
Insights from recent episode analysis
Audience Interest
Podcast Focus
Publishing Consistency
Platform Reach
Insights are generated by CastFox AI using publicly available data, episode content, and proprietary models.
Most discussed topics
Brands & references
Est. Listeners
Insufficient chart data. Estimates will improve as the show charts.
- Per-Episode Audience
Est. listeners per new episode within ~30 days
N/A🎙 ~2x weekly·135 episodes·Last published 2mo ago - Monthly Reach
Unique listeners across all episodes (30 days)
N/A - Active Followers
Loyal subscribers who consistently listen
N/A
Market Insights
Platform Distribution
Reach across major podcast platforms, updated hourly
Total Followers
—
Total Plays
—
Total Reviews
—
* Data sourced directly from platform APIs and aggregated hourly across all major podcast directories.
On the show
From 10 epsHosts
Recent guests
Recent episodes
AI, Automation, & Humans' Role In Security: A View From Rsac 2026 With Jeff Man and Dwayne McDaniel
Apr 1, 2026
42m 50s
Avoiding Operational Chaos While Defending A Credit Union With Data Classification - John Wallace
Mar 25, 2026
19m 43s
OIDC And IAP In Production: Scaling Startup Security For Deepfake Defense - Talia Smiley
Mar 18, 2026
20m 01s
The PCI Ultimatum -Thrift Store OSINT, and "Lost Media" with Dwayne Edwards and Mike Radigan
Mar 17, 2026
22m 23s
From Annual Checkbox To Continuous SDLC Testing: Operationalizing AI Pentests - Andy Dennis of XBow
Mar 13, 2026
19m 47s
Social Links & Contact
Official channels & resources
Official Website
Login
RSS Feed
Login
| Date | Episode | Topics | Guests | Brands | Places | Keywords | Sponsor | Length | |
|---|---|---|---|---|---|---|---|---|---|
| 4/1/26 | ![]() AI, Automation, & Humans' Role In Security: A View From Rsac 2026 With Jeff Man and Dwayne McDaniel✨ | AI in cybersecurityautomation+4 | Jeff Man | Security Repo PodcastOnline Business Systems+3 | — | cybersecurityAI+5 | — | 42m 50s | |
| 3/25/26 | ![]() Avoiding Operational Chaos While Defending A Credit Union With Data Classification - John Wallace✨ | data classificationdata protection+3 | John Wallace | Security Service Federal Credit UnionAmazon+2 | — | data classificationcredit unions+5 | — | 19m 43s | |
| 3/18/26 | ![]() OIDC And IAP In Production: Scaling Startup Security For Deepfake Defense - Talia Smiley✨ | OIDCIAP+4 | Talia Smiley | SilversightGoogle | — | OIDCIAP+5 | — | 20m 01s | |
| 3/17/26 | ![]() The PCI Ultimatum -Thrift Store OSINT, and "Lost Media" with Dwayne Edwards and Mike Radigan✨ | cybersecuritystorytelling+3 | Dwayne EdwardsMike Radigan | The ICS Security Radio HourThe PCI Ultimatum+1 | — | cybersecurityPCI compliance+3 | — | 22m 23s | |
| 3/13/26 | ![]() From Annual Checkbox To Continuous SDLC Testing: Operationalizing AI Pentests - Andy Dennis of XBow✨ | AI penetration testingcontinuous testing+3 | Andy Dennis | XBOWGoldsmith’s College+1 | — | AIpenetration testing+5 | — | 19m 47s | |
| 3/11/26 | ![]() Why Compliance Isn’t Governance & How GovOps Rebuilds Trust Boundaries – Mike Schwartz✨ | GovOpscompliance+4 | Mike Schwartz | GluuLinux Foundation+6 | — | GovOpscompliance+6 | — | 37m 45s | |
| 2/11/26 | ![]() Building AI Solutions with a Security-First Mindset: Frameworks and Lessons with Henry Odibi✨ | AI solutionsdata engineering+3 | Henry Odibi | IngredionAzure Data Factory+3 | — | AIdata engineering+5 | — | 18m 46s | |
| 2/4/26 | ![]() Link Safety, Lightweight AI & Operationalizing Threat Modeling - Nathan Koester✨ | security toolslightweight AI+3 | Nathan Koester | Pwnbook.ioCharlemagne Labs+1 | — | securityAI+3 | — | 20m 45s | |
| 1/28/26 | ![]() Tackling the Root of Incidents: Culture, Credentials, and AWS Insights – Robert Saul✨ | incident responsesecurity incidents+4 | Robert Saul | AWS Security Incident Response ServicesAWS+1 | — | security incidentscredential loss+5 | — | 25m 48s | |
| 1/21/26 | ![]() Hacking WebMethods: Legacy Systems, Modern Threats – Ryan Bonner✨ | legacy systemsvulnerabilities+4 | Ryan Bonner | WebMethodsIceland’s top bug bounty hunter+2 | — | WebMethodsvulnerabilities+6 | — | 17m 53s | |
Want analysis for the episodes below?Free for Pro Submit a request, we'll have your selected episodes analyzed within an hour. Free, at no cost to you, for Pro users. | |||||||||
| 1/14/26 | ![]() Why Attackers Don’t Care About Your Contracts: A Deep Dive Into Exploit Markets – Evan Dornbush | In this episode of the Security Repo Podcast, we dive into the world of zero-day exploits, marketplace dynamics for vulnerability research, and the evolving role of cybersecurity in boardroom decision-making. Guest Evan Dornbush, founder of Desired Effect, shares his journey from government cyber-ops to founding multiple security startups, and explains why attackers don’t care about compliance paperwork. We also explore the real-world consequences of hardware vulnerabilities, how a plug won’t save your hotel lock, and why we might be fooling ourselves by trying to “out-tech” cybercriminals.https://www.linkedin.com/in/evandornbush/https://www.desiredeffect.io/Evan Dornbush is the founder and CEO of Desired Effect, which helps vulnerability researchers get fairly compensated and helps defenders act before attacks begin. He hosts the researcher-focused Hackers On The Rocks podcast. Previously, Evan co-founded Point3 Security, a cybersecurity workforce development firm acquired in 2021, and served as CEO. He co-founded P3F, a cybersecurity research firm acquired in 2021. He led Customer Experience at Vulnerability Research Labs, a security research firm acquired in 2010. He worked as a Computer Network Operator for the National Security Agency. Evan holds an M.S. in computer science from The George Washington University and has four ridiculously good-looking children. | — | ||||||
| 1/7/26 | ![]() Untangling Identity: From Active Directory to Entra ID with Eric Woodruff | In this episode of the Security Repo Podcast, Eric Woodruff dives deep into the complexities of identity and access management (IAM), from the evolution of Active Directory to the future of non-human identities. He explains the real-world challenges of hybrid environments, governance, and over-engineered identity solutions. Eric also highlights practical ways for newcomers to start learning IAM and emphasizes the importance of soft skills in security roles.https://www.linkedin.com/in/ericonidentity/https://idpro.org/body-of-knowledge/https://ericonidentity.com/Throughout his 25-year career in the IT field, Eric Woodruff has sought out and held a diverse range of roles. Currently the Chief Identity Architect for Semperis; Eric previously was a member of the Security Research and Product teams. Prior to Semperis, Eric worked as a Security and Identity Architect at Microsoft partners, spent time working at Microsoft as a Sr. Premier Field Engineer, and spent almost 15 years in the public sector, with 10 of them as a technical manager.Eric is a Microsoft MVP for security, recognized for his expertise in the Microsoft identity ecosystem. Eric is a strong proponent of knowledge sharing and spends a good deal of time sharing his insights and expertise at conferences as well as through blogging. Eric further supports the professional security and identity community as an IDPro member, working as part of the IDPro Body of Knowledge committee. | — | ||||||
| 12/19/25 | ![]() A Special Holiday Message from The Security Repo Podcast | Hi everyone, It's Dwayne, host of the security repo podcast. The show is taking a 2-week break over the holidays to give you a chance to catch up on our backlog of security conversations. Our next new episode premieres January 7th, 2026. It's one to look forward to. And I wanted to say a huge thank you to each and every one of our listeners and subscribers. Thanks to you, in 2025, we gained 1300 new subscribers and crossed the 3500 mark on YouTube. Thank you. And I honestly hope you all are learning as much as I am from the amazing guests.I am honored to get to talk to some of the smartest people I have ever met and get to ask them about stuff I care about.I wish you the very best in 2026 and beyond, and may you and your loved ones have the best holiday season ever.Thanks, Dwayne | — | ||||||
| 12/17/25 | ![]() The CISO Whisperer Approach: Security Leadership, Empathy, and ‘Dad Bod’ Metrics – Douglas Brush | In this episode of the Security Repo Podcast, Douglas Brush, digital forensics expert and self-proclaimed "CISO Whisperer," shares his journey from early IT consulting to guiding CISOs and boards through complex security decisions. He breaks down his “Dad Bod Security” framework, connecting personal health metrics to meaningful cybersecurity goals, and highlights the need to move beyond vanity KPIs to focus on sustainable security programs. With candid insights on executive communication, legal challenges, and cultural resistance, Douglas offers a blueprint for building trust and progress in modern security leadership.https://www.linkedin.com/in/douglasabrush/https://brushcyber.com/Douglas Brush, the founder of Brush Cyber, excels in data privacy, cybersecurity, litigation, and information governance. His unique combination of technical skills and business insight has earned him the respect and admiration of clients and colleagues.What truly sets Douglas apart is his unwavering dedication to his clients. He understands that protecting data in today’s digital age is a technical challenge and a business imperative. Whether testifying as an expert witness or providing virtual CISO services, Douglas always brings his A-game with an engaging yet intelligent approach. He translates bits and bytes to dollars and cents like no other professional in his field.In fact, he’s so good at what he does that he is a federally court-appointed Court Appointed Neutral (formally known as a “Special Master”) and neutral expert in high-profile litigation matters. Douglas Brush is a beacon of light in a world where data breaches and cyberattacks are becoming increasingly common. He is always ahead of what is coming next, and you’d think he’s got his crystal ball. He’s a leader who inspires confidence and empowers organizations to embrace the digital age without fear. With Douglas at the helm, organizations can rest assured that their data is safe, allowing them to focus on their core business objectives and drive growth in the digital economy. Douglas is a heavyweight in his field, with over three decades of experience in information governance, data privacy, cybersecurity, and dispute consulting is second to none. His unique approach, blending technical expertise with a light-hearted touch, sets him apart, making the complex world of cybersecurity and privacy more accessible and engaging. His unique ability to break down complex technical concepts into easy-to-understand language has made him a sought-after speaker at industry events and conferences. | — | ||||||
| 12/10/25 | ![]() Scaling Open Source Observability and Managing Risk in the Software Supply Chain – Avi Press | Scaling Open Source Observability and Managing Risk in the Software Supply Chain – Avi PressIn this episode of the Security Repo Podcast, Avi Press, founder and CEO of Scarf, dives deep into the evolving world of open source observability and its intersection with security. He unpacks how better visibility into software usage can inform both defensive strategies and smarter commercialization, while raising concerns over the concentrated risk in critical open source dependencies. Avi also shares his thoughts on dependency management, security tooling, and the importance of nuanced data collection in a privacy-conscious world.https://about.scarf.sh/Avi Press is the Founder and CEO of Scarf, a company focused on open source usage analytics. We process over 2 billion open source package downloads every day. Open source maintainer and advocate. Functional programming enthusiast. Avi serves on the Haskell Foundation board, as well as the Haskell.org committee. Avi is a former engineer at Pandora and is based in Oakland, California | — | ||||||
| 12/3/25 | ![]() Decoding Threat Actor Names: Marketing, Confusion & the MITRE Solution – Jeffrey Bell | In this episode of the Security Repo Podcast, Jeffrey Bell, Principal Security Engineer and founder of CatchingPhish.com, discusses the confusion surrounding the naming conventions of threat actor groups across different security vendors. He explains how companies like CrowdStrike, Palo Alto, and Mandiant label the same adversaries with different names due to marketing and commercialization pressures, creating challenges for threat intelligence. Jeffrey also introduces MITRE ATT&CK Groups as a reliable, centralized resource to demystify these aliases and strengthen defenses based on shared TTPs.https://catchingphish.comhttps://attack.mitre.org/groups/https://github.com/mcdwayne/mitre-gang-lookupJeffrey Bell is a Principal Information Security Engineer and Threat Intelligence Lead at a Pharmaceutical Intelligence company. He graduated from UNC-Charlotte with a B.S. in Computer Science, specializing in Cybersecurity. Jeffrey has over 6 years of experience in Threat Intelligence, Incident Response, and Security Engineering. When not working, he writes for his blog, catchingphish.com, and loves to ski! He currently live near the beach in North Carolina. | — | ||||||
| 11/26/25 | ![]() Why Technical CISOs Matter and How AI Is Shaping Security Ops - David Cross on Leading Security | In this episode of the Security Repo Podcast, David Cross, CISO at Atlassian and former Microsoft, Google, and Oracle security leader, shares his journey from Navy electronic warfare to global cybersecurity leadership. He offers hard-won insights on breaking into the industry, the evolving demands of the CISO role, and the practical impacts of AI on security operations. David also delivers candid advice for aspiring professionals and emphasizes the value of veterans in the cybersecurity workforce.https://www.linkedin.com/in/david-b-cross-b856657/David started his work in security with his five years’ active-duty service with the aviation electronic warfare community of the United States Navy. David was awarded with numerous honors including a Navy Achievement Medal, Southwest Asia Service Medal, Armed Forces Service Medal and NATO medal for his combat-based tours. David is now the CISO for Atlassian after 6.5 years as the CISO for the Oracle SaaS Cloud Security organization. Previously, David was a Director and built the Google Cloud Security Engineering organization for 3 years with his preceding 18 years spent with Microsoft in numerous security platform, cloud, product and engineering leadership roles. David is also a Venture Partner with Rain Capital VC. David holds a B.S. in CIS as well as an MBA with a MIS concentration along with 30+ issued patents with all in security technology related areas. | — | ||||||
| 11/19/25 | ![]() Identity Risks in Email: Your Inbox Might Be Lying About You – Amy Devine | In this episode of the Security Repo Podcast, Dwayne McDaniel sits down with Amy Devine, a systems architect who transitioned from embedded wireless systems to cybersecurity. Amy shares the eye-opening story behind her Blue Team Con talk on how misdirected emails exposed sensitive personal data and what that means for digital identity. The conversation dives deep into privacy, data brokers, and what we sacrifice when companies prioritize convenience over security.https://github.com/bitsdanceforme/email_scrubbinghttps://bitsdanceforme.blog/https://www.linkedin.com/in/bitsdanceforme/Amy Devine worked in embedded systems development of wireless protocols before switching over to cybersecurity. She currently works as a Systems Architect for AV while also contributing to her cybersecurity community. Her talks to the local community include securing your email and how to avoid online scams. When she’s not sitting at a keyboard, you can find her working out in her other happy place - her home gym. Or running errands. Or trying to keep up with her kid. Or sleeping. You can find her online at her somewhat out of date website https://bitsdanceforme.blog/She has a bachelors in Computer Engineering from the University of Illinois and a masters in cybersecurity from DePaul University. | — | ||||||
| 11/12/25 | ![]() From Military Intel to CISO: Navigating Security Leadership in the Age of AI – Darren Desmond | In this episode of the Security Repo Podcast, we sit down with Darren Desmond, a seasoned CISO with a background in UK military intelligence, to unpack his unconventional journey from fish and chips to threat intelligence. He shares how his military forensics experience shaped his InfoSec leadership and dives deep into the evolving role of the CISO in a world increasingly driven by AI. Darren also gives candid insights into AI governance, red flags in hiring, and why the basics of cybersecurity still matter most.https://www.linkedin.com/in/desmondo/Darren Desmond is an information security leader and Certified Information Systems Security Professional with diverse experience in security risk management within the UK Defence sector, global online gambling industry, a major UK telecommunications & media company, a ‘Big Four’ managed services company and latterly as the CISO at one of the UK’s most recognizable brands. | — | ||||||
| 11/5/25 | ![]() Mapping the InfoSec Community: Building InfoSecMap & Global Security Events – Martín Villalba | In this episode of the Security Repo Podcast, we sit down with Martín Villalba, founder of InfoSecMap, to explore how his platform is transforming the way InfoSec professionals discover global events, communities, and CFPs. We dive into the origin story of InfoSecMap, its recent growth surge, and its strategic partnerships with organizations like OWASP. Martín also shares practical advice on building strong security cultures and the importance of addressing root causes over chasing vulnerabilities.https://infosecmap.com/LinkedIn: https://www.linkedin.com/in/wmvillalba/Twitter:https://twitter.com/act1vand0W. Martín VillalbaFounder & Principal, C13 SecurityFounder & Principal, InfoSecMapMartín is an application and product security consultant with over 15 years of industry experience. He founded C13 Security, where he specializes in Secure SDLC, pentesting, and vulnerability management. He is an active member of the InfoSec community, collaborating with local groups and global organizations such as BSides and OWASP. He also built InfoSecMap, an open-access platform for discovering InfoSec events and communities from all around the world. | — | ||||||
| 10/29/25 | ![]() Supply Chain Warfare: CI/CD Threats and Open Source Security with François Proulx | Supply Chain Warfare: CI/CD Threats and Open Source Security with François ProulxIn this episode of the Security Repo Podcast, François Proulx, VP of Security Research at Boost Security, discusses the evolving threats in software supply chain security, particularly focusing on attacks targeting CI/CD pipelines. He explains how open source tools like "Poutine" are being used both defensively and offensively in the ongoing battle to secure build systems. François also shares his journey into security, lessons from working at Intel, and practical advice on dependency pinning, short-lived credentials, and password best practices.https://www.linkedin.com/in/francoisp/https://boostsecurity.io/blog/unveiling-poutine-an-open-source-build-pipelines-security-scanner[https://nsec.io /](https://nsec.io/)François is VP of Security Research at BoostSecurity, where he leads the Supply Chain research team. With over 10 years of experience in building AppSec programs for large corporations (such as Intel) and small startups he has been in the heat of the action as the DevSecOps movement took shape. François is one of founders of NorthSec and was a challenge designer for the NorthSec CTF. | — | ||||||
| 10/22/25 | ![]() Fighting Tool Squatting And Prompt Injection & The Security Gaps In MCP – Srajan Gupta | In this episode of the Security Repo Podcast, we welcome Srajan Gupta, a security engineer exploring the evolving security implications of Model Context Protocol (MCP) servers. Shrojan breaks down how MCPs act as AI connectors to external systems and the alarming rise in attack surfaces, including tool squatting and indirect prompt injections. The conversation dives into emerging threats, authorization challenges, and how securing MCPs mirrors early API and cloud security lessons.Srajan Gupta is a security engineer and builder focused on uncovering how systems fail — not just through vulnerabilities, but through the architecture itself. With a background in application security, platform engineering, and threat modeling, Srajan works at the intersection of usability and risk, helping teams identify and address design-level security flaws before they become incidents.Srajan is passionate about building practical security tools, automating guardrails, and making threat modeling an everyday engineering skill.Blog - https://srajangupta.substack.com/BSides LV talk - https://www.youtube.com/watch?v=Wld0VVRMN4c&t=21977shttps://www.linkedin.com/in/srajan-gupta/Their research often explores trust boundaries, secure defaults, and the hidden assumptions baked into the applications and infrastructure. They are especially interested in how attackers exploit the gray areas between platforms, automation, and access controls — and how defenders can close those gaps without slowing down delivery. | — | ||||||
| 10/15/25 | ![]() Fixing Hiring, Fostering Diversity, and Finding Your Place in Security – Matt Torbin | In this episode of the Security Repo Podcast, we sit down with Matt Torbin to explore his inspiring journey from jazz musician to cybersecurity advocate and leader. We dive deep into the origins and impact of Day of Shecurity, a one-day conference aimed at increasing representation and mentorship for women and non-binary individuals in infosec. Matt also shares innovative ideas around fixing the broken technical interview process, mentorship, and his passion for building inclusive, opportunity-rich communities in cybersecurity.Day of Shecurity:https://securediversity.org/dos/Matt's talk from BSidesLV: “Your Interview Game is Weak: Gamifying Technical Interviews through Role-Playing” https://www.youtube.com/watch?v=3Ih-ul9qe3E&t=14985sLearn more about Fabric: https://github.com/danielmiessler/fabricMatt Torbin has been a driving force in secure software development for over 20 years, influencing all aspects of the software development lifecycle. He began his career as a full-stack engineer with a focus on UI/UX, creating user experiences for renowned brands including the Philadelphia Inquirer, Anthropologie, and VEVO, engaging millions of users.In the last several years, Matt has shifted his focus to information security. In his current role as the Manager of Application Security at Quanata, he collaborates closely with product and engineering teams to advance product security best practices and deliver comprehensive security training. His industry contributions span public speaking, authorship, and community involvement. He has presented at conferences such as DEF CON, BSidesLV, and Day of Shecurity (DoS), authored privacy articles for 2600 Magazine: The Hacker Quarterly, and held key volunteer roles in initiatives including the Packet Hacking Village, Day of Shecurity, and BSidesSF. Among his achievements, he co-founded the DoS conference, realizing his vision for a more inclusive event.Outside of work, Matt mentors emerging professionals in the DoS community. A passionate skateboarder and longboarder, he often spends time with his son at skate parks throughout the San Francisco Bay Area. | — | ||||||
| 10/8/25 | ![]() Dev Engagement in Security: From Content Strategy to Community Strategy with Alyssa Miles | In this episode of the Security Repo Podcast, we chat with Alyssa Miles, a product marketing leader at CyberArk, about building authentic developer communities in the security space. She shares her journey from agency marketing to driving developer engagement, along with insights from Hacker Summer Camp and strategies for enabling community-driven identity tooling. Alyssa also discusses how to shift from traditional marketing to true enablement and why "thinking like a hacker" is key to building impactful security communities.https://lp.cyberark.com/20251110-cyberark-workload-identity-day-zero-atlanta-registration.htmlhttps://www.linkedin.com/in/alyssanoellemiles/https://infocondb.org/con/def-con/def-con-33/thinking-like-a-hacker-in-the-age-of-aiAlyssa is a product marketing leader passionate about making security easy for developers. At CyberArk, she drives developer experience initiatives that help platform engineers, DevOps teams, and cloud security pros adopt identity tools that fit naturally into their workflows. She also leads efforts to grow and engage CyberArk’s developer community. When she's not working, she's probably driving her ten-year-old daughter to ballet or hanging out at a brewery. | — | ||||||
| 10/1/25 | ![]() Beyond Controls: Building Trust and Communication in Security – Featuring AriaDear | In this episode of the Security Repo Podcast, Aria Langer returns to share deep insights from her work in privileged access management and the challenges of implementing security controls without alienating coworkers. She and Dwayne dive into the often-overlooked importance of empathy in cybersecurity, exploring how human connection can make security efforts more effective. The conversation touches on the cultural shifts needed in security teams, how storytelling can foster understanding, and the risks of relying too heavily on tools like AI without understanding their underlying mechanics.What you need to know about AriaDear is that she’s a Security Engineer by day, DuckBurg resident by night!Been working in SecOps for almost 5 years, specializing in Privilege Access ManagementHave spoken at BlueTeamCon, ChibrrCon and the Defcon Furs village on that topic. | — | ||||||
Showing 25 of 134
Pitch Fit is a Pro feature
See how bookable this show is for guests, which brands already advertise, the per-episode ad value, and the best-fit guest and sponsor profile. The numbers are blurred on the free plan.
How readily this show books outside guests like you.
How proven this show is for host-read sponsorships.
For Guests
ProFor Advertisers
ProUpgrade to Pro to unlock guest cadence, sponsor categories, fit scores, and per-episode ad value for this show.
