dashboard radar bug_report school newspaper sensors

Learning Hub › Career Timeline › Application Security Engineer

Career prep · Specialist track

Application Security Engineer

AppSec engineers help developers ship secure software: they find bugs in code and running apps, design risk out before code is written, and automate security checks into the pipeline. This is an interactive prep kit. Build a plan for your background, track your skills, then practise the things interviews actually test: live code review, threat modelling, pipeline design and scenario questions.

9–12 months · ~10–12 hrs/week Best from: developer · QA · pentester · SOC OWASP Top 10:2025
01

What the job really looks like

Job ads say "secure the SDLC". In practice the work is a mix of reviewing, building, teaching and firefighting, and most of it happens with developers rather than after them. Click through a typical week.

Illustrative week

Where the time goes

Rough split for a product-company AppSec role; consultancies lean more towards testing, platform teams more towards tooling.

02

Build your plan

Where you start changes what you can skip and where you need to slow down. Pick your background and weekly hours to get a phase-by-phase timeline.

I'm coming from

Your timeline

Estimate
03

Skill tracker

Tick skills as you can do them without looking things up. Each phase lists the best free resources and the milestone project that proves the skill. Your ticks are saved in this browser only.

04

OWASP Top 10:2025

The vocabulary every AppSec interview assumes. The 2025 edition adds Software Supply Chain Failures (A03) and Mishandling of Exceptional Conditions (A10), and folds SSRF into Broken Access Control. Click a category for what it means, a typical bug, the fix, and what interviewers ask.

05

Code review drill: spot the bug

The most common AppSec interview exercise: "here's some code, what's wrong with it?". For each snippet, click the vulnerable line, then name the weakness. You'll see the fix and how to explain it.

0 / 7 solved

Step 2 · Which weakness?

06

Threat modelling with STRIDE

Threat modelling answers four questions: What are we building? What can go wrong? What are we going to do about it? Did we do a good job? STRIDE is a checklist for the second question. Click an element of this OTP login design to see which threats apply to it.

▭ external entity◯ process═ data store→ data flow┅ trust boundary

Classify the threat

Six findings from a design review of the same feature. Pick the STRIDE category for each.

07

Pipeline builder: design the security gates

"Design a DevSecOps pipeline" is a classic interview prompt. Switch gates on or off, then run six risky changes through it. Every gate costs developer time, so aim to catch everything with the least friction, not to switch everything on blindly.

Simulated pipeline
08

Interview question bank

Real questions asked in AppSec loops, with the points a strong answer covers. Say your answer out loud first, then reveal the outline and mark how it went.

09

Certifications and portfolio

In AppSec hiring, proof of skill beats certificates. A hands-on cert plus a public portfolio is the strongest combination. Filter the ladder by level, and use the portfolio checklist to see what reviewers look for.

Portfolio that gets interviews

Career ladder

    10

    Sources & further reading

    Practise next: run a real security gate in the SAST in CI/CD lab, score bugs with the CVSS calculator, or go back to the Career Timeline.