Skill · 01
← All skills
Security

Application Security

Embedding secure-by-design into the SDLC.

At a glance
30–40%
Production security defects reduced
25%
Faster remediation turnaround
Capabilities
5
Tools & platforms
5
Discipline
Security
Overview

Lead AppSec strategy across web, API, and cloud-native platforms. Identify and remediate vulnerabilities at the design stage and across the entire delivery pipeline.

Capabilities
5 areas
  • SAST, DAST and SCA tooling integration
  • Secure code review across .NET, Java, Node.js
  • Threat modeling using STRIDE
  • Authentication, authorization and input validation review
  • Vulnerability management lifecycle ownership
Software & Tools

The stack behind the work.

The tools I reach for day to day — with a rough sense of where my depth sits.

Expert
Advanced
Proficient

Burp Suite

Expert

Manual web app pentesting & interception

OWASP ZAP

Advanced

Automated DAST scanning in CI

Checkmarx

Advanced

Static analysis (SAST) for code review

Snyk

Advanced

Dependency & SCA vulnerability scanning

SonarQube

Proficient

Code quality & security gating

Let's work together

Have a project that needs Application Security?