Skip to content
AppSec PodcastThe Application Security Podcast — home
35 min

Jessica Robinson and Vandana Verma-- WIA: Women in #AppSec

With Vandana Verma and Jessica Robinson

OWASP Top 10Careers in AppSecConferences and Community

How can application security become a field where more women enter, contribute, and advance? Jessica Robinson and Vandana Verma discuss OWASP Women in AppSec, its local committees, mentoring, training, and conference activities.

Listen

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 10 chapters
  1. 00:00Women in application securityAudio
  2. 03:07Vandana Verma’s path into securityAudio
  3. 05:19The purpose of Women in AppSecAudio
  4. 07:46Local committees and chapter activitiesAudio
  5. 12:48Training events and NullconAudio

About this episode

How can application security become a field where more women enter, contribute, and advance? Jessica Robinson and Vandana Verma discuss OWASP Women in AppSec, its local committees, mentoring, training, and conference activities. They explain how chapters can create opportunities without isolating the initiative from the broader community, and why visible leaders and practical support matter. The conversation includes lessons from OWASP Bangalore, Nullcon, networking events, and the challenge of sustaining volunteer programs across geographies. Jessica and Vandana also offer concrete guidance to chapter leaders and allies who want to help: make an explicit commitment, create space for participation, and support people as they build expertise and confidence. The episode frames inclusion as community work that requires repeated action.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Jessica Robinson and Vandana Verma:
OWASP Women in AppSec
Vandana Verma

Resources
OWASP Women in AppSec
OWASP Bangalore
Nullcon

Actionable

From this conversation

  1. Build mentorship programs

    It's about helping to make sure we have the right mentorship programs.

    8:03
  2. Send chapter representatives to WIA calls

    The next thing that I would say is that as much as possible, start— get— because we do have monthly meetings, there should be a representative from your chapter on these monthly calls.

    17:56
  3. Include women speakers deliberately

    The other thing is because men many times at conferences are leading these conferences, they're the presidents of the chapter, there's more men on boards even here at OWASP, that when we have conferences like this and we're thinking, okay, we want to have speakers, how can we make sure that we have women speakers?

    31:19
Transcript · 35 min conversation

0:00Chris RomeoSeason 4, episode 10 of the Application Security Podcast. This is the final interview from AppSecEU that I did while I was there. And in this episode, we're joined by a couple of the ladies behind Women in AppSec, which is an OWASP project that's focused on getting more women involved in this whole application security thing. So we hope you enjoy. hearing what is Women in AppSec and also how can everybody become involved with this very important project.

0:32The Application Security Podcast. Here we go. Hey folks, welcome to this episode of the AppSec Podcast.

1:07Chris RomeoI am still at AppSecEU and I am joined today by Vandana and Jesse.

1:14And so let's start with Jesse as far as your security origin story. Our listeners, every episode, they're, they're glued to the edge of their chair waiting to hear people's origin stories about how they got into security. So How'd you get into this, this world of AppSec?

1:28Yeah, you know, for me, security, security is a calling. It's something that I've always wanted to do. I've never really wanted to do anything else. Even in the 5th grade, I worked as a security patrol person in my elementary school, and from there I was passionate and read all of our Nancy Drew books in the 8th grade year and saw this woman who was doing this incredible work and And I saw myself in her. And then of course, WarGames back in the '80s with Matthew Broderick. And I said, oh— I love that movie. I know, I know, me too. And I was like, oh, that's what I want to do. Yeah, so I really grew up with this idea of what does it mean to kind of work in the physical area of cybersecurity and also kind of be a hacker. And I have a twin sister, and she too works in security. She actually works for the Secret Service. So, we both really have kind of grown up with this passion of doing this work and contributing and seeing how we can really contribute our work to create a more consciously secure world. And so, with that, I— my parents are really amazing, and when we were young and got us involved in different engineering programs, and then I went to university and focused on computer science and law and security. And I think for me, it's been— I think what's been interesting about my career just doing different things within security, but at the end of the day, it all comes back to— it just comes back to this passion that I have that I think just is innate about really what it means to be able to contribute to our society as a whole, which includes obviously the organizations and also individuals and really creating a more consciously secure world.

3:07Cool, thank you. And then Vandana, how did you get into security?

3:12Okay, so it started way back in 2005, wherein I started as a developer. And I was coding, but then there was something in me that really wanted to experiment. And then I had a discussion with my boss and he said, why don't you try security? Because he was heading security as well. And I moved to one of the network security projects, stayed there for a couple of years. Okay. And then got an opportunity to work in application security, wherein my development background helped me in grooming it more and refining it more. I was there and I started training the new members who came into the team. Alongside, the mobile security was booming, so I got to grow my mobile security skills as well with one of the certifications in mobile hacking. Then after doing that for like a couple of years, I thought, now the cloud is booming. Let's go ahead and learn cloud. All the wonderful ladies out there, they helped me in growing my career in cloud security as well. I got to learn so many things from the community. I've been part of OWASP Bangalore chapter from past 6 years, and, um, uh, now leading as well, uh, the Bangalore chapter. So when, uh, Women in AppSec, OWASP VIA, came into the picture, I said, yes, this is— I— this is what I want to do, grow more women in security. Because in the, in the India chapters, I've seen only a couple of women show up, no more than that. But, um, because of VIA, I can see the number is growing.

4:59Yeah.

4:59Last month we had close to 18 women in the meetup, which is like a huge number.

5:04So you have a— do you have a specific meetup? Well, let's actually back up and talk about women in AppSec a little bit, kind of, kind of, um, maybe more of a fundamental definition, kind of help us understand when we say women in AppSec, what is— what does that actually mean?

5:19Okay, so when we talk about women in AppSec, it's more about getting more women in application security. And helping them in growing their career in application security. We are targeting the women that are already there in the market. They are developers and from the other background, but they want to come here and join and be part of application security. Alongside, we are also targeting the college students because they are super amazing. They have a zeal to learn. security, and they know they are day in and day out as part of engineering, they are working on the coding. It's just that we are going to the colleges and helping them out and be part of a bigger community.

6:04Okay, and so Jessica, is this a— this isn't an OWASP project per se. Is there another word for how this fits into OWASP?

6:14Yeah, so within greater OWASP, Women in Application Security is a committee.

6:19Committee.

6:19And so, and it's really, the idea is that every single chapter around the world would have a WIA committee. That's what we call it, WIA, Women in Application Security. And so the idea is that the chapter leaders themselves are really encouraging the growth of this committee. And it's, and it's great for a number of situations, for all the reasons that Vandana said, for why it is that we want to increase the number of women within application security in general. But also, not only does it increase the, um, just kind of general diversity, but it increases the chapter, the number of people within chapters. Uh, right now, um, across the world, having an increase, um, of women in within application security is a wonderful thing for businesses. So it helps support the greater pipeline and the increase and the need for talent. Um, and then of course, within any organization, and I think an important thing for all chapter leaders to know is that also when you're looking at thinking of developing relationships and partnerships with businesses, this is a wonderful opportunity for them to be able themselves to have access to great talent and for them to also increase their own numbers when it comes to the talent that they have within their organization. And so I think that, you know, for OWASP to really take this on and to really own it and to really instill the importance of this within their chapter leaders to be able to grow their WIA committee or to start a WIA committee within their own chapters, I think it only support— support them in probably some of the more fundamental things that are super important when we look at statistics and growth for an organization, which are membership and also sponsorship support.

7:46And so when we talk about when a chapter has a WEA committee, do they do some things with the chapter meeting and then some things that are separate? Like, what are, what are the, what are the activity pieces that would fit under the WEA committee?

8:03Well, I would say, you know, whether— I'll speak from the North America perspective, and I'd love to hear your thoughts from India and some of the things you've done there, Vandana. You know, North America, I would say that, you know, when we think about our New York chapters and Brooklyn chapter that I'm a part of, is a lot of it in some ways is similar. We're looking to bring in speakers to be able to share their knowledge and share their information. We're looking to bring in young individuals who are in college to help build the talent pipeline. We're focused on really supporting mentorship and getting people involved in different OWASP projects. The difference within WIA is that there's more of an emphasis on really supporting women in doing these things. So for example, having women speakers come in, even though we do have male speakers, but having women speakers, giving women an opportunity to practice speaking so that they can increase their own confidence in it and so they can speak in other places. It's about helping to make sure we have the right mentorship programs. Mentorship is really important, and mentorship varies in many different ways, and sometimes it's successful and sometimes it's not. But this allows specifically for women within application security to be mentored in a specific way that can really help them to develop their own skill sets.

9:10So you have a specific approach that's WIA-specific?

9:14Chris RomeoYes.

9:16So what does that look like then from a mentorship perspective for somebody Because we may have some listeners who are women who are interested in getting into AppSec, but tell us a little bit more about what that looks like if they come to the meeting and they say, I'd like to be mentored. What does that look like?

9:33Right. So when we talk about mentorship and mentee program, it's for all the women that are coming out, and it's more of a global approach that we are trying to make it. And currently we have a monthly webinars that happen for all the women across wherein the speakers are specifically women. We're targeting male speakers as well because it's good to have male speakers and inclusivity on those webinars so that all the women who are present in the webinars, they can hear from the male speakers as well. Apart from that, when we talk about the main goal in the mentorship and mentee program wherein Um, we would be— we would have a plan wherein, uh, we have a plan wherein there is a mentor and that person has a mentee as well. So it's like a give and take, and, uh, that, that information would only be with us and with the person who is working on that.

10:30Okay.

10:30Yeah, so that, uh, it, it is actually kind of bringing in a kind of a closed loop wherein the visa officers knows, yes, these are the people assigned. And the mentor, before assigning a mentee to them, we would ask them, we would request them that if they are okay with it. And there are a lot of women who have reached out to us and want to be mentees as well, wherein they want mentorship. And they are, they're actually, uh, very senior women as well, wherein certain points they, they really need guidance. So, and, uh, mentors can be, uh, male speakers as well. where they can guide the women, uh, and in specifically how to grow their career, not just in application security but in general security. Because when we talk about the statistics, there are only 5% of women are there across the world. Uh, people say 11%, but yeah, it's more of a 5% women in security across the globe.

11:25Mm-hmm.

11:25So we wanna have more of that. And, um, I can see that the representation is growing high and high because of the help from the community, the bigger community.

11:36And I think what's unique about this is that a lot of it is crowdsourced from the community, meaning it's the community also telling us what it is that they want. Because the truth of the matter is, is that there are many different ways to mentor someone, and there's many different ways to be mentored, and not everything works for everyone. And I think when we really talk about the unique, the unique population of women that are in application or want to develop their skill sets in application security, the truth is, is that what they need might be different than what the traditional mentoring model is. And so the key thing here is that we're interested in developing a new innovative approach that can really help us to really kind of explode this pipeline and really support established leaders in gaining their skill sets in application security and bringing in new leaders.

12:18Right. Yeah.

12:20And so I guess, Jessica, you kind of gave us the North American perspective perspective. And then, Vandana, I think you were going to come back and give us kind of more of the perspective from kind of the Asia perspective of how this approach— and I know we were talking before and you had mentioned something about OWASP Kids and some of the other training events. Can you tell us more about the training events you've done? And then also, I'm interested in this OWASP Kids idea too. I think it's cool.

12:48Okay. So, when we— I would start off with the training events that we had done as part of the OWASP. Last year at one of the conferences in India, uh, NullCon, we had a specific OWASP women's event wherein it was more of a quiz for them so that they can play around and understand what OWASP is and what Women in AppSec is all about and be part of it. And also as part of Women in AppSec, we had a workshop that was complete hands-on on OWASP top 10, and a little bit overview on the new projects that we have from OWASP this year at NullCon 2018. And actually a good number of women showed up. We made it open for all the women, all the women who are part of the conference, and the same we are planning at other conferences as well so that more and more women can be part of it and leverage it as free.

13:41Okay, and it's the same OWASP Top 10 is where you're starting.

13:45Yes.

13:46And replicating that training for other locations.

13:49Yes, that's right. And, um, more of it, uh, we are refining the content. And apart from OWASP Top 10, we are trying to integrate it with DevSecOps as well, wherein women want to— I have taken the feedback in the last training wherein they said, yeah, we're very interested in OWASP Top 10, but how can we integrate it with our DevSecOps model? Because we are students and then We are developers, a lot of developers were there, so they are really interested in combining both of them and then bring it like a cake with a cherry on top of it.

14:20Okay, and then the OWASP Kids was a separate— is that part of Women in AppSec or is that something that's kind of separate?

14:28That was a separate event altogether.

14:30I'd still love to hear about it because I think it's cool.

14:32Okay, so that's kind of an a model wherein we wanted kids also to be part of the security. The kind of gadgets that we are getting and the technology is growing, our kids when they just get born, when they are born, they start playing around with the gadgets. So we thought that why don't we bring out something for the kids who are going to school. So there is an age defined that from 7th grade till 12th grade, we would open it up for the for all the schools. We shared the information across the sites and we shared it with the conference organizers. And we actually bought hardware for them so that they can open it and see what exactly is inside a computer. They know computer, they're playing around with computer, the desktops, laptops, but they don't know what's inside. So we actually asked them to open it. We got the screwdrivers and other things. They opened it up. And then apart from that, we had drones, when they can play around with drones and how can they change the battery, how can they try and spoof all the information from the drones. And there was one section wherein we had made Scratch and Python coding available for them so that at least they can get a little bit idea on how the coding works, where can they our round. And there was one very interesting section wherein we had a soldering. So that was the booth wherein every kid was going. We were like very scared in the beginning that whether they would be interested in that, but every kid soldered an OWASP bee.

16:13Okay.

16:13I was running. Wow, that was the most amazing section.

16:17Chris RomeoYeah, very cool.

16:18Okay, so yeah, that's, that's cool. I think it It's, it's once again, it's, it's opening AppSec ideas to another population, which is, you know, we need to get some more of those next generation, those kids excited about AppSec when they're in high school. So when they get to college, they can start pushing their teachers to teach them about AppSec.

16:36Right.

16:36Chris RomeoAfter the break, Jesse explains how different OWASP chapters can become involved with Women in AppSec. The Application Security Podcast operates with support from Security Journey. A security belt program provides the 3 pillars of successful AppSec training: learning, application, and experience. Visit us on the web at www.securityjourney.com to learn how you can teach and empower your developers using a new kind of security training. Jesse dives back in with how the chapters of OWASP can get involved with women in AppSec.

17:18Yeah, so what I would say is, I think one of the things, and you can correct me if I'm wrong, Vandana, but we— there is a place where you can go in and you could, you can select to get on the mailing list. But one of the things that we are interested in doing is better tracking how to be able to support the different chapters, but also the membership within different chapters for WIA, particularly within North America, as I'm leading that. But the biggest thing that we're focused on doing, and one of the things that came out of the WIA committee meeting yesterday, is our commitment to create kind of a set of different documents that can help chapters in launching WIA.

17:55Okay.

17:56And so whether that's having an initial kind of deck or presentation that you can present at a chapter meeting, whether it's having a kind of a list of kind of a best practice on how to really engage women in general within Women in Application Security or developing that committee. But I would say as a chapter leader, I think, you know, outside of that and to just be able to start immediately right away would be talking about this at every single meeting. The second thing that I would say is that whatever email communication you're sending out, this should be in every single email communication. that should go out. There should just be an area for WEA. The next thing that I would say is that as much as possible, start— get— because we do have monthly meetings, there should be a representative from your chapter on these monthly calls.

18:43Okay.

18:44And it can be also people who are just simply interested that are part of the community interested in participating, but it would also be great to have an actual person from the chapter that is actually a part of these calls. And then one of the things that we're committed to doing is, just like we had yesterday, the WIA luncheon, is doing this at every single OWASP conference in the future. And so we had a great room that was packed yesterday, so, but what can we continue to do to grow this? And the other thing that I would say which is super important is, you know, how can we leverage the incredible numbers of membership within the current chapter to be able to increase the membership within the WIA community? So for example, it's not an additional investment to become a member of the, of the WIA committee. It's the— it's just the same part of the investment of becoming a member of OWASP. So, but, you know, and let's say even in North America, could we increase the number of women that are participating in WIA or a part of the WIA chapters across the country and within, you know, also thinking of Canada, from let's say maybe 60 where we maybe have active users now to 1,000? And what would it mean to be able to do that in a year, really by going through chapter leaders and really having that vision. And so that means then every chapter having their own goal for how it is that they're also engaging and the number of people that they would want to have engaged in participating in WIA events and also in having women participate within their own chapters.

20:03And also what we have done in India, Bangalore chapter and Delhi chapter, wherein we would have a specific slot for for women, wherein we are trying to encourage women. I have seen personally that there are a lot of women who come up and say that we want to speak but we don't know where to start off. So we actually try and help them on starting with the basic topic, at least the lightning talk, and helping them in actually making their presentation. That's very important. And then guiding them on how to present. Sometimes we actually get on a call with them and, uh, do a demo talk so that they are comfortable. And when they go on the stage, they are really comfortable in speaking with a wider audience because, uh, Bangalore is, is in a way called as a Silicon Valley of India, wherein sometimes you would see more than 150 members also coming up to the meeting. So which is like a huge number at a meetup. And we're also planning that we would have one of the meetups wherein Um, we will have all female speakers, so it will be like a surprise meetup for everybody.

21:10Yeah, yeah, yeah, it's fun.

21:13That'll be fun.

21:14Yeah.

21:15And also, um, we also, uh, got to know that, uh, women want to know more about it. There are a lot of women who are part of OWASP, and in general they are members, but they are not— they want to know more about it. So we would be sending emails not just to the mailing list, via mailing list and the leaders mailing list. We would be sharing it with a wider audience as we grow, as we move to the static site and the new medium of sharing the information. So that the leaders which receive the email, they can also share it across because it's not just we women have to do it, but it's all, all of us have to do it as a leader.

21:52Chris RomeoYeah.

21:53And so I'm going to pick on my chapter again.

21:55Yeah.

21:56Because I would say we have less than 5% membership are women, yet we have a very robust technological community with— and there's lots of women that work in, in these other— in, in a lot of big companies that are right around our chapter. And so what are some things that we can do to better connect with the local women in the tech populations to get to invite them. The only thing I can imagine is we're not— we're doing something, we're missing something.

22:31Yeah.

22:31And I don't know what it is, and I've got both of you sitting here, so I'm thinking I want to get your thoughts on this because I can take that back. That could become actionable for me and a lot of other people who might be struggling with the same thing. Like, they want— like, I want to support, I want to help this mission, but I don't feel like my chapter is doing a good job and I don't really know how to do a good job.

22:53Yeah, the first thing I could say just right off the bat that definitely is actionable is, so there are a couple people here that I've met that are from North Carolina. So one of them is going to be our closing speaker tonight, Allison, who's actually really passionate about this. And so our closing kuna, I would say she is someone who would, I think, love to get involved. And I think, and she works within the finance industry, and so I think that she is someone that can be a gateway to helping to connect and bring women to the event. So I think it's looking for people that are like that, that are kind of these key influencers, what I would call key influencers, that can leverage their own network and bring them to different events. So that's the first thing.

23:28Okay.

23:28The second thing is really the onus is on all of us, you know, the accountability is on all of us as OWASP members to be able to, to be able to help increase these numbers. So the second thing I would say say is for anyone that comes to an OWASP meetup in the future, it's required that they bring a woman. And it can be their sister, it can be their— it could be their coworker, it could be someone who maybe even doesn't have a security background. But the key is to bring women into the fold that are passionate about learning more about this area. And I think that is one of the really key things, and that's something that can easily happen. And then the third thing I would say is You know, I think as you are continuing to, you know, I think we all are leveraging social media, really make sure that there is a target for women on social media, that there is, that we're using specific hashtags that encourage that focus on women. And then, you know, the, the fourth thing I would say is go to the universities.

24:23Yeah.

24:23You know, North Carolina has incredible universities. They have incredible technology programs. I'm not sure, you know, I think there's I think any one of the departments there that focus on information technology would be happy to post about the different OWASP meetups and really encourage students to come. And I think literally within a matter of 3 months you could easily increase the number of women that are coming to meetups.

24:46Absolutely. And I buy your point wherein that we can pick up the women who are really passionate because women actually pull the other women because they're really comfortable. And when the other women get comfortable, they would pull the other people. Yeah, so it's like a chain that gets built up. Sometimes they, they really want to come out, but they're not very comfortable. When they see a woman is actually helping them come out, so they, they, they, they get, uh, well-versed with their environment, and then they actually bring other women as well, part of that.

25:16Yeah, yeah.

25:18And college is the best place to target that.

25:21Chris RomeoYeah.

25:23So what do you, what do you consider, I guess a final question, what do you consider success for, I mean, 2018 seems like it's flying away from us here, like we're almost thinking 2000, let's say for 2019 because then we get a full year of time. What would you consider success for OWASP Women in AppSec? What are the metrics or the goals or things you're kind of thinking about for the future?

25:47So currently we have— when we talk about the mailing list in Women in AppSec, we have close to 75 women and, um, 5 leaders we have across the geography. And we want to make sure that we have at least threefold of women in the community. That's what it's going to be like. That's what we are planning, that if we at least reach that target, we are helping those women.

26:09Yes.

26:10We are achieving. And then yes, it'll grow up and we'll have more leaders. more women leaders in the community who will share it across. Currently it's more like region-wise, wherein, um, I am taking care of Asia, uh, Jess is taking care of North America, then we have Loredana who's— she's taking care of, uh, Italy, and, uh, we, uh, she's also part of one of the vice chair, and Zoe is part of the, uh, US chapter.

26:37Yeah.

26:38So we are trying to cover all the geographies, and we want to have more leaders coming up from different places. So, um, yeah, that'll be— that's what our approach is.

26:49Yeah, you know, the, the one thing I would add to that is that, you know, I think about OWASP, and, you know, the reason why I've really been passionate about getting involved in OWASP is because of the influence that OWASP has globally. Um, it's the— it's their ability to also influence enterprises' behavior, right, when they're thinking about pen testing they're thinking of the OWASP Top 10 and they're looking at OWASP focuses and information in order to be able to focus and to be able to think about how they can strengthen their program. And so, with that, what I would say is that I think that the next edge, and I'll use that term for OWASP, and really thinking globally and how to grow the organization, both in terms of numbers, but also, and really in terms of growing it in terms of also sponsorship dollars, is to really think about how to bring in women. Because this is the frontier for businesses right now.

27:42Mm-hmm.

27:43And so, if they're looking for talent, if they're looking to have the best types of leaders, if they're looking to be able to grow and they're looking for flexibility among their leaders, they need to have the strongest ones. And that, and their biggest focus right now is helping to increase women within their workplace and also helping to bring in skilled talent leaders, but also what we know in the United States is we're looking for the best security leaders as well and the most talented tech leaders. And so, I think if OWASP can have specific metrics around and really focus on helping their chapter leaders to think about how does every single chapter leader make sure that we have a representative of every single chapter, that if we look and go, okay, whatever the number of people that we have that are members within OWASP, 10% of that by the end of 2019 have to be members of WIA.

28:29Mm-hmm.

28:30So, if that— so, whatever that happens to be, so, maybe that's, let's say, I'll just throw out, I'm not gonna, 'cause I don't know the exact numbers, but let's just say that it's 100,000 members that we have at OWASP, or 50,000, then 10% of that should be members within WIA, because why not? I mean, this is for both and women, and it's about people who are championing the growth of women within not just in security but also within the workplace. And I think those are metrics that if you can say, and I think as an organization, if they can, if OWASP can say, hey, these are the amount of women that we have engaged in that, women in application security across the world, the, you know, and these are them, we can break it down to you for per chapter, these are the type of events events that we have globally. These are the number of women that are attending our conferences, speaking at our conferences. I think that it'll put OWASP on a completely different level than any organization in the world, particularly security organizations. So I think that we're just in this new frontier as we really think about what does it really mean not to just set ourselves apart in security, in terms of security, and also what we're offering in terms of value to our members, but I think it's also thinking how can we offer value to organizations as well? And I think, I think that's the next frontier, to really, to really grow and to really think and to be cutting-edge.

29:47Yeah, yeah. I know I said finally, but I've got another question too. So when I think about— I think a lot of, a lot of men that are looking towards the kind of women in AppSec kind of movement, I think there's a lot of confusion for what is like, what, what, what can men do to support support this effort. And some men may step— may just look at it and say, well, that's not— there's no rollout, there's nothing for me to do that's a part of that. And I don't think that's where— I've heard you say a couple of things here that I know that's not the direction, that's not kind of your vision. So I think it'd be— you could help to just really clearly kind of lay that out right now, just so folks know what men can do to be a part of this movement.

30:31I would say, so a couple of things. I would say right off the bat is because we have more men as chapter leaders, then if you make the commitment yourself as a chapter leader to say, we're committed to having a representative of WEA within our chapter, that alone will send a message to the rest of the chapter that this is important and this is something we're committed to.

30:47Yeah.

30:48I would say that's the first thing. The second, if you do say, hey, men, we would like you to bring a woman next time with you when you come to a chapter meeting, that alone also sends a message. where maybe there may be someone who's not even thinking about that, will all of a sudden maybe change the way he looks at his environment. And I'm sure he'll notice a woman who's passionate about security and invite her to come, whether the person's in the workplace or someplace else. The second thing— the third thing I would say is that, you know, we talk about mentoring, and women can't do it alone. We can have women mentor women, but there's still only a certain number of women.

31:19That's right.

31:19You know, and women are mothers and they're traveling, and we have men that are fathers, but there's so many competing priorities. And so men mentoring women is absolutely critical. And I just think there's a perspective that men can bring that, you know, that a woman maybe won't be able to bring, or just bring a different perspective. So I think that's absolutely critical. And I think too, I think the fourth thing that I would say is also because of their experience, because we do have more men in the, in this industry, that I think that they just will bring a completely unique perspective that, that will be able to help women in navigating their career. The other thing is, is because men many times at conferences are leading these conferences, they're the presidents of the chapter, there's more men on boards even here at OWASP, that when we have conferences like this and we're thinking, okay, we want to have speakers, how can we make sure that we have women speakers? And they're, and they're the ones actively making sure that this happens. They're the ones, you know, that are making sure that they're, you know, looking at all of the applications that are coming in and looking at all the women that have applied and, okay, you know, maybe this isn't the best, you know, application that came in, but what can we do to connect with her and say, hey, how can we help you with— make sure your presentation is great? It doesn't have to be perfect, but it can be better than maybe what we initially saw. Or maybe it's reaching out and inviting a woman to come and participate. I think these are all things that men can do that are— that seem— that are— that that are very simple, and it doesn't necessarily— in that many ways they would be doing anyway, just in their natural day of life, they would just be doing it for a man.

32:49Yeah.

32:49And so we're just asking them to do it for a woman. And also to think about it in terms of your own wife, your own daughter, your own niece, your own sister, because that, that's, that's what this is too. This is about creating a new generation of leaders, and I think it, I when I think about when we're connecting, it's no different than thinking about the fact that you're really helping to support another, another man's daughter, or another, you know, another friend's, you know, wife, whatever, whatever that happens to be. And also, how would you want your daughter or your wife to be treated if the situation was reversed? And I think just looking at it from that lens, I think, is, is, are just things that men can do. And of course, creating a safe environment where we're and feel safe. I mean, that's the biggest thing too.

33:35Yeah, I think that's a great place to end our conversation here. Thank you very much for taking the time, and we'll be looking for ways to, I know, to move forward with Women in AppSec for the Raleigh, North Carolina chapter at least, because I have some involvement in that and I can, I can do something with that. And thank you for your efforts promote this and to be leaders, and let us know how we can help more in the future.

34:04Absolutely.

34:04Sounds great. Thank you so much. Thank you for the opportunity.

34:08Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter Twitter @AppSecPodcast or on the web at www.appsecpodcast.org.

6,532 words · transcript by assemblyai

More on Conferences and Community

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.