Episode

Empowering Developers: Fostering a Culture of Security in AppSec - Danielle Ruderman - CSP #213

Podcast
CISO Stories Podcast (Audio)
Published
Jun 9, 2025
Duration seconds
1837
Processing state
not_requested
Canonical source
https://cspaudio.libsyn.com/empowering-developers-fostering-a-culture-of-security-in-appsec-danielle-ruderman-csp-213
Audio
https://dts.podtrac.com/redirect.mp3/traffic.libsyn.com/secure/cspaudio/CSP_213_1--66b93f86-34de-4599-b48b-93743501ad93--audio-converted--dfb12c39-a90a-48fc-9b87-d71f21943d63.mp3?dest-id=2584793
JSON
/v1/public/podcasts/ciso-stories-podcast-audio-3570889/episodes/empowering-developers-fostering-a-culture-of-security-in-appsec-danielle-ruderman-csp-213
Markdown
/podcast/ciso-stories-podcast-audio-3570889/empowering-developers-fostering-a-culture-of-security-in-appsec-danielle-ruderman-csp-213.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/ciso-stories-podcast-audio-3570889/episodes/empowering-developers-fostering-a-culture-of-security-in-appsec-danielle-ruderman-csp-213/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/ciso-stories-podcast-audio-3570889/empowering-developers-fostering-a-culture-of-security-in-appsec-danielle-ruderman-csp-213.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

In this episode, we explore the crucial role of cultivating a strong security culture to drive change in AppSec, where training and collaboration are key. Our distinguished guest, Danielle Ruderman, discusses the importance of executive support in ensuring that application development isn't just about churning out apps on time, but also about adopting a secure-by-design approach. We also dive into how to empower developers, foster psychological safety, and make security everyone's responsibility. Tune in for actionable insights on transforming your security culture within your applications team and beyond. Segment Resources: • AWS Security Blog How the unique culture of security at AWS makes a difference: https://aws.amazon.com/blogs/security/how-the-unique-culture-of-security-at-aws-makes-a-difference/ • AWS Security Blog How AWS built the Security Guardians program, a mechanism to distribute security ownership: https://aws.amazon.com/blogs/security/how-aws-built-the-security-guardians-program-a-mechanism-to-distribute-security-ownership/ • AWS Security Blog How to build a Security Guardians program to distribute security ownership (part 2): https://aws.amazon.com/blogs/security/how-to-build-your-own-security-guardians-program/ • Application Security in the AWS Well Architected Framework: https://aws.amazon.com/blogs/security/how-to-build-your-own-security-guardians-program/ • AWS Security Blog How to approach threat modeling: https://aws.amazon.com/blogs/security/how-to-approach-threat-modeling/ • GitHub: Threat Composer is a simple threat modeling tool to help humans to reduce time-to-value when threat modeling: https://github.com/awslabs/threat-composer • Workshop: Threat Modeling the right way for builders: https://catalog.workshops.aws/threatmodel/en-US Visit htt…