Company
Date Published
Author
Sarah Wills
Word count
922
Language
English
Hacker News points
None

Summary

Dun & Bradstreet and Shutterstock have adopted "shift left" approaches to security, bringing developers earlier into the security process or moving security earlier in development. Their security champions programs aim to address the massive security talent shortage and strengthen a company's security by identifying passionate individuals who can share knowledge and collaborate with development teams. Key aspects of successful programs include setting clear expectations, gathering metrics, building a strong community, and making security events accessible to all teams. Both companies have found that partnering with security champions from development teams helps scale security measures throughout the organization and promotes a culture of security awareness. To start a new security champion program, it's recommended to start small, define roles and responsibilities, and make security events inclusive to all teams. Ultimately, these programs enable a shift in perception where security is embraced, making developers self-sufficient in secure development.