World Congress 2022 Jun 15, 2022

Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together

Stefania Chaplin

Relying on a few security champions when developers outnumber them 100-to-1 is a recipe for burnout. Discover how to seamlessly integrate contextual security remediation into your CI/CD workflows.

Pause
Mute Enter Fullscreen
#1 about 3 min

The lifecycle and cost of recurring security bugs

The cycle of discovering, ticketing, and repeatedly fixing the same security vulnerabilities causes developer friction.

#2 about 2 min

Expanding threat awareness beyond top ten lists

Human error and semantic flaws create unique vulnerabilities outside of standard compliance lists.

#3 about 1 min

Addressing developer burnout and context switching

Context switching from changing requirements and repeating bug fixes directly contributes to developer fatigue.

#4 about 3 min

Breaking down silos between developers, security, and ops

Realigning conflicting metrics between departments reduces infrastructural misconfigurations and overall business risk.

#5 about 1 min

Scaling knowledge through security champions programs

Equipping everyday developers with targeted security knowledge bridges the numerical gap between development and security teams.

#6 about 2 min

Leveraging free tools for application security auditing

Utilizing open source applications and dependency checkers builds a more secure baseline before code shifts to production.

#7 about 4 min

Integrating security testing and training in pipelines

Embedding static code analysis and contextual vulnerability training directly into developer commits accelerates remediation.

#8 about 3 min

Balancing workflow efficiency with personal developer wellness

Allocating dedicated time to upskill and addressing technical debt helps maintain both project velocity and mental health.

#9 about 3 min

Prioritizing professional empathy and technical debt reduction

Approaching security gaps as addressable technical debt rather than personal failures fosters better team collaboration.

#10 about 2 min

Transitioning from software development to security roles

Leveraging internal conversations and a strong developer foundation provides a practical pathway into cybersecurity.

#11 about 3 min

Exploring diverse resources for continuous security learning

Engaging with video tutorials, ethical hacking labs, internal hackathons, and local meetups broadens threat awareness.

#12 about 1 min

Exploring offensive security with red team tooling

Using offensive penetration testing platforms helps practical defenders understand how threat actors manipulate systems.

Matching moments

4:58 min

Scaling security teams through developer advocates

Tanya Janca · WWC 2021

2:30 min

Bridging the gap between developers and security tools

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

1:00 min

Encouraging broader team adoption of security automation practices

Ramona Schwering Ramona Schwering · WWC 2024

3:58 min

Identifying bottlenecks in traditional software security approaches

Nazneen Rupawalla · WWC 2022

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois