--- title: "Karen Staley -- A Conversation with Karen" url: https://appsecpodcast.com/karen-staley-a-conversation-with-karen/ date: 2018-09-25 duration_seconds: 1025 guests: ["Karen Staley"] topics: ["Conferences and Community"] audio: https://www.buzzsprout.com/1730684/episodes/8122671-karen-staley-a-conversation-with-karen.mp3 transcript: true --- # Karen Staley -- A Conversation with Karen *September 25, 2018 · 17 min* with [Karen Staley](https://appsecpodcast.com/guests/karen-staley/) on [Conferences and Community](https://appsecpodcast.com/topics/conferences-and-community/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122671-karen-staley-a-conversation-with-karen.mp3) ## Show notes What should OWASP members expect from the foundation’s executive leadership, and how can a global nonprofit remain connected to its volunteer community? Karen Staley joins Chris and Robert during AppSec Europe to discuss her early experience as OWASP’s executive director. She explains how her nonprofit background prepared her for a passionate technical community, how members and chapter leaders interact with the foundation, and why conferences, membership, and diverse participation matter to OWASP’s future. The conversation also explores fundraising, strategic priorities, and the challenge of supporting local chapters while preserving an open organization. Karen closes with a call for greater community engagement and partnership. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Karen Staley and OWASP: → [OWASP Foundation](https://owasp.org/) Mentioned in this episode: → [OWASP Foundation](https://owasp.org/) → [OWASP Chapters](https://owasp.org/chapters/) Chapters: 00:00 A conversation with OWASP leadership 01:08 Karen Staley’s nonprofit background 02:16 Joining OWASP as executive director 05:26 How members connect with the foundation 08:52 Conferences, developers, and broader participation 10:26 Membership and supporting local chapters 12:23 Strategic priorities for OWASP 15:27 Building stronger community engagement 16:20 Closing thoughts ## Transcript *3,064 words · assemblyai* **0:00 Chris Romeo:** Hey folks, season 4, episode 9 of the AppSec Podcast. On this episode, we're joined by Karen Staley, who is the executive director of the OWASP Foundation. I had a chance to catch up with Karen at AppSecEU and just talk about OWASP in general and just get a bit of an idea about what's going on behind the scenes. And so we hope you enjoy. **0:19 Robert Hurlbut:** The Application Security Podcast. Here we are. Hey folks, we are once again at AppSec EU in London, and I am joined by Karen from the OWASP Foundation. And so Karen, we like to always start with what is your security origin story. So if you could introduce yourself and then tell us your security origin story. **1:08 Karen Staley:** Hi, good afternoon. My name is Karen Staley. I'm the Executive Director for the OWASP Foundation, having a great time in London. And I came to OWASP through experience as an executive director. My experience is nonprofit foundations, nonprofit trade organizations, and I was looking to do something new and different and found this incredible organization filled with passionate volunteers. And that really triggered something in me, and I thought, if these people are so passionate and so dedicated and devoted, we can do something with this foundation to create a very professional, growing and sustainable foundation that is dedicated and devoted to— I know we say application security, but I guess we could say software security too, and in an open and transparent way. I like that too. I think that, you know, talking about everything openly and allowing the community to contribute to the growth and pathway of the foundation is hugely important. **2:16 Robert Hurlbut:** So how long have you been at this role? **2:19 Karen Staley:** I started in November of 2017, so 8 months. **2:24 Robert Hurlbut:** So you were— you came on right after AppSec USA Orlando? **2:28 Karen Staley:** Yes, I did. I did. **2:29 Robert Hurlbut:** And so this is— this your first conference? **2:31 Karen Staley:** This is my first AppSec. **2:32 Robert Hurlbut:** All right, so what's your— I'm curious now as to what your perception is now seeing behind the scenes and seeing the conference. **2:38 Karen Staley:** Well, I think the conference is phenomenal and the community is incredible. So I've traveled a little bit. I went to, um, I went to AppSec Cali. I went to SnowFrock. I've been to New York chapter meetings just to get a feel and also to present myself and let people talk. I felt as though there were a lot of people that had a lot to say and weren't quite sure who to say it to. And so I wanted to be very welcoming and open and learn as much as I could about the community as I begin to understand how to serve the community. So when I came— oh, B-Sides, I've attended B-Sides and some other conferences too, and I see a lot of my fellow colleagues from BSides. Anyhow, so I began to get a feel for the dedication and the passion and the incredible extensive knowledge that everybody has about application or software security. And so coming here, I just wasn't sure how people would interact, what, you know, what their goals would be. And once again, you know, as usual, when you get deep into the community and meet people, you're so overwhelmed and pleasantly surprised at the sweetness, the dedication of the speakers, what they have to share, their passion, their unique features which make it always very interesting, and how important networking and being together is for the community. And so that just reconfirms that these gatherings, these AppSec conferences, training, and bringing together people with commonalities and philosophies about application security is highly, highly important. And so, um, yeah, I've enjoyed it. I've enjoyed it. **4:20 Robert Hurlbut:** Definitely a passionate group. I think it's— it's in— I've had experience with OWASP for, I don't know, probably since in the beginning. I used to work with Jeff Williams and Dave Wickers. Almost seems like at least decades ago, maybe feels longer than decades ago. But yeah, I mean, the thing I love about OWASP is no matter where you go, you find that same amount of passion. And it's a respectful passion though. Like, I've seen some other communities where people are not so— it just seems like people are generally nice to each other in the OWASP world. And I'm sure there's always corner cases, but it's just, it's a great type of community to be a part of. **4:59 Karen Staley:** So, um, yeah, we said that too. I was talking to a couple guys last night. We said, you know, you could travel anywhere in the world and get online and find somebody from OWASP. If you needed something, they'd be there to help you. Yeah, yeah, they'd be like, all right, what do you need? How can I help you? What are you doing? You know, come over here, my brother or sister. So I think that that's really cool. And I got that feeling when I was interviewing, you know, that that was hugely important. And for me, that's important. I want to be in a place where I can make a difference for a community. **5:26 Robert Hurlbut:** So I guess for the average person who's an OWASP member, what, what should they expect? Or what is their interface? Why would they interface with you? What, how do, how do I as a member, I'm just trying to kind of figure out how do I connect, or how do I connect with you? Or what's, for what reasons would I connect with you? **5:44 Karen Staley:** So, so one of my perspectives is that perhaps maybe that the community has been slightly more disengaged with the foundation over the past couple years. **5:54 Robert Hurlbut:** Okay. **5:54 Karen Staley:** We've had a little bit of a bumpy road, so to speak, and we've lost quite a few staff members. We've gained quite a few staff members, and I think that the foundation has grown very quickly and that looking ahead we can see ourselves finding ways to structure ourselves organizationally, internally, to be more supportive and to be more engaged with the community. So, you know, staffing and looking ahead to creating more opportunities for bringing the community together. **6:28 Robert Hurlbut:** Okay. **6:28 Karen Staley:** You heard in the board meeting we will do 3 global conferences next year. For me, that's highly important to be out amongst the community and go meet you where you are. **6:37 Chris Romeo:** Okay. **6:39 Karen Staley:** us also supporting the initiative of more regional events. **6:42 Robert Hurlbut:** Okay. **6:43 Karen Staley:** Sharing and supporting chapters to be more successful, to grow. We have over 220 chapters, you know, at all different stages of evolution, if you will, and experience and maturity. So we want to find ways to meet people where they are, that one box does not fit all, and to provide them with what they need to be successful at their level. success can be measured in all different ways. So we want to make sure that we are supporting them so that they feel successful at whatever level they're at and provide them with the opportunity to grow, give them opportunities to generate revenue, also be, you know, a voice for the foundation and membership. We would love to find more opportunities to provide members with greater benefits. Right now you get your email. **7:31 Robert Hurlbut:** Yeah. **7:32 Karen Staley:** You're OWASP.org. You also receive, you know, a discount when you register for our conferences. We'd like to find more opportunities at providing training at a discounted rate, perhaps for members, perhaps online training through different university channels, build relationships with universities. I think that we could be a great bridge connection between the practical working world and the academic world. **7:59 Robert Hurlbut:** Yeah. **8:00 Karen Staley:** Providing speakers at different, you know, educational opportunities and also bringing students in because I think youth is important to the life and the vitality of a foundation or any organization. **8:10 Chris Romeo:** After the break, Karen answers how we can deal with the shortage of people in cybersecurity and AppSec. The Application Security Podcast operates with support from Security Journey. A Security Belt program provides the 3 pillars of successful AppSec training: learning, application and experience. Visit us on the web at www.securityjourney.com to learn how you can teach and empower your developers using a new kind of security training. We jump back in with Karen discussing how to deal with the shortage of people in cybersecurity and specifically in application security. **8:52 Karen Staley:** Yeah, and I think that's where the developer view comes into play, that we want to look at, see if we can maybe do some conversions and bring people from other diverse backgrounds and convert them into AppSec people. So we'll be looking at the conference also. We had a conference call with the community the other day to talk a little bit about the conference and what, what things we could add to it to encourage more participation. **9:18 Robert Hurlbut:** Okay. **9:18 Karen Staley:** And a commonality among, among the, the people on the call said, you know, let's make it easier to come in here because some people may think, oh, you you know, I don't know anything about this, but I'm a developer, would I fit in? And the community is so open and they embrace anyone who's interested, but people aren't aware of that, so we have to communicate that more. So, you'll see us trying to communicate a lot more about the conference and what it means to be a part of the conference if you're not already an AppSec person. **9:45 Robert Hurlbut:** That's great. **9:46 Karen Staley:** You'll see more education. We are organizing— Matt Tesaro just came back on board, we hired Harold Blinkenstaff— Ship, also Blinkenship— to be part of the projects. We want to pull the projects back out. Some of them have been languishing for quite a while. **10:01 Robert Hurlbut:** Yes. **10:01 Karen Staley:** We have over 200 projects, and we really want to talk more about them and lift them up and support them. And in general, just, you know, continue to find a way to professionalize the foundation, create a real strong organizational structure internally that supports the community, and then also look at, you know, continued financial sustainability, which has been somewhat of our challenge over the past year. **10:26 Robert Hurlbut:** Yeah, and a couple things that I want to point out here. I think it's time for an OWASP membership drive, at least for our podcast listeners here. And I can tell you, I was at AppSec USA last year, and I was standing at the edge of the membership lounge, and I think Kelly was actually sitting there, and she says, are you an OWASP member? And I'm like, No, but I really should be since I've really taken a lot— I've taken advantage of this organization and the resources that are available for a long time. And so yeah, let me, let me just make that plea here. Like, if you're, if you're involved and you're someone who uses OWASP and attends chapter meetings and does those type of things and you're not a member, you should really consider because 40% of the membership goes to the local chapter. **11:09 Karen Staley:** You can, you can determine that. That's up to you. So you can give it to any chapter. If you're in Arizona and you want to give it to a chapter in Germany, that's up to you. **11:17 Robert Hurlbut:** Okay. **11:18 Karen Staley:** You know, we are a nonprofit foundation. We are dedicated to returning everything that we have back to the community, but it does take money to do the things that we're doing. And, you know, some people said, what do I get as a member? And I said, you know, you're also supporting and committing your relationship to the foundation by paying the $50 as an individual member and saying that this matters to you and that you want to see this organization continue to grow and thrive. And the only way you can do is to engage, and the first step for engagement is to sign up as a member. **11:47 Robert Hurlbut:** Yep. **11:48 Karen Staley:** So we do want you to be a member. We want you to be part of our community. We want you to talk to us, whether it's through our Slack channels or GitHub or, you know, Meetup or whatever it is that you're on. We want to hear from you. We want to know what's important to you. And we want to bring our relationship much closer from the community and the chapters back to the global foundation. And so that will be something that we'll be working on more and more as we develop, you know, our supportive projects, our supportive chapters, start engaging with chapters on different levels, regional events, and of course the global events. **12:22 Robert Hurlbut:** Yeah, and it sounds like that's a pretty good summary of kind of your thinking about where you're for the next year, so the next 1 to 2 years. Is there anything else that you kind of see that fits into your strategy other than, you know, focusing on the community, building out some more regional events, trying to bring new people in? Anything else that's kind of top of mind for you as far as where you want to see OWASP go in the next 1 or 2 years? **12:44 Karen Staley:** Well, I think if you look at the— if you look at application security or cybersecurity in general, you know, it's doing really, really well, and we should be reflecting the industry ourselves as a foundation. And I'm not so sure that's true today. And so I'd like to see us be more of a mirror image of what the industry is currently doing. And we can only do that through the community, the support of the community, being engaged with the community, and also being a part of the community. That's why it was so important when we hired Harold and we hired Matt. They're community people. **13:15 Robert Hurlbut:** Mm-hmm. **13:16 Karen Staley:** And so, you know, I would like to surround myself with more of those people. I spend a lot of time talking to chapter leaders, just trying to understand what I can do as a nonprofit executive to prepare the structure to allow those who know the community really well to support the community. You know, I think education is huge. Being a liaison between academic facilities and the foundation is very important. Seeking other revenue sources through endowments and grants. We do so much education. projects are open, transparent, anyone can use them. That means a lot. That means a lot, and that says a lot about who we are. **13:54 Robert Hurlbut:** It's a unique— I mean, OWASP is a unique entity in the world of technology because everything is open, and there's no price tag on what we give you, except for you. **14:04 Karen Staley:** You gain a lot. There's great value. **14:06 Robert Hurlbut:** Yeah, that's the— actually, the talk that I just did here at AppSecEU was about building an AppSec program for a budget of zero using only OWASP Oh, awesome. And I was able to go through and pinpoint all the way across the board programmatically, here's all the things you can use. You still need people to drive a program, but with everything with a price tag of zero on all the, all the projects, you can string those together and actually build a program out of it. And that's huge. From, you know, find, find me someplace else in tech where you can do that. Another— **14:36 Karen Staley:** Greatest membership recruitment message we could have right now. No, and that's really the basis of who we are. Yeah, yeah. And I want to continue to fortify that and grow that. **14:47 Robert Hurlbut:** Yeah, that's awesome. And I'll definitely— I want to commend you and the rest of the staff. I know you operate on a very small— it's a skeleton crew is the only way I can think of to describe it. And you do so many— the group of OWASP Foundation employees do so much for the community. with a very small group. And so I just want to thank you for taking this role and helping us to bring OWASP into the future. But also, I know there's a lot of people that work with you that are, that are crucial to even pull off an event like we are. We're sitting at AppSecEU and the event has gone flawless. There's been really— it's just been a great event with a great community connection. And I know it's a lot of hard work behind the scenes. **15:27 Karen Staley:** So, but you know, it's, it's, it's wonderful because by working on these things, with the chapters that are supporting us, the Bristol chapter, the Dublin chapter, you know, the Cambridge chapter, the London chapter. We already are much more engaged with the community than we ever would have been with just doing it as a professional organization and just handing it to you and saying, please come. So I've gained great relationships, you know, developed a much better understanding of how to serve the community in this region, and I wouldn't do it any other way. **15:56 Robert Hurlbut:** Yeah, yeah, yeah, it's a great model. **15:58 Karen Staley:** We thank, we thank everybody. We thanked them last night, but thank you is just really not enough sometimes when I think about the phone calls. What do you need? How can I help? And some of the guys that are running around here with the red shirts on from 8 to 8 is amazing. It's amazing. So we're very thankful. **16:14 Robert Hurlbut:** Great group of volunteers as always. So Karen, thank you for taking the time to introduce our listeners and hopefully even a bigger audience to what's happening at OWASP, and we wish you good luck, and we'll be looking for ways to partner with you into the future to make this successful. **16:29 Karen Staley:** Thank you, thank you. I look forward to the partnership, and thank you for your time, and thank you for even, you know, interviewing me and giving me this opportunity. **16:35 Robert Hurlbut:** Awesome, thank you. **16:36 Karen Staley:** I really appreciate it. **16:38 Robert Hurlbut:** Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ. And the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org. --- Source: https://appsecpodcast.com/karen-staley-a-conversation-with-karen/