About securing.dev
Welcome! My name is Keith Hoodlet; in case you couldn’t tell by the site name - my passion for technology resides at the intersection of Application Security and Software Development.
If you’re looking for information on what I do professionally, feel free to check out my LinkedIn profile. Likewise, if you’re interested in learning about the sort of trouble I’m getting up to, you can navigate to either my Mastodon or GitHub pages where I’m either talking about or working on various projects to help make software security easier for developers. You can also view some of the (usually off-topic) things I’m reading about over at Instapaper.
In terms of my other work, I am an Offensive Security Certified Professional (OSCP) as well as Offensive Security Web Assessor (OSWA) - and have previously been named as one of the world’s 50 Influential DevSecOps Professionals on Peerlyst (2019). I suspect that accolade is largely due to starting the Application Security Weekly podcast with Paul Asadoorian, where I acted as show host for episodes zero through fifty-five.
In addition to the podcast, back in 2017 I re-launched the InfoSec Mentors Project with the help of my friend and mentor - Jimmy Vo. This site ran successfully for a little over 3 years before we archived the project in 2020. At the height of its usage, the project had over 500 users and connected more than 165 people to mentors in the field. Someday I may go back and revive the site again - albeit with a more robust framework next time.
Anyway, between kicking off the InfoSec Mentors Project and my final episode with the podcast I worked at security companies such as Rapid7 and Bugcrowd. After leaving Bugcrowd to start the Application Security / DevSecOps program at Thermo Fisher Scientific, I eventually went on to become a Top 100 Security Researcher and MVP on the Bugcrowd platform under my hacker handle “andMYhacks” (2018). I have recently returned to the space after several years’ hiatus with a #1 finish in the first-ever U.S. Dept of Defense Chief Digital and Artificial Intelligence Office Bias Bounty contest 😈
Nowadays I spend most of my free time learning, thinking, discussing, and writing about complex problems. When I’m not doing that, I’m usually reading a book, cuddling with one of my two black cats, or traveling with my wife. As part of my travels I have delivered both talks and trainings globally on the topics of DevSecOps, Secure Software Development, Offensive Web Hacking, and Application Security - a trend I hope to continue for many years to come. Below you’ll find links to recordings for some of the talks and podcast interviews I’ve had the pleasure to give.
Oh, and if you find my writing useful or interesting, you are always welcome to support my content through Patreon. Thanks for stopping by; I hope you enjoy the content!
Cheers,
Keith // securingdev
Conference Talks
- BSides Dublin (2022) - Speaker, “Security is a Feature” (v2)
- GitHub Universe (2020) - Speaker, “Security is a Feature” (v1)
- DerbyCon 8.0 (2018) - Speaker, “Hacking the Tardis” (Mental Health & Wellness Village)
- OWASP AppSecDay Australia (2018) - Keynote Speaker, “We Broke the Build”
- InfoSec World Orlando (2018) - Speaker, “Attack Driven Development”
- HackFest Canada (2017) - Speaker, “Attack Driven Development”
- DerbyCon 7.0 (2017) - Trainer, “Offensive Web Hacking”
- DevSecCon Boston (2017) - Speaker, “Attack Driven Development”
- BSides Boston (2017) - Conference Organizer & Panel Moderator, “Breaking into InfoSec”
Podcast Appearances
- ZERO SIGNAL (Ep. 12) - Oct. 3, 2025
- Risky Business News (Ep. 198) - Sept. 8, 2025
- ZERO SIGNAL (Ep. 3) - Sept. 3, 2025
- MLSecOps Podcast - Apr. 2, 2025
- Application Security Weekly (Ep. 323) - Mar. 25, 2025
- Critical Thinking (Ep. 71) - May 16, 2024
- Application Security Weekly (Ep. 284) - May 6, 2024
- Application Security Weekly (Ep. 224) - Jan. 3, 2023
- Application Security Weekly (Ep. 200) - Jul. 8, 2022
- AppSec Engineer Podcast - Aug. 6, 2021
- AppSec Engineer Podcast - Mar. 11, 2021
- Application Security Weekly (Ep. 129) - Nov. 9, 2020
- Hacking Into Security (Ep. 29) - Oct. 16, 2020
- Risky Business Podcast (Ep. 588) - June 17, 2020
- Absolute AppSec (Ep. 43) - Jan. 15, 2019
- Paul’s Security Weekly (Ep. 564) - Jun. 20, 2018
- Risky Business Podcast (Ep. 483) - Jan. 17, 2018
- Application Security Weekly (Ep. 0) - Jan. 9, 2018 (main host through Ep. 55)
- Paul’s Security Weekly (Ep. 504) - May 10, 2017
- … and more! You can find additional content I’ve contributed to on YouTube