The Security Champions Podcast
Automation, Generative AI, Shift Left - the world of application security is evolving fast, and so are the conversations that shape it.
Welcome to The Security Champions Podcast, the go-to resource for insights from the front lines of application security. The podcast is cohosted by Michael Burch, Director of Application Security for Security Journey, and Dustin Lehr, the Director of AppSec Advocacy. Each month, one of them shares a candid conversation with security leaders, engineering voices, and software experts.
From championing secure development practices to navigating real-world challenges in modern SDLCs, this show explores how teams are scaling appsec, strategy and culture.
New Episodes drop monthly, with even more security content at https://www.securityjourney.com/
Always remember: Security is a Journey, not a Destination.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
This podcast is sponsored by Security Journey.
FOLLOW US to stay up-to-date with new content!
X (https://x.com/SecurityJourney)
LinkedIn (https://www.linkedin.com/company/7574213)
Instagram (https://www.instagram.com/securityjourney/?hl=en)
YouTube (https://www.youtube.com/@UCBVPnBCNcZqx_WAuCsV6BuA )
Online (securityjourney.com)
CONTACT: hello@securityjourney.com
The Security Champions Podcast
Michael Erquitt - The Future of Security Champions in an AI World
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this special episode of The Security Champions Podcast, Michael Burch passes the hosting reins to Security Journey senior security engineer Michael Erquitt.
Together, they reflect on the podcast’s evolution and explore how the role of the security champion is changing in an AI-driven world. As developers increasingly work alongside AI agents, and more employees gain the ability to build software, security champions must expand beyond traditional secure coding education to influence workflows, architecture, governance, risk, and the human-AI relationship. They also examine how champions can help teams integrate security directly into AI-enabled workflows rather than treating it as an afterthought.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Podcast sponsored by Security Journey, Secure Coding Training for Developers and Everyone in the SDLC. Learn more at securityjourney.com.
FOLLOW US to stay up-to-date with new content!
- LinkedIn (linkedin.com/company/security-journey)
- Instagram (https://www.instagram.com/securityjourney)
- YouTube (youtube.com/c/securityjourney)
- Twitter (twitter.com/SecurityJourney)
- Online (securityjourney.com)
- CONTACT: hello@securityjourney.com
Get your free VIBE Coding Field Guide: https://hubs.ly/Q043-zdS0
The Security Champions Podcast is brought to you by Security Journey. We help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC. Learn more at SecurityJourney.com.
SPEAKER_01Welcome back to another episode of the Security Champion Podcast. This one is a very special episode. I'm joined by my guest, Michael Urquet. Um, gonna be quite more than a guest on this episode. So we're gonna do a kind of an announcement for what we're gonna be doing today, right? What is the topic? Usually I talk about what are we gonna be talking about today? And actually, um, the topic is AI champions and actually a transition, uh a transition to the idea that uh Michael Irquet, um, one of our amazing security engineers at here at Security Journey, is going to be taking the lead as the host of the Security Champion podcast. Um, as I slowly change where my focus and work's gonna be. Um, as we kick this off, though, I think what we're gonna do is we're gonna start. I'm gonna do do a little bit of a reflection, a little talk about where we've come, how I've got to be where we are with the security champion podcast. And then I'm gonna have uh Mike share a little bit about himself and his journey, and then uh we'll kind of take it from there. As we kick it off, kind of talk about where I am, where I've gone, what what's what is this transition about, right? All this type of stuff. Um, let's talk about my story though. Let's I I think really it's not about my story, it's about a story about the podcast itself, is what it really is. Um interestingly, though, years ago now, it's actually surprising for me to say that now, it's been years. Um, Security Journey, the main had a podcast, right? And it was actually um led by Chris Romeo. He still runs that podcast, uh, an amazing podcast, the Application Security Podcast. If you ever get a chance to check it out, big kudos, a great program. I've been on, I've actually been on a guest there too, which was a great, great honor to be able to come in and talk about that, the type of stuff we did. Um, but when Security Journey was acquired, Chris Romeo kind of went on and started some other passion projects, continued with this podcast. But here in our in our world, we had a gap. And I had been super passionate about the space and the idea of podcasting and continuing that type of culture we had built of communicating with the rest of the world about the things that we think of and believe of, and enabling people to be champions. And the idea came around security champions. Uh, security journey has always had a special part place in their heart for champions. We have a part of our product that helps it. Um, we involved, work with a lot of our customers on their champion programs and building and educating and enabling them. So it seemed like the perfect fit to create a podcast around security champions. Um, so we started that out. It was just kind of a pilot idea, started, and the best part was my first actually, my very first guest was Chris Romeo himself. Um, and he had actually created a maturity framework around champion programs. He actually uh he has an open source project. You can actually go and look at the security champion framework that he developed. And we just got to jump in and have a conversation. And it was uh this kind of those, but actually, it was almost kind of in the same vein of what we're doing today, right? Is the fact is I was able to do my first podcast as kind of a handoff starting, tank in the mantle of starting this new brand around champions. Um, and and it grew from there. And the best part, and as I kind of look back and I think about all these, especially the early on conversations, is um, I got to reach out to my friends that were in the industry, that were thought leaders around defining what this stuff looks like. And I got to invite them on to have a conversation with me. Um, quite a few amazing people, right? I I think every one of the talks I had, I learned something. And one of the interesting things, it wasn't just learning more about being a champion. It was learning more about this, right? About running a podcast, finding the right people, having the right conversations. And some conversations were stronger than others. Uh, that's one of the things I realized before. They were all valuable, right? But it redefined the way I think of like, how do you find the right person that is passionate about this? Um, someone that isn't just selling a product or that just kind of wants the 30 seconds to be able to come up here and say something that's their message, right? That has a real passion about sharing knowledge. Um, that was the most exciting part. Like, whether it's people that had written books on the topic, um, some of my favorite people were people that had run champion programs in their own organizations that had stories to tell, or there were champions themselves. Um, we even branched out, right? When I first started, I was like, everything's gonna be champion. And one of the coolest, some of the coolest conversations actually came from stuff that had nothing to do with actual champions, it just was good app sec fun conversations. Um, whether we're talking, I've talked on quantum computing or um talking about other just passionate things around security testing, or what what does it mean to be a developer in the world of um champions and culture and change and its value. I think that was some of the best stuff that I kind of gained from from this experience is is not only learning about champ more about champion programs and bringing that passion to people that need it, but learning about how to communicate and build community and culture. And actually, founded one of my other favorite things that came out of this is we created the conference, right? The security champion conference last year was a direct growth from running this podcast, um, which is another one. And actually, like teaser, we're gonna be doing a call for papers here really soon for this coming year's in October Security Champion Summit that we're gonna be running again this year. Virtual conference, everybody should join and kind of be a part of that. Um, teaser, there will be an AI twist to some of the stuff that we're talking about. Um, big surprise, right? Um, but yeah, I mean that that's like I said, the valuable lessons learned, the amazing people that have been found. It's been such an amazing experience, and I'm very honored and humbled of all the people that take their time to actually listen to me talk about these topics and meet with people on this. Um, even and actually, and I got to throw a shout out to Dustin Lair, who for a while had come in and had brought his own like flavor and different people to share their stories and thoughts and everything else. So it's been it's been a multi-person project that's kind of changed and adapted over the years, depending on what's been going on. So that's been it's been a big, it's been a big, very passionate about this. Very uh a little heartbroken to be handing it off, but really excited to see what you're gonna be doing with it. Um, so I want to with all that said about me, Mike, I would love to like give you the moment in this stage to kind of talk about kind of you coming in as this educator and champion lead and kind of tell your story behind it.
SPEAKER_02Yeah, no, appreciate it, Mike. And just another shout out to Dustin and Chris and just being associated with them and what they've built and really added to this podcast as you kind of take your direction forward. And, you know, myself, I've been here at Security Journey for a few years, worked under Mike. They just call me mini Mike sometimes because it's just we have similar background, but we have a very different kind of perspective on, you know, security champions, what that's meant in the past, and now, especially in the last 18 months, what it means in the future. Uh everyone's heard, you know, AI this, AI that. And it's very important. Obviously, we need to understand these concepts, but we need to also understand how it affects that person. And that's really where I want to kind of drive it through, because this is no longer just app sec. We're moving beyond it. We have, you know, cyber physical systems that are controlled by AI that affect real-world people, you know, from autonomous driving to satellite security, all the way throughout, you know, from literally up into space all the way down. So we're going to take a more diverse approach with these new episodes. But yeah, just a little bit about myself and really honored to be uh the new host and excited to take it somewhere new.
SPEAKER_01And and you this isn't the first time you've been on the podcast, right?
SPEAKER_02No, yeah. Yeah. We had a great talk, um, what was that, about eight months back or something. And yeah, it's just great to just have, you know, a platform to be able to just share your thoughts and then have people on to give counterpoints and kind of learning through it all together and not get caught up in a in a hype circle or vendor log. You know, it's just it's a great platform for that. And I'm excited to kind of build that and the community around it.
SPEAKER_01Yeah, I'm excited for a fresh perspective on this, right? Because uh I don't know if anyone's met me. I have a few opinions about things, right? And I'm pretty dug into my opinions. It'll be good to have a new lens to think about this and view this in for sure. Um, interesting part, like you kind of hint towards like similar backgrounds. I do want to call out. I'm kind of excited to hand off uh the podcast to another Green Beret. Uh so another someone from another very similar background uh coming from us, like just by chance happens to be the way it worked out. Um also as kind of that teaser of why, right? Why, why, why is some of this transition, right? Um, one of the big things, and uh kind of an announcement for the podcast, my role has changed with security journey. Um, I am no longer the director of application security. I'm now the VP of AI enablement and acceleration. Big emphasis on that enablement part, right? Um, which which is interesting, right? Because we talk about what's the AI impact on everything, right? Well, AI, AI has definitely had a huge impact here, the way we think about what we're doing at Security Journey. Um, but also at the idea of like, what is a security champion? How does all that work? Everything else, right? So it's very impactful. And as such, um, I'm gonna be leading on to drive some more of those AI efforts here um in the the near future. Um so yeah, I think uh I think that's an interesting part. So here's what I'm gonna do though, right? Because part of this is this is a transition. This is uh handing off the mantle. So so at almost this point, um, I don't know it's uh necessarily about me asking you questions, right? It's about you taking the driving seat and maybe you driving the questions, our conversation as we put this. By the way, I didn't prep Mike for this, so he's now in the hot seat. And now you you're gonna lead this transitional um podcast for us of moving into the future.
SPEAKER_02Yeah, and I think that's really the best starting point. And I'm gonna share my view completely with you. I think from when you started and took over this podcast until now, the role of security champions has completely broadened out. I don't think it's, you know, that security focused developer on a small team or shifting left like we used to talk about. I think that's incredibly now opened up. And I want to hear kind of your opinion on that and maybe where some of these gaps are from that point to this point and really what we need to look at in the future.
SPEAKER_01Well, the interesting part about that, right, is we bring up the the AI impact, right? And and why would that change the way we think about champions, right? And and fundamentally, um, part of that is is the that's like defining the original, right? The original champion is, and at least the way we use it here, is I have a team that does work. They aren't necessarily security experts, they're engineers, they solve problems, they might have some security knowledge, but that's not their primary focus. So, us as a security team, we find somebody on that team to evangelize about security and help embed security as part of the development workflow, right? And there's a lot of different strategies we talk about finding the right person, enabling, educating everything else. In a world, though, that worked in a world where the interaction was I had a human that wrote code and developed products, and I had another human that I wanted to help embed next to that one to help them better understand the security. In a world where the human now interacts with agents and um they have agent skills and workflows and all these other things that are that are actually having a even more impact on what code and security implementations are being built. I think the dynamic changes, right? Because it's no longer about just evangelizing the human. There's a new player on the field, right? It's a lot of the code quality has gone from human education gaps to how do I influence an agent and a human working together, right? There's a new, it's how do I influence that relationship that is being used to build a product? Because that's what the new world is. It's not human writing code, it's not even agent writing code. Because I mean, unless you're on like one of these austere like campaigns where Anthropic says agents just write all our product and we don't look at it, like, I don't know. Right, okay. But that's not the way 99% of the world's gonna work. And I highly don't recommend that's the way anybody that we know works. But you now have this dynamic of a human and agent that are working together in parallel to accomplish a task and goal, and along the way, code's getting written, right? And that's that it's more I like people call intent development. I don't call intent development. It's it's it's a it's human-agent relationship development, right? It's and the way we affect the code quality isn't by necessarily finding tools that just affect the agent, and it's not just by educating and empowering the individual. You have to, you have to actually tackle the relationship between the agent and the human to affect the quality of the code being written, right? And so, what's the role of a champion in that dynamic, right? It it I think it completely changes, right? Uh like, does the same tactics we use before work? And I'm I'm saying this out of the side of like, I don't know the answer to these. This is kind of the emergent thought of this, but that does I'm guessing a lunch in learning isn't going to solve our problems here, right? That's a human dynamic, a tackle. That's where we all our champion effort was before. So I think the the the real question is, right, how do we redefine champions in a world where they have to influence more than the humans to be effective?
SPEAKER_02Yeah, and you made a great point there from one, that relationship coming together. And I think of it now, and especially in the last six months, where we see a lot of these frontier models that are pretty good. Like at the end of the day, you can be a naysayer, you can have your opinions, but can't really argue at some of the results. And it's just really driving up a lot of new issues and you know, rising those to the surface, which brings in a security champion even more responsibility. But it also code is now just commoditized. You have an intent, you have an architecture, and the real security is around those not only agent-to-human relationships, but agent-to-agent and MCP. So it's kind of taking on, as I was saying, a broader role. And personally, I think it needs to, we need to keep that same, you know, evangelize, enable, and recognize the people in the organization that are doing this great work. It's just that the game board has changed, the pieces have changed, but the core values and the core end like mission is still, still the same. Like we want to champion that security throughout. Because one of the biggest concerns I have now is really the velocity of code. Like, you know, I mean, if you have agents running or like you get rid of your whole dev team, this happens near instantaneously. And then you even push to, you know, prod without human oversight. Like, so this velocity is really going to bring a whole new, I'm not going to say burden, but a whole new bag for that security champion to carry and to carry for the organization and the new members of the team. So question to you is of all the conversations you've had, you know, from security champions to people in the industry that are kind of making that shift, maybe development teams aren't as built up. What do you feel that relationship and that responsibility of the ski security champion moving into a more strategic or architectural role? Or do you think they still need to be embedded on those small teams, you know, as they have been in the past?
SPEAKER_01Yeah, I guess the the real world answer now goes back to, and I it's the same question I ask companies, right? When I come in and they're the company's like, I want to start a champion program, or I am running a champion program. Um, my first question is great. What is your end state goal? Like what's your what's your what's your business mission? What's your mission statement? What is the metrics that you're using to measure the impact that your champions are having? Um quite often it's I don't know, champions are showing up. Um interestingly, it's it's it's the same kind of actually conversation I'm having around of like AI, right? So I'll translate this to a lot of things I've been talking about recently. Um, a lot of companies I'm talking about with, they're like, oh, like what's what is my new title, VP of AI Enablement. What is or what are you doing in your organization for enablement, right? And the first response I get from company is, well, we bought a bunch of people licenses and they have access to cloud. I'm like, that's cool, right? You've just explained to me what you're spending on AI. You didn't tell me what you're getting out of AI. You didn't tell me how you're preparing your workforce to use AI, right? Now we go back to the same transition lens of what a champion is, right? And quite often we run into this idea of, well, what is your champion program? Like, oh, well, I have this many champions. We do lunch and learns. Um, I uh I like, like, like I've I've I've enabled them and I've bought training for them. I'm like, that's great. You've told me all the money you're spending on your champions and the time they're giving up, but you still haven't translated to the impact you're measuring and hoping to get out of these champions. And a lot of time that's because that people are going, well, I know I need a champion program, it's the right thing. I think culture is important. I like the idea of being a force multiplier, but they still don't have the end state goal in mind. So when we rethink about the impact that we're having with our current champion audience and how how what our devs are doing are changing, maybe it's a question of what's the impact that we want the champions to have, right? Is the goal still to educate securely? And then maybe if that is the same goal, if we don't change, like if we look at the lens of maybe we don't change the approach, but we change the focus, that's where we get affected, right? So the champions are still educating and there to be, have the right answers. But now what we prepare the champion with has to change. Because before I teach them SQL injection, I teach them secure design and secure coding principles and these showing them how attacks can happen, right? Have that attacker mindset. But when the devs not writing the tool, I'm pretty sure that the lecture on concatenating strings is not going to fall dead. But maybe, maybe if we just now empower them with, hey, by the way, this is what a new secure development lifecycle looks like in an era of AI. And by the way, I've seen a bunch of little pop-ups of what people kind of say they think the new SDLC is with AI is. And guess what? None of them are right. All of them are useful, kind of like the way we think of models, right? Threat model, yeah, yeah. They're all they're all wrong, but they're all useful. Like anytime you represent it, represent anything. These new SDLCs are the same, and no one's unified the way that we did on the traditional SDLC, right? Um, because the way that people are using these tools, I haven't seen two companies that code the same, right? Like it's it's it's completely different now, right? So when we think about the the idea of the the champions, before I would say this to companies what your champions do in your organization is 100% dependent on what's important to your organization, right? What's your business uh model? How do you operate, and how can you make sure that what you're asking the champions to do are aligned to what your business is trying to achieve? Um, that was what we did. And that means what champions did from organization to organization were just different, right? Some people were literally like pair coders that were like part of the app sec team that did heavy, they set the SaaS tools and did the security scanning and threat modeling and a bunch of this stuff. I had other ones that were like, Oh, I just get some edu extra education sometimes and talk about security on a stand up every now and then, right? And for that organization, that might be the fit in this world where the the sprawl of the way people are writing software and leveraging these tools and different approaches. And by the way, every company thinks they have the most novel new approach to using AI to write code. Should see what we're doing. It's completely different. Well, yeah, all right. It's probably not that different to how another couple other dozen companies are thinking about doing it too. Just nobody's talking about it because they all think they got some big, great secret. Uh eventually in a couple of years, that'll die down. But that does mean that everyone's doing stuff a little bit different right now from kind of everyone else for a lot of the ways. So what your champions are going to do is gonna have to be completely aligned to the new way and workflow you're trying to do and the impact you're trying to have.
SPEAKER_02Yeah. And even within like this modern champion that we're talking about, like they will continue and always be that secure code advocate, that overarching kind of signal to the team with that security focus. But now we're gonna ask them to, you know, be a workflow guide. They're gonna have to help people set up workflows, they're gonna have to do risk and risk signaling of different developers, as well as the organization as a whole, and then even serve as that, as I was saying, secure code advocate. Like you have to have someone look at the code before it goes through. Even I mean, no matter what. So they're gonna need engineering, product, data, like all these different fields and learnings all coming together to be able to be the best, you know, modern security champion that they can be. And then we got to throw in governance and compliance into that as well. Is like, do you think that should fall on, you know, a security champion? No and yes, but I think they should drive it, you know, and I I think that's what it really comes down to, and you hit the nail on the head. This role will differ between each organization. Each organization's in a different industry, different sector, different needs, and a different stage of maturity. So that's really what I wanted to kind of take this modern security champion term and approach and take these episodes in a in a broader direction where we're gonna look at those operations, those, you know, AI risk signals, those workflow guides, and bring in all these different aspects to really empower this modern security champion and hopefully security champion teams, where there's a group of people for these larger organizations to be able to influence it securely and not just throw it to the machines and because it goes quick and we can't find anything, it's good to go. It's just be machine on machine, and that's not the best future in my mind for both secure coding, especially as all of this code kind of comes into the physical world more and more.
SPEAKER_01What are you talking about, man? I just have copilot review. This little button, right? I do a PR, it says copilot, we'll do my review, we're done. AI generated the code, AI reviewed it, I had AI host it and do the PR for me. Like I I don't even know why we have people anymore. Like we're kind of becoming obsolete as a product.
SPEAKER_02Yeah, you just put the effort to you know extra high, and that that'll make sure that everything, everything's good except, you know, your token cost at the end of the month when you get that bill. But okay.
SPEAKER_01So so here's my proposal. We're gonna solve all the world's problems right now. All right, so here's what we're gonna do. I'm going to write a AI champion agent. I'm gonna hook it up to an MCP, and I'm just gonna I'm gonna put it directly to, I don't know, what would be a good connection there? Uh I'm gonna just I'm just gonna hook it up to all the clawed, open AI, I don't know, it's something. I'm gonna give it all the the good code and guidance and call it done, right? So, so interestingly, here as we think about this, right? I I'm talking facetiously, right? I'm joking here, but but realistically, right? Like in a world of AI enablement and AI first companies, and apparently AI is solving all our problems or making all of them, it's kind of hard to decide one day. Um, why why can't we just have an AI agent that's our champion, right? It's your secure coding co-pilot, right? And I I I've I've heard people, I've seen, I've looked at the LinkedIn's and a million other people building the the secure coding co-pilot or whatever it is. Like, I will say this code quality is going like interestingly, is going to change. Now, I didn't say better or worse because I don't know yet, right? We talk about these new like modern models like Fable. I've played with Fable, it's impressive. I'm gonna admit it, right?
SPEAKER_02Yeah, don't ask anything about security or anything of that, and you'll just kind of get bumped off. But downgrades.
SPEAKER_01Interestingly, you know, I saw a LinkedIn post, I was literally reading it today, and some guys like, I've hacked the way to bypass Fable's not more responsive security, and then just do this, and it'll answer your security questions, right? By the way, all these guardrails on AI, you can't guardrail AI. Like it just that's just not the way it works well. Like you can get like you can keep low stuff, but there's always gonna be failure points, right? But also, let me throw out this though. I don't know the last time anyone here's actually ran a task on Fable and looked at the dollar signs that comes behind that. But just because there's a powerful model does not mean I'm gonna have it doing my security reviews for me. Um, when when the model becomes more than the hourly wage I'm paying the person to write the code, at some point it starts getting ridiculous, right? You start having a hard time proving that I'm generating value versus all the cost I'm throwing out of this.
SPEAKER_02Yeah. And my first claim, first podcast claim, is that that is gonna work like every other subscription model in the past. And those token costs are gonna continually increase, increase until you you hit that point that some of these large companies, you know, start losing customers because of that cost. So I think that's gonna continue to go up and up, at least for the foreseeable future.
SPEAKER_01Well, you think about that too, though, and it goes back to this AI. So I I do think champions are like interestingly enough, I like the joke of an A champion agent isn't crazily far-fetched for maybe a tool that you get champions to use, right? Like, say you have internal policy and secure code practices and things you want your company to follow. There's no reason you can augment an agent with that data that could support your dev teams, right? Um, because here's what here's the problem, though. Here's what everyone's expecting, and here's where they're gonna run into the issue. They're hoping the foundational models will save solve all their problems, right? Eventually Cloud will be good enough. Eventually, Codecs will be good enough, eventually I'll be able to use curse or any of these things, right? And it'll be good enough, right? Um, copilot, whatever. But the problem is they're generalistic tools, right? They're meant for like they have the coding ones, right? You have your codecs or clawed code, but even so, like the companies are moving away from them being just coding tools. I don't know if you know like OpenAI, right? They put they have a new work tab, right, in your chat. And if you can go on chat or work, if you go to work, surprise, it's just codecs under the hood that they're now feeding to the workers to be able to do agentic work, right? It's just codecs, right? It's just now been reframed as an engine to help them. Now don't quote me on that on specificity. Like I I heard it's a go-to-market person explaining it before. I just want to so if I'm a little inaccurate in the way you described that, like don't hold me to it. But but the reality of the way it was explained to me is it's just codecs under the hood, right? So when when this all changes, right? And that this is actually an interesting part. When we think about champions, right? Um, the ch traditional champion, you're talking about looking to the future, it changing. Um we've thought about just devs. I've always touched on, I even did an episode once with somebody that helped write the top 10 threats for low-code, no code, right? I remember that being a great episode and the person that runs that OAS project. Um, with the fact that citizen developers are a massive threat landscape and probably need the most championing um to be able to be effective. But now we have these AI citizen developers, right? Um, I'm interested to see how do you tap into that world and do you start finding citizen developers that are not necessarily like they don't understand code. I think in the new world, if you're gonna have that ecosystem, you're gonna have to find security champions in that group too. Interestingly enough, you might even find, and I say this like maybe incorrectly, but I might I have a weird feeling, you might find better, more passionate champions in the workforce than you would in the developer audience, the knowledge workers, because you have a lot of people that are really excited and passionate about the power of the tool they've gotten access to and they're hungry to learn. Where I will say a lot of the developers, like they're great, they're highly educated, and sometimes it's just harder to get them to care about security, just because it just is. It's just the nature of the beast. And if like I I've always been passionate that that's not a developer problem, that's a we're not reaching the developer the right way problem, that's a security team problem. Um, but the reality is it's just harder, it's just a harder problem to solve. And it might not be for the knowledge workers, especially right now, because everyone's so hungry to learn. Like this, I feel like this is a perfect time to branch out to that audience and get as many champions as you can to embed with these new people that are using AI to write code that aren't devs.
SPEAKER_02Yeah. And I I love talking and arguing with you and especially being right. But what you just did was you took my kind of perception of now the security champion is going to be in charge of all of these different aspects and coming together because that's what a security champion does. But I love what you just said about the empowerment to the rest of the organization and really what it comes down to. It's that hunger to learn and to continuously learn, as well as, you know, that desire and your own perspective of where you're coming from. So I I'm definitely gonna take that into the future, especially with some of our guests, on how more people can be security champions beyond just your dev team, your CS majors. And that that's a really great point to bring up because I think we're gonna see that very, very soon and love to hear more thoughts on that later. But that's really cool.
SPEAKER_01Well, I think it directly aligns. Uh, I our CEO said this before. I'm stealing his quote here. Um not everyone's a coder anymore, but everyone has the power to be a developer because they asked have access to tools that can help them build software and well. Now, I didn't say good or bad or secure or insecure, right? Just the de facto you are because you have the capability. Whether you're doing that well or securely, yeah, that's a whole nother argument and string to pull on, right? Um, but that broadens our case that broadens our need for bigger champion programs, I think. I think that's so I'm very excited to see the the new angles you get to bring into this conversation and the people you get to bring in in this kind of new era, right? Um I'm gonna I'm gonna ping you on this, right? So what are you what like doing this transition, doing this handover, um what's your vision of the future for this? Like what's like you start touching, you're gonna broaden, right? You're gonna broaden, you're bringing some more people, you're gonna see some perspectives on technologies or areas that we just never touched on before, which I think is gonna be fresh, right? Something completely new, some some reason to come back instead of just hearing Mike talk about the same stuff every time, right? I think I'm excited for that, right? Now you get to hear another Mike talk about something new this time.
SPEAKER_02Really switching it up, yeah.
SPEAKER_01Really, really changing things up here, right? Um but uh so but what do you see that future as for where where you're taking the direction of this?
SPEAKER_02I really see it being an outreach, as you were saying, to all these different sectors, all these different teams within the organizations. Because now that everyone's a coder, now that code is commoditized and it can be thrown in all different directions into any product with the velocity to get that product into market, no matter what sector you're in, things are gonna be different. A lot of the same vulnerabilities will be the same, a lot of the different security champions' responsibilities will be similar, but we're gonna take all these different perspectives from, you know, we can we're gonna start talking, you know, robotics and then into satellite security, where the security champion is completely embedded throughout, you know, the entire development phase, the testing, all the things that go into, you know, satellite engineering, facing against radiation. But then once all that is done, the security champion did a great job, the team, it's launched and now it's in space. You can't update anything. You, you know, it takes a little bit more, there's FPGAs and different steps like that. But these are long-lived systems that are going to continuously operate with really out the ability to give updates and patch, and now they're all moving around and they're like chasing each other now. But that's just one example of that perspective on how this specific aerospace industry is gonna treat security champions completely different than from a drone perspective or an app sec, you know, perspective, which we'll always touch on as well. But just bringing in those different views, I think, will really be able to give the listener the ability to take that from something they would never have, you know, experience in or access to and bring in those lessons to their own team and their own organization. So it's going to be really about connecting that cybersecurity risk to the human, that security champion and security champion teams, to then be able to provide, you know, all the security features needed for that product, as well as experiment and drive the security as it happens. Because I keep going back into it. The velocity of this is pretty mind-blowing to me. That you can, you know, have code pushed to prod automatically in seconds, no matter what, which probably leads to some of the outages we've seen in the recent past. But again, the speed is what I want to concentrate on and taking all those perspectives and bringing it back into the security champion because they're not just, you know, helping the product or the business. They're they're really helping everyone as all these new systems start interconnecting. You know, we'll move into telecom a little bit, 6G, AI ran. Yeah. So now we have AI attached to cell phone towers. You know, there's there's a lot of different things going on. And I think just being at that cutting edge, bringing in all these experts who are security champions in their fields, is gonna give the listener a more broad understanding and be able to have them continuously learn and drive their own experience.
SPEAKER_01That's amazing.
SPEAKER_02Yeah, well, you beat me to the draw on that one. I was gonna ping you on um from all the episodes you've done, from you know where you and Chris started to where you've brought it to now, what would you like to see actually be carried for, you know, carried forward and continually going along with this podcast? Because as I've said, I have my own opinions, my own perspective on how this will be so valuable, but what would you like to see kind of carry through?
SPEAKER_01You know what? I think the most interesting, and I love the freshness, right? The idea is that you'll be hitting on tech and topics, I think, that were just gonna be interesting for people to understand. I think I'll always have a focus back to like, like how does this apply to me? But it's but it's new, it's a new perspective, new problems. That's that's that's a really exciting. Um my my only hope is that I continue you see passionate people come share passionate stories, right? I think as long as you we have that coming into this environment, um, I think it's be value and it's gonna be great to listen to. Um, I I'm excited about it. I'm excited to see who you get to kind of bring in and the type of conversations you're gonna be having. Um, because once again, something fresh. We've been doing one approach for for a while. Um really excited to see what what what you what you're gonna bring to the table and how you're gonna change it up for sure. Um other interesting thought too, right? And and as we're kind of kind of talking through this, I'm gonna do my pitch of why I'm leaving, right? So, so I mentioned that I moved in as the VP of AI enablement acceleration here, right? And what's what's that actually mean? And what what that actually means is I'm leaving the lens of just developers. AI, just what you brought up the citizen developers, right? That like as a new problem, right? The workforce has been given access to one of the most powerful generative tools on their everyday life. And the honest reality is 99% of them are using it to write fancy emails or make a nice PowerPoint deck. And and companies are struggling with proving ROI or value or what are we getting out of this, right? Um, because I'm gonna tell you right now, a fast written email or a fancy PowerPoint, 99% of the time isn't gonna lead to revenue, right? It's gonna reduce the work, right? It may feel easier for me to do. But here's the reality: if a PowerPoint was gonna take me five hours to make and I got AI to make it in like 10, that's great. But the reality is I probably wasn't gonna spend the five hours to make that PowerPoint. So did I gain, did I, did I really gain the value there? Unless I absolutely had to, right? It's gonna get for a few people, but most people would have just done a lower quality one for less time and accomplished the goal, right? So tying that type of change in work is it doesn't show value, right? What we have to do is we have to rethink what a workflow is. How do I go from point A to point B in my company where I have a signal I have to do work to the work is done? Developer word is feature request to delivering a feature in production that people are using, all the steps and things that went along the way, right? You have your ticket creation, you have your validating the ticket, you have uh a proposal and a breakdown, a meeting with the customer to align on the objectives, and then you take that same workflow, and all of a sudden you have to break it out into subtickets and do sprints on it and QA and deliveries and feedback on the feature. Like there's this whole workflow, right? Being able to look at that workflow and optimize where AI fits in the best to generate real repeatable revenue. And by the way, not just looking at the workflow and adding AI in, but realizing you have a new capability and restructuring the workflow around that capability to optimize the revenue it generates. That's a way that most companies are struggling. They're the experiment. We bought licenses and everybody's just using AI. No, very, very few people are optimizing and rethinking their workflows and enabling everyone from Susie at HR all the way to sales, RevOps, like marketing, to be AI literate, AI capable, and generating value and solving business problems with AI rather than writing fancy emails, right? And that's where my entire focus is. And interestingly enough, um, we've launched an entire new part of the product and security journey that is just for that audience to solve that problem, to educate, enable and empower the workforce to become AI first capable workforce, to be to be on the frontier and able to leverage this tool that they have to generate revenue, value, and expand their capabilities in ways that they never thought possible. And that's where my entire new world focus is helping drive that lead. Um, but it's interesting, right? It's parallel because here's the part about that I think that we uniquely sit, right? Think about the idea of the security champion is with all that comes so much risk. So when can we at the moment we teach people and empower them to do this work? Can we just teach them, empower them to do it safely and right the first time? So, unlike the dev world where we basically have spent everyone teaching them capability and at the end, when they get to companies, try to patch on some security so we quit getting in trouble. Well, like, how about when I first time I teach you to use AI along the way? I I teach you where it fails. I teach you how the the vulnerabilities, so that when I call you AI capable, when I call you an AI first company, the security is just a de facto part of the way you do it. And it's not something we have to call out separate. It just is because it's not right if it's not secure. Yeah. And with AI, that that's so important now.
SPEAKER_02I mean, it's probably how it always should have been. Um, but as you said, with AI now, it's it's kind of changed the playing field. And out of principle, I write all my emails myself. That is just for me. I know other people do it, but it's good to keep some human-to-human interaction. Like, and humans are really good at seeing what has been AI tweaked or recognizing those patterns within the system. But that's a question I'm going to be asking every single one of our guests. Like optimizing revenue, great for CEOs and shareholders, but it's about optimizing your workflow. So we'll be asking that to every guest and their discipline and what they have to deal with and what things were really helped by, you know, getting some AI involved, speeding up this process that allows you to use your own expertise in learning to concentrate on what matters in this piece. So it'll be a lot about optimizing that workflow throughout their individual experience and companies. So thanks for that one. I just came up with that there. That that'll be every question, every guess. So no, that's appreciate all that and all the stuff you're doing for AI enablement and really helping these organizations adopt it safely, securely, and so their whole, you know, life is more efficient to concentrate on things that matter.
SPEAKER_01Yeah. And hey, Mike, I am so excited because I I think we're coming near the end. I've told the story. We're doing the handoff. We know what you're doing in the future. We know why I'm leaving. Um, this is, like I said, this is this has been such a passion project. No pressure. No pressure, right? Handing off the podcast, allow you to take the take the wheel. Uh don't mess it up. Uh I have every confidence in you that you're gonna, this is gonna be great. And by the way, I'm gonna be around. There's definitely times I probably come in and we talk again, right? Just uh that that'll be your driver now versus my driver.
SPEAKER_02Yeah, I'll definitely drag you back in, especially on as we kind of develop, you know, what we're doing and that that workflow optimization is just so good for every single listener. So you want to do uh your one last closer and do my I'm gonna do my one, I'm gonna do the last closeout.
SPEAKER_01My last security journey, security champion podcast closeout. Um, I want to thank you, Mike, for joining us. Uh I can't wait to see what you kind of take this and do with this. I want to thank all my guests that have been listening over the years, that have joined me for my security journey as we became champions for organizations in our for champions for security in our organization. And as I always end, and always to remember, um, security is a journey, not a destination.
SPEAKER_00The Security Champions Podcast is brought to you by Security Journey. Security Journey is an enterprise class secure coding training platform with lessons that are built on learning science principles to deliver long term, measurable results. Learn more at securityjourney.com.