Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Your AppSec Bottleneck Is a People Problem

48 min7 september 2026

Om avsnittet

Most security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product security, which means she has argued both sides of this from inside the trenches. Drawing on the talk she and Mireia Cano gave at OWASP Global AppSec EU 2026, Lisi walks us through the four things that actually make these programs work: psychological safety first, then cognitive load, then influence when you hold no formal authority, then a champions community so the whole thing doesn't stall the week security goes on vacation. We also get into cutting security wait times, winning organizational support, what AI does and doesn't change here, and why she will tell you never to record the champions meeting.

This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.

About Corgea
Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
Learn more about Corgea

Connect with Lisi Hocke:
Lisi Hocke on LinkedIn
A Tester's Journey — Lisi's blog

Mentioned in this episode:
Slides: Security Champions — Lessons from Opposite Trenches (with Mireia Cano)
OWASP Juice Shop

Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast

Chapters:
00:00 Cold open — what psychological safety actually means
00:56 Meet Lisi Hocke
02:25 Lisi's security origin story
05:42 "That place was taken" — becoming a champion anyway
07:39 Moving into a full-time product security role
08:39 Meeting Björn Kimminich, the Juice Shop project lead
09:23 Why role play instead of a normal conference talk
12:27 Security and development, disconnected
14:19 The first full-time security role
15:14 Making people wait is the real damage
17:10 Cutting the backlog and the turnaround time
19:31 What Lisi got dead wrong
20:08 What testing and quality work taught her
21:31 The four things that make champions programs work
22:07 One: fostering psychological safety
24:50 Champions without their manager's blessing
28:45 Two: managing cognitive load
29:46 Three kinds of load, and which one to cut
31:21 Three: power sources when you have no formal authority
33:03 Four: build a champions community
34:38 Keeping security people from burning out
36:37 How AI changes who you recruit and what you need
39:32 Should AI change champions programs at all?
40:33 Psychological safety when a bot joins the meeting
42:25 Don't record the champions meetings
43:26 Programs that outlive the person who started them
45:59 Key takeaway and homework
47:21 Closing thoughts

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.