The AI Workflow that Fixes AppSec Silos

The AI Workflow that Fixes AppSec Silos

🎙 Cloud Security Podcast 👥 39K 📅 November 4, 2025 ⏱ 71 min 👁 11K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

AIAppSecCloudSecThreat ModelingAgentic AI

Summary

In this episode of the Cloud Security Podcast, hosts Ashish Rajan and Shilpi Bhattacharjee interview Tejas Dakve (AppSec lead at Bloomberg Industry Group) and Aditya Patel (VP of Cybersecurity Architecture) about how AI is breaking down traditional silos between application security and cloud security. The conversation covers the challenges posed by AI-generated code, the need for security teams to shift from being a ‘Department of No’ to a ‘Department of Safe Yes’, and the importance of building ‘paved road’ solutions for developers. They discuss the evolution of threat modeling from a one-time event to a continuous process, the merging of AppSec and CloudSec threat models, and the rise of ‘T-shaped’ security engineers. The episode also explores agentic AI security, emphasizing the critical role of IAM and permissions. The speakers share practical advice for implementing AI security governance, using frameworks like MITRE ATLAS and OWASP LLM Top 10, and adapting security practices to keep pace with AI-driven development. The discussion concludes with career advice for security professionals in the age of AI.

171 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information is high for practitioners looking to understand the practical implications of AI on security workflows. The speakers provide concrete examples and analogies (e.g., ‘paved roads’, ‘Department of Safe Yes’) that illustrate actionable strategies. The argumentation is solid, grounded in real-world experience, and acknowledges the complexity of the topic. However, the discussion is largely opinion-based and lacks empirical evidence or case studies, which limits its scientific rigor. The speakers do not present data or formal research, but their insights are coherent and align with industry trends.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate: the speakers reference established frameworks (MITRE ATLAS, OWASP LLM Top 10) and industry practices, but they do not cite specific studies or publications. The sources provided in the description are primarily promotional (podcast website, bootcamp, newsletter) and do not directly support the content. The title accurately reflects the content, focusing on AI workflows to address AppSec silos. The discussion is well-structured and stays on topic, with no significant digressions.

179 words

Title / Content Match

The title accurately reflects the core theme: using AI workflows to bridge the gap between AppSec and CloudSec teams.

Quality & Reliability

7/10

The discussion features two experienced security professionals (AppSec and CloudSec) sharing practical insights and industry perspectives. While the content is largely anecdotal and based on personal experience, it aligns with recognized industry trends and references established frameworks (MITRE ATLAS, OWASP LLM Top 10). The lack of empirical data and reliance on opinion lowers the score slightly.

Chapters

Cited Sources

Concurring Sources

Contribution & Novelties

The episode provides a valuable perspective on how AI is forcing collaboration between AppSec and CloudSec teams, offering practical advice on integrating security into AI workflows. It emphasizes the shift from gatekeeping to enabling, and the importance of continuous threat modeling. The discussion on agentic AI security, particularly the focus on IAM, is a timely contribution.

Pour aller plus loin :

98 words

Radar Profile

The radar profile shows a balanced but moderate performance across all dimensions, with quantity of information being the strongest point. The episode offers substantial content but lacks deep technical depth and empirical rigor, making it more suitable for a general audience than for specialists seeking advanced technical details.

Reliability 7/10