learn more about Corgea
Connect with Jeevan Singh:
→ Jeevan Singh on LinkedIn
Mentioned in this episode:
→ Rippling
→ Dwarkesh Patel: "The Rise and Fall of Agent Civilizations" (essay on the OpenAI–Hugging Face incident)
Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast
Chapters:
00:00:00 - Cold open: vulnerability jail
00:00:55 - Meet Jeevan Singh
00:01:11 - Welcome and Robert's AI lab
00:02:37 - What gets Jeevan away from the machines
00:04:51 - Hardware projects with his son
00:06:20 - What's changed for the AppSec engineer since AI
00:08:17 - Shipping production code and fixing whole vulnerability classes
00:09:13 - Why AppSec has to become less collaborative
00:10:02 - From democratized vuln management to vulnerability jail
00:11:50 - How engineering reacted and the feature flag jail precedent
00:14:05 - From manual jail to automated checks
00:15:30 - An AI bot that reviews SLA extensions
00:16:06 - Can AI wipe out an entire vulnerability class?
00:17:36 - Building an anti-SSRF library and rolling it out
00:19:40 - Which AppSec skills matter now
00:22:28 - Validating all that AI-generated code
00:22:57 - Agents that hunt for vulnerability classes
00:24:38 - Is this the death of classic AppSec tools?
00:26:51 - Code review and humans in, on, and out of the loop
00:28:00 - Objective-based agents that find RCEs
00:28:59 - Build vs. buy for AppSec teams
00:31:29 - Advice for teams of one to five AppSec engineers
00:32:58 - Cutting SLAs to 3, 5, 7, and 10 days
00:34:31 - Parachuted in as the only AppSec engineer
00:37:59 - One investment to make this quarter
00:39:09 - The Hugging Face and OpenAI agent incident
00:40:13 - Is bug bounty dead?
00:42:19 - Key takeaways: be an engineer, run toward AI
00:43:53 - Wrap-up
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.