Security is not a post-development check – it’s a mindset, spanning design, development and testing. OWASP – the Open Web Application Security Project – is a community that produces articles, methodologies, documentation, tools and technologies in the field of application security. In this talk, I will cover the OWASP Top 10 risks as well as how certifications can help in the world of AppSec. I will also share how you can build a sustainable program with open source resources.