Uploaded December 2025 | Updated September 2026, 1 week ago
This talk is a postmortem of a well-intentioned but ultimately failed Application Security program—led by a solo AppSec engineer who tried to do everything, too fast, without consensus. It’s not a case study in success. It’s a breakdown of how security can go wrong even when the ideas are sound, the tooling is industry-standard, and the motivation is genuine.
Over the course of 18 months, I went from planning a robust, scalable AppSec strategy to alienating engineering teams, breaking trust, and unintentionally turning automation into friction. From SAST and container scanning to OWASP SAMM assessments and visibility dashboards, the pieces were there -- but the delivery and alignment weren’t. What followed was organizational silence, resentment, and eventual collapse of both budget and collaboration.
This talk will walk through where the program failed, what I would do differently, and what signals security teams should watch for -- especially if they’re working solo, without resourcing, and under pressure to “just make it work.” Most importantly,I will talk about how to rebuild -- not just pipelines or tooling -- but credibility.
Thomas Jost
Senior Application Security Engineer
Writes code. Builds security programs. Lights fires, and talks so you don't have to.
thomasjost.com (blog)
linkedin.com/in/mmtjost
Managed by the OWASP® Foundation
owasp.org
This talk is a postmortem of a well-intentioned but ultimately failed Application Security program—led by a solo AppSec engineer who tried to do everything, too fast, without consensus. It’s not a case study in success. It’s a breakdown of how security can go wrong even when the ideas are sound, the tooling is industry-standard, and the motivation is genuine.
Over the course of 18 months, I went from planning a robust, scalable AppSec strategy to alienating engineering teams, breaking trust, and unintentionally turning automation into friction. From SAST and container scanning to OWASP SAMM assessments and visibility dashboards, the pieces were there -- but the delivery and alignment weren’t. What followed was organizational silence, resentment, and eventual collapse of both budget and collaboration.
This talk will walk through where the program failed, what I would do differently, and what signals security teams should watch for -- especially if they’re working solo, without resourcing, and under pressure to “just make it work.” Most importantly,I will talk about how to rebuild -- not just pipelines or tooling -- but credibility.
Thomas Jost
Senior Application Security Engineer
Writes code. Builds security programs. Lights fires, and talks so you don't have to.
thomasjost.com (blog)
linkedin.com/in/mmtjost
Managed by the OWASP® Foundation
owasp.org










