The Boring AppSec Podcast

The Future of Developer Security with Travis McPeak

Dec 15, 2025
Travis McPeak, a security leader and entrepreneur, discusses the future of developer security, having led initiatives at major companies like Symantec and Netflix. He emphasizes the role of AI in shifting security 'left' and integrating it seamlessly into developer tools. Travis highlights the challenges of compliance in cloud security and how AI can make threat modeling feasible. He also debates the benefits and risks of AI for developers, particularly emphasizing the importance of ownership in using AI-generated code effectively.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Acqui‑Hire Reality Check

  • Travis describes Resourcely being acqui‑hired because the product lacked demand but the team was valuable.
  • He learned that many cloud security problems aren't driven by compliance, which limited adoption for his product.
INSIGHT

AI As The Left‑Shift Lever

  • Travis argues AI is the best injection point to shift security all the way left because developers already adopt AI tools.
  • Providing AI with secure design context lets it enforce guardrails during development.
ADVICE

Apply AI To Threat Modeling

  • Use AI to make previously unscalable practices, like threat modeling, practical by having models generate architecture diagrams and trace code.
  • Ask AI to triage upgrade impact so engineers get better signals about risk before changing dependencies.
Get the Snipd Podcast app to discover more snips from this episode
Get the app