S2E4 - Varun Badhwar

S2E4 - Varun Badhwar

Update: 2025-01-27
Share

Description

In Season 2 Episode 4, we talk to Varun Badhwar, Founder & CEO @ Endor Labs.

We discuss the current state of application security, the challenges faced by development teams, and the importance of integrating security into the software development lifecycle. Varun shares insights from his previous experiences in building and acquiring cybersecurity companies, emphasizing the need for effective compliance strategies and the balance between platform solutions and best-of-breed tools. In this conversation, Varun Badhwar discusses the evolving landscape of cybersecurity, emphasizing the importance of compliance, product usability, and the integration of AI technologies like LLMs in vulnerability management. He highlights the need for a user-centric approach in AppSec, the challenges of providing context to engineers, and the future implications of AI in security governance.

Key Takeaways

- Endor Labs aims to make AppSec more engaging and effective.
- Many existing AppSec tools create friction between teams.
- The future of software development will involve AI-generated code.
- Understanding the software supply chain is crucial for security.
- Acquisitions in cybersecurity often fail due to integration issues.
- Founders must empathize with practitioner pain to build effective products.
- Compliance often drives security priorities in organizations.
- Effective integration of tools can enhance security outcomes.
- The industry needs to focus on enabling faster business operations.
- Balancing platform capabilities with best-of-breed tools is essential.
- Compliance is essential for sales enablement in cybersecurity.
- First-time founders should focus on product and distribution.
- User experience and developer experience are critical in AppSec products.
- Contextual information is vital for engineers to make informed decisions.
- Automation can help reduce noise in security alerts.
- Reachability analysis improves visibility in code dependencies.
- Impact assessment is crucial for effective vulnerability remediation.
- LLMs can assist in reasoning but need rules for effective application.
- AI governance is a growing concern in the software development space.
- The industry must adapt to the rapid advancements in AI technology.

Tune in to find out more!

Contacting Varun
* LinkedIn: https://www.linkedin.com/in/vbadhwar/
* Endor Labs: https://www.endorlabs.com/

Contacting Anshuman
* LinkedIn: ⁠⁠⁠⁠https://www.linkedin.com/in/anshumanbhartiya/
* X: ⁠⁠⁠⁠https://x.com/anshuman_bh
* Website: ⁠⁠⁠⁠https://anshumanbhartiya.com/
* ⁠⁠⁠⁠Instagram: ⁠⁠⁠https://www.instagram.com/anshuman.bhartiya

Contacting Sandesh
* LinkedIn: ⁠⁠⁠⁠https://www.linkedin.com/in/anandsandesh/
* X: ⁠⁠⁠⁠https://x.com/JubbaOnJeans
* Website: ⁠⁠⁠⁠https://boringappsec.substack.com/

Comments 
In Channel
S2E9 - Ali Mesdaq

S2E9 - Ali Mesdaq

2025-03-0344:27

S2E8 - Ankita Gupta

S2E8 - Ankita Gupta

2025-02-2443:10

S2E7 - Jonathan Cran

S2E7 - Jonathan Cran

2025-02-1745:40

S2E5 - Drew Dennison

S2E5 - Drew Dennison

2025-02-0142:15

S2E4 - Varun Badhwar

S2E4 - Varun Badhwar

2025-01-2747:05

S2E3 - Robert Wood

S2E3 - Robert Wood

2025-01-2044:05

S2E2 - Dustin Lehr

S2E2 - Dustin Lehr

2025-01-1348:52

S2E1 - Jimmy Mesta

S2E1 - Jimmy Mesta

2025-01-0654:00

S1E09 - Incidents

S1E09 - Incidents

2024-05-1337:48

S1E05 - Threat Modeling

S1E05 - Threat Modeling

2024-04-0101:01:47

S1E03 - Bug Bounties

S1E03 - Bug Bounties

2024-03-1801:11:17

S1E02 - First Security Hire

S1E02 - First Security Hire

2024-03-1101:07:31

loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

S2E4 - Varun Badhwar

S2E4 - Varun Badhwar

The Boring AppSec Podcast