Security Champions at Scale: Transforming Security Culture by Aligning Incentives and Gamification @OWASPGLOBAL
Security Champions at Scale: Transforming Security Culture by Aligning Incentives and Gamification  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 2 weeks ago
Many organizations grapple with how to effectively scale Security Champion programs beyond initial awareness efforts. While the concept is popular, the path to sustained engagement and measurable impact at an enterprise level often remains unclear.

This talk will share the lessons learned from running a program that supports nearly 800 Security Champions at a large software organization that serves over 60% of the Fortune 500 companies and has more than 11,000 customers worldwide.

Our experience shows that Security Champions programs are most effective when organizational and participant incentives are aligned to co-create security tools, processes, practices, and an ever-present security culture.

From an operational perspective, our program serves as a gamification success story where participant contributions are measured by their impact and recognized using a flexible framework that any organization can adopt.

Hernán Palombo
Workday
Principal Cybersecurity Engineer

Dr. Hernán Palombo is a seasoned security leader, engineer, and researcher with nearly 15 years of experience in the field. He currently leads Workday's Security Champions Program, supporting nearly 800 engineers across over 500 teams. His research includes one of the longest ethnographic studies on security culture to date, and his earlier works, featuring formal models of security, were published in top peer-reviewed conferences. Hernán earned his Ph.D. from the University of South Florida for his work on "Models of Secure Software Enforcement and Development," where he also taught Computer Science and Security courses.
linkedin.com/in/hernanpalombo

Managed by the OWASP® Foundation
owasp.org
Security Champions at Scale: Transforming Security Culture by Aligning Incentives and Gamification202010 October 2020 Global Board MeetingConnecting the dots: 5 lessons learned from an 8 year journey of an AppSec Program track 1Beyond the Checklist: Building an AppSec Culture That Engineers Don’t DreadOWASP Software Assurance Maturity Model (SAMM) - Aram Hovsepyan, Sebastien DeleersnyderHow to Defend Your PKI Estate: Lessons Learned from Eight Years of CAA and Certificate TransparencyExhibitor : Over a Decade of Software Security  What Have We Learned -  Adam BrownOWASP Cornucopia Abuse Case ModelingExploitable In The Wild CVE Appears! But Should We Fix em All?OWASP Global Board of Directors - September 2025OWASP Global Board of Directors - October 2025Plugins Gone Rogue: Attacking Developer Environments
OWASP Foundation |

Security Champions at Scale: Transforming Security Culture by Aligning Incentives and Gamification

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER