With agile development and DevOps on the rise, the speed of modern software development increases rapidly. Software has long become a vital part of many businesses (sometimes to their own surprise), but news about application related data breaches won’t stop. Security teams in many organizations hardly managed to keep up with application security in a waterfall world, let alone during the now ongoing adoption of cloud and container based technologies with agile and independent DevOps teams. As application security is also gaining increasing attention from management, security teams need to react - but what to do when your resources are limited and the number of projects isn’t? How can you build - and scale - your application security strategy in a large organization? Shift-Left and DevSecOps to the rescue, together with a chain of modern security tools like SAST, DAST, IAST and OSA. But can finding thousands of security bugs really help? And should you train your developers for security awareness - or just expand your application security team? (Spoiler: Better do both.) This talk is a journey through bootstrapping application security programs in small organizations and large enterprises, the challenge of keeping management and development teams happy, while trying to (not make things worse) improve security - and a self-critical reflection on what worked well and what didn’t.