OWASP Candidate Debate - 2025 Edition
on OWASP Projects, Software Supply Chain, Careers in AppSec and Conferences and Community
Audio hosted by Buzzsprout. Nothing loads until you press play.
In this special episode of the Application Security Podcast we meet nine of the OWASP Board of Directors candidates. Each candidate discusses their unique qualifications, experiences, and vision for OWASP’s future. Topics include enhancing OWASP’s impact, improving outreach and education, securing funding, and engaging local chapters. Don’t miss this insightful debate as these candidates share their strategies to help secure a brighter future for OWASP.
Mentioned in this episode
- OWASP 2025 Global Board Electionsboard.owasp.org
- OWASP Global Board Candidatesowasp.org
- OWASP Foundationowasp.org
- OWASP Dependency-Checkowasp.org
- OWASP Dependency-Trackdependencytrack.org
- OWASP CycloneDXcyclonedx.org
- OWASP Nettackerowasp.org
- OWASP Application Security Verification Standard (ASVS)owasp.org
- OWASP Security Champions Guidesecuritychampions.owasp.org
Enjoyed this one? Get Reasonable AppSec, the newsletter with new episodes and picks from the archive.
Transcript
10,238 words · assemblyai
0:00Chris RomeoIn today's episode of the Application Security Podcast, we are joined by 9 OWASP Board of Directors candidates to discuss their qualifications and visions for the organization's future. Each candidate emphasizes their unique experiences and proposes strategies to enhance OWASP's impact and resources.
0:17Robert HurlbutThe Application Security Podcast is brought to you by Security Journey. We help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC.
0:28Chris RomeoLearn more at securityjourney.com. Hey folks, welcome to a very special episode of the Application Security Podcast. This is Chris Romeo. I'm a VP at Security Compass and a general partner at Curve Ventures, as always joined by my good friend, Robert. who is the timer guy today, because it is debate season. Hey, Robert. Hey, Chris. Yeah, Robert Hurlbut, Principal Product Security Architect and Threat Modeling Trainer at Torion. And yeah, fantastic day to be here. Special program. Enjoy it. Yeah, here we go. So, we're going to jump right in because we got a lot to talk about and a lot of ground to cover. So, we have with us 9 candidates who are going to have an opportunity to introduce themselves. And with this first question, we're asking them to to introduce themselves, but also talk about why you're uniquely positioned to be on the board of directors and what prior experience you have that you think is going to— is really going to help you be successful in this role. Robert's running the timer. We're going to start with Jerry, first candidate up. Hey, everybody. My name is Jerry Hoff, longtime OWASP contributor. I'm also the co-lead of the OWASP Virtual Chapter, owasp.vc. Feel free to join us anytime. I've also been a project leader. If you're familiar with antisami.net, webgoat.net, or the OWASP AppSec tutorial series, which I put out over a decade ago, I led all those up as well. I also speak at a lot of OWASP chapters. In fact, I'm right here right now in Dallas. Right after this show, I'm going to go speak at the OWASP Dallas chapter on the intersection of AI and AppSec. A little bit of my past. I used to be head of security at Sony, so Sony Electronics and Sony Semiconductor. I was based out of Japan, and it was a large organization where we did security across the board, including application security. I've— I want to mention on why I think I'm uniquely qualified for this role, but I will mention I don't know that I'm uniquely qualified. I think everybody is really uniquely qualified, and we've got such a great panel. The good thing about this election is it almost doesn't matter who you vote for, you're gonna get somebody good. But I will tell you a few things that I've been doing that give me a little bit more insight onto the board than kind of your normal OWASP-er. I, along with Kelly Santa Lucia, we've been running a project called the OWASP EAR. So that is the Executive Advisory Report, where we went out and we spoke to the heads of AppSec in many large organizations, and we asked them, why is your organization not a member of OWASP? And we got phenomenal insights. What's great about that project is so many organizations around the world use OWASP materials on a daily basis, but yet they're not members. So there's clearly a disconnect there. So that is definitely one thing. The other thing is I do have experience running large organizations. So as my, you know, my day job when I was head of security, for example, over at Sony Electronics, Had hundreds of people in my organization, and we dealt with application security and security in many different areas. So that's it. Hand it over back over to you, Chris. Thanks, Jerry. Yeah, thanks, Jerry. All right, up next we have Gustavo. Hi, everyone. My name is Gustavo Nieves Arriaza. I came from South America, but I'm based in United States. I was honored receiving the O-1 visa, talent visa for or talent visa for. Extraordinaries abilities in the reserves or AppSec and ExecOps. I started like volunteer in OWASP. After that, I was OWASP chapter leader for 5 years and coordinator of the OWASP LATAM. In the last meetings, we had like subcontinent. I am referenced in the definition of Wikipedia about the SAST tool. That means static application security testing, reference number because I was publisher for the IEEE in Paris and also one of the major and more prestigious universities in Paris, the Télécom ParisTech. And after that, I wrote a couple of papers like co-author for the Cloud Security Alliance. I created a video course for the EC-Council about hands-on under penetration testing.
5:03Robert HurlbutWow.
5:04Chris RomeoAnd like owner or a business entity in United States, I also learning about taxes, compliance, regulations, and that bring me the possibility to bring the vision I have about application security from Europe, America, South America in general. And my goal here is integrate another regions like South America to be more stronger, Asia and Africa. Okay, thanks, Gustavo. Up next, we have Adrian. Hi, everyone. My name's Adrian Winkles. I'm a cybersecurity professional, academic, and community leader, I guess, with over 3 decades of experience. I'd say my career spanned academia, industry, and international organizations. My contribution to OWASP has been going on about 14 years. I joined OWASP in 2011. I've led the Cambridge UK chapter all that time, hosting monthly community events, bringing together practitioners, researchers, and students. One of my claims to fame, in 2014, I was the joint chair of the OWASP Europe AppSec conference in Cambridge, involved in all aspects of it, and I was co-opted onto the European board in 2015. And I've been contributing to certainly AppSec Europe events, both as reviewing speakers, reviewing training proposals, and helping with the university challenge up until about 2019. I've also since 2019 served as the chair of the Education and Training Committee overseeing strategies for education, training, and moving on to certification at the moment. I've also been a project leader. I've led the Distributed Web Honeypot Project and also the Application Security Curriculum Project. So I think my multitude of experience across OWASP places me in good stead to represent the board. Outside OWASP, I also volunteer with the British Computer Society, and I chair one of their special interest groups, the Cybercrime Forensics Group, developing initiatives and skill frameworks. I'm And I also am director of the Cyber East, the local cybersecurity cluster in the east of England. Very good. Thanks, Adrian. Up next is Fred. Everyone, this is Fred Donovan. I am a divisional security lead and application architect, security architect for a large multinational company based out of the Netherlands. I helped lead an application security program of over 350 security champions with thousands of technologists. I have a lot of experience in OWASP. I think the first chapter meeting I went to was in 2005, but I've been— became more active when I joined the New York chapter in 2007. And I have had an opportunity to speak at a lot of the different OWASP conferences across the world and had several contributions to projects. But most importantly, I've just enjoyed the OWASP family and want to see it continue to grow. We have got a lot of great people here on the board, and I'm excited to see everybody running. I think OWASP has a lot of great opportunities. to push our brand across the globe. And I think if you've seen my video, there are some poignant possibilities that we can do. But we thrive basically on fresh perspectives. And I'm glad that there's a turnover on board members every 2 years. Well, every year I should say, we see new board members come in like me who are really in the trenches and doing everything that really you would expect of application security veterans. So, I think the track record of everybody here is excellent, and everybody's a really good choice. My skills, frankly, are probably transferable to everybody and back. So, we've been doing a lot of the good things, but I think there's some things that we need to improve on, and I hope to get a chance to talk about those more today. I've been a lecturer for computer science and cybersecurity. So, thank you very much. All right. Up next is Steve. All right. Hello, everyone. My name is Steve Springett. I am currently the Director of Product Security at ServiceNow, where me and my team help upwards of 1,000 different development teams build and deliver secure and resilient software. It is a challenge. The— I've had a— my first intro in OWASP was back in 2012. I was the very first contributor to the OWASP Dependency Check project before Jeremy did his announcement back at the Black Hat, I think the same year. I'm the current lead of the OWASP Dependency Track project, OWASP CycloneDX. I'm the lead and co-author of the OWASP Software Component Verification Standard and the newest one, which is the OWASP Common Lifecycle Enumeration. My work is— my work and its guidance is used by— is referenced by governments, by industry, and by international standards. I currently serve as the vice chair on the global board of directors, my first year. I was fortunate enough to be elected and I served as a member at large my first year, kind of learning the ropes of what it means to be a board member. And I had a lot of great mentors, Avi and Grant, for example, 2 of the former chairs that I learned from. Currently serving as vice chair and hope to continue that with another term. So thank you. All right, thanks, Steve. Up next is Marissa.
11:42Robert HurlbutGreat, thanks everyone. Marissa Fagan here. I'm currently a product manager at a startup called Catalyst, but also by my early mornings, I am working in the Secure Security Champions Guide project as a contributor in OWASP, and I'm also the the track lead for the global conferences. I've been doing that for the past year. I think there's 4 specific reasons why I am uniquely suited to be on the board, such as the prompt goes. The first thing is I have been on a board before. I was board on a nonprofit for the conference in San Francisco called Bay Threat for several years. The next thing is that I have my entire career based on technical program management. So my background is actually as a TPM. And so I'm very familiar with what the roles and responsibilities of the board are, and also what they are not, which I think is a really good power to have to understand how to work with leadership. And I, Yeah, had served as the director of security program management in a large corporation. So very familiar with that. I also have a longtime background in behavioral science and ran security awareness programs for many years. And I think that's sort of a unique characteristic that I have as somebody that kind of understands how to work well with people and understanding what their motivations are. And then I do have 16 years as an AppSec practitioner. So I have built secure SDLC programs and run security champions programs at many large organizations over the years. And I have— I think I can say that it is literally my job to understand how to get developers to like security. Thanks.
13:50Chris RomeoThanks, Marissa. Up next, we have Sam. Hi everyone, my name is Sam Stepanian. I am a chapter leader of the OWASP London chapter, and I'm actually another long-timer. I'm an active member of OWASP community going back to 2007 when I joined the OWASP London chapter, became OWASP member in 2010. I've been organizing lots and lots of OWASP London chapter meetings since then, obviously running the community there. I also had a role of the OWASP chapter committee chair recently as well. I'm also an OWASP project leader. I lead OWASP Netacker project. If you don't know what Netacker is, do check it out. It's a great project. We did a podcast on that with Chris. I contributed to a few other projects, including OWASP Top 10. A few other things to mention. I served as a mentor in the Google Summer of Code program, guiding students to work on OWASP projects. Lots of talks at local universities in London, basically evangelizing OWASP to cybersecurity. and computer science students, speak at various OWASP conferences all around the world, as well as BSides conferences. And just like Steve, I'm also currently on the OWASP board. So to answer the question, what qualifies me to be on the board? I'm currently an OWASP board member. This year I've been serving as a secretary of the board. And I think we've been working very, very well together. The board this year, I think, is achieving quite great harmony in the way how we work, how we think, which I think is great. Obviously, I would like to continue that this year. Thanks, Sam. Up next is Arunesh.
16:03Robert HurlbutArunesh.
16:05Chris RomeoHi, good afternoon, good evening everyone. I assume everybody is in US by the looks of it. So my name is Harunish Salhotra based out of New York, been a long-time New Yorker almost for 21 years, married with 2 daughters itself. And I think at the get-go itself what defines me is 3 different areas that I really enjoy doing. It's more of a lifelong learner, I believe we cannot know everything at any given point in time with AI coming in. there is so much we don't know. And the second aspect is I'm known for uplifting communities and not just like organization stuff, right, it's like I volunteer time at a New York public school, PS 51, for over like last 11 years where I teach elementary math and English itself. So that is like part of things that are ingrained into my upbringing itself. And again from a professional perspective I bring like more than 2 decades of experience in cross-section of technologies whether it's like development, system engineering to infrastructure security. And I think at the very get-go of my career, I never wanted to settle to just being like in one particular domain, right. So I kind of delved into like program management, audit, security, compliance, and also of late I've been like doing a lot of investment in companies. So which actually brings the natural stuff that comes with it like go-to-market, marketing. And that's something I really enjoy. I had one successful exit almost like a decade plus ago, I sold that company and have an advisory business that I've been running for the last 11 years focused on DevSecOps. Talking about a board of directors experience, again, like as a former founder also I serve on at least 3 boards, one is a nonprofit and there are 2 boards for companies. And also, what else? In terms of what provides me uniqueness, I think it's a couple of things, right? One aspect is having the business acumen, working with different people. All right. Thanks, Sardines. And then Arvind is our final candidate to introduce.
18:16Robert HurlbutHey.
18:17Chris RomeoHi, everyone. I'm Arvind Janardhanan. I'm currently the principal engineer and interim director of an application security and SecurePort program at a large sports athletic retail apparel brand from Pacific Northwest. So I have been leading and building programs from an enterprise perspective. I have been a longtime consumer of OWASP, and obviously I should have been— I'm not a big contributor into the project, so I'm probably a non-traditional candidate here, but I basically consume pretty much, you know, the dependency check, the OWASP Top 10. And in my program, we have, you know, your SAST, SCA, secrets, DAST, you know, API security. All of it is as part of my program. We generally build it from an engineering mindset. So So we deliver it with cost constraints as well as making sure that it's not vendor dependent. A lot of the open source mindset is applied within the enterprise boundaries, and I feel I can bring those learnings into OWASP to figure out how we can, you know, apply some of the enterprise mindset into the OWASP as an organization. From my perspective, why I believe being uniquely positioned, I don't believe I'm uniquely positioned as the most qualified candidate, but I do believe that I bring a new perspective into the group because being a longtime consumer, and I've actually been a longtime member, permanent member of the OWASP, of OWASP, but I've not really had the time or maybe for focus on investing. Maybe being a part of the board helps me drive that focus, enterprise focus here. In terms of prior board experience, I don't have prior board experience, but I do have prior director experience and principal engineering experience within enterprise place in our systems. All right. Thanks, Arvind. Yeah, so I mean, this is quite a group of folks who stepped forward to represent OWASP here. I'm a bit in awe at the moment of everybody's qualifications. This is just a great group. I'm really excited about what the future holds. First public service announcement of the day, if you are an OWASP member, get out and vote. Okay, that's that's what it all really boils down to here. Like we we have to we have to you know raise our hand and and choose candidates here, and it takes membership getting out and voting. And you got to be an OAS member to do that. But when you get that email coming in, go do it, please. Okay, we're going to move into our second question on the list, and this will be first for Gustavo. And that question is. What out-of-the-box ideas do you have to make OWASP more relevant? And you're gonna have one minute. Everybody gets one minute for this answer. Go ahead, Gustavo. Thank you. In my personal opinion, I believe the people is not reading anymore. And secondly, we are repeating the same tools and presentations in the majority of the OWASP events. What happens if we create an AI, OWASP AI, free, open source, and we share the documentation and the projects we have there? And from there we create customized courses, small courses, media courses, video for YouTube, TikTok, and Instagram. Because when I review the numbers or the social media group we have around the world, the majority of the speakers to have presence in person don't have the numbers or don't bring too much attention in the channels. By using the AI also, we can identify the possible source of funding and possible sponsor for the next event. Okay, thanks, Gustavo. Adrian, coming to you next. Just a reminder, out-of-box ideas to make OWASP more relevant. I think to make OWASP relevant is education and all aspects of education. Bringing OWASP into the classroom, be it from tertiary level upwards or even before, so that those that are studying cybersecurity or any aspect of information security know about OWASP, know about its projects, know about its chapter meetings, know about its educational programs. Bringing OWASP into education, there are lots of linkages to education, but we're not doing a global job of this. And having more representation for education in our chapters, bringing— we've started certification program, but going a lot further, making sure that education is at the heart And the education is a continuous cycle. We need to retrain, developers need to retrain. So making education central to the goals. Okay, up next we have Fred. So there's a few things that I think that out-of-the-box ideas perhaps that we need to do. Revise our funding model. So that means making sure that corporations that are not tech providers, not tool providers, but those people that, those companies that ingest our OWASP products can support the projects in a different way. And the way you do this is give them an opportunity to invest in OWASP as a sponsor, but allow them an opportunity internally to create OWASP chapters in their corporation. Also, community involvement. I talked about this in my video. I think it's important that we do monthly workshops, led by board members who have experience at these types of international topics or just the EPSEC topics, because we have an opportunity to be the conveyors of the discussion. And we get a chance to talk about critical topics to everyone and be involved more in a better way and just engage people better. All right. Steve is up next. Uh, yeah, so, um, for me, it's, it's really about 3 things. Uh, fundraising and revenue diversification. Uh, it's one thing to try to just get additional revenue from your existing streams. It's something entirely different to diversify the types of streams that you actually have, uh, which is, we actually have some work in progress. With the current board to make that a reality. Some of the ideas around hosting of OWASP projects, education and certifications, along with assessments such as ASVS, OWASP SAM, et cetera. Outreach is a big one. So, not just outreach in traditional AppSec sense, we need to speak their language, whether that's developer communities, CISOs and policymakers, or international standards bodies. We need to be present and we need to speak their language. Third is actually communicating our impact. OWASP has a tremendous impact across the entire security space, yet not a lot of visibility. Thank you. Okay, Marissa.
25:54Robert HurlbutThanks, Chris. I also have 3 ideas, mine most entirely in the outreach category. Number one, I think we could do more to reach out to developers, and I would love to see us at the Game Developers Conference. There's a— GDC is in March in San Francisco, and I think it would be really cool if we were there. Uh, second thing is, when we have a head of marketing that's about to be hired, I would love to see them make a training for all of our project leads and our chapter leads to give a marketing training to everyone to fill in the gaps of our knowledge so that we have a very action-oriented marketing strategy that everyone feels like they're a part of. The third thing is I would like to see 3 global conferences, the third one in the Arab region. We've talked about this on our website proposals. So if you want more information about that and then moving our US conference out of D.C., moving it out of San Francisco, maybe moving it to Atlanta. a place that is much more economical to host a conference.
26:59Chris RomeoOkay.
27:01Robert HurlbutTime.
27:01Chris RomeoUp next is Sam. Yeah, my out-of-the-box idea is the OWASP Certified Secure Developer certification. My idea that I brought to the board when I was elected, and I'm still pushing on with it because historically OWASP never had a certification, not been a certification body, and I think it's time. I started working on this and that work is ongoing. I've had lots of support both from the community, from the developers, and also from various organizations including the industry and academia as well. I've got Adrian here helping me out from the Education and Training Committee. This is something that OWASP never done before, and this is something that we started doing. Everyone I talk to, they say, why isn't OWASP providing certification on secure development. Well, I believe we should be doing this. And outreach is another thing that we should be reaching out to developers. We should be present at developer conferences more. I manned a booth of OWASP at MDC London conference. And yeah, thank you.
28:10Robert HurlbutArunesh.
28:12Chris RomeoYeah, I think from my perspective, I think we kind of talked about the certificate integration, which Andrei and Sam were talking about, sponsorship, which Fred and were talking about. I think there are other areas which is going to be important around the internal alignment and consistency which can be done through working groups. But I think even beyond that one, right, I would love to see the foundation like working with other foundations. Like for example, I was at the Open Source Congress in Brussels a few weeks ago and OWASP was not even there at that particular table, right, which is a missed opportunity, right. So if you want to make it very, very relevant, We have to be at the right seats, right? Speak to regulators and policymakers. And cross-functional collaboration is going to bring us a lot of value on this particular front, right? And also from a sponsorship, again, AI Exchange and the AI Bomb project that we recently started, looking at those models, successful models for sponsorship, like raised almost like $100K and $200K in sponsorship for AIX, that is the model we should replicate across the organization, right? Not just at the project level, but at the chapter level, right? And that's where I'm—
29:19Robert HurlbutOkay.
29:20Chris RomeoSo my out-of-the-box idea would be that, you know, we are at an inflection point right now when it comes to application development, right? So our focus has always been in terms of reaching to the developer. I think it's, uh, and most of the enterprises do consume, um, or most of, uh, you know, OS resources. So there is an opportunity here to partner one with your open source program offices. Second, I think there is a, uh, change in the way, uh, the development is going to happen in the next 2 or 3 years. So code might become opaque, like how infrastructure as code, building infrastructure became opaque. So how are we going to start refocusing on critical domains to have projects that are focused on those critical domains that are maybe AI/ML development adjacent, or, uh, you know, supply chain and dependency security adjacent? So I think that would add more value. And I think I agree with a lot of the points here. I think there needs to be education. OWASP needs to be part of college curriculums, not only from a security standpoint, but from a core developer standpoint. OWASP is not a security organization, it's a developer resource. And I think that, that narrative has to change from a brand perspective. Okay. Coming back to Jerry. We need to have a giant mission. And the giant mission I would love to see is every developer on the planet having an OWASP micro certification so that this is something that's done every year. I went out and I spoke to multiple people who run— I'm sorry, run AppSec for their organization. And they all said education, education, education. Not only that, but on top of developers, you've got shadow developers. People who are going to Claude and pulling out Python and running it on their— they need education as well. We need to support the chapters. We got some amazing chapters. The conversation needs to be expanded. Trust, resilience, AI, et cetera. Funding. We absolutely need to have more corporate funding. I went out and asked corporations, why don't they fund OWASP? They said, give us education, give us conversations with our peers, give us—
31:27Robert HurlbutYeah.
31:28Chris RomeoSecurity Champions training. That's what we're going to do. And then finally, last out-of-the-box thing is OWASP VC. So not my— not the virtual chapter, but investment into the projects. All right. Well, that concludes the second question. So we're going to move on to the third, which is what is OWASP currently doing poorly and how would you improve or change it? And we're going to start with Adrian for this 3rd question.
31:59Robert HurlbutAll right.
32:01Chris RomeoI think what's OWASP doing poorly? I think outreach, as we've already discussed a lot, we're just not in the right places all the time. I would actually say we need ambassadors, be it project ambassadors, education ambassadors. We need people to represent OWASP in the, in the right places. We've already mentioned about being on the right committees, the standards bodies. That's one part of it. And also internally, we don't know what we know. We have got a very large volunteer base. We have lots of chapters that have links. We have lots of chapters that have links to education. We have lots of projects that have links to education, but we don't know what those linkages are. And when, if we don't know them, we're not able to utilize them. So a lot of our mission goes, doesn't get seen. People know the OWASP Top 10, but they don't know a lot of the other valuable things that we do and we could be doing. But something improving that information flow.
33:04Robert HurlbutOkay.
33:05Chris RomeoFred. Okay. I think we need to revise our global focus. And so just to increase our worldwide exposure, We need to have what I call global workshops. So this is where you have experienced people that are integrating with NIST and ENISA and other organizations, but bringing them in so that OWASP has an opportunity to do a podcast where each month we have these experts within these different communities, and then on an international level, we are integrating our thoughts together. Working together just on convening discussions on every topic that's extremely important to us and to other development organizations to increase our extensive international presence, make it more worldwide, get in those regulation bodies, get in those standards, and bring those experts into us where we facilitate these workshops. Thanks, Fred. Steve. What does OWASP do poorly? Oh, there's so many things. Marketing, as was said before. However, we gave the ED a directive earlier in the year to focus on marketing, and I'm really glad that we have found somebody, and that person is starting very, very shortly. So yay. Communications. Whether it's outreach to other communities or even within our own community, we are a big community and sometimes we don't know like what we don't know. I think, Adrian, you were kind of alluding to that fact. We don't really communicate our impact very well. OWASP has tremendous amount of impact, not just in application security, but in policy and in regulations, etc. And finally, sustainability, open source sustainability. We have hundreds and hundreds of projects. So many of them are unmaintained. We need to be able to communicate their status because when people— And you can, and just so everybody knows, you can definitely finish your thought when we cut you off. So, yeah. Okay. Marissa. Coming up to you.
35:27Robert HurlbutYeah, great. Well, what does OWASP do poorly? I would like to push back, and it feels appropriate that we've just heard from Steve because I do want to give a great shout out to what the Board has accomplished in the past 2 years up till this point. I don't think that I would be sitting here right now if the Board hadn't made a concerted effort to push on diversity and inclusion initiatives. There was a fantastic meetup at the past 2 or 3 conferences where I met Steve and I met Avi in person and they encouraged me. And so I think that the— that what we need to do is give more energy to initiatives that are already in motion. We have a board of directors hiring a marketing person. They just haven't started yet. So when I say that what I think OWASP is doing poorly is outreach and engagement, I'm confident that no matter who is sitting on the board in the future, We will be doing more to serve the outreach function, and I'm so excited about that. Something that may not have been covered yet is projects. Robert, did you say time?
36:32Chris RomeoYeah, we're at time. Yeah.
36:34Robert HurlbutOkay.
36:35Chris RomeoI was letting you finish your thought, but— Appreciate it. Sam, coming up to you. Yes, outreach, I think, already been mentioned, but one thing that I believe OWASP is doing poorly is we're not running enough regional events and the events that we run are not frequent enough. And I think the problem with that is people really do get together, the community gets together when there is an event, an organization running an event. So one of the things that we discussed, and I believe this is how we can make it better, is if we run summits instead of running Bleach Conference, we also run focus summits, summits focused on a particular topic. or a project, OWASP AI Summit project, OWASP Supply Chain Summit, right? OWASP Security Champions Summit, right? If we create these focused summits, I think that, and make, and run them more frequently, and run them as mini conferences, I think this will bring a lot. Okay. Thanks, Sam.
37:50Robert HurlbutArunesh.
37:50Chris RomeoYeah, I think I kind of agree with Marisa, how she put it. Like, I think the board as well as the foundation has done a phenomenal job over the past few years since I've been involved in this one. And I think like it's the only way forward to address— focus on the opportunities that I think have been missed in the past, right, whether it's for sponsorship. I mean, like, OASIS started like almost 25 years ago and today if you look at the budget between OWASP and Linux Foundation, we have an answer, right? Certification is a perfect example why our membership is so low. I mean, it can definitely scale. The communication is one thing that I would say, I mean, that can be improved. Sponsorship aspect, again, like so many billion-dollar companies have actually made big foundations, big companies, and they have never like contributed back to the foundation itself. Those are like important considerations. Like my motto in life is like, if you don't ask, you will never get. And if you look at what has been done with the 2 projects that I'm responsible for, you ask and you build trust and people would actually come back, right? So you just have to like wake up and ask.
38:56Robert HurlbutArvind.
38:57Chris RomeoYeah, I think there is an opportunity to increase our influence with data. I think some of the panelists actually spoke about membership. I think we have leaders and contributors who understand what membership means. But consumers, you get everything right there. So why do I become a member? What is the advantage of being a member? Right? I think we need to have an SOP for members to understand how they can contribute as well as gain from being a member. And additional point is, I think every organization has an OS top ten training that is internal to their organization. There is an opportunity for us to certify, increase our influence. OS as a brand, how can we bring that brand into organizations that might create that funding? I think there is— there has to be a value model into getting funding versus a donation model, right? So I think if there is a value model that OWASP is able to create, that will drive more focus and more funding to come into the organization. Thanks, Arvind. Jerry? I want to be clear, OWASP has already changed the world for the better. So there are things that we could do better. Number one, I think we can amplify OWASP expertise. When I go to news.google.com, I type in OWASP, I don't see a lot of OWASP experts or members really kind of out there in front of the press. I think OWASP needs to be that platform to help that. I think when you talk to your average CISO, there's still a lot of misconceptions on application security. How could that be with OWASP existing? And there's clearly, there's still room for growth. Secure SDLC is still a little bit confusing to a lot of people. Along with security champion training, etc. Local chapters funding. They need funding, they need support, but they don't want to be— they don't want Big Brother there. I speak at chapters all the time. There isn't an easy way to contact all the chapters and propose speaking, you know, speaking opportunities. There needs to be some other way that we can help the speakers to get in front of all these different chapters. And the projects are very complicated. I have organizations coming to me frequently saying, Jerry, how do we start an OWASP project? And these are security companies, right? So clearly the mechanism to start projects, OWASP needs to be a little bit more user-friendly. Okay.
41:14Robert HurlbutAll right.
41:14Chris RomeoAnd to complete this round, Gustavo has the final answer.
41:18Robert HurlbutOkay.
41:19Chris RomeoFor the lack of indexing in the projects, we can create an AI to index all the projects. Secondly, the lack of regional review committees. Third one, the poor performance of the internal ticketing we have currently. We need to improve that. Also, we need to create an editorial framework for risk certification. Fourth one and last one. Well, the last one is balance the investment strategy, giving more resource to Asia, Africa, and South America. Okay. Thanks, Gustavo. So we'll go to our 4th question, which is, what ideas do you have to make local chapters more unified, active, and impactful globally? And we're going to Fred for the first answer for this question. I think it's not just current chapters, but also expanding chapters. And the reason why I said that we should have other companies that are not tech providers, tool providers, become funding models for us is because internally, when you— when we get an OWASP project, whether it be Top 10 or ASVS or whatever, we don't just take that and say, all right, everybody comply with this. No, we look through that and we tear apart the pieces that fit what we need. We improve on some things that fit better. to what we need as an international organization. And when we can put these chapters within these bodies of companies, we're going to get more output because they'll be joining what already exists as a body of chapters. Okay, thanks, Fred. Up next is Steve. Got to find the unmute button. Yeah, so I think I'm always in awe of Sam and others who lead or have led the London chapter. It's one of these model chapters that you want every chapter to eventually be. I'm a big fan of, let's see, making local chapters a little bit more impactful because the, for the global conferences, travel is currently being restricted, travel budgets are being slashed, et cetera. But I'm in big favor of like more regional events like IEEE style and more specialized events. Sam was talking about this earlier, such as AI, supply chain, you know, that sort of thing where the local chapters could actually host these, you know, specialized summits. Okay. Thanks, Steve. Marissa.
44:01Robert HurlbutAs is my way, I'd like to just take a look at the question itself and ask, is it really important to drive more more chapters, or should we invest in the chapters that we already have? I think it's important to have a strategy, and a strategic investment in chapters that are making a proposal and asking for certain investments would be a very important part of the strategy. If there is not currently a chapter that is in operations and meeting, then it's simply not a region that the market will support. There's all— these are volunteer chapters. And so understanding that volunteer-run initiatives need to have desire and support from the community to grow. Otherwise, it's better use, a better use of our time to have the investment in other areas where they are requesting and have a plan.
44:57Chris RomeoOkay, thanks, Marissa. Sam? Yeah, as a chapter leader, I think it's a good question for me because I've been running one of the, I think, Top five all West chapters, London chapter for ten years now. My main point here would be is to bring chapters together and to make them successful is to help them find sponsorship. This is all I'm trying to do: reach out to our corporate supporters to say, "Hey, company XYZ, do you have offices in Chicago, Toronto, Ottawa, London?" Latin America, can you help local chapters there grow? Because chapters need support, right? Chapters need basics sometimes, right? Just to run the events. And if we can get more and more local supporters, and this is what I've been doing for the past 10 years, all my events been sponsored. tried not to use any money from the OVAS funds, basically. Okay, thanks, Sam. Umesh, up next. Yeah, I think from a chapter perspective, I think like Sam brilliantly talked about, like the successes of various chapters, whether it's LA, New York City, London. I think there are a lot of examples of those, but I think speaking to other chapters across the globe at some point and I met a bunch of them in San Francisco and DC in the last 2 years. I think there is a common struggle that they have is like how do you actually bring consistency across the board, right, why is it only these 4 maybe 5 different chapters which are successful itself, right. How can we take what has worked for these ones and apply it to that one whether it's like templating, approaching the sponsors in that specific region. And I think there is another aspect which is going to be important is the foot traffic at all major conferences going down including us itself, right? So I think chapter enhancement and chapter like viability becomes an important aspect, right? How do you actually make chapter more important as a central stage, right? I mean, like, again, from my perspective, I don't get funded for all the travel that I do, right? So I think if you have like local access to all these chapter events, whether it's New York City where I live, I think it's much easier. Yeah. And Arvind? Okay, I think Arvin's having a technical difficulty. We'll circle back to him at the end of this round. Let's go to Jerry. So I've spoken at 8 OWASP chapters this year, and they all have interesting strengths and weaknesses, but most of them do definitely need support, financial support. Some don't. Denver, for example, they're great, and it looks like they've You know, things are topped up very well there. Other chapters like New York, yeah, they they got their they they got their venue pulled out from underneath them, and they're still trying to figure out how to get back. You know, kind of back to square one. So definitely, if the organization, if if the OWAS Foundation can help those chapters, if we had somebody on staff that can help reach out to the chapters, make sure that we hook them up with sponsors, make sure that they have a venue, maybe even getting a. It's gonna sound crazy, getting a global Dave Buster's contract for organizations where there is, 'cause that's a great venue to hold. That would be great. Also speakers. Right now it's pretty much they just wait for speakers to submit. But again, a speaker circle where we could make sure that people who wanna go and do the rounds have a one-stop shop of submitting their talk and going around.
48:42Robert HurlbutOkay, Gustavo.
48:43Chris RomeoOkay, we need to create a regional ambassador program where we have 3 guys to give to us in United States and Europe the information about the other regions and also the region they are currently. We also need to remove the lifetime member check. We need to evaluate every member of the chapter every 6 months or 1 year to see they continue contributing. Also evaluate the volunteer effort, give to this volunteer space to be speakers. That is it. Okay, thanks, Gustavo. Adrian. Hi, I'm going back to some of my other answers. I think local chapters need to embed with their local community the educational support. support, team up with a local university, local colleges, and it becomes two-way. If you get the educational support into the chapter, you can push that through into the education establishment. The education establishment can help you host meetings, can provide student volunteers, can get students engaged in the community and into some of the other OWASP opportunities. Google Summer of Code and all the sort of mentoring type things that we could do successfully. It's a 2-way process. So I think having that outreach back to the ambassador program again, educational ambassadors, project ambassadors, working with the chapters to get the projects into the chapters, to get education to the chapters, and to feed that back, getting that information flow. Thanks, Adrian. Arvin, circling back around to see if you're able to, to get back. Okay. All right. Well, I'll check back in with Arvin. I'm going to move to our final question, and then after that, we'll have a chance for a closing statement. But our final question is about resources, and this one will actually be Steve's to answer first. The question is, Where will you find the resources, financial, human, or otherwise, to achieve the goals and promises you've outlined? The first thing that we need to do is kind of figure out where we are. And this is the first year that we've actually had OKRs for the ED, and we will make those available to the community. But we're also going to be expanding that upon the future. That will allow us to at least measure our progress. OWASP is primarily volunteers, so we're going to obviously rely on that. We do have work that's ongoing for a commercial entity that would help fund a lot of this activity. And finally, we're actually starting to collect data from our projects, from the various websites, on all the organizations that actually utilize OWASP resources. Okay, thanks, Steve. Marissa, Where will you find the resources?
51:50Robert HurlbutI love this question. It's very to the heart of things. My experience as a conference promoter and as a startup lead, I'm just very used to doing things lean and mean. And I know that a lot of the things we do now can take advantage of our volunteer workforce very differently and really focus on If there's not a volunteer that can provide or a sponsor that can provide, then perhaps we shouldn't be doing it at this time until we can find the right mix of 2. So I would really hope that everyone could, you know, hold me accountable in this and to say that we would not increase our budget and we would repurpose the budget that we already have, bring it back to lean scrappy startup mindset, and really emphasize that our volunteers feel passionate about this. And so enabling them to do what they want to do anyway.
52:44Chris RomeoOkay, thanks, Marissa. Sam? My answer is we will find the resources in the community and within our corporate supporters as well. The community is vast, is absolutely great, and it has been working collaboratively for a long time. And I think we can make that impact. In terms of the corporate supporters as well, a lot of them are nowadays quite happy to help OWASP to achieve its goals as well, because they understand that we are here to save the world, to achieve the greater good of securing software for everyone. And another thing about corporate supporters is a lot of them, there are a lot of companies there, like big companies, which are using OWASP projects resources, but they're not giving back. So this is another thing to reach out to some of the largest organizations there, and which I've been trying to do as well, to make sure that they are giving back to OWASP. Thanks, Sam.
53:55Robert HurlbutArunesh?
53:56Chris RomeoYeah, I think personally speaking, I think much of this that you're asking, at least from my perspective, it's already underway, whether it's looking at the sponsorship for the 2 projects that I'm responsible for, It's already in the works. In fact, like at this point in time, I'm speaking to at least 4 major vendors out there, including Cisco, IBM. They're looking to actually come in as a sponsor for those projects. And this is what we need to actually do and more. In terms of the volunteers and stuff, right, I do it for both AI Exchange and AI Bomb itself, where we need like more and more volunteers to come in, right? So you actually have to pitch it the right way. And another aspect is going to university, which was kind of alluded in a few minutes ago, like looking at university and I'm speaking to NYU, Stony Brook, and a couple of local universities in Long Island to ensure we can actually kind of engage them, right? Bring the curriculum back to the university itself, right? Why can't we have some sort of a curriculum or like a partnership? And I think the collaboration that we have, SANS Institute, actually goes in that line very, very strongly itself, right? And there are more things that I would say. but I think I don't have the time. Okay, thank you.
55:03Robert HurlbutJerry.
55:03Chris RomeoOWASP definitely needs more funding. I've, uh, when I speak to the, the staff and, and so forth, there's definitely a need for, for more funding. I went out and spoke to heads of companies, their AppSec departments, and asked them why they're not sponsors, and they said because the, um, the benefits of membership don't align with what we want. Uh, right now it's things like you get to use the OWASP logo on your website and so forth. Organizations told me directly they want training, they want to be able to talk with their peers, they want OWASP to help facilitate questions on how they do application security at scale and so forth. So the market's told us what they want and we, we just need to deliver that. And that's going to fulfill our mission and that's going to definitely put more money in the OWASP coffers, which is going to in turn allow us to do all the things that everybody's talked about. I love every— all these ideas. Local chapters, local, more regionalized events, chapters inside of companies like Fred said. I mean, these are all great, but we definitely need money so we can do advertisement, we can get more members, and we can fulfill our mission. Okay, thanks, Jerry. Gustavo. One, discipline in finance. Second one, we need to index all the projects in OWASP Project in AI. Like I mentioned before, this AI can create the courses. And we can charge the money from YouTube views, TikTok views, things like that. Also, we can sell services related to the implementation of this AI. And tier 1, bring more people. That means mentorship. Every chapter need to, or every chapter leader need to mentorship 2 guys per year. After that, these 2 guys, need to mentor another 2 guys. We gain people, we gain money, and we gain visibility. With that, we can increase the funding. And also the AI can identify the sponsor and the founder. Okay, thanks, Gustavo. Adrian. I think for OWASP to improve, Its financial position needs to— we need to get more funding in. We need to increase our base of volunteers because volunteers are the lifeblood of the organization and making sure that volunteers are respected and well looked after. And I think making use of what I call stale resources. We've got a lot of projects that have gone stale. We can still use their resources for education, get students involved in old open source projects that don't have a current lead. They form student projects, they form— it's the next level of engagement. And you can, if you can then sponsor those projects, with students to bring them up to a level. There are other resources that are there. Find that space. Yeah. Thanks, Adrian. And then Fred has the final answer on the 5th question. Okay. And can you please repeat that? Yeah, the question is about resources. Where are you going to find the resources to do the stuff we need to do? Thanks. So monetary, I mean, we need to have direct corporate sponsorships. We need to have other non-tech companies engage with us, and I've talked about that before. In leadership, we need to directly engage and improve the way that our leaders can present the topics on OWASP, work with their projects, and this includes project team leads as well. And then people, we have universities that have excellent programs in computer science, cyber, whatever, risk management that are ready to have somebody come in to help engage their students. There's some chapters ready. There's some easy engagement from students in these facilities. Okay. Thanks, Fred. All right. So, we're going to do a round of closing statements. And so, we'll give you 1 minute. This is just, you your time now to make your argument for why an OWASP member should vote for you in this upcoming election. We're gonna start with Marissa with her closing statements.
59:41Robert HurlbutThe mission of OWASP is to support a global community in making more secure software through education, tools, resources. And I think in order to meet this mission, as many people have talked about today, we really need to increase our engagement and also our reach globally into more regions of the world. I have a proposal for how to do that. And I'm really excited. Regardless of the outcome of the Board of Directors, I'm very excited about the future of OWASP because I'm already seeing these, these pieces in motion. And I'm very excited about the way that this will enable the current project leads and— sorry, project leads and chapter leads to be more successful in, in their endeavors and really empower them to get the support that they need.
1:00:49Chris RomeoThanks, Marissa. Sam, closing statement. OWASP is great. It is loved by many people. Why? Because it fosters a sense of community and a sense of belonging. So people who participate in OWASP, they become a part of something impactful, and they feel that when they collaborate, they actually that collaboration leads to change. So they've really changed the world. So this is why I think our community is our greatest asset. So the experience of working together to tackle all the problems and security challenges, I think, is the— and the collaborative spirit is what makes OWASP quite unique organization. If reelected, I will continue to support and strengthen this community and making sure that OWASP is a welcoming and impactful place for everyone. Thank you.
1:01:53Robert HurlbutOkay.
1:01:54Chris RomeoThanks, Sam. Or Raneesh? Yeah, I think from my perspective, my motto is threefold, right? Co-learning and co-sharing and finding creative solutions itself and uplift communities and produce like next set of leaders across the board, right? That's how I approached OWASP since inception, right? I act with a doer mentality. and I make things happen. I mean, example for that would be the working group proposal itself that I drafted, got reviewed with Sam, Steve, Star, and bunch of other folks itself, right? And this was something which was accepted in Barcelona. I built AI Exchange along with Rob to its flagship status in less than like 18 months, raised $100K in funding already, and another $100K is in the pipeline. Did the same thing for AI Bomb. I would Personally attest that I brought almost like 50, it encouraged like 50+ members to join OAS this particular year itself. I'm working with SANS Institute on grants with OpenAI and Foresight Institute, which is upwards of half a million dollars. If it happens, it's going to be such a big win for OAS. And again, like I build communities and empower like volunteers. It's not done alone. Thanks, Subranish. And Jerry. Folks, I love it. I love OWASP. Uh, it's been an organization that's definitely changed my life. I think it's changed all of your lives. I don't think OWASP has even achieved 1% of its potential. I think we can get out there. And like I said, there's a world of developers and non-developers that need OWASP's help. Vote for me if you want to help achieve that mission and have that much larger vision of OWASP. I would also say that there were 2 candidates who weren't able to make it today. Jeremy Long, who is awesome, and Kelly Santalucia, who's also awesome. So I encourage anybody listening to also listen to what they have to say when you're making your, your decision on who to vote for. And thank you all. And Chris and everybody, thanks for hosting this debate. Sure thing. A couple more closing statements. Gustavo. Well, in this technological world, I believe the more important thing we need to do right now is, and this is my personal experience in different organizations and continents, is modernize the organization and also filter. We need to clean house, clean the house and see what is still continuing working and what things not continuing working. This is not an honor when you win a position like this one. This is a responsibility. And that is the thing you need to choose. What is the guy or the woman you want to represent in that responsibility? Thank you for watching.
1:04:35Robert HurlbutOkay.
1:04:37Chris RomeoThanks, Gustavo. Adrian. Like I said before, I think my big emphasis and OWASP's emphasis, I think, needs to move into education. Education is the big The thing that we're missing, the thing that joins the dots, whether it be developers, whether it be security analysts, whether it be crossing that bridge, we need to make sure we have educational programs that industry wants. We have the skills agenda. We are starting down this journey, but there is a lot more to do. And my, because of my unique position in industry, I am the person to help push that educational agenda. Thank you. Thanks, Adrian. Fred? I think overall, OWASP needs to really increase our global focus. We have a great mission. We have a lot of great members, many of them on here with me that are going to make great board members. But although we have some excellent contributors, We're not reaching everywhere. How can we reach everywhere? Do these workshops, have global workshops where we become the leaders and we facilitate people getting together to talk about our initiatives that we're doing and the focuses that they're looking at from corporations on AI or supply chain risk management, whatever it is that the current focus is that our industry, our vertical is looking at. We have these opportunities to be the leaders and facilitate these groups of people to come together and, and we gather intelligence. So it's intelligence gathering and we're missing that in OWASP. Thanks, Fred. And final closing statement will be from Steve. It's, it's really great that every year there's somebody there's another opportunity because for, for it to become a board member, because every single one of us, I think, sees OWASP as almost like an extended family, right? It's an amazing community that we contribute to. You can't put a price on that. I'm going to be advocating for increased transparency because the community wants such great things, right? Well, how do you measure the progress of the foundation in achieving those things? That's one of the things I'm going to be striving for, and I would appreciate your vote going forward. Thanks, Steve. And that concludes our prepared questions. And I want to thank each and every one of you for stepping forward as candidates for the OWASP Board. Like, this is a— it's a labor of love. I know just from talking to lots of board members over the years and project leaders and chapter leaders, and I'm just really excited about OWASP's future. We've got a great group of folks here, and I'm telling you, it's gonna be— I sat here and hosted the debate. It's gonna be tough to cast my vote now when that email comes in here in the next couple of days. But once again, just another reminder for our audience. If you're an OWASP member, you're gonna get an email. It's gonna be your call to vote. You've heard from the candidates. Go cast your vote and help to shape where our community is going into the future. Your every vote counts. In this process, and so definitely get out there and cast your vote. Candidates, good luck to you, and thank you for being a part of this application security podcast OWASP debate. Thanks, sir.
1:08:05Robert HurlbutThank you.
1:08:06Chris RomeoThanks, Robert. Thank you.
1:08:07Robert HurlbutThank you.
1:08:08Chris RomeoThanks, Chris. Thanks, Robert.
More like this
- Careers in AppSecSeason 5 Finale — A cross section of #AppSec
Threat modeling, secrets, mentoring, self-care, program building, and much more. Clips from Georgia Weidman, Simon Bennetts, Izar Tarandach, Omer Levi…
- Conferences and CommunityOWASP Board of Directors Debate
The Application Security Podcast presents the OWASP Board of Directors Debate for the 2023 elections. This is a unique and engaging discussion among six candidates vying for a position on the board.
- Careers in AppSecKevin Johnson -- Samurai Swords and Zap's Departure
Kevin Johnson is the CEO of Secure Ideas. He began his career as a developer but turned toward security when he discovered that the interface for an intrusion detection system, Snort, was out of date.