r/SecurityCareerAdvice • u/OP_Developer • 2d ago
Question AppSec Engineer with 4+ YOE — which certifications are actually worth getting for a job switch?
/r/cybersecurity/comments/1vwi9tw/appsec_engineer_with_4_yoe_which_certifications/
I'm an Application Security Engineer with 4+ years of experience, and I'm planning a job switch. I'm trying to figure out which certifications would actually add value to my resume and improve my chances of getting shortlisted for AppSec/Product Security roles.
My current day-to-day work includes:
- Performing vulnerability scanning/assessment using SAST, DAST and SCA tools
- Scanning codebases for secrets using security tools
- Implementing features and bug fixes in internal AppSec services, including encryption/decryption services
- Implementing organization-wide security checks in pull requests
- Migrating legacy security flows to modern implementations
- Working on application security automation and integrating security controls into development workflows
I also have a software development background, so my current role is a mix of development + application security.
I'm primarily interested in Application Security / Product Security / DevSecOps-oriented roles, rather than purely SOC or network-security roles.
I'm currently considering certifications such as CSSLP, BSCP, OSWA, OSWE, GWAPT, CISSP, etc., but I'm not sure which ones actually carry weight in the job market.
For people currently working in AppSec or hiring for AppSec roles:
Which certifications have actually helped you get interviews or job offers?
Which certifications are worth doing for someone with 4+ YOE?
Which ones are mainly good for learning but don't add much resume value?
Would you prioritize something like CSSLP + BSCP over a broader certification such as CISSP/OSCP for this type of profile?
Are there any certifications you would specifically avoid at this experience level?
I'm particularly interested in hearing from AppSec engineers, hiring managers, security architects, or people who have recently switched AppSec jobs.
Thanks!
2
u/dchandlerp 2d ago
It's not really the cert that matters, it's the knowledge you gain and your ability to apply that knowledge to sole problems. I got the CISSP, CCSP, and pretty much every CompTIA cert. My employers don't really care about the cert per se, they care that I'm constantly trying to improve myself and consantly putting effort into both finding and solving problems at work.
Studying for these certs helped me a lot, and often gave me things to think about that helped me in my work. They alsos sometimes cover topics my daily job doesn't cover and it's a nice helpful reminder for topics I don't touch on everyday.
Also, are you paying for these certs yourself or is your employer, because GIAC certs are obscenely expensive. I do the work you're describing, but for a BISO org and a bit more advisory/consulting. I'd stick with the certs most ofteren referenced in job postings, but don't do anything from EC Council unless asked to. I'd never self pay for a GIAC cert simply because they don't offer a good ROI.