Security · 3 min read · 749 words

Dev and Security Champ: Managing the Dual Role

By Chris Clark · AppSec practitioner & AWS Solutions Architect

Disclosure: Some links in this article are affiliate links. We may earn a commission at no extra cost to you if you purchase through them.

You're the Dev and the Security Champ. That's Not a Pep Talk.

Someone put "security champion" next to your name. You still ship features. You still own bugs. Now you're also the person who gets the scanner noise, the threat model invite, and the "can you just look at this CVE?" ping.

That role is real. The unpaid-second-job version of it is also real. Official AppSec frameworks say so out loud. Read them before you pretend the title alone fixes anything.

What a security champion actually is

OWASP's Developer Guide defines a Security Champion as a team member who acts as liaison between Information Security and developers. Goal: embed security into how the team builds, not leave it as a ticket that lands after merge.

The champion can be a developer, tester, product manager — whoever's willing to learn. Enthusiasm matters more than a CISSP. The work: researching, verifying, and prioritizing security defects. Joining threat assessments and architecture reviews. Helping shrink the attack surface. Sitting in briefings so the team builds expertise instead of vibes.

OWASP SAMM (Software Assurance Maturity Model — a framework for measuring how grown-up your security program is) puts this under Governance → Education and Guidance. Maturity level 1 is blunt: identify a Security Champion within each development team.

SAMM spells out the job you just inherited:

Tags: security champion · application security · developer responsibilities · security culture · AppSec