Oh, hi there, it’s us again! As Cybersecurity Awareness Month rumbles on, we’re thrilled to dive into the second part of our ongoing Q&A series. In case you missed the first entry or just want to read it again (we wouldn’t blame you), click here.
The term “evangelist” pops up a lot in the security industry, and those that have this title bestowed upon them carry many different responsibilities. What many don’t realize is just how critical the evangelist role is, bridging the gap between their respective companies, customers, the media, general public, and much more.
To better understand everything that’s required of someone in this position, and in this case, how these individuals foster a culture of software security in today’s organizations, we sat down with Susan St. Clair, evangelist and subject matter expert here at Checkmarx.
Thanks for joining me, Susan! The evangelist role seems like it’s quite hectic, but also very rewarding. So, can you walk us through what a normal day looks like for you?
It really varies on a day-to-day basis, but in general, I’m really focused on spreading AppSec awareness and connecting Checkmarx with end users, current and potential customers, and the broader security community. I’m lucky in that I spend a lot of time with very smart people learning about their challenges related to AppSec, security testing, and more.
I consider myself and others in the evangelist role to be consultants of sorts. Our job is to get organizations and security teams thinking about existing gaps in their systems and to serve as trusted partners that help set realistic and transparent expectations about what’s needed to optimize their security processes and tools. While sales is certainly a component of being an evangelist, spreading awareness and driving real change is the ultimate goal.
Given that you work closely with many different groups, how have conversations around software security evolved as of late?
Over the past few months in particular, we’re seeing this digital-first shift. And with this, all organizations – no matter the maturity of their AppSec infrastructure – are wanting to know how they can operate online in a secure manner. Simply, “how do we become more secure? From education to government organizations, COVID has really placed this question at the forefront of everyone’s mind – whether they’re developers or on the Board.
Another interesting shift that’s taken place simultaneously is security teams’ understanding of emerging tools. When I first started in this position a few years ago, I spent the majority of my time educating people about what IAST was. Now, it’s more about how IAST, and other emerging tools, integrate with existing AppSec technologies to address software risk more holistically.
What creates the best interaction with organizations? Developers?
It depends on who I’m speaking with, but the best and most productive conversations are exactly that – conversational. I like to start things off by simply asking what they would like to have in an ideal world. Assuming cost, resources – any sort of limitations – aren’t factors, what do they envision security to look like?
This leads down some very interesting roads and opens doors to paths they likely haven’t yet explored. From there, we can work on prioritizing what’s most important and creating a comprehensive action plan that fits their specific needs and requirements.
This year’s Cybersecurity Awareness Month theme is “Do Your Part.” What role do evangelists play in advancing security practices across the industry?
First and foremost, it’s about spreading awareness and education. It’s about opening people’s eyes and ears to new concepts and technologies that they may not have previously heard of or considered. It’s about helping organizations think about different ways to approach persistent problems.
This is accomplished in a variety of ways. It can be through 1:1 conversations with AppSec and security teams or through larger trade shows and webinars where I’m able to reach bigger and more diverse audiences. These events in particular are really where awareness spreads like wildfire because it gets many people with many different viewpoints conversing and sharing ideas.
As an evangelist, I want to put security teams, DevOps leaders, developers – you name it – in a position to do their jobs as effectively and efficiently as possible.
Narrowing it down, what are the top trends impacting the state of software security most right now?
Automation is a big one, especially in terms of automated tools that fit into the way developers and DevOps operate to streamline workflows.
The growing voice and authority of the developer is another. Developers are now a force to be reckoned with, and they’re largely influential over where security budgets are allocated. As developers increasingly play a bigger role in owning security, they’re being granted more control over what’s needed to achieve DevSecOps.
What does success or a job well done feel/look like to you?
It’s really exciting to see awareness turn to action and shifting traditional views into modern ways of thinking. Speaking with a customer, looking back a year or two ago, and seeing just how far they’ve come in terms of shoring up their security posture is incredibly rewarding.
Any advice for aspiring evangelists?
Open your mind. Regardless of your background, whether you come from security or not, your past experiences will give you a unique perspective that can change the way people think about things. Read up on industry trends, talk to customers and thought leaders. Always stay curious!
Catch Susan on our webinar to learn more about the biggest trends impacting today’s software landscape, reasons why organizations need to be prioritizing software security, and best practices for getting a running start on the road to DevSecOps. And, if you haven’t already, download our new eBook to help raise your AppSec awareness.
Cybersecurity Awareness Month Week 2: Day in the Life, Security Evangelist

Cam Martin
Cam Martin serves as Public Relations Manager and a security writer for Checkmarx, bringing a background in public relations, marketing, and communications to his role. As part of overseeing global PR efforts, he has helped raise the profile of Checkmarx and its executives, resulting in media coverage in Forbes, Fortune, TechRepublic, and more.
View All Posts
Latest Blog Posts
CTparental Vulnerabilities Enabled Filter Bypassing
August 19, 2021
Checkmarx – Making Waves Once Again
August 18, 2021
Follow Us
Checkmarx 推出业界最全面的供应链安全解决方案,以帮助组织阻止以前无法检测到的恶意开源软件包
现在可与 Checkmarx 软件组合分析 (SCA) 一起使用,该解决方案恢复了对现代应用程序开发的信任,同时让开发人员接受开源代码
March 29, 2022
Checkmarx 推出业界最全面的供应链安全解决方案,以帮助组织阻止以前无法检测到的恶意开源软件包
现在可与 Checkmarx 软件组合分析 (SCA) 一起使用,该解决方案恢复了对现代应用程序开发的信任,同时让开发人员接受开源代码 中国,上海, 2022年3月29日 – (ACN Newswire) – Checkmarx,以开发人员为中心的应用安全测试 (AST) 解决方案的全球领导者,今天宣布推出 Checkmarx 供应链安全 解决方案,以识别现代应用程序开发生命周期中的可疑和潜在恶意开源包。 据 Gartner®[i] 称,”到
March 29, 2022

How API Use Cases Have Evolved, and What It Means for API Security
APIs are like telephones: they have been around for quite a while, yet they have changed tremendously in recent years.
August 25, 2021
Checkmarx Launches New Global Partner Program
Empowers partners and distributors to grow and retain customer bases while meeting accelerating demand for AST solutions NEW YORK &
August 24, 2021

CTparental Vulnerabilities Enabled Filter Bypassing
For those who don’t know me, I am a mother to two brilliant children who are better at the game
August 19, 2021

Checkmarx – Making Waves Once Again
In organizations that encourage the usage of modern application development techniques to expedite the development, delivery, and deployment of custom
August 18, 2021
Checkmarx Named a Strong Performer in Software Composition Analysis by Leading Analyst Firm
NEW YORK & RAMAT GAN, ISRAEL – August 18, 2021 – Checkmarx, the global leader in developer-centric application security testing (AST) solutions, today announced
August 18, 2021

Why Developers Worldwide Benefit from Secure Coding Education
Global Developers think secure coding education can save time and money while adding personal and organizational value. The impact of
August 16, 2021

Why Centralized Risk Management and Governance Are Key to Modernizing Legacy Applications
A Mandate from Federal Government Today, security is an absolute requirement. The Federal Government knows that security is a critical
August 11, 2021

The Magic of GitLab’s Templates: What’s New with Checkmarx GitLab Integration
Last year at GitLab Commit, I presented our integration with GitLab to initiate Checkmarx security scans within your GitLab CI/CD
August 9, 2021
Checkmarx Acquires Software Supply Chain Security Provider, Dustico
Acquisition brings behavioral source code analysis to Checkmarx customers to defend against open source software supply chain attacks RAMAT GAN,
August 5, 2021

KICS is Exceeding All Expectations
KICS (Keeping Infrastructure as Code Secure) has had an incredibly successful launch with over 273k downloads as of date! As
August 3, 2021

What’s Lurking Within: Stopping Malicious Actors in Software Supply Chains
What’s Lurking Within? Malicious Code. Supply chain attacks occur when cyberthreat actors insert malicious code into trusted software, creating a
August 3, 2021

Business Benefits of Buying Your Application Security Solution on AWS Marketplace
The rise of cloud technology has revolutionized the way we think about software and how organizations buy it. Long procurement
July 29, 2021

Chained RaspAP Vulnerabilities Grant Root Level Access
According to its official documentation, “RaspAP” is a wireless router software for many popular Debian-based devices, including the Raspberry Pi. It
July 29, 2021