
My guest today is Petra Vukmirovic, Head of Information Security and IT at Numan, and she also works with DevArmor on automating threat modeling and security design reviews. Outside of that she started the OWASP Threat Model Library, an open collection of real threat models the community can learn from.What makes her path unusual is that she didn't come to AppSec through development, she came through emergency medicine, where she worked as a doctor.In this episode, we talked about what transfers from the ER to incident response, which is mostly the protocols: risk scores, runbooks, decision trees you can follow when things are on fire. She also thinks threat modeling stops too early. Most teams model protective controls and stop, when recovery deserves the same attention. We also got into automating threat models with LLMs, catching drift between the model and the code, and where design reviews end and threat modeling begins.And much more!This podcast is brought to you byEscape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions.
Podzilla Summary coming soon
Sign up to get notified when the full AI-powered summary is ready.
Free forever for up to 3 podcasts. No credit card required.

The Docker mistakes everyone's still making and how to fix them with Advait Patel

Why Security Loses Influence in High-Growth Companies (And What to Do About It) with Kavia Venkatesh

The Lethal Trifecta or why your AI agent knows too much - Jason Fernandes

25 years of the same problem in Application Security - Sam Stepanyan
Free AI-powered recaps of The Elephant in AppSec and your other favorite podcasts, delivered to your inbox.
Free forever for up to 3 podcasts. No credit card required.