Vulnerability Jail and the AI-Era AppSec Engineer
Three years ago, Jeevan Singh mapped out what an application security engineer needed to know. AI has rewritten the job since. Jeevan, Director of Security Engineering at Rippling, returns to unpack how his team polices thousands of engineers shipping 10x more code: a "vulnerability jail" that locks non-compliant teams out of the main branch, AI-reviewed extension requests, and homegrown agents that hunt for entire classes of vulnerabilities instead of one bug at a time. He and Chris debate whether AI has killed classic SAST and DAST, whether code review still needs a human in the loop, and whether bug bounty programs still make sense when the researchers on both sides are running the same models. Plus: one concrete move every AppSec leader can make this quarter. This episode is sponsored by Security Compass. Make modern software development secure, consistent, and provable. About Security Compass AI writes code faster than anyone reviews the design. Threats do not wait for an annual assessment. Security Compass models threats continuously and turns them into requirements developers act on, not a report read after ship. → Learn more about securing the AI-DLC with Security Compass This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it. About Corgea Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely. → Learn more about Corgea Connect with Jeevan Singh: → Jeevan Singh on LinkedIn Mentioned in this episode: → Rippling → Dwarkesh Patel: "The Rise and Fall of Agent Civilizations" (essay on the OpenAI–Hugging Face incident) Follow the Application Security Podcast: ➜ Home: appsecpodcast.com ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast Chapters: 00:00:00 - Cold open: vulnerability jail 00:00:55 - Meet Jeevan Singh 00:01:11 - Welcome and Robert's AI lab 00:02:37 - What gets Jeevan away from the machines 00:04:51 - Hardware projects with his son 00:06:20 - What's changed for the AppSec engineer since AI 00:08:17 - Shipping production code and fixing whole vulnerability classes 00:09:13 - Why AppSec has to become less collaborative 00:10:02 - From democratized vuln management to vulnerability jail 00:11:50 - How engineering reacted and the feature flag jail precedent 00:14:05 - From manual jail to automated checks 00:15:30 - An AI bot that reviews SLA extensions 00:16:06 - Can AI wipe out an entire vulnerability class? 00:17:36 - Building an anti-SSRF library and rolling it out 00:19:40 - Which AppSec skills matter now 00:22:28 - Validating all that AI-generated code 00:22:57 - Agents that hunt for vulnerability classes 00:24:38 - Is this the death of classic AppSec tools? 00:26:51 - Code review and humans in, on, and out of the loop 00:28:00 - Objective-based agents that find RCEs 00:28:59 - Build vs. buy for AppSec teams 00:31:29 - Advice for teams of one to five AppSec engineers 00:32:58 - Cutting SLAs to 3, 5, 7, and 10 days 00:34:31 - Parachuted in as the only AppSec engineer 00:37:59 - One investment to make this quarter 00:39:09 - The Hugging Face and OpenAI agent incident 00:40:13 - Is bug bounty dead? 00:42:19 - Key takeaways: be an engineer, run toward AI 00:43:53 - Wrap-up
- Chapters