Ahead of the Breach
Eptura’s Sean Finley on Building Risk-Based Application Security Programs
28 Jan 2025
What if vulnerability management was less about filling backlogs with findings and more about strategic risk reduction? Sean Finley, Director of Application & Product Security at Eptura, brings a refreshing perspective to application security to his conversation with Casey on this episode of Ahead of the Breach. Shaped by years of experience as both a software analyst and security leader, his approach challenges the traditional "dump truck of data" mentality, instead advocating for thoughtful prioritization and strong stakeholder partnerships. From building bridges with development teams to making the case for security investments to business leaders, Sean shares practical wisdom for creating AppSec programs that truly serve organizational goals while keeping risks in check. Topics discussed: Understanding the limitations of traditional vulnerability management and why flooding backlogs with findings doesn't equate to effective security. Building strategic partnerships with business stakeholders to ensure security efforts align with organizational priorities and risk tolerance. Integrating security tools seamlessly into developer workflows to reduce friction and increase adoption across engineering teams. Advocating for security considerations during the design phase to prevent costly fixes and potential data breaches later. Managing the delicate balance between development speed and security requirements in modern Agile environments. Creating effective risk-based approaches to vulnerability prioritization based on business context and threat intelligence. Developing strategies for earning developer trust and respect while educating teams about security concepts and threats. Implementing repeatable security processes that work across different release cadences, from quarterly to daily deployments. Building quality assurance into the software development lifecycle through consistent security testing and validation. Fostering a collaborative security culture that emphasizes enablement rather than obstruction or purely compliance-driven approaches.
No persons identified in this episode.
This episode hasn't been transcribed yet
Help us prioritize this episode for transcription by upvoting it.
Popular episodes get transcribed faster
Other recent transcribed episodes
Transcribed and ready to explore now
Eric Larsen on the emergence and potential of AI in healthcare
10 Dec 2025
McKinsey on Healthcare
Reducing Burnout and Boosting Revenue in ASCs
10 Dec 2025
Becker’s Healthcare -- Spine and Orthopedic Podcast
Dr. Erich G. Anderer, Chief of the Division of Neurosurgery and Surgical Director of Perioperative Services at NYU Langone Hospital–Brooklyn
09 Dec 2025
Becker’s Healthcare -- Spine and Orthopedic Podcast
Dr. Nolan Wessell, Assistant Professor and Well-being Co-Director, Department of Orthopedic Surgery, Division of Spine Surgery, University of Colorado School of Medicine
08 Dec 2025
Becker’s Healthcare -- Spine and Orthopedic Podcast
NPR News: 12-08-2025 2AM EST
08 Dec 2025
NPR News Now
NPR News: 12-08-2025 1AM EST
08 Dec 2025
NPR News Now