Stefania Chaplin
Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together
#1about 3 minutes
Understanding the recurring bug cycle and its impact
Recurring vulnerabilities like SQL injection create a cycle of context switching and developer burnout that goes beyond the OWASP Top 10.
#2about 3 minutes
Breaking down silos between developers, security, and operations
Misaligned KPIs and communication gaps between developers, security, and operations teams can be bridged by creating a culture of security champions.
#3about 6 minutes
Integrating security tools into the developer workflow
Empower developers with free OWASP tools like Zap and dependency checkers, and integrate automated scanning and just-in-time training directly into the CI/CD pipeline.
#4about 2 minutes
Sharpening the saw with personal well-being and learning
Applying the "sharpen the saw" principle through continuous learning and maintaining personal balance helps prevent burnout and improves developer flow.
#5about 2 minutes
Key strategies for building a secure code culture
Build a stronger security posture by prioritizing time to learn, addressing technical debt, adopting an empathetic approach, and using OWASP resources.
#6about 1 minute
Transitioning from a developer to a security role
To move from development to security, start internal conversations, join a security champion program, and explore your company's specific security priorities.
#7about 1 minute
Finding resources for continuous security learning
Beyond the OWASP Top 10, developers can learn security through internal hackathons, online platforms, community meetups, and exploring red team versus blue team concepts.
Related jobs
Jobs that call for the skills explored in this talk.
Matching moments
28:01 MIN
Fostering a developer-first security culture
Walking into the era of Supply Chain Risks
15:05 MIN
Scaling AppSec teams by empowering developers
Why Security-First Development Helps You Ship Better Software Faster
00:03 MIN
Why security teams must scale through developer collaboration
Building Security Champions
05:07 MIN
Addressing the security education gap for developers
Climate vs. Weather: How Do We Sustainably Make Software More Secure?
01:10 MIN
Making web application security accessible to developers
What The Hack is Web App Sec?
00:03 MIN
From vulnerability researcher to automated security founder
The transformative impact of GenAI for software development and its implications for cybersecurity
07:31 MIN
Balancing developer and stakeholder security priorities
What The Hack is Web App Sec?
24:17 MIN
Shifting security left with collaborative threat modeling
We adopted DevOps and are Cloud-native, Now What?
Featured Partners
Related Videos
Simple Steps to Kill DevSec without Giving Up on Security
Isaac Evans
Building Security Champions
Tanya Janca
Real-World Security for Busy Developers
Kevin Lewis
Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?
Tino Sokic
What The Hack is Web App Sec?
Jackie
Why Security-First Development Helps You Ship Better Software Faster
Michael Wildpaner
DevSecOps culture
Ali Yazdani
Security Pitfalls for Software Engineers
Jasmin Azemović
Related Articles
View all articles


.png?w=240&auto=compress,format)
From learning to earning
Jobs that call for the skills explored in this talk.



IT-Security Engineer Awarness Training and Security Roadmap
Paris Lodron-Universität Salzburg
Microsoft Office

DevSecOps Engineer Jr-Mid | Remote | *Attention - developers with a passion for security*
Punk Security Ltd.
Remote
€30-40K
Junior
Docker
Node.js
Kubernetes
+1



Security Developer / Engineer SOC Rotterdam
Working Class Heroes
Remote
Linux
Ansible
Terraform
Elasticsearch
+1

