Tanya Janca
Building Security Champions
#1about 3 minutes
Why security teams must scale through developer collaboration
The significant ratio of developers to security professionals necessitates scaling security programs by empowering developers as champions.
#2about 5 minutes
What a security champion is and what they do
A security champion acts as the primary security advocate, communicator, and first line of defense within a development team.
#3about 4 minutes
Recruiting volunteer champions with manager support
Attract willing volunteers by creating opportunities for them to show interest and ensuring you have manager buy-in from the start.
#4about 6 minutes
Keeping champions engaged through inclusion and trust
Keep champions engaged by involving them in security incidents, sharing sensitive information to build trust, and giving them early access to new tools and policies.
#5about 7 minutes
How to effectively train your security champions
Focus training on practical skills champions need, such as secure coding, threat modeling, relevant policies, and using security tools effectively.
#6about 4 minutes
Coaching champions and setting clear delegation rules
Use a coaching approach for continuous support and clearly define what security tasks can be delegated to champions versus what must remain with the security team.
#7about 3 minutes
The importance of recognizing your champions' work
Formally recognize champions' efforts through public praise, certificates, and direct feedback to their managers to ensure their extra work is valued.
#8about 2 minutes
Using rewards to motivate and value your champions
Reinforce good security practices by rewarding champions with gifts like books and training, team-building events, and dedicated time from the security team.
#9about 3 minutes
Why consistency is key to a successful program
Ensure the long-term success of the program by maintaining consistent communication and activities, even if small, to prevent momentum from fading.
#10about 13 minutes
Program recap and answers to common challenges
The talk concludes with a summary of the champion-building recipe and a Q&A session addressing practical challenges like uncooperative teams and alternative champion models.
Related jobs
Jobs that call for the skills explored in this talk.
Technoly GmbH
Berlin, Germany
€50-60K
Intermediate
Network Security
Security Architecture
+2
Matching moments
01:32 MIN
Organizing a developer conference for 15,000 attendees
Cat Herding with Lions and Tigers - Christian Heilmann
03:58 MIN
Making accessibility tooling actionable and encouraging
Developer Time Is Valuable - Use the Right Tools - Kilian Valkhof
03:17 MIN
Selecting strategic partners and essential event tools
Cat Herding with Lions and Tigers - Christian Heilmann
03:12 MIN
Creating psychological safety as the foundation for performance
Sustainable High Performance: Build It or Pay the Price
02:48 MIN
Building trust through honest developer advocacy
Devs vs. Marketers, COBOL and Copilot, Make Live Coding Easy and more - The Best of LIVE 2025 - Part 3
04:49 MIN
Using content channels to build an event community
Cat Herding with Lions and Tigers - Christian Heilmann
05:12 MIN
How to build structure and culture without killing agility
From Data Keeper to Culture Shaper: The Evolution of HR Across Growth Stages
03:14 MIN
Proactively managing the risks of employee personal branding
Leveraging Leaders’ Voices: The Business Power of Personal Branding
Featured Partners
Related Videos
Building Security Champions
Tanya Janca
Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together
Stefania Chaplin
Organizational Change Through The Power Of Why - DevSecOps Enablement
Nazneen Rupawalla
Simple Steps to Kill DevSec without Giving Up on Security
Isaac Evans
Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?
Tino Sokic
What The Hack is Web App Sec?
Jackie
Why Security-First Development Helps You Ship Better Software Faster
Michael Wildpaner
Security Pitfalls for Software Engineers
Jasmin Azemović
Related Articles
View all articles.gif?w=240&auto=compress,format)



From learning to earning
Jobs that call for the skills explored in this talk.



Accenture
Municipality of Madrid, Spain
API
C++
GIT
Java
.NET
+25


NTT Data Deutschland SE
Erfurt, Germany
Remote
Java
Python
Node.js
Continuous Integration

NTT Data Deutschland SE
Erfurt, Germany
Remote
Java
Python
Node.js
Continuous Integration


Atlassian
Manchester, United Kingdom
£40-51K
Senior
VMware
Windows Server
Microsoft Office

NTT Data Deutschland SE
München, Germany
Java
DevOps
Python
Node.js
Continuous Integration