About the Application Security Leader of the Year category
Who this award is for
This award is for the person who makes an organization's software safer to build and run. Recent nominees include a security manager who leads application security for generative AI services at a cloud provider, a program manager who set up application security from the ground up at a financial services firm, and an application security lead at a security vendor who runs its threat modeling and trains developers as security champions.
You do not need a management title, as long as the nominee is the person who leads application security. A nominee whose work is mainly finding and fixing flaws across many systems can also enter Vulnerability Management Professional of the Year, and the team can be entered in Cybersecurity Team of the Year.
Related categories to enter
Each category is judged separately, so you can enter a nominee in every category that fits their work, with a separate nomination for each. Tailor each nomination to that category's focus. Entering several related categories gives the work more than one chance to be recognized.
How entries are judged
An independent jury of security practitioners, analysts and CISOs scores each nomination on leadership, innovation and impact. Each nomination competes in its category against peers in a similar setting and region. Your entry package, any sponsorship and public votes do not affect the jury's scores.
Strong entries in this category show:
- Leadership — how the nominee gets developers to build securely: the standards they set, the developers they trained as security champions and the product teams they work with.
- Innovation — what the nominee changed in how software is secured, such as scanning built into the pipeline, threat modeling for AI features or a new way to rank findings.
- Impact — what improved: applications covered, flaws caught before release, time to fix, incidents avoided. Include coverage and fix-rate numbers if you have them.
The jury awards Gold, Silver or Bronze, or a Finalist badge, and results are published on this site and announced to the 600,000+ member Cybersecurity Insiders community. Every approved nomination also enters the separate Community Choice award, decided by public votes.
How to enter
Anyone can submit a nomination: the nominee, a colleague or manager, the organization, or an agency entering a client. The nomination form has a confidential field for detail that is shared with the judges and not published, such as internal figures, customer names or incident details. Deadlines, pricing and entry steps are on the How it Works page.