World Congress 2021 Jun 30, 2021

Building Security Champions

Tanya Janca

Stop bottlenecking your DevOps pipeline due to AppSec staffing shortages. Discover a practical, six-step framework to transform everyday developers into an active first line of defense as security champions.

Pause
Mute Enter Fullscreen
#1 about 5 min

Scaling security teams through developer advocates

Why organizations must rely on software developers to overcome the severe shortage of application security professionals.

#2 about 3 min

Defining the security champion role in software teams

How interested developers act as the primary security advocate and first line of defense within their teams.

#3 about 4 min

Recruiting the right security champions without forcing participation

Strategies to attract volunteers by providing opportunities for developers to reveal their interest naturally.

#4 about 7 min

Engaging software developers deeply in secure engineering practices

Methods to involve champions deeply through incident response participation, appropriate secret sharing, and team building.

#5 about 11 min

Teaching and coaching security concepts for lasting impact

Providing scoped training on secure coding, architecture, and tooling while delegating appropriate responsibilities effectively.

#6 about 3 min

Recognizing champion efforts publicly and formally

How to provide meaningful recognition in performance reviews and among peers to validate supplementary work.

#7 about 3 min

Rewarding champions for positive security behaviors

Reinforcing effective behavior with security-related gifts, dedicated mentoring time, and varied tokens of appreciation.

#8 about 6 min

Maintaining long-term momentum and consistency in security programs

Why treating security culture as a continuous practice prevents program collapse and ensures long-term viability.

#9 about 10 min

Audience Q&A on security risks and team models

Questions concerning artificial intelligence risks, managing security incidents, and structuring team representation appropriately.

Matching moments

48 sec

Scaling knowledge through security champions programs

Stefania Chaplin · WWC 2022

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

12:35 min

Q&A on security automation and building champions programs

Mathias Tausig · LIVE

2:39 min

Establishing a center of excellence and security champions

Nazneen Rupawalla · WWC 2022

2:27 min

Nominating accountable security champions to drive adoption

Nazneen Rupawalla · WWC 2022

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

Culture Doesn't Scale Itself: Leading Engineering Teams Through Hypergrowth and the AI Transition

Thanos Baskous

VP of Engineering and Co-founder of Cogent Security

Thanos Baskous