
Your AppSec Bottleneck Is a People Problem
Om avsnittet
Most security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product security, which means she has argued both sides of this from inside the trenches. Drawing on the talk she and Mireia Cano gave at OWASP Global AppSec EU 2026, Lisi walks us through the four things that actually make these programs work: psychological safety first, then cognitive load, then influence when you hold no formal authority, then a champions community so the whole thing doesn't stall the week security goes on vacation. We also get into cutting security wait times, winning organizational support, what AI does and doesn't change here, and why she will tell you never to record the champions meeting.
This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
About Corgea
Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
→ Learn more about Corgea
Connect with Lisi Hocke:
→ Lisi Hocke on LinkedIn
→ A Tester's Journey — Lisi's blog
Mentioned in this episode:
→ Slides: Security Champions — Lessons from Opposite Trenches (with Mireia Cano)
→ OWASP Juice Shop
Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast
Chapters:
00:00 Cold open — what psychological safety actually means
00:56 Meet Lisi Hocke
02:25 Lisi's security origin story
05:42 "That place was taken" — becoming a champion anyway
07:39 Moving into a full-time product security role
08:39 Meeting Björn Kimminich, the Juice Shop project lead
09:23 Why role play instead of a normal conference talk
12:27 Security and development, disconnected
14:19 The first full-time security role
15:14 Making people wait is the real damage
17:10 Cutting the backlog and the turnaround time
19:31 What Lisi got dead wrong
20:08 What testing and quality work taught her
21:31 The four things that make champions programs work
22:07 One: fostering psychological safety
24:50 Champions without their manager's blessing
28:45 Two: managing cognitive load
29:46 Three kinds of load, and which one to cut
31:21 Three: power sources when you have no formal authority
33:03 Four: build a champions community
34:38 Keeping security people from burning out
36:37 How AI changes who you recruit and what you need
39:32 Should AI change champions programs at all?
40:33 Psychological safety when a bot joins the meeting
42:25 Don't record the champions meetings
43:26 Programs that outlive the person who started them
45:59 Key takeaway and homework
47:21 Closing thoughts
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.