
The Boring AppSec Podcast The Future of Developer Security with Travis McPeak
Dec 15, 2025
Travis McPeak, a security leader and entrepreneur, discusses the future of developer security, having led initiatives at major companies like Symantec and Netflix. He emphasizes the role of AI in shifting security 'left' and integrating it seamlessly into developer tools. Travis highlights the challenges of compliance in cloud security and how AI can make threat modeling feasible. He also debates the benefits and risks of AI for developers, particularly emphasizing the importance of ownership in using AI-generated code effectively.
AI Snips
Chapters
Transcript
Episode notes
Acqui‑Hire Reality Check
- Travis describes Resourcely being acqui‑hired because the product lacked demand but the team was valuable.
- He learned that many cloud security problems aren't driven by compliance, which limited adoption for his product.
AI As The Left‑Shift Lever
- Travis argues AI is the best injection point to shift security all the way left because developers already adopt AI tools.
- Providing AI with secure design context lets it enforce guardrails during development.
Apply AI To Threat Modeling
- Use AI to make previously unscalable practices, like threat modeling, practical by having models generate architecture diagrams and trace code.
- Ask AI to triage upgrade impact so engineers get better signals about risk before changing dependencies.
