The People Problem in AppSec
After talking to over 100 security leaders, Charikova heard the same answer. The hardest part of AppSec has nothing to do with scanners, vulnerability triage, or tech stacks. It is about humans. Jacob Solomon told her people problems are the hardest to fix because you cannot apply engineering logic to them. The gap between AppSec theory and practice lives in information asymmetry, integration complexity, and velocity versus rigor. None of those are solved by better tools. They require trust between security and engineering.
The Diversity Gap and Self-Reinforcing Cycle
ISACA reports women represent 22% of security teams. At an OWASP conference Charikova co-organized, only 1 of 15 speakers was a woman. Out of 100+ CFP submissions for BSides Amsterdam, 6 came from women — despite outreach to local women-in-security groups. Fewer role models on stage means fewer applicants, leading to even fewer role models. The system does not fix itself. Visibility is a resource, and the cycle only breaks when someone actively redistributes it.
Archetypes and the Value of Soft Skills
Larkin Carvalho’s framework defines four AppSec archetypes: the orchestrator, the builder, the specialist, and the rapid responder. The orchestrator succeeds through relationships and coalition building — no single technical superpower, but the one who scales security programs in large organizations. Charikova asks the room to flip the usual priority. For some profiles, soft skills should come first, technical skills as the bonus. Trusted security teams with a good internal brand solve more problems than teams with deeper technical knowledge but no developer trust.
Actionable Steps: Visibility and Sponsorship
Externally, conference organizers can send direct DMs to underrepresented groups and partner with local diversity groups. Internally, spotlight someone’s win in an all-hands or share a Slack message about their work. Write about unglamorous work — how you rebuilt trust with an engineering team that hated security. That kind of blog post shows that people skills belong in AppSec. Sponsorship is different from mentorship: a sponsor uses their own capital to open doors for someone who has not yet proven themselves in that context.
Notable Quotes
if you see them you think and if they can I can. Alexandra Charikova · ▶ 12:15
people problems are actually very challenging and hard and probably the hardest ones to address. Alexandra Charikova quoting Jacob Solomon · ▶ 3:52
security is internally marketing and that it’s marketing itself is a skill. Alexandra Charikova quoting Kun Hendrick and Kavya · ▶ 10:33
Key Takeaways
- AppSec’s hard problems are human, not technical — trust and relationships matter more than tools.
- The lack of diverse role models creates a self-reinforcing cycle that requires deliberate interruption.
- Sponsorship — using your capital for someone else — redistributes power, not just opportunity.
About the Speaker(s)
Alexandra Charikova is AppSec Community & Growth lead at Escape, a cybersecurity content creator, co-organizer of BSides Amsterdam & OWASP AppSec Days France, and host of “The Elephant in AppSec” podcast. She transitioned from engineering into community building, driven by a curiosity about why security leaders say people are the hardest part of the job.