You're the Dev and the Security Champ. That's Not a Pep Talk.
Someone put "security champion" next to your name. You still ship features. You still own bugs. Now you're also the person who gets the scanner noise, the threat model invite, and the "can you just look at this CVE?" ping.
That role is real. The unpaid-second-job version of it is also real. Official AppSec frameworks say so out loud. Read them before you pretend the title alone fixes anything.
What a security champion actually is
OWASP's Developer Guide defines a Security Champion as a team member who acts as liaison between Information Security and developers. Goal: embed security into how the team builds, not leave it as a ticket that lands after merge.
The champion can be a developer, tester, product manager — whoever's willing to learn. Enthusiasm matters more than a CISSP. The work: researching, verifying, and prioritizing security defects. Joining threat assessments and architecture reviews. Helping shrink the attack surface. Sitting in briefings so the team builds expertise instead of vibes.
OWASP SAMM (Software Assurance Maturity Model — a framework for measuring how grown-up your security program is) puts this under Governance → Education and Guidance. Maturity level 1 is blunt: identify a Security Champion within each development team.
SAMM spells out the job you just inherited:
- Set hours per week for InfoSec work (not "whenever you have free time")
- Extra training so you can act as a security subject-matter expert
- Help research, verify, and prioritize security defects
- Show up for risk assessments and architectural reviews
- Brief the team on security issues so everyone sees the backlog, not just you
- Review external testing results before they dump into the backlog
- Named hours. SAMM expects a set number of hours per week for InfoSec activity. Put them on the calendar. If leadership won't protect them, escalate with the SAMM/OWASP language, not guilt.
- Liaison, not lone wolf. You're the bridge to InfoSec, not a replacement AppSec team of one.
- Triage before heroics. Research, verify, prioritize. Don't swallow every scanner finding as personal debt.
- Show the team the queue. Periodic reviews so security is a team problem, not your private inbox.
- Demand the program pieces. Training, community, recognition, succession plan. The manifesto calls those principles, not nice-to-haves.
- https://devguide.owasp.org/en/08-culture-process/02-security-champions/
- https://devguide.owasp.org/en/08-culture-process/02-security-champions/02-security-champions-guide/
- https://securitychampions.owasp.org/
- https://securitychampions.owasp.org/manifesto/
- https://owaspsamm.org/model/governance/education-and-guidance/
- https://owaspsamm.org/model/governance/education-and-guidance/stream-b/
That is a job description. Not "forward every Alert email and hope."
The tension nobody puts on the LinkedIn post
You still have sprint commitments. Security work does not magically subtract story points.
OWASP is explicit: champions often take on an extra role on top of their day job, and the program has to support their well-being or you get disillusionment and burnout. The Developer Guide says the same: if possible, give the champion time for InfoSec work, and you may have to negotiate that with management.
If your manager celebrates the title and schedules zero capacity, that is not a mature program. That is a name tag.
The OWASP Security Champions Manifesto lists guardrails: secure management support, trust your champions, create a community, reward responsibility, invest in your champions, anticipate personnel changes. "Invest" means training, conferences, recognition — not another Slack channel and a badge emoji.
SAMM assumes training happened, that AppSec and Dev get periodic status from the champion, and that external test results get reviewed before becoming backlog sludge. If none of that is true where you work, you're wearing the title without the program.
What "good" looks like when you're still shipping code
Use the frameworks as a checklist against your real week:
OWASP's Security Champions Guide is deliberately not one-size-fits-all. Pick the pieces your org can actually run. A custom thin program beats a copied manifesto poster nobody funded.
If your title is champion and your calendar is still 100% feature work, you don't have a security champion program. You have a risk with a sticky note on it.
Chris's take: The job is liaison: make sure the practices exist and the team is actually following them. What I keep seeing is the opposite — the team treats the champion as the person who just takes care of all things security. Measure the role by what leaves your inbox, not what enters it. If after a quarter you're still the only person who can close a finding, the program failed, even if leadership loves the title.
Sources: