Fifty two episodes in and we still cannot agree on where AppSec ends and ProdSec begins.
This week Cameron and Kurt mark one year of the show with a reflection episode. No news roundup, no breach breakdown, just a hard look back at what changed, what did not, and what they got wrong along the way.
They revisit the founding question from Episode 1, defining ProdSec, and admit the answer is still messy a year later. They cover the shift from strict deterministic tooling to AI powered security tools quietly running deterministic checks underneath, the SOC and GRC backgrounds that keep landing people in ProdSec leadership roles they were never built for, and why compliance checked boxes still are not the same thing as actual security. Cameron breaks down why buying still beats building for most teams stretched thin on headcount, and Kurt will not let the short lived identity crowd forget who gets the page when it breaks at 2 AM.
Plus the real highs and lows of a year behind the mic, including the blooper neither of them will ever live down.
If you work in Product Security, Application Security, or DevSecOps and you have ever argued about what your own job title actually means, this one is for you.
☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.
Podden och tillhörande omslagsbild på den här sidan tillhör
Cameron Walters and Kurt Hendle. Innehållet i podden är skapat av Cameron Walters and Kurt Hendle och inte av,
eller tillsammans med, Poddtoppen.