What should OWASP members expect from the foundation’s executive leadership, and how can a global nonprofit remain connected to its volunteer community? Karen Staley joins Chris and Robert during AppSec Europe to discuss her early experience as OWASP’s executive director.
Audio hosted by Buzzsprout. Nothing loads until you press play.
Episode chapters · 9 chapters
- 00:00A conversation with OWASP leadershipAudio
- 01:08Karen Staley’s nonprofit backgroundAudio
- 02:16Joining OWASP as executive directorAudio
- 05:26How members connect with the foundationAudio
- 08:52Conferences, developers, and broader participationAudio
- 10:26Membership and supporting local chaptersAudio
- 12:23Strategic priorities for OWASPAudio
- 15:27Building stronger community engagementAudio
- 16:20Closing thoughtsAudio
About this episode
What should OWASP members expect from the foundation’s executive leadership, and how can a global nonprofit remain connected to its volunteer community? Karen Staley joins Chris and Robert during AppSec Europe to discuss her early experience as OWASP’s executive director. She explains how her nonprofit background prepared her for a passionate technical community, how members and chapter leaders interact with the foundation, and why conferences, membership, and diverse participation matter to OWASP’s future. The conversation also explores fundraising, strategic priorities, and the challenge of supporting local chapters while preserving an open organization. Karen closes with a call for greater community engagement and partnership.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Karen Staley and OWASP:
→ OWASP Foundation
Resources
→ OWASP Foundation
→ OWASP Chapters
Actionable
From this conversation
- 4:59
Ask the OWASP community for help
We said, you could travel anywhere in the world and get online and find somebody from OWASP.
- 10:26
Join OWASP
If you're, if you're involved and you're someone who uses OWASP and attends chapter meetings and does those type of things and you're not a member, you should consider because 40% of the membership goes to the local chapter.
- 12:44
Support a representative security community
We can only do that through the community, the support of the community, being engaged with the community, and being a part of the community.
Transcript · 17 min conversation
0:00Chris RomeoHey folks, season 4, episode 9 of the AppSec Podcast. On this episode, we're joined by Karen Staley, who is the executive director of the OWASP Foundation. I had a chance to catch up with Karen at AppSecEU and just talk about OWASP in general and just get a bit of an idea about what's going on behind the scenes. And so we hope you enjoy.
0:19Robert HurlbutThe Application Security Podcast. Here we are. Hey folks, we are once again at AppSec EU in London, and I am joined by Karen from the OWASP Foundation. And so Karen, we like to always start with what is your security origin story. So if you could introduce yourself and then tell us your security origin story.
1:08Karen StaleyHi, good afternoon. My name is Karen Staley. I'm the Executive Director for the OWASP Foundation, having a great time in London. And I came to OWASP through experience as an executive director. My experience is nonprofit foundations, nonprofit trade organizations, and I was looking to do something new and different and found this incredible organization filled with passionate volunteers. And that really triggered something in me, and I thought, if these people are so passionate and so dedicated and devoted, we can do something with this foundation to create a very professional, growing and sustainable foundation that is dedicated and devoted to— I know we say application security, but I guess we could say software security too, and in an open and transparent way. I like that too. I think that, you know, talking about everything openly and allowing the community to contribute to the growth and pathway of the foundation is hugely important.
2:16Robert HurlbutSo how long have you been at this role?
2:19Karen StaleyI started in November of 2017, so 8 months.
2:24Robert HurlbutSo you were— you came on right after AppSec USA Orlando?
2:28Karen StaleyYes, I did. I did.
2:29Robert HurlbutAnd so this is— this your first conference?
2:31Karen StaleyThis is my first AppSec.
2:32Robert HurlbutAll right, so what's your— I'm curious now as to what your perception is now seeing behind the scenes and seeing the conference.
2:38Karen StaleyWell, I think the conference is phenomenal and the community is incredible. So I've traveled a little bit. I went to, um, I went to AppSec Cali. I went to SnowFrock. I've been to New York chapter meetings just to get a feel and also to present myself and let people talk. I felt as though there were a lot of people that had a lot to say and weren't quite sure who to say it to. And so I wanted to be very welcoming and open and learn as much as I could about the community as I begin to understand how to serve the community. So when I came— oh, B-Sides, I've attended B-Sides and some other conferences too, and I see a lot of my fellow colleagues from BSides. Anyhow, so I began to get a feel for the dedication and the passion and the incredible extensive knowledge that everybody has about application or software security. And so coming here, I just wasn't sure how people would interact, what, you know, what their goals would be. And once again, you know, as usual, when you get deep into the community and meet people, you're so overwhelmed and pleasantly surprised at the sweetness, the dedication of the speakers, what they have to share, their passion, their unique features which make it always very interesting, and how important networking and being together is for the community. And so that just reconfirms that these gatherings, these AppSec conferences, training, and bringing together people with commonalities and philosophies about application security is highly, highly important. And so, um, yeah, I've enjoyed it. I've enjoyed it.
4:20Robert HurlbutDefinitely a passionate group. I think it's— it's in— I've had experience with OWASP for, I don't know, probably since in the beginning. I used to work with Jeff Williams and Dave Wickers. Almost seems like at least decades ago, maybe feels longer than decades ago. But yeah, I mean, the thing I love about OWASP is no matter where you go, you find that same amount of passion. And it's a respectful passion though. Like, I've seen some other communities where people are not so— it just seems like people are generally nice to each other in the OWASP world. And I'm sure there's always corner cases, but it's just, it's a great type of community to be a part of.
4:59Karen StaleySo, um, yeah, we said that too. I was talking to a couple guys last night. We said, you know, you could travel anywhere in the world and get online and find somebody from OWASP. If you needed something, they'd be there to help you. Yeah, yeah, they'd be like, all right, what do you need? How can I help you? What are you doing? You know, come over here, my brother or sister. So I think that that's really cool. And I got that feeling when I was interviewing, you know, that that was hugely important. And for me, that's important. I want to be in a place where I can make a difference for a community.
5:26Robert HurlbutSo I guess for the average person who's an OWASP member, what, what should they expect? Or what is their interface? Why would they interface with you? What, how do, how do I as a member, I'm just trying to kind of figure out how do I connect, or how do I connect with you? Or what's, for what reasons would I connect with you?
5:44Karen StaleySo, so one of my perspectives is that perhaps maybe that the community has been slightly more disengaged with the foundation over the past couple years.
5:54Robert HurlbutOkay.
5:54Karen StaleyWe've had a little bit of a bumpy road, so to speak, and we've lost quite a few staff members. We've gained quite a few staff members, and I think that the foundation has grown very quickly and that looking ahead we can see ourselves finding ways to structure ourselves organizationally, internally, to be more supportive and to be more engaged with the community. So, you know, staffing and looking ahead to creating more opportunities for bringing the community together.
6:28Robert HurlbutOkay.
6:28Karen StaleyYou heard in the board meeting we will do 3 global conferences next year. For me, that's highly important to be out amongst the community and go meet you where you are.
6:37Chris RomeoOkay.
6:39Karen Staleyus also supporting the initiative of more regional events.
6:42Robert HurlbutOkay.
6:43Karen StaleySharing and supporting chapters to be more successful, to grow. We have over 220 chapters, you know, at all different stages of evolution, if you will, and experience and maturity. So we want to find ways to meet people where they are, that one box does not fit all, and to provide them with what they need to be successful at their level. success can be measured in all different ways. So we want to make sure that we are supporting them so that they feel successful at whatever level they're at and provide them with the opportunity to grow, give them opportunities to generate revenue, also be, you know, a voice for the foundation and membership. We would love to find more opportunities to provide members with greater benefits. Right now you get your email.
7:31Robert HurlbutYeah.
7:32Karen StaleyYou're OWASP.org. You also receive, you know, a discount when you register for our conferences. We'd like to find more opportunities at providing training at a discounted rate, perhaps for members, perhaps online training through different university channels, build relationships with universities. I think that we could be a great bridge connection between the practical working world and the academic world.
7:59Robert HurlbutYeah.
8:00Karen StaleyProviding speakers at different, you know, educational opportunities and also bringing students in because I think youth is important to the life and the vitality of a foundation or any organization.
8:10Chris RomeoAfter the break, Karen answers how we can deal with the shortage of people in cybersecurity and AppSec. The Application Security Podcast operates with support from Security Journey. A Security Belt program provides the 3 pillars of successful AppSec training: learning, application and experience. Visit us on the web at www.securityjourney.com to learn how you can teach and empower your developers using a new kind of security training. We jump back in with Karen discussing how to deal with the shortage of people in cybersecurity and specifically in application security.
8:52Karen StaleyYeah, and I think that's where the developer view comes into play, that we want to look at, see if we can maybe do some conversions and bring people from other diverse backgrounds and convert them into AppSec people. So we'll be looking at the conference also. We had a conference call with the community the other day to talk a little bit about the conference and what, what things we could add to it to encourage more participation.
9:18Robert HurlbutOkay.
9:18Karen StaleyAnd a commonality among, among the, the people on the call said, you know, let's make it easier to come in here because some people may think, oh, you you know, I don't know anything about this, but I'm a developer, would I fit in? And the community is so open and they embrace anyone who's interested, but people aren't aware of that, so we have to communicate that more. So, you'll see us trying to communicate a lot more about the conference and what it means to be a part of the conference if you're not already an AppSec person.
9:45Robert HurlbutThat's great.
9:46Karen StaleyYou'll see more education. We are organizing— Matt Tesaro just came back on board, we hired Harold Blinkenstaff— Ship, also Blinkenship— to be part of the projects. We want to pull the projects back out. Some of them have been languishing for quite a while.
10:01Robert HurlbutYes.
10:01Karen StaleyWe have over 200 projects, and we really want to talk more about them and lift them up and support them. And in general, just, you know, continue to find a way to professionalize the foundation, create a real strong organizational structure internally that supports the community, and then also look at, you know, continued financial sustainability, which has been somewhat of our challenge over the past year.
10:26Robert HurlbutYeah, and a couple things that I want to point out here. I think it's time for an OWASP membership drive, at least for our podcast listeners here. And I can tell you, I was at AppSec USA last year, and I was standing at the edge of the membership lounge, and I think Kelly was actually sitting there, and she says, are you an OWASP member? And I'm like, No, but I really should be since I've really taken a lot— I've taken advantage of this organization and the resources that are available for a long time. And so yeah, let me, let me just make that plea here. Like, if you're, if you're involved and you're someone who uses OWASP and attends chapter meetings and does those type of things and you're not a member, you should really consider because 40% of the membership goes to the local chapter.
11:09Karen StaleyYou can, you can determine that. That's up to you. So you can give it to any chapter. If you're in Arizona and you want to give it to a chapter in Germany, that's up to you.
11:17Robert HurlbutOkay.
11:18Karen StaleyYou know, we are a nonprofit foundation. We are dedicated to returning everything that we have back to the community, but it does take money to do the things that we're doing. And, you know, some people said, what do I get as a member? And I said, you know, you're also supporting and committing your relationship to the foundation by paying the $50 as an individual member and saying that this matters to you and that you want to see this organization continue to grow and thrive. And the only way you can do is to engage, and the first step for engagement is to sign up as a member.
11:47Robert HurlbutYep.
11:48Karen StaleySo we do want you to be a member. We want you to be part of our community. We want you to talk to us, whether it's through our Slack channels or GitHub or, you know, Meetup or whatever it is that you're on. We want to hear from you. We want to know what's important to you. And we want to bring our relationship much closer from the community and the chapters back to the global foundation. And so that will be something that we'll be working on more and more as we develop, you know, our supportive projects, our supportive chapters, start engaging with chapters on different levels, regional events, and of course the global events.
12:22Robert HurlbutYeah, and it sounds like that's a pretty good summary of kind of your thinking about where you're for the next year, so the next 1 to 2 years. Is there anything else that you kind of see that fits into your strategy other than, you know, focusing on the community, building out some more regional events, trying to bring new people in? Anything else that's kind of top of mind for you as far as where you want to see OWASP go in the next 1 or 2 years?
12:44Karen StaleyWell, I think if you look at the— if you look at application security or cybersecurity in general, you know, it's doing really, really well, and we should be reflecting the industry ourselves as a foundation. And I'm not so sure that's true today. And so I'd like to see us be more of a mirror image of what the industry is currently doing. And we can only do that through the community, the support of the community, being engaged with the community, and also being a part of the community. That's why it was so important when we hired Harold and we hired Matt. They're community people.
13:15Robert HurlbutMm-hmm.
13:16Karen StaleyAnd so, you know, I would like to surround myself with more of those people. I spend a lot of time talking to chapter leaders, just trying to understand what I can do as a nonprofit executive to prepare the structure to allow those who know the community really well to support the community. You know, I think education is huge. Being a liaison between academic facilities and the foundation is very important. Seeking other revenue sources through endowments and grants. We do so much education. projects are open, transparent, anyone can use them. That means a lot. That means a lot, and that says a lot about who we are.
13:54Robert HurlbutIt's a unique— I mean, OWASP is a unique entity in the world of technology because everything is open, and there's no price tag on what we give you, except for you.
14:04Karen StaleyYou gain a lot. There's great value.
14:06Robert HurlbutYeah, that's the— actually, the talk that I just did here at AppSecEU was about building an AppSec program for a budget of zero using only OWASP Oh, awesome. And I was able to go through and pinpoint all the way across the board programmatically, here's all the things you can use. You still need people to drive a program, but with everything with a price tag of zero on all the, all the projects, you can string those together and actually build a program out of it. And that's huge. From, you know, find, find me someplace else in tech where you can do that. Another—
14:36Karen StaleyGreatest membership recruitment message we could have right now. No, and that's really the basis of who we are. Yeah, yeah. And I want to continue to fortify that and grow that.
14:47Robert HurlbutYeah, that's awesome. And I'll definitely— I want to commend you and the rest of the staff. I know you operate on a very small— it's a skeleton crew is the only way I can think of to describe it. And you do so many— the group of OWASP Foundation employees do so much for the community. with a very small group. And so I just want to thank you for taking this role and helping us to bring OWASP into the future. But also, I know there's a lot of people that work with you that are, that are crucial to even pull off an event like we are. We're sitting at AppSecEU and the event has gone flawless. There's been really— it's just been a great event with a great community connection. And I know it's a lot of hard work behind the scenes.
15:27Karen StaleySo, but you know, it's, it's, it's wonderful because by working on these things, with the chapters that are supporting us, the Bristol chapter, the Dublin chapter, you know, the Cambridge chapter, the London chapter. We already are much more engaged with the community than we ever would have been with just doing it as a professional organization and just handing it to you and saying, please come. So I've gained great relationships, you know, developed a much better understanding of how to serve the community in this region, and I wouldn't do it any other way.
15:56Robert HurlbutYeah, yeah, yeah, it's a great model.
15:58Karen StaleyWe thank, we thank everybody. We thanked them last night, but thank you is just really not enough sometimes when I think about the phone calls. What do you need? How can I help? And some of the guys that are running around here with the red shirts on from 8 to 8 is amazing. It's amazing. So we're very thankful.
16:14Robert HurlbutGreat group of volunteers as always. So Karen, thank you for taking the time to introduce our listeners and hopefully even a bigger audience to what's happening at OWASP, and we wish you good luck, and we'll be looking for ways to partner with you into the future to make this successful.
16:29Karen StaleyThank you, thank you. I look forward to the partnership, and thank you for your time, and thank you for even, you know, interviewing me and giving me this opportunity.
16:35Robert HurlbutAwesome, thank you.
16:36Karen StaleyI really appreciate it.
16:38Robert HurlbutThanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ. And the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org.
3,064 words · transcript by assemblyai
More on Conferences and Community
View all episodes →- July 29, 2019 · 23 minErez Yalon and Liora Herman – The Application Security Village @ DefCon
- November 29, 2016 · 27 minChris Romeo -- Security Community at Any Scale
- March 9, 2023 · 38 minJames Mckee -- Developer Security