Nazneen Rupawalla
Organizational Change Through The Power Of Why - DevSecOps Enablement
#1about 3 minutes
Why traditional security engagement creates bottlenecks
Security teams become a bottleneck when accountability is misplaced and feedback is provided too late in the development cycle.
#2about 1 minute
Creating a center of excellence for security
A center of excellence was established to make security planning scalable, measurable, and easier for teams to adopt.
#3about 3 minutes
Integrating security into existing team workflows
A security champion program and mapping controls into project management tools like Trello helps embed security into daily work.
#4about 4 minutes
Structuring security controls with the power of why
Each security control is framed with a 'why' to provide business context and a 'how' with actionable steps and tools.
#5about 3 minutes
Automating security tooling within the SDLC
Security tools for SAST, runtime security, and cloud misconfigurations are integrated into the CI/CD pipeline as acceptance criteria for controls.
#6about 2 minutes
Visualizing security progress with data-driven dashboards
Data from Trello boards is automatically collected via webhooks to create dashboards that track team progress on security controls.
#7about 3 minutes
Creating a security maturity model for leadership
Team-level data is aggregated into a high-level security maturity model to give leadership visibility and drive accountability.
#8about 1 minute
Building an effective security champion program
Nominating champions through tech leads, rather than relying on volunteers, increases the program's impact and motivation.
#9about 1 minute
Key takeaways for building a security culture
Explaining the 'why' behind security empowers teams to take ownership, while relationship building and automation are key to cultural change.
#10about 3 minutes
Q&A on program implementation and threat modeling
The discussion covers the program's 1.5-year implementation timeline, managing high-impact risks, and doing threat modeling every iteration.
Related jobs
Jobs that call for the skills explored in this talk.
Matching moments
06:01 MIN
Navigating cultural shifts during rapid growth and investment
From Data Keeper to Culture Shaper: The Evolution of HR Across Growth Stages
05:12 MIN
How to build structure and culture without killing agility
From Data Keeper to Culture Shaper: The Evolution of HR Across Growth Stages
03:58 MIN
Making accessibility tooling actionable and encouraging
Developer Time Is Valuable - Use the Right Tools - Kilian Valkhof
03:28 MIN
How to quickly adapt and add value in a new organization
From Data Keeper to Culture Shaper: The Evolution of HR Across Growth Stages
02:57 MIN
Defining shared responsibility for employee performance
Sustainable High Performance: Build It or Pay the Price
03:22 MIN
The essential ingredients for successful organizational transformation
Turning People Strategy into a Transformation Engine
06:51 MIN
Balancing business, technology, and people for holistic success
The Future of HR Lies in AND – Not in OR
02:55 MIN
Key strategies for managing fear during organizational change
Turning People Strategy into a Transformation Engine
Featured Partners
Related Videos
DevSecOps culture
Ali Yazdani
Building Security Champions
Tanya Janca
Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together
Stefania Chaplin
Real-world Threat Modeling
Ali Yazdani
Simple Steps to Kill DevSec without Giving Up on Security
Isaac Evans
Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?
Tino Sokic
Why Security-First Development Helps You Ship Better Software Faster
Michael Wildpaner
Security Pitfalls for Software Engineers
Jasmin Azemović
Related Articles
View all articles

.gif?w=240&auto=compress,format)
.png?w=240&auto=compress,format)
From learning to earning
Jobs that call for the skills explored in this talk.

Accenture
Municipality of Madrid, Spain
API
C++
GIT
Java
.NET
+25

NTT Data Deutschland SE
München, Germany
Java
DevOps
Python
Node.js
Continuous Integration

Computacenter (UK) Ltd
Berlin, Germany
Remote
Senior
GIT
Linux
DevOps
Openshift
+3

Infosec K2K Ltd
Charing Cross, United Kingdom
£37-38K
Java
Unix
REST
Azure
+7



NTT Data Deutschland SE
Erfurt, Germany
Remote
Java
Python
Node.js
Continuous Integration

NTT Data Deutschland SE
Erfurt, Germany
Remote
Java
Python
Node.js
Continuous Integration

Accenture
Municipality of Madrid, Spain