Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Kyser Clark - Cybersecurity. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Kyser Clark - Cybersecurity or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

#49 He Found Vulnerabilities in His Own Code: Then Made a Career Out of It ft. John Kounelis

41:06
 
Share
 

Manage episode 488216948 series 3583577
Content provided by Kyser Clark - Cybersecurity. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Kyser Clark - Cybersecurity or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

In this episode of The Hacker’s Cache, Kyser Clark interviews John Kounelis, a Senior Product Security Engineer with a background in software development and AppSec. John shares how discovering vulnerabilities in his own code led him to a full-time role in application security, and explains the key differences in AppSec across defense, biotech, and SaaS industries. They discuss the realities of bug bounty hunting, the limitations of CTFs, how developers unintentionally introduce vulnerabilities, and why understanding vulnerability chaining is critical for advanced web app testing. Whether you're transitioning from development to security or looking to sharpen your real-world pentesting skills, this episode delivers practical insight into what it truly takes to thrive in AppSec.

Connect with John Kounelis on LinkedIn: https://www.linkedin.com/in/john-k-765b42148/

Connect
---------------------------------------------------
https://www.KyserClark.com
https://www.KyserClark.com/Newsletter
https://youtube.com/KyserClark
https://www.linkedin.com/in/KyserClark
https://www.twitter.com/KyserClark
https://www.instagram/KyserClark
https://facebook.com/CyberKyser
https://twitch.tv/KyserClark_Cybersecurity
https://www.tiktok.com/@kyserclark
https://discord.gg/ZPQYdBV9YY
Music by Karl Casey @ White Bat Audio
Attention Listeners: This content is strictly for educational purposes, emphasizing ETHICAL and LEGAL hacking only. I do not, and will NEVER, condone the act of illegally hacking into computer systems and networks for any reason. My goal is to foster cybersecurity awareness and responsible digital behavior. Please behave responsibly and adhere to legal and ethical standards in your use of this information.
Opinions are my own and may not represent the positions of my employer.

  continue reading

Chapters

1. Introduction (00:00:00)

2. From Software Engineering to AppSec (00:03:00)

3. Rapid-Fire Questions (00:10:51)

4. Favorite Hacking Tool (00:14:58)

5. Community Question (00:19:20)

6. Vibe Coding (00:27:15)

7. AppSec Differences Across Industries (00:30:26)

8. What Pentesters Often Miss About Developers (00:33:57)

9. Final Thoughts & Wisdom (00:38:05)

50 episodes

Artwork
iconShare
 
Manage episode 488216948 series 3583577
Content provided by Kyser Clark - Cybersecurity. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Kyser Clark - Cybersecurity or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

In this episode of The Hacker’s Cache, Kyser Clark interviews John Kounelis, a Senior Product Security Engineer with a background in software development and AppSec. John shares how discovering vulnerabilities in his own code led him to a full-time role in application security, and explains the key differences in AppSec across defense, biotech, and SaaS industries. They discuss the realities of bug bounty hunting, the limitations of CTFs, how developers unintentionally introduce vulnerabilities, and why understanding vulnerability chaining is critical for advanced web app testing. Whether you're transitioning from development to security or looking to sharpen your real-world pentesting skills, this episode delivers practical insight into what it truly takes to thrive in AppSec.

Connect with John Kounelis on LinkedIn: https://www.linkedin.com/in/john-k-765b42148/

Connect
---------------------------------------------------
https://www.KyserClark.com
https://www.KyserClark.com/Newsletter
https://youtube.com/KyserClark
https://www.linkedin.com/in/KyserClark
https://www.twitter.com/KyserClark
https://www.instagram/KyserClark
https://facebook.com/CyberKyser
https://twitch.tv/KyserClark_Cybersecurity
https://www.tiktok.com/@kyserclark
https://discord.gg/ZPQYdBV9YY
Music by Karl Casey @ White Bat Audio
Attention Listeners: This content is strictly for educational purposes, emphasizing ETHICAL and LEGAL hacking only. I do not, and will NEVER, condone the act of illegally hacking into computer systems and networks for any reason. My goal is to foster cybersecurity awareness and responsible digital behavior. Please behave responsibly and adhere to legal and ethical standards in your use of this information.
Opinions are my own and may not represent the positions of my employer.

  continue reading

Chapters

1. Introduction (00:00:00)

2. From Software Engineering to AppSec (00:03:00)

3. Rapid-Fire Questions (00:10:51)

4. Favorite Hacking Tool (00:14:58)

5. Community Question (00:19:20)

6. Vibe Coding (00:27:15)

7. AppSec Differences Across Industries (00:30:26)

8. What Pentesters Often Miss About Developers (00:33:57)

9. Final Thoughts & Wisdom (00:38:05)

50 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play