> Markdown version of [/videos/193-building-security-champions](https://www.wearedevelopers.com/videos/193-building-security-champions). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Building Security Champions Stop bottlenecking your DevOps pipeline due to AppSec staffing shortages. Discover a practical, six-step framework to transform everyday developers into an active first line of defense as security champions. - **Speakers:** Tanya Janca - **Event:** World Congress 2021 - **Published:** June 30, 2021 - **Duration:** 48:02 - **URL:** https://www.wearedevelopers.com/videos/193-building-security-champions ## Summary Addressing the extreme staffing shortage of application security professionals, this presentation outlines a practical framework for scaling security by building a Security Champions program. Rather than bottlenecking approvals, organizations can cultivate developer advocates who act as a first line of defense within their own devops teams. Establishing this program requires a six-step recipe starting with organic recruitment, attracting volunteers through educational events rather than forced assignments. Once engaged through incident response shadowing and exclusive architectural discussions, champions must be taught applied skills. Security teams should focus solely on what developers need to know, such as threat modeling, secure coding, and utilizing SAST tools, rather than irrelevant theoretical concepts. To sustain this momentum, organizations must implement strong recognition structures, like logging security wins in official performance reviews, and gamify learning via CTF challenges. Ultimately, security culture is a continuous, yoga-like practice; maintaining consistent communication and continuous coaching ensures software development lifecycles remain resilient and secure over the long term. **Keywords:** application security programs, security champions advocacy, incident response shadowing, secure software development lifecycle, threat modeling sessions, SAST and SCA tools, security program scaling, CI/CD pipeline security, secure coding practices, developer security coaching, gamified coding CTF, vulnerability remediation training, appsec team collaboration, devops security integration, security compliance policies ## Chapters 1. **Scaling security teams through developer advocates** (00:02) — Why organizations must rely on software developers to overcome the severe shortage of application security professionals. 1. **Defining the security champion role in software teams** (05:01) — How interested developers act as the primary security advocate and first line of defense within their teams. 1. **Recruiting the right security champions without forcing participation** (07:47) — Strategies to attract volunteers by providing opportunities for developers to reveal their interest naturally. 1. **Engaging software developers deeply in secure engineering practices** (11:15) — Methods to involve champions deeply through incident response participation, appropriate secret sharing, and team building. 1. **Teaching and coaching security concepts for lasting impact** (17:19) — Providing scoped training on secure coding, architecture, and tooling while delegating appropriate responsibilities effectively. 1. **Recognizing champion efforts publicly and formally** (27:54) — How to provide meaningful recognition in performance reviews and among peers to validate supplementary work. 1. **Rewarding champions for positive security behaviors** (30:24) — Reinforcing effective behavior with security-related gifts, dedicated mentoring time, and varied tokens of appreciation. 1. **Maintaining long-term momentum and consistency in security programs** (32:44) — Why treating security culture as a continuous practice prevents program collapse and ensures long-term viability. 1. **Audience Q&A on security risks and team models** (38:21) — Questions concerning artificial intelligence risks, managing security incidents, and structuring team representation appropriately. ## Related Moments - [Scaling knowledge through security champions programs](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) (from " Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together") - [Shifting left and creating internal security champion programs](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) (from "Stranger Danger: Your Java Attack Surface Just Got Bigger") - [Q&A on security automation and building champions programs](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) (from "Maturity assessment for technicians or how I learned to love OWASP SAMM") - [Establishing a center of excellence and security champions](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) (from "Organizational Change Through The Power Of Why - DevSecOps Enablement") - [Nominating accountable security champions to drive adoption](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) (from "Organizational Change Through The Power Of Why - DevSecOps Enablement") - [Addressing the shortage of application security specialists](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) (from "How GitHub secures open source") ## Related Articles - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [I have a stream! Why it’s definitely worth speaking at tech conferences.](https://www.wearedevelopers.com/magazine/24-i-have-a-stream-why-it-s-definitely-worth-speaking-at-tech-conferences) ## Related Jobs - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Security Architect - AI](https://www.wearedevelopers.com/jobs/ext/1581899-security-architect-ai) at **ZEISS Group** - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Staff Engineer, Security Engineering Partners](https://www.wearedevelopers.com/jobs/ext/1187268-staff-engineer-security-engineering-partners) at **Twilio** - [Security Engineer](https://www.wearedevelopers.com/jobs/ext/1574416-security-engineer) at **Twilio** - [Senior Software Engineer](https://www.wearedevelopers.com/jobs/ext/15942-senior-software-engineer) at **GitHub**