Learning Hub › Career Timeline › Application Security Engineer
Career prep · Specialist track
Application Security Engineer
AppSec engineers help developers ship secure software: they find bugs in code and running apps, design risk out before code is written, and automate security checks into the pipeline. This is an interactive prep kit. Build a plan for your background, track your skills, then practise the things interviews actually test: live code review, threat modelling, pipeline design and scenario questions.
What the job really looks like
Job ads say "secure the SDLC". In practice the work is a mix of reviewing, building, teaching and firefighting, and most of it happens with developers rather than after them. Click through a typical week.
Where the time goes
Rough split for a product-company AppSec role; consultancies lean more towards testing, platform teams more towards tooling.
Build your plan
Where you start changes what you can skip and where you need to slow down. Pick your background and weekly hours to get a phase-by-phase timeline.
I'm coming from
Your timeline
EstimateSkill tracker
Tick skills as you can do them without looking things up. Each phase lists the best free resources and the milestone project that proves the skill. Your ticks are saved in this browser only.
OWASP Top 10:2025
The vocabulary every AppSec interview assumes. The 2025 edition adds Software Supply Chain Failures (A03) and Mishandling of Exceptional Conditions (A10), and folds SSRF into Broken Access Control. Click a category for what it means, a typical bug, the fix, and what interviewers ask.
Code review drill: spot the bug
The most common AppSec interview exercise: "here's some code, what's wrong with it?". For each snippet, click the vulnerable line, then name the weakness. You'll see the fix and how to explain it.
Step 2 · Which weakness?
Threat modelling with STRIDE
Threat modelling answers four questions: What are we building? What can go wrong? What are we going to do about it? Did we do a good job? STRIDE is a checklist for the second question. Click an element of this OTP login design to see which threats apply to it.
Classify the threat
Six findings from a design review of the same feature. Pick the STRIDE category for each.
Pipeline builder: design the security gates
"Design a DevSecOps pipeline" is a classic interview prompt. Switch gates on or off, then run six risky changes through it. Every gate costs developer time, so aim to catch everything with the least friction, not to switch everything on blindly.
Interview question bank
Real questions asked in AppSec loops, with the points a strong answer covers. Say your answer out loud first, then reveal the outline and mark how it went.
Certifications and portfolio
In AppSec hiring, proof of skill beats certificates. A hands-on cert plus a public portfolio is the strongest combination. Filter the ladder by level, and use the portfolio checklist to see what reviewers look for.
Portfolio that gets interviews
Career ladder
Sources & further reading
- OWASP Top 10:2025
The ten categories used in section 04.
- PortSwigger Web Security Academy
The best free hands-on labs for every web vulnerability class, and the path to BSCP.
- OWASP Cheat Sheet Series
Concise fix guidance; the source for most remediation advice on this page.
- OWASP ASVS
Security requirements you can turn into acceptance criteria and test cases.
- OWASP API Security Top 10 (2023)
BOLA, BOPLA, BFLA and the other API-specific risks.
- Threat Modeling Manifesto
The four questions and the values behind them. See also Adam Shostack's Threat Modeling: Designing for Security.
- NIST SP 800-218: Secure Software Development Framework
The practices a secure SDLC programme is measured against. See also SLSA for supply chain levels.
- MITRE CWE Top 25
The weakness IDs used in the code review drill.
Practise next: run a real security gate in the SAST in CI/CD lab, score bugs with the CVSS calculator, or go back to the Career Timeline.