CSCP S03EP 26 – Nathan – From music to cybersecurity – the appsec symphony

CSCP S03EP 26 – Nathan – From music to cybersecurity – the appsec symphony

Phoenix Security
Phoenix Security
CSCP S03EP 26 - Nathan - From music to cybersecurity - the appsec symphony

CSCP S03EP 26 – Nathan – From music to cybersecurity – the appsec symphony

Phoenix Security
Phoenix Security
CSCP S03EP 26 - Nathan - From music to cybersecurity - the appsec symphony


Phoenix Security
Phoenix Security
CSCP S03EP 26 - Nathan - From music to cybersecurity - the appsec symphony


Nathan is the manager of the application security team at Intuit Mailchimp. He has over 7 years of experience in application security working at both startups and Fortune 500 companies. In that time, Nathan has been both an engineer and a leader. His primary focus has been on building out application security programs by implementing scalable processes and efficient methodologies. Nathan holds a Master’s in Digital Forensics and CyberSecurity from John Jay College of Criminal Justice and a Bachelor’s in Music Composition from University of the Arts.


In this show, Nathan and Francesco discuss the start in application security, how to mentor new interns and bridge the skillgap and how to measure application security progress when deploying shift left methodologies in devsecops 


The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the most important vulnerabilities and reduce your exposure to modern attacks. See it for yourself. Go to https://www.phoenix.security for a free 14-day licence.



2:00 – Nathan’s Intro

7:30 – from music to cybersecurity and new generation

11:00 – State of application security

14:00 – Vulnerability – What is a vulnerability in software

18:00 – How do you bring in the business in appsec – Product security

12:00 – Cybersecurity technicalities – Pen-tests  and regulation

16:00 – Cybersecurity and regulation in USA

19:00 – SBOM, Digital Software supply chain

20:00 – Risk for application security and business perspective

22:00 – Business categories of risk for application security

24:00 – Business criticality vs low criticality – how to talk about risk

26:00 – Prioritize work based on risk in application security   

27:00 – Avoiding burnout and preventing risk – Mailchimp program of work – SPIDER

31:00 – Doing more with less in application security

33:00 – Measuring shift left effectiveness – Dentist story

37:00 – Positive message and conclusion




Blog: https://nathancooke.com/ 

Linkedin: https://www.linkedin.com/in/nathancooke7/



Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

Linkedin: linkedin.com/in/fracipo 

#CSCP #cybermentoringmonday cybercloudpodcast.com 


Social Media Links 
Follow us on social media to get the latest episodes:
Website: http://www.cybercloudpodcast.com/
You can listen to this podcast on your favourite player:
Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463  
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ 
Linkedin: https://www.linkedin.com/company/35703565/admin/  

Twitter: https://twitter.com/podcast_cyber   

Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/ 



Francesco is an internationally renowned public speaker, with multiple interviews in high-profile publications (eg. Forbes), and an author of numerous books and articles, who utilises his platform to evangelize the importance of Cloud security and cutting-edge technologies on a global scale.

Follow us on social media to get the latest episodes:

Discuss this podcast with our community on Slack

Join our AppSec Phoenix community on Slack to discuss this blog and other news with our professional security team

More episodes

Discover innovative strategies to overcome the cybersecurity talent shortage in this insightful episode with Jitendra Arora, CISO at Deloitte. Dive deep into discussions on talent sourcing, nurturing diverse skills, fostering positive work culture, and self-care in the high-stress field of cybersecurity. Featuring expert insights and practical advice, this episode is a must-watch for cybersecurity professionals and enthusiasts. #CybersecurityInsights
Generated by Feedzy

Jeevan Singh

Founder of Manicode Security

Jeevan Singh is the Director of Security Engineering at Rippling, with a background spanning various Engineering and Security leadership roles over the course of his career. He’s dedicated to the integration of security practices into software development, working to create a security-aware culture within organizations and imparting security best practices to the team.
In his role, Jeevan handles a range of tasks, from architecting security solutions to collaborating with Engineering Leadership to address security vulnerabilities at scale and embed security into the fabric of the organization.

James Berthoty

Founder of Latio Tech

James Berthoty has over ten years of experience across product and security domains. He founded Latio Tech to help companies find the right security tools for their needs without vendor bias.

Christophe Parisel

Senior Cloud Security Architect

Senior Cloud Security Architect

Chris Romeo

Security Journey

Chris Romeo is a leading voice and thinker in application security, threat modeling, and security champions and the CEO of Devici and General Partner at Kerr Ventures. Chris hosts the award-winning “Application Security Podcast,” “The Security Table,” and “The Threat Modeling Podcast” and is a highly rated industry speaker and trainer, featured at the RSA Conference, the AppSec Village @ DefCon, OWASP Global AppSec, ISC2 Security Congress, InfoSec World and All Day DevOps. Chris founded Security Journey, a security education company, leading to an exit in 2022. Chris was the Chief Security Advocate at Cisco, spreading security knowledge through education and champion programs. Chris has twenty-six years of security experience, holding positions across the gamut, including application security, security engineering, incident response, and various Executive roles. Chris holds the CISSP and CSSLP certifications.

Jim Manico

Founder of Manicode Security

Jim Manico is the founder of Manicode Security, where he trains software developers on secure coding and security engineering. Jim is also the founder of Brakeman Security, Inc. and an investor/advisor for Signal Sciences. He is the author of Iron-Clad Java: Building Secure Web Applications (McGraw-Hill), a frequent speaker on secure software practices, and a member of the JavaOne Rockstar speaker community. Jim is also a volunteer for and former board member of the OWASP foundation.

Join our Mailing list!

Get all the latest news, exclusive deals, and feature updates.