> Markdown version of [/videos/360-building-security-champions?t=207](https://www.wearedevelopers.com/videos/360-building-security-champions?t=207). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Building Security Champions You can't hire your way out of the cybersecurity talent shortage. Scale application security organically by transforming enthusiastic developers into empowered security champions. - **Speakers:** Tanya Janca - **Event:** WeAreDevelopers LIVE - **Published:** February 24, 2022 - **Duration:** 42:40 - **URL:** https://www.wearedevelopers.com/videos/360-building-security-champions ## Summary The cybersecurity industry faces a severe talent shortage, making it impossible to secure every application merely by increasing workloads. To scale application security effectively, organizations must build a Security Champions program that transforms enthusiastic software developers into active security advocates. By empowering these local advocates to bridge the gap between development and security teams, security practices can scale organically without burning out dedicated professionals.<br><br>A successful program relies on a structured methodology of recruiting, engaging, teaching, and rewarding. Rather than forcing compliance, leaders should attract volunteers who already demonstrate curiosity during training sessions and secure their manager's approval to prevent organizational friction. Engaging these champions involves establishing regular touchpoints to ask how security can assist their current projects, alongside building trust by bringing them into incident response shadowing or sharing upcoming security tooling.<br><br>When training champions, it is vital to respect their time by teaching only the specific secure coding practices, architecture guidelines, and compliance frameworks like GDPR that they actually need. Recognizing their efforts through performance reviews, manager notifications, and tangible rewards reinforces this positive behavior. Ultimately, building a security culture requires continuous practice; maintaining regular communication and consistent programming, even during busy organizational periods, ensures the champions program remains a permanent and effective fixture in the development lifecycle. **Keywords:** security champions program, application security scaling, appsec program development, secure coding practices, developer engagement strategies, software security advocacy, incident response shadowing, vulnerability scanning workflows, gdpr compliance training, peer security mentoring, devops security integration, cross-team security collaboration, security culture building, developer retention and recognition ## Chapters 1. **Scaling application security to overcome professional shortages** (00:02) — A shortage of security professionals requires scaling application security programs to secure all software applications effectively. 1. **Defining the role of a security champion** (03:27) — Security champions act as internal advocates who bridge the communication gap between security and development teams. 1. **Recruiting and identifying ideal security champions** (06:50) — Attracting passionate volunteers and gaining manager approval yields better results than forcing developers into the role. 1. **Engaging champions through collaboration and trust** (13:29) — Involving champions in incident response and sharing upcoming tools builds a strong, reciprocal working relationship. 1. **Teaching targeted security concepts to champions** (17:15) — Providing concise and relevant training respects their time while ensuring they grasp necessary security policies. 1. **Recognizing security champions for their contributions** (18:58) — Acknowledging efforts through performance reviews and peer validation emphasizes the value of the extra work performed. 1. **Rewarding positive security behaviors and efforts** (20:42) — Providing tangible rewards like training access or early tool previews reinforces continuous strong security practices. 1. **Maintaining program momentum through consistent communication** (22:51) — Regular check-ins and continuous communication prevent the security culture from deteriorating over long periods. 1. **Free resources for building security programs** (26:18) — Online communities, podcasts, and DevOps books provide ongoing self-guided education for securing software applications. 1. **Implementing champion models in small businesses** (29:44) — Short, targeted educational moments during all-staff meetings effectively integrate basic security and privacy into smaller organizations. 1. **How software developers can become champions** (33:10) — Consistently reporting vulnerabilities and showing enthusiasm for internal security projects naturally transitions developers into champion roles. 1. **Allocating security champions across development teams** (35:36) — Assigning one champion per development team ensures contextual security assistance without relying on a rigid company-wide percentage. 1. **Preventing champion burnout and securing management support** (39:23) — Transparent communication regarding real security incidents secures executive support and protects champions from excessive, unsupported workloads. ## Related Moments - [Scaling knowledge through security champions programs](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) (from " Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together") - [Defining the security champion role in software teams](https://www.wearedevelopers.com/videos/193-building-security-champions) (from "Building Security Champions") - [Scaling security teams through developer advocates](https://www.wearedevelopers.com/videos/193-building-security-champions) (from "Building Security Champions") - [Shifting left and creating internal security champion programs](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) (from "Stranger Danger: Your Java Attack Surface Just Got Bigger") - [Establishing a center of excellence and security champions](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) (from "Organizational Change Through The Power Of Why - DevSecOps Enablement") - [Recruiting the right security champions without forcing participation](https://www.wearedevelopers.com/videos/193-building-security-champions) (from "Building Security Champions") ## Related Articles - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) ## Related Jobs - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/2628442-staff-developer-advocate-github-security-lab) at **GitHub** - [Security Architect - Senior Associate](https://www.wearedevelopers.com/jobs/ext/2817742-security-architect-senior-associate) at **PwC** - [Senior Supply Chain Security Engineer](https://www.wearedevelopers.com/jobs/48462-senior-supply-chain-security-engineer) at **Docker, Inc.** - [SoC Security Architecture](https://www.wearedevelopers.com/jobs/ext/3020627-soc-security-architecture) at **ARM** - [Senior Principal Software Engineer, Docker and Ecosystem](https://www.wearedevelopers.com/jobs/48456-senior-principal-software-engineer-docker-and-ecosystem) at **Docker, Inc.** - [Staff Hardware Security Engineer](https://www.wearedevelopers.com/jobs/ext/1915092-staff-hardware-security-engineer) at **Arm**