Nazneen Rupawalla
Organizational Change Through The Power Of Why - DevSecOps Enablement
#1about 3 minutes
Why traditional security engagement creates bottlenecks
Security teams become a bottleneck when accountability is misplaced and feedback is provided too late in the development cycle.
#2about 1 minute
Creating a center of excellence for security
A center of excellence was established to make security planning scalable, measurable, and easier for teams to adopt.
#3about 3 minutes
Integrating security into existing team workflows
A security champion program and mapping controls into project management tools like Trello helps embed security into daily work.
#4about 4 minutes
Structuring security controls with the power of why
Each security control is framed with a 'why' to provide business context and a 'how' with actionable steps and tools.
#5about 3 minutes
Automating security tooling within the SDLC
Security tools for SAST, runtime security, and cloud misconfigurations are integrated into the CI/CD pipeline as acceptance criteria for controls.
#6about 2 minutes
Visualizing security progress with data-driven dashboards
Data from Trello boards is automatically collected via webhooks to create dashboards that track team progress on security controls.
#7about 3 minutes
Creating a security maturity model for leadership
Team-level data is aggregated into a high-level security maturity model to give leadership visibility and drive accountability.
#8about 1 minute
Building an effective security champion program
Nominating champions through tech leads, rather than relying on volunteers, increases the program's impact and motivation.
#9about 1 minute
Key takeaways for building a security culture
Explaining the 'why' behind security empowers teams to take ownership, while relationship building and automation are key to cultural change.
#10about 3 minutes
Q&A on program implementation and threat modeling
The discussion covers the program's 1.5-year implementation timeline, managing high-impact risks, and doing threat modeling every iteration.
Related jobs
Jobs that call for the skills explored in this talk.
Information Security Officer - Part-time (w/m/d)
aedifion GmbH
Köln, Germany
€30-45K
Intermediate
Network Security
Security Architecture
+1
Senior Backend Engineer Electrical Engineering
envelio
Köln, Germany
Remote
Senior
Python
Software Architecture
Matching moments
00:03 MIN
Why security teams must scale through developer collaboration
Building Security Champions
1:23:29 MIN
How to shift left with a security champions program
Stranger Danger: Your Java Attack Surface Just Got Bigger
16:02 MIN
Why security is a shared responsibility for every role
What The Hack is Web App Sec?
24:17 MIN
Shifting security left with collaborative threat modeling
We adopted DevOps and are Cloud-native, Now What?
28:01 MIN
Fostering a developer-first security culture
Walking into the era of Supply Chain Risks
00:03 MIN
From vulnerability researcher to automated security founder
The transformative impact of GenAI for software development and its implications for cybersecurity
15:05 MIN
Scaling AppSec teams by empowering developers
Why Security-First Development Helps You Ship Better Software Faster
00:17 MIN
The cultural shift from DevOps to DevSecOps
You can’t hack what you can’t see
Featured Partners
Related Videos
DevSecOps culture
Ali Yazdani
Building Security Champions
Tanya Janca
Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together
Stefania Chaplin
Real-world Threat Modeling
Ali Yazdani
Simple Steps to Kill DevSec without Giving Up on Security
Isaac Evans
Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?
Tino Sokic
Why Security-First Development Helps You Ship Better Software Faster
Michael Wildpaner
Security Pitfalls for Software Engineers
Jasmin Azemović
Related Articles
View all articles
.gif?w=240&auto=compress,format)

.png?w=240&auto=compress,format)
From learning to earning
Jobs that call for the skills explored in this talk.


Software Engineer - SDLC Security - Public Artifacts
Datadog
Paris, France
DevOps
Python
Kubernetes
Configuration Management

Application Security Consultants - Security by Design
Accenture
Municipality of Madrid, Spain
Scrum
DevOps
Agile Methodologies

Application Security Consultants - Security by Design
Accenture
Municipality of Madrid, Spain
Scrum
DevOps
Agile Methodologies




Security Architect - Privileged Access Management
Devoteam
IIS
Linux
Google Cloud Platform
Amazon Web Services (AWS)
Microsoft Active Directory

Security Solution Designer - (Application/SDLC/Segmentation)
DevNull Security
Sheffield, United Kingdom
Remote
£70-80K
UML
JIRA
Confluence