World Congress 2021 • Jun 30, 2021

Building Security Champions

Tanya Janca

Stop bottlenecking your DevOps pipeline due to AppSec staffing shortages. Discover a practical, six-step framework to transform everyday developers into an active first line of defense as security champions.

Pause
Mute Enter Fullscreen
#1 about 5 min

Scaling security teams through developer advocates

Why organizations must rely on software developers to overcome the severe shortage of application security professionals.

#2 about 3 min

Defining the security champion role in software teams

How interested developers act as the primary security advocate and first line of defense within their teams.

#3 about 4 min

Recruiting the right security champions without forcing participation

Strategies to attract volunteers by providing opportunities for developers to reveal their interest naturally.

#4 about 7 min

Engaging software developers deeply in secure engineering practices

Methods to involve champions deeply through incident response participation, appropriate secret sharing, and team building.

#5 about 11 min

Teaching and coaching security concepts for lasting impact

Providing scoped training on secure coding, architecture, and tooling while delegating appropriate responsibilities effectively.

#6 about 3 min

Recognizing champion efforts publicly and formally

How to provide meaningful recognition in performance reviews and among peers to validate supplementary work.

#7 about 3 min

Rewarding champions for positive security behaviors

Reinforcing effective behavior with security-related gifts, dedicated mentoring time, and varied tokens of appreciation.

#8 about 6 min

Maintaining long-term momentum and consistency in security programs

Why treating security culture as a continuous practice prevents program collapse and ensures long-term viability.

#9 about 10 min

Audience Q&A on security risks and team models

Questions concerning artificial intelligence risks, managing security incidents, and structuring team representation appropriately.

Matching moments

48 sec

Scaling knowledge through security champions programs

Stefania Chaplin · World Congress 2022

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

12:35 min

Q&A on security automation and building champions programs

Mathias Tausig · LIVE

2:39 min

Establishing a center of excellence and security champions

Nazneen Rupawalla · World Congress 2022

2:27 min

Nominating accountable security champions to drive adoption

Nazneen Rupawalla · World Congress 2022

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 11:00–11:30

Stage 6

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

September 25, 2026 · 15:00–17:00

Stage 12

Secure development from pull request to production with GitHub

Sam Jarvinen

Senior Solutions Engineer, GitHub

Sam Jarvinen
Open session

World Congress 2026 North America

September 24, 2026 · 16:00–18:00

Stage 11

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

September 23, 2026 · 15:45–17:45

Stage 10

Securing the Agentic Stack: Docker Hardened Images and Supply Chain Security

Ajeet Raina

Developer Advocate, Docker

Ajeet Raina
Open session

World Congress 2026 North America

September 25, 2026 · 09:00–09:30

Stage 4

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

September 25, 2026 · 13:30–14:00

Stage 9

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy