Subcapability 04 of 04 · Security Engineering

Security Champions Program

OWASP SAMM-structured Security Champions network that distributes security capability across squads, eliminates the central team bottleneck and multiplies protection without multiplying headcount.

What is at stake

The central security team has four people for twenty squads. Centralized review delays every release. The product team learns to work around the process to meet deadlines. Security becomes an adversary of speed instead of a part of it.

What it is, in practice

A central security team that reviews every delivery from every product squad has capacity that does not scale. With five squads the pace is manageable. With twenty, centralized review becomes the bottleneck that forces every product team to choose between waiting for approval or skipping the process. The second option becomes standard practice. Security stops working not from lack of intention but from an operational design that does not sustain organizational scale.

How we work

Measurable gains

What changes in the result when this subcapability matures.

Frequently asked questions

What is the expected workload for a Security Champion?

In mature programs, Champions dedicate between 10% and 20% of their time to security activities: code review with a security perspective, participation in threat modeling, response to SAST or SCA alerts and knowledge updates. This workload varies with squad pace. What defines sustainability is formal recognition of this contribution in performance assessment, without which the Champion inevitably prioritizes activities that appear in the delivery record.

How to measure whether the Security Champions program is working?

By three complementary indicators. Coverage: percentage of squads with an active and trained Champion. Activity: vulnerabilities identified by Champions per quarter versus vulnerabilities that escaped to production. Culture: percentage of squads that initiate threat modeling without a request from the central team. The third indicator is the most relevant because it measures whether the security culture has been internalized or still depends on external impulse.

Does the Champions program replace a central security team?

The program complements the central team, it does not replace it. The central team sets standards, maintains tools, conducts high-impact pentests, responds to major incidents and acts as technical reference for Champions in complex situations. Champions execute day-to-day security in squads within the standards set by the central team. Both need to exist. The ratio between them changes with program maturity.

How to select who will be a Security Champion in each squad?

By genuine security interest, not by mandate or arbitrary designation. A developer who already demonstrates curiosity about vulnerabilities, who questions authentication decisions during code review or who reads security advisories on their own initiative is a natural candidate. Designation without genuine interest produces the anti-pattern of champion in title only: a compliance checkbox without real operational impact.

How long does it take for the Champions program to show measurable results?

A program with structured training, defined autonomy and clear escalation criteria starts showing results in the second or third sprint after initial training. The first indicators are qualitative: champions participating in design reviews, questioning security decisions before code review, escalating situations that previously went unnoticed. Quantitative indicators like vulnerabilities identified per squad become measurable by the end of the first quarter of operation.

Want clarity on where to invest first?

A complete technology capability assessment with an evolution roadmap connected to financial result.