Warrior Insider: Nelnet - Nurture your security champions and create a culture of secure development from within
Warrior Insider: Nelnet - Nurture your security champions and create a culture of secure development from within
![](https://cdn.prod.website-files.com/5fec9210c1841a6c20c6ce81/63e39c47d98fcc49932cc12c_61680575876d8f24aa90886a_alex-kotliarskyi-QBpZGqEMsKg-unsplash.webp)
![](https://cdn.prod.website-files.com/5fec9210c1841a6c20c6ce81/63e39c47d98fcc51b72cc12b_61680575876d8f24aa90886a_alex-kotliarskyi-QBpZGqEMsKg-unsplash.webp)
Micha Martinez is a Cybersecurity Analyst and Cinematographer at Nelnet, a US conglomerate that deals in the administration and repayment of student loans and education financial services. When he was tasked with creating a training program for developers around secure coding, he took on creative ways to engage his team. We were so impressed with how he runs his secure code training program that we sat down with him to learn more.
The bottom line?
Create a culture of security and nurture your internal security champions from within your development teams “to be the force of good.”
“By focusing on secure code, we’ve helped make the company stronger and safer.”
At Nelnet, Micha and his security team understood the importance of building secure code from the start. They wanted to achieve this in an engaging, relevant, and rewarding way. He discovered that by identifying developers with a strong interest and proficiency in secure coding and nurturing them to become security champions, those champions became the catalyst for changing the mindset around security training as a whole. These individuals mentor their colleagues who need more help at a peer-to-peer level, and become the leaders in implementing changes in secure code practices within the organization.
Here’s more from Micha about how he and his team shifted the mindset and culture around security prevention, which made their company “stronger and safer”.
It’s all about the bragging rights… and reducing vulnerabilities
Micha doesn’t run your average security training program. He uses competition and his cinematography talents to make tournaments hugely engaging and successful. What developers gain is highly relevant, practical knowledge that leads to stronger secure code.
The business wins too as their products become more secure and provide a higher level of protection against software vulnerabilities. Learning software security doesn’t have to be a typical and boring learning experience that does little more than check a box. Developers want training experiences that are immersive and challenging, as well as relevant to their daily work.
Watch Micha talk about how he makes secure coding training fun through tournaments including physical championship belts a la wrestle mania as the prize. All it takes is a little healthy competition to keep security top of mind for his team.
Who doesn’t love some bragging rights?
Embrace a culture centered around secure coding... the tool is not enough
Micha left us with one last thought about why he recommends Secure Code Warrior. The platform was the vehicle that led him to create a preventative culture and proactive learning. It took time to build the training program and also invest in the developers who train and perform well. It takes a transformative culture to build the skills in each developer to adopt a preventative approach to coding securely.
Here more from Micha about why embracing a culture of secure coding makes all the difference with Secure Code Warrior.
Secure Code Warrior delivers an immersive and engaging secure coding learning platform for developers. Interested in a demo? Book one below.
Resources to get you started
Trust Agent by Secure Code Warrior
Discover SCW Trust Agent, an innovative solution designed to enhance security by aligning developer secure code knowledge and skills with the work they commit. It provides comprehensive visibility and controls across an organization's entire code repository, analyzing each commit against developers' secure code profiles. With SCW Trust Agent, organizations can strengthen their security posture, optimize development lifecycles, and scale developer-driven security.
Resources to get you started
Women in Security are Winning: How the AWSN is Setting Up a New Generation of Security Superwomen
Secure-by-Design is the latest initiative on everyone’s lips, and the Australian government, collaborating with CISA at the highest levels of global governance, is guiding a higher standard of software quality and security from vendors.
Women in Security are Winning: How the AWSN is Setting Up a New Generation of Security Superwomen
Secure-by-Design is the latest initiative on everyone’s lips, and the Australian government, collaborating with CISA at the highest levels of global governance, is guiding a higher standard of software quality and security from vendors.
SCW Trust Agent - Visibility and Control to Scale Developer Driven Security
SCW Trust Agent, introduced by Secure Code Warrior, offers security leaders the visibility and control needed to scale developer-driven security within organizations. By connecting to code repositories, it assesses code commit metadata, inspects developers, programming languages used, and shipment timestamps to determine developers' security knowledge.
Warrior Insider: Nelnet - Nurture your security champions and create a culture of secure development from within
![](https://cdn.prod.website-files.com/5fec9210c1841a6c20c6ce81/63e39c47d98fcc49932cc12c_61680575876d8f24aa90886a_alex-kotliarskyi-QBpZGqEMsKg-unsplash.webp)
Micha Martinez is a Cybersecurity Analyst and Cinematographer at Nelnet, a US conglomerate that deals in the administration and repayment of student loans and education financial services. When he was tasked with creating a training program for developers around secure coding, he took on creative ways to engage his team. We were so impressed with how he runs his secure code training program that we sat down with him to learn more.
The bottom line?
Create a culture of security and nurture your internal security champions from within your development teams “to be the force of good.”
“By focusing on secure code, we’ve helped make the company stronger and safer.”
At Nelnet, Micha and his security team understood the importance of building secure code from the start. They wanted to achieve this in an engaging, relevant, and rewarding way. He discovered that by identifying developers with a strong interest and proficiency in secure coding and nurturing them to become security champions, those champions became the catalyst for changing the mindset around security training as a whole. These individuals mentor their colleagues who need more help at a peer-to-peer level, and become the leaders in implementing changes in secure code practices within the organization.
Here’s more from Micha about how he and his team shifted the mindset and culture around security prevention, which made their company “stronger and safer”.
It’s all about the bragging rights… and reducing vulnerabilities
Micha doesn’t run your average security training program. He uses competition and his cinematography talents to make tournaments hugely engaging and successful. What developers gain is highly relevant, practical knowledge that leads to stronger secure code.
The business wins too as their products become more secure and provide a higher level of protection against software vulnerabilities. Learning software security doesn’t have to be a typical and boring learning experience that does little more than check a box. Developers want training experiences that are immersive and challenging, as well as relevant to their daily work.
Watch Micha talk about how he makes secure coding training fun through tournaments including physical championship belts a la wrestle mania as the prize. All it takes is a little healthy competition to keep security top of mind for his team.
Who doesn’t love some bragging rights?
Embrace a culture centered around secure coding... the tool is not enough
Micha left us with one last thought about why he recommends Secure Code Warrior. The platform was the vehicle that led him to create a preventative culture and proactive learning. It took time to build the training program and also invest in the developers who train and perform well. It takes a transformative culture to build the skills in each developer to adopt a preventative approach to coding securely.
Here more from Micha about why embracing a culture of secure coding makes all the difference with Secure Code Warrior.
Secure Code Warrior delivers an immersive and engaging secure coding learning platform for developers. Interested in a demo? Book one below.
Resources to get you started
Women in Security are Winning: How the AWSN is Setting Up a New Generation of Security Superwomen
Secure-by-Design is the latest initiative on everyone’s lips, and the Australian government, collaborating with CISA at the highest levels of global governance, is guiding a higher standard of software quality and security from vendors.
SCW Trust Agent - Visibility and Control to Scale Developer Driven Security
SCW Trust Agent, introduced by Secure Code Warrior, offers security leaders the visibility and control needed to scale developer-driven security within organizations. By connecting to code repositories, it assesses code commit metadata, inspects developers, programming languages used, and shipment timestamps to determine developers' security knowledge.
Trust Agent by Secure Code Warrior
Discover SCW Trust Agent, an innovative solution designed to enhance security by aligning developer secure code knowledge and skills with the work they commit. It provides comprehensive visibility and controls across an organization's entire code repository, analyzing each commit against developers' secure code profiles. With SCW Trust Agent, organizations can strengthen their security posture, optimize development lifecycles, and scale developer-driven security.