Why a 200-Person Security Team Cannot Cover 1,200 Engineering Teams

▶ Watch (3:39)

Workday serves 11,000 customers, including 65 of the Fortune 500, with 75 million users. Internally, 2,500 engineers work across 1,200 engineering teams. The core security team holds about 200 people. Fewer than 10 of them (called security partners) handled over 2,500 security reviews in a single year. That backlog slowed engineering and burned out the team. The numbers made the case for a champions program before any strategy paper did.

What Champions Actually Do Inside Engineering Teams

▶ Watch (5:44)

Champions at Workday run threat modeling workshops, onboard teams to static analysis tools, and remediate vulnerabilities. They work as first contacts when critical issues need attention. The role works because advice from a peer reads differently than directives from a central security org. Champions also translate security policy into each team’s specific stack, making guidance actionable. They surface practical pain points and emerging risks back to security leadership so that policies and tooling can be adjusted.

What Failed Before the Framework Worked

▶ Watch (18:07)

The early failures were predictable in hindsight. Workday announced a threat modeling campaign at a guild meeting, built a leaderboard, promised shoutouts to top performers. Very few champions engaged. Security partners hadn’t been briefed on the campaign, and shoutouts weren’t enough incentive. A separate effort to attribute security assets to owning teams ran for months before hitting a dead end. Nobody wanted to own a system that required chasing people for updates. Both failures pointed to the same gap: campaigns without organizational alignment stall.

Co-Creation: Asking Champions What They Actually Wanted

▶ Watch (22:59)

After the growing pains, the team asked champions directly what would motivate them. The answer was not money. Champions wanted training, education, and chances to work alongside security teams. That insight shaped a co-creation model with three groups: leadership (to fund training and acknowledge work), security teams (to include champions in pentest readouts and incident investigations), and the program itself (to offer security gigs and paid conference travel). Security gigs are short-term projects supervised by security engineers to build tooling or training.

The Belt System That Doubled Engagement in One Month

▶ Watch (25:19)

The current framework maps contributions to belt levels. Yellow belt requires onboarding to SAST tools. Green belt requires security reviews. Black belt means building training for the entire organization. Belt assignments are dynamic: champions must make periodic contributions to keep them. When the program launched its impact opportunity map and told champions their belt would lapse without completing pending actions, engagement doubled that month. The mechanism was loss aversion. Palombo framed the intent plainly: the goal is not manipulation, but making security behaviors visible and easy to act on.

Q&A

Do you allow champions to self-nominate, or are they pulled in by leadership? Both paths exist, though voluntold champions tend to be less motivated; the large-scale campaign used manager nominations to hit broad coverage quickly and then worked to convert those nominees into committed contributors. ▶ 30:13

Does management act on belt loss, or is the consequence purely personal? Belt status is visible in dashboards, but the primary effect is individual loss aversion; management-level consequences for belt loss are not yet formalized. ▶ 30:45

How much time are champions expected to spend on security work? The guideline is 20%, but the program focuses on security posture metrics rather than prescribing exact hours, since teams operate differently across a global organization. ▶ 38:22

Notable Quotes

Uh I like to say they’re force multipliers because they enable uh small the small centralized security team to scale its influence across the entire organization. Hernán Palombo · ▶ 6:47

they were feeling invisible. Hernán Palombo · ▶ 22:52

it turns out champions didn’t want more money. Uh they wanted training in the form of education and opportunities to work with other uh security teams. Hernán Palombo · ▶ 23:15

Champions did not want to lose their belt. Hernán Palombo · ▶ 28:39

Key Takeaways

  • Centralized security review teams cap out: fewer than 10 partners covered 2,500 annual reviews at Workday.
  • Champions stay engaged through intrinsic rewards: education, conference access, and inclusion in real security work.
  • Dynamic belt assignments that expire without activity outperform static recognition in sustaining long-term participation.

About the Speaker(s)

Dr. Hernán Palombo is a security leader, engineer, and researcher with nearly 15 years in the field. He began his career as a software engineer more than 20 years ago, later pursued a PhD in computer science that included ethnographic research on security culture, and now leads Workday’s Security Champions Program, supporting nearly 800 engineers across more than 500 teams.