What does An Application Security (AppSec) Engineer do?
An Application Security (AppSec) Engineer is responsible for embedding security into the software development lifecycle through code review, threat modelling, and automated security tooling in the CI/CD pipeline.
Day-to-day responsibilities
- Running static and dynamic application security testing
- Threat-modelling new features with engineering teams
- Triaging vulnerabilities from bug bounty and pen test reports
- Building security tooling into CI/CD pipelines
Very High demand+15% SAST/DAST tooling+13% Threat modelling+12% Secure CI/CD pipeline design