
The OWASP Podcast Series
The OWASP Podcast Series is a recorded series of discussions with thought leaders and practitioners who are working on securing the future for coming generations.
Latest episodes

Dec 23, 2024 • 1h
ep2024-12 Tanya Janca: Happy Holidays are Secure Code
In this engaging discussion, Tanya Janca, an AppSec expert and author of 'Alice and Bob Learn Secure Coding', dives into the essentials of secure coding practices. She shares insights on the lack of formal security education and advocates for improved AppSec curricula. Tanya emphasizes practical training and accessible resources for developers, while also reflecting on her personal journey in learning and teaching. Key topics include the importance of not trusting input and the principle of defense in depth, all presented with a relatable touch.

Oct 31, 2024 • 37min
ep2024-10 Don't be Scared, It's just a Pen Test with Brad Causey
There's no reason to be scared about a pen test - especially when it's run by a professional like Brad Causey. I catch up with Brad in this episode to discuss what's recently changed in pen testing in how you test and people's motivations for hiring a pen testing. Interesting and not spooky at all.
Show Links:
Brad on LinkedIn
- https://www.linkedin.com/in/bradcausey/
SecurIT360
- https://www.securit360.com/
- https://www.linkedin.com/company/securit360/
OWASP Testing Guide
- https://owasp.org/www-project-web-security-testing-guide/

Sep 25, 2024 • 36min
ep2024-09 Threat Modeling with Takaharu
What happens when you get interested in Threat Modeling and you want to share. For some, that means you do one work shop, then another, then another. What happens when you start down this path. Takaharu Ogasa tells us what it's been like to become a threat modeling evangelist in Japan, what he's learned and what he's got planned next. It's a great story on how sharing what you learned can make the world just that much better for you and those lucky enough to be involved.
Threat Modeling Community (Japanese):
- https://threatmodeling.connpass.com/
Takaharu on Twitter
-https://x.com/TakaharuOgasa

Aug 30, 2024 • 36min
ep2024-08 OWASP Projects Roundup
The August episode is a review of projects from a recent OWASP project showcase. We talk to the leaders of the OWASP pytm, OWASP Developer Guide, OWASP State of AppSec Survey Project. Get up on the latest news and update on these OWASP projects.
OWASP pytm:
- https://owasp.org/www-project-pytm/
- https://github.com/izar/pytm
OWASP Develper Guide:
- https://owasp.org/www-project-developer-guide/
- https://github.com/OWASP/www-project-developer-guide
OWASP AppSec Survey Project:
- https://owasp.org/www-project-state-of-appsec-survey/

Jul 12, 2024 • 32min
ep2024-07 Safety belts for AppSec with Lisa Plaggemier
After a long and unplanned pause, the OWASP podast is back with a home run of an episode. We have Lisa Plaggemier as our guest who reprises her eloquent keynote topic from AppSec DC. All hope isn't lost, we are making progress - just look at safety in the auto industry to understand where we are and where we're going.
Links:
Lisa's keynote from AppSec DC
https://www.youtube.com/watch?v=Rirxc1OXR4Q&list=PLpr-xdpM8wG_3eyVQxB0oXqVJwlNKs85x&index=38&ab_channel=OWASPFoundation
Kubikle web series
https://kubikleseries.com/
Convene Seattle 2024 event
https://staysafeonline.org/programs/events/convene-seattle-2024/

Oct 2, 2023 • 33min
ep2023-09 Vulnerable Data Gathering for AI with Arturo Buanzo Busleiman
Arturo Buanzo Busleiman, a cybersecurity and government expert, discusses potential vulnerabilities in web crawlers used for AI systems. They explore the PGP signing of HTTP requests, vulnerability analysis in access logs, and the importance of implementation details. They also touch on space exploration, Python's capabilities, and their appreciation for the OWASP community.

Aug 31, 2023 • 33min
ep2023-08 Finding Next Gen Cybersecurity Professionals with Brad Causey
Brad Causey, an expert in finding next-gen cybersecurity professionals, discusses the shortage of cybersecurity professionals and his successful approach to address it. They cover building and training entry-level professionals, the evolution of cybersecurity testing, security vulnerabilities in outdated payment devices and Linux-powered IoT devices, avenues for finding cybersecurity professionals, and the need for cybersecurity professionals in the future.

Jul 31, 2023 • 34min
ep2023-07 What's Audit got to do with IT
In this episode we talk with Zain Haq and take a leap and bound over the first and second line to discover more about the third line - internal audit. We discover answers to a number of questions: What role does audit play in the overall cybersecurity of an organization? What does the CISO gain from having an audit function? What makes a good auditor? Learn how to get the most out of audit and what they bring to the table. Special thanks to Tina Turner for inspiring the show title. ;-)
Show Links:
- Zain Haq: https://www.linkedin.com/in/zainhaq25/

Jun 27, 2023 • 30min
SBOMS, CycloneDX and Dependency Track: Automation for Survival with Steve Springett
Software supply chain seems to be front and center for technologists, cybersecurity and many governments. One of the early pioneers in this space was Steve Springett with two highly successful projects: OWASP Dependency Track and CycloneDX. In this episode, we catch up with Steve to talk about how he got started in software supply chain management as well as the explosive growth for Dependency Track and ClycloneDX. We also touch on future developments for CycloneDX and places where Steve never expected to see his projects go. Enjoy!
Show Links:
- OWASP Dependency Track: https://dependencytrack.org/
- Dependency Track Github: https://github.com/DependencyTrack
- CycloneDX: https://cyclonedx.org/
- CycloneDX Github: https://github.com/CycloneDX
- Software Component Verification Standard: https://scvs.owasp.org/
Social Media links:
- https://twitter.com/stevespringett
- https://infosec.exchange/@stevespringett
- https://www.linkedin.com/in/stevespringett/

May 22, 2023 • 44min
AppSec at 40,000 feet
In this episode I speak with Jerry Hoff who provides some very interesting perspective on application security especially at scale and from a high level view like that of a CISO. Even if you're not in a senior leadership position, you're likely to be reporting to one. Understanding that point of view can help you successfully frame your work and accomplish your goals. We touch on multiple topics and have some great back and forth that I'm sure will entertain and inform you. Enjoy!