
Today, I’m joined by Sam Stepanyan, an OWASP Global Board member and an OWASP London Chapter Leader. Sam is an Independent Application Security Consultant and Security Architect with over 20 years of experience in the IT industry.Sam has worked for various financial services institutions in the City of London specialising in Application Security consulting, Secure Software Development Lifecycle (SDLC), developer training, source code reviews and vulnerability management. He is also a Subject Matter Expert in Web Application Firewalls (WAF) and SIEM systems.In this episode, we explore why, despite OWASP being around for over 25 years, many developers are still unaware of it—and why shifting focus toward developer conferences might be key to spreading security knowledge more effectively.We also discuss the impact of AI on modern security practices, the growing role of automated penetration testing tools, and how even small changes—like adding the word “secure” to a vibe coding prompt—can help nudge developers toward more security-conscious decisions.Dive right in! This podcast is brought to you byEscape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions.
Podzilla Summary coming soon
Sign up to get notified when the full AI-powered summary is ready.
Free forever for up to 3 podcasts. No credit card required.

Don't just model the attack, model the recovery with Petra Vukmirovic

The Docker mistakes everyone's still making and how to fix them with Advait Patel

Why Security Loses Influence in High-Growth Companies (And What to Do About It) with Kavia Venkatesh

The Lethal Trifecta or why your AI agent knows too much - Jason Fernandes
Free AI-powered recaps of The Elephant in AppSec and your other favorite podcasts, delivered to your inbox.
Free forever for up to 3 podcasts. No credit card required.