
Jonathan Rende of Checkmarx on why the model writing your code cannot also be the control that validates it, and why rules-based and AI-driven scanning turn out to find almost entirely different bugs.
In this episode I sit down with Jonathan Rende of Checkmarx. Jonathan worked with Fortify and SPI Dynamics back in the day, spent most of the last decade leading product teams in developer and DevOps tooling, and came back to security eighteen months ago because, as he puts it, this is the heart of the hurricane. His argument is that AI is a bigger disruption than the internet, SaaS, or mobile were, not because of any single capability, but because it hits roles, process, and productivity all at once.
We get into the two waves he has watched play out with CISOs and their CEOs, why the pendulum has swung back toward program and posture questions in the last quarter, what his research team found when they benchmarked deterministic and probabilistic scanning side by side, and why he thinks agentic AppSec raises the profile of the security team rather than automating it away.
In this episode:
● Why the first half of 2026 became a real inflection point rather than another AI talking point
● The two waves: engineering told to run at any cost, then the pendulum swinging back toward posture and program design
● Why functional AI-generated code and secure AI-generated code are still two different things
● Separation of church and state, and the conflict of interest in letting the model that generates code also validate it
● Benchmarking deterministic and AI-based scanning across dozens of open source projects, and why the overlap stayed consistently under 10%
● Fidelity, F1 scores, and the absence of real standards or shared benchmarks in AppSec
● Why an incentive to reduce risk and an incentive to sell tokens are not the same incentive
● Why agents free AppSec professionals for higher-order work, and why this is not a dark factory
● Shadow IT becoming shadow AI, and early scans where half surfaced models, agents, and MCP servers security teams did not know existed
● Why new threat vectors show up first in fast-moving unregulated companies while regulated ones see more code-level issues
● Low-priority vulnerabilities chained into real impact, and why backlogs now matter as much as incoming code
● What to change first: metrics defined up front, in-workflow AppSec, and security reviews that went from annual to monthly
Chapters:
0:00 Intro
0:18 Fortify, SPI Dynamics, and a decade in developer tooling
1:24 Why he came back to AppSec
2:54 Why the first half of 2026 was the inflection point
5:27 Two waves, and the pendulum swinging back
9:08 Functional AI code versus secure AI code
11:58 Layered defense and the condensed lifecycle
15:04 What agents free AppSec teams to actually do
17:50 Separation of church and state
20:15 Fidelity, F1 scores, and not selling tokens
23:25 New threat vectors and organizational maturity
25:47 Shadow AI and what the inventory scans found
27:58 What to change first in your AppSec program
30:44 Closing
Connect with Jonathan:
LinkedIn: https://www.linkedin.com/in/jonathanrende/
Checkmarx: https://checkmarx.com
Resilient Cyber: https://www.resilientcyber.io
Subscribe for more conversations with security practitioners and leaders.
#appsec #aisecurity #devsecops #shadowai #vulnerabilitymanagement #ciso
Flere episoder fra "Resilient Cyber"



Gå ikke glip af nogen episoder af “Resilient Cyber” - abonnér på podcasten med gratisapp GetPodcast.








