World Congress 2022 • Jun 15, 2022

Organizational Change Through The Power Of Why - DevSecOps Enablement

Nazneen Rupawalla

Why does application security constantly stall deployments? Learn how explaining the business context and empowering developer champions transforms security from a late-stage bottleneck into a seamless agile workflow.

Pause
Mute Enter Fullscreen
#1 about 4 min

Identifying bottlenecks in traditional software security approaches

Discover why centralizing secure development responsibilities within an infosec team creates friction and limited scalability.

#2 about 3 min

Establishing a center of excellence and security champions

How building a security center of excellence and establishing an empowered champions program drives cultural change.

#3 about 2 min

Embedding security controls into project management tools

Map security requirements directly into existing developer workflows utilizing standard issue tracking boards.

#4 about 3 min

Contextualizing the why and how of security requirements

Providing real-world threat context and specific implementation guidance helps developers understand the value of secure coding.

#5 about 2 min

Pairing with teams for continuous threat modeling

Mentor security champions in identifying system vulnerabilities using established threat modeling methodologies during product kickoff.

#6 about 2 min

Integrating security scanning tools early in the pipeline

Implement standard security tooling directly into the build and deployment lifecycle to prevent vulnerabilities from reaching production.

#7 about 3 min

Automating compliance tracking with customized project dashboards

Utilize simple scripting and webhooks to generate team-specific project boards and visualize real-time security progress.

#8 about 3 min

Visualizing organizational risks through a maturity model

Aggregate team-level security data into an overarching framework to facilitate meaningful discussions with governance forums.

#9 about 3 min

Nominating accountable security champions to drive adoption

Why asking technical leads to actively select members builds stronger accountability than relying on pure volunteers.

#10 about 4 min

Structuring implementation timelines and threat modeling cadence

Determine the time investment required to establish proactive security processes and establish cadence for threat modeling.

Matching moments

2:57 min

Securing team and management buy-in for DevSecOps adoption

Moataz Nabil Moataz Nabil · LIVE

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

4:58 min

Scaling security teams through developer advocates

Tanya Janca · WWC 2021

48 sec

Scaling knowledge through security champions programs

Stefania Chaplin · WWC 2022

6:32 min

Embracing DevSecOps and automating the software development lifecycle

Mathias Tausig · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

Your Threat Model Is Lying to You: Why Modeling the Design Isn’t Enough in 2026

Farshad Abasi

CEO/Founder, Eureka DevSecOps + Forward Security

Farshad Abasi
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

It passed auth, then production caught fire

Alex Olivier

Co-founder & CPO @ Cerbos | OpenID AuthZEN Co-chair

Alex Olivier