Absolute AppSec
Hosted by Ken Johnson & Seth Law
Two working AppSec practitioners arguing about what actually helps developers ship safer code.
- Level
- Practitioner, assumes you work in or study security
- Status
- Active, last episode
- Who's behind it
- Independent, Ken Johnson and Seth Law sourceThe hosts also sell training and run a newsletter under the same brand.
- Last verified
- No transcripts
Listed underAppSec
Editorial take
The most practitioner-flavored AppSec show in this directory. Ken Johnson and Seth Law have run it weekly since 2018, alternating two-host news discussion with guest interviews, and the conversation stays close to the job: threat modeling, false positives, dependency risk, security champions, and lately what LLM coding tools do to review work. They are opinionated and unpolished, which is the appeal. The limitation is production: the show's own site lists only MP3 files, there are no episode pages, show notes, or transcripts, and the feed does not publish durations, so finding a past topic means scrolling titles. Expect roughly an hour per episode.
Last hand-checked 2026-09-30.
Listen if you …
- run or work on an application security program and want peers' honest opinions
- are a developer moving into AppSec and want to hear how the job looks day to day
- care about supply chain, dependency, and code review problems more than breach news
Skip if you …
- you want searchable show notes or transcripts, the site is a bare MP3 list
- you are new to security, episodes assume you know OWASP basics and SDLC vocabulary
Start with these 3 episodes
- 01
Episode 277 - w/ Kyle Rippee - AppSec Support, Security Red Flags, Getting Into AppSec
· 62 min · Beginner
The gentlest way in: how people actually get into AppSec and what the support side of the job looks like.
- 02
Episode 303 - w/Prof. Brian Glas - OWASP Top 10 2025
· 62 min · Practitioner
One of the OWASP Top 10 maintainers explains how the 2025 list was built, which helps you read it critically.
- 03
Episode 306 - w/ Paul McCarty - Open Source Malware
· 69 min · Practitioner
A researcher who tracks malicious packages full time on why registry malware is now a routine AppSec problem.
About the show
Absolute AppSec is a weekly application security podcast hosted by Ken Johnson and Seth Law. Episodes mix two-host discussion of recent AppSec news and research with interviews of practitioners, tool builders, and OWASP contributors.
The show started in 2018 and passed episode 334 in September 2026. The hosts also run a newsletter, a Slack community, and paid training under the Absolute AppSec name.
Notable guests
- Jason Haddix
- Tanya Janca
- Clint Gibler
- Brian Glas
- Paul McCarty
- Jeevan Singh
- Rami McCarthy
- Jerry Gamblin
- Justin Collins
- Avi Douglen
Pairs with
If Absolute AppSec works for you, these likely will too.
Application Security Weekly
Mike Shema · John Kinsella · Kalyani Pawar
An hour a week on finding and fixing software flaws, from secure design to LLM-written code.
Listen if you build or secure software and want one reliable AppSec interview a week.
mixedweekly60m+Open Source Security
Josh Bressers
Half-hour conversations with the maintainers and foundations who keep open source secure.
Listen if you own dependency risk, SBOMs, or vulnerability management for a software team.
interviewweekly30–60mCritical Thinking - Bug Bounty Podcast
Justin Gardner · Joseph Thacker · Brandyn Murtagh
Full-time bug bounty hunters trading techniques, write-ups, and payout war stories every week.
Listen if you hunt bugs on HackerOne, Bugcrowd, or Intigriti, or want to.
mixedweekly60m+