World Congress 2022 Jun 15, 2022

Organizational Change Through The Power Of Why - DevSecOps Enablement

Nazneen Rupawalla

Why does application security constantly stall deployments? Learn how explaining the business context and empowering developer champions transforms security from a late-stage bottleneck into a seamless agile workflow.

Pause
Mute Enter Fullscreen
#1 about 4 min

Identifying bottlenecks in traditional software security approaches

Discover why centralizing secure development responsibilities within an infosec team creates friction and limited scalability.

#2 about 3 min

Establishing a center of excellence and security champions

How building a security center of excellence and establishing an empowered champions program drives cultural change.

#3 about 2 min

Embedding security controls into project management tools

Map security requirements directly into existing developer workflows utilizing standard issue tracking boards.

#4 about 3 min

Contextualizing the why and how of security requirements

Providing real-world threat context and specific implementation guidance helps developers understand the value of secure coding.

#5 about 2 min

Pairing with teams for continuous threat modeling

Mentor security champions in identifying system vulnerabilities using established threat modeling methodologies during product kickoff.

#6 about 2 min

Integrating security scanning tools early in the pipeline

Implement standard security tooling directly into the build and deployment lifecycle to prevent vulnerabilities from reaching production.

#7 about 3 min

Automating compliance tracking with customized project dashboards

Utilize simple scripting and webhooks to generate team-specific project boards and visualize real-time security progress.

#8 about 3 min

Visualizing organizational risks through a maturity model

Aggregate team-level security data into an overarching framework to facilitate meaningful discussions with governance forums.

#9 about 3 min

Nominating accountable security champions to drive adoption

Why asking technical leads to actively select members builds stronger accountability than relying on pure volunteers.

#10 about 4 min

Structuring implementation timelines and threat modeling cadence

Determine the time investment required to establish proactive security processes and establish cadence for threat modeling.

Matching moments

2:57 min

Securing team and management buy-in for DevSecOps adoption

Moataz Nabil Moataz Nabil · LIVE

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

4:58 min

Scaling security teams through developer advocates

Tanya Janca · World Congress 2021

48 sec

Scaling knowledge through security champions programs

Stefania Chaplin · World Congress 2022

6:32 min

Embracing DevSecOps and automating the software development lifecycle

Mathias Tausig · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 24, 2026 · 14:50–15:20

Stage 1

The Era of Machine-Driven Defense is Here: Headless Security

Loris Degioanni

Founder & CTO of Sysdig

Loris Degioanni
Open session

World Congress 2026 North America

September 25, 2026 · 15:00–17:00

Stage 12

Secure development from pull request to production with GitHub

Sam Jarvinen

Senior Solutions Engineer, GitHub

Sam Jarvinen
Open session

World Congress 2026 North America

September 24, 2026 · 16:00–18:00

Stage 13

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

September 23, 2026 · 15:45–17:45

Stage 10

Securing the Agentic Stack: Docker Hardened Images and Supply Chain Security

Ajeet Raina

Developer Advocate at Docker

Ajeet Raina
Open session

World Congress 2026 North America

September 24, 2026 · 16:10–16:40

Stage 7

Your Threat Model Is Lying to You: Why Modeling the Design Isn’t Enough in 2026

Farshad Abasi

CEO/Founder, Eureka DevSecOps + Forward Security

Farshad Abasi
Open session

World Congress 2026 North America

September 25, 2026 · 13:30–14:00

Stage 9

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy