DiscoverThe Application Security PodcastAkansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps
Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps

Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps

Update: 2025-09-02
Share

Description

Our guest today is Akansha Shukla, an information security professional with over 10 years of experience in application security, DevSecOps, and API security. We’re discussing why API security remains one of the least mature areas of AppSec today and exploring the challenges developers face when securing APIs. Akansha shares her insights on incorporating APIs into threat modeling exercises, the ongoing struggles with API discovery and inventory management, and the authorization challenges highlighted in the OWASP API Security Top 10. The conversation also touches on whether "shift left" is truly dead and why we still haven't solved basic security problems like input validation despite having the frameworks to address them.



FOLLOW OUR SOCIAL MEDIA:

➜Twitter: @AppSecPodcast
➜LinkedIn: The Application Security Podcast
➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast

Thanks for Listening!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps

Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps

Chris Romeo and Robert Hurlbut