Application security podcasts
Podcasts for developers and AppSec engineers: secure code review, bug bounty technique, open source supply chain, and the tooling debates in between.
These shows assume you write or review code. Some are practitioner banter about the week's research; some are slow, careful discussions of supply chain and open source risk. The level tag on each review tells you which.
9 shows, grouped by level. Each review lists three episodes to start with.
Practitioner
Absolute AppSec
Ken Johnson · Seth Law
Two working AppSec practitioners arguing about what actually helps developers ship safer code.
Listen if you run or work on an application security program and want peers' honest opinions.
panelweekly60m+AI Security Podcast
Ashish Rajan · Caleb Sima
Two former CISOs separate real AI security risk from vendor noise, for the people who have to sign off on it.
Listen if you are a CISO or security architect being asked to approve AI agents and copilots.
mixedbiweekly30–60mApplication Security Weekly
Mike Shema · John Kinsella · Kalyani Pawar
An hour a week on finding and fixing software flaws, from secure design to LLM-written code.
Listen if you build or secure software and want one reliable AppSec interview a week.
mixedweekly60m+Cloud Security Podcast
Ashish Rajan
Practitioners from Netflix, Block, and Adobe explain how they actually run cloud security, now with a heavy AI tilt.
Listen if you are a cloud or platform engineer moving into security.
interviewbiweekly30–60mOpen Source Security
Josh Bressers
Half-hour conversations with the maintainers and foundations who keep open source secure.
Listen if you own dependency risk, SBOMs, or vulnerability management for a software team.
interviewweekly30–60mResilient Cyber
Chris Hughes
Supply chain, vulnerability management and AI agent security, from a practitioner who writes the books on them.
Listen if you work in AppSec, product security or vulnerability management and want the current debates.
interviewweekly30–60mSecurity Now
Steve Gibson · Leo Laporte
Steve Gibson takes one security story apart every Tuesday, slowly, until you understand how it actually works.
Listen if you want security news explained down to the protocol or code level, not just reported.
panelweekly60m+
Expert
Critical Thinking - Bug Bounty Podcast
Justin Gardner · Joseph Thacker · Brandyn Murtagh
Full-time bug bounty hunters trading techniques, write-ups, and payout war stories every week.
Listen if you hunt bugs on HackerOne, Bugcrowd, or Intigriti, or want to.
mixedweekly60m+Day[0]
Specter · zi
A finished archive of 283 episodes on how real vulnerabilities were found and exploited.
Listen if you are learning exploit development or vulnerability research and want worked examples.
panelcompleted60m+