> Markdown version of [/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement?t=307](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement?t=307). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Organizational Change Through The Power Of Why - DevSecOps Enablement Why does application security constantly stall deployments? Learn how explaining the business context and empowering developer champions transforms security from a late-stage bottleneck into a seamless agile workflow. - **Speakers:** Nazneen Rupawalla - **Event:** World Congress 2022 - **Published:** June 15, 2022 - **Duration:** 26:50 - **URL:** https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement ## Summary Application security often stalls when it is treated as a delayed compliance step managed exclusively by external infosec teams. To prevent security from becoming a bottleneck, organizations must shift away from late-stage manual approvals toward decentralized, developer-owned accountability. By creating a center of excellence and integrating security controls directly into the project management tools teams already use, engineering units can plan, evaluate, and execute secure development directly within their standard agile rituals. Driving organizational change requires explaining the "why" behind security controls before detailing the "how." Providing business context—such as recent breach impact or adherence to the CIA triad—transforms abstract checklist requirements into clear value drivers for product owners. Practical execution is further embedded into CI/CD pipelines using tools like Talisman and Whisper for secrets management, Semgrep for SAST, Aqua for runtime security, and Scout Suite for AWS misconfigurations. Mapping these tasks through standard board workflows ensures security is treated as functional work rather than a disruptive external trigger. A successful DevSecOps cultural shift relies heavily on an empowered security champion program. Having tech leads actively nominate champions, rather than relying solely on volunteers, gives the role critical legitimacy and management backing. These upskilled champions can then facilitate lightweight, 30-minute STRIDE threat modeling sessions during standard iteration planning. Furthermore, tracking this progress against an OWASP SAMM-inspired maturity model using webhook-driven dashboards not only highlights risk for governance forums but organically gamifies security improvement across mission-critical teams. **Keywords:** devsecops enablement, application security posture, security champion programs, OWASP SAMM maturity model, STRIDE threat modeling, CI/CD security integration, secrets management automation, data-driven security dashboards, infosec bottleneck resolution, talisman pre-commit hooks, semgrep SAST implementations, AWS misconfiguration scanning, agile security workflows, runtime security monitoring, iterative threat modeling, decentralized risk accountability ## Chapters 1. **Identifying bottlenecks in traditional software security approaches** (01:09) — Discover why centralizing secure development responsibilities within an infosec team creates friction and limited scalability. 1. **Establishing a center of excellence and security champions** (05:07) — How building a security center of excellence and establishing an empowered champions program drives cultural change. 1. **Embedding security controls into project management tools** (07:46) — Map security requirements directly into existing developer workflows utilizing standard issue tracking boards. 1. **Contextualizing the why and how of security requirements** (09:20) — Providing real-world threat context and specific implementation guidance helps developers understand the value of secure coding. 1. **Pairing with teams for continuous threat modeling** (11:59) — Mentor security champions in identifying system vulnerabilities using established threat modeling methodologies during product kickoff. 1. **Integrating security scanning tools early in the pipeline** (13:32) — Implement standard security tooling directly into the build and deployment lifecycle to prevent vulnerabilities from reaching production. 1. **Automating compliance tracking with customized project dashboards** (15:30) — Utilize simple scripting and webhooks to generate team-specific project boards and visualize real-time security progress. 1. **Visualizing organizational risks through a maturity model** (18:14) — Aggregate team-level security data into an overarching framework to facilitate meaningful discussions with governance forums. 1. **Nominating accountable security champions to drive adoption** (20:56) — Why asking technical leads to actively select members builds stronger accountability than relying on pure volunteers. 1. **Structuring implementation timelines and threat modeling cadence** (23:23) — Determine the time investment required to establish proactive security processes and establish cadence for threat modeling. ## Related Moments - [Securing team and management buy-in for DevSecOps adoption](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) (from "DevSecOps: Injecting Security into Mobile CI/CD Pipelines") - [Shifting left and creating internal security champion programs](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) (from "Stranger Danger: Your Java Attack Surface Just Got Bigger") - [Shifting security left using the DevSecOps approach](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) (from "DevSecOps: Security in DevOps") - [Scaling security teams through developer advocates](https://www.wearedevelopers.com/videos/193-building-security-champions) (from "Building Security Champions") - [Scaling knowledge through security champions programs](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) (from " Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together") - [Embracing DevSecOps and automating the software development lifecycle](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) (from "Maturity assessment for technicians or how I learned to love OWASP SAMM") ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) ## Related Jobs - [Tribe Lead - ( Software) Engineering Centre of Excllence](https://www.wearedevelopers.com/jobs/ext/1475530-tribe-lead-software-engineering-centre-of-excllence) at **SD Worx** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Staff Engineer - Offensive Security](https://www.wearedevelopers.com/jobs/ext/1226927-staff-engineer-offensive-security) at **Twilio** - [Endpoint Security Engineer](https://www.wearedevelopers.com/jobs/ext/1962698-endpoint-security-engineer) at **ZEISS Group** - [Security Architect - AI](https://www.wearedevelopers.com/jobs/ext/1581899-security-architect-ai) at **ZEISS Group**