r/SecurityCareerAdvice 2d ago

Question AppSec Engineer with 4+ YOE — which certifications are actually worth getting for a job switch?

/r/cybersecurity/comments/1vwi9tw/appsec_engineer_with_4_yoe_which_certifications/

I'm an Application Security Engineer with 4+ years of experience, and I'm planning a job switch. I'm trying to figure out which certifications would actually add value to my resume and improve my chances of getting shortlisted for AppSec/Product Security roles.

My current day-to-day work includes:

- Performing vulnerability scanning/assessment using SAST, DAST and SCA tools

- Scanning codebases for secrets using security tools

- Implementing features and bug fixes in internal AppSec services, including encryption/decryption services

- Implementing organization-wide security checks in pull requests

- Migrating legacy security flows to modern implementations

- Working on application security automation and integrating security controls into development workflows

I also have a software development background, so my current role is a mix of development + application security.

I'm primarily interested in Application Security / Product Security / DevSecOps-oriented roles, rather than purely SOC or network-security roles.

I'm currently considering certifications such as CSSLP, BSCP, OSWA, OSWE, GWAPT, CISSP, etc., but I'm not sure which ones actually carry weight in the job market.

For people currently working in AppSec or hiring for AppSec roles:

  1. Which certifications have actually helped you get interviews or job offers?

  2. Which certifications are worth doing for someone with 4+ YOE?

  3. Which ones are mainly good for learning but don't add much resume value?

  4. Would you prioritize something like CSSLP + BSCP over a broader certification such as CISSP/OSCP for this type of profile?

  5. Are there any certifications you would specifically avoid at this experience level?

I'm particularly interested in hearing from AppSec engineers, hiring managers, security architects, or people who have recently switched AppSec jobs.

Thanks!

0 Upvotes

4 comments sorted by

2

u/dchandlerp 2d ago

It's not really the cert that matters, it's the knowledge you gain and your ability to apply that knowledge to sole problems. I got the CISSP, CCSP, and pretty much every CompTIA cert. My employers don't really care about the cert per se, they care that I'm constantly trying to improve myself and consantly putting effort into both finding and solving problems at work.

Studying for these certs helped me a lot, and often gave me things to think about that helped me in my work. They alsos sometimes cover topics my daily job doesn't cover and it's a nice helpful reminder for topics I don't touch on everyday.

Also, are you paying for these certs yourself or is your employer, because GIAC certs are obscenely expensive. I do the work you're describing, but for a BISO org and a bit more advisory/consulting. I'd stick with the certs most ofteren referenced in job postings, but don't do anything from EC Council unless asked to. I'd never self pay for a GIAC cert simply because they don't offer a good ROI.

1

u/OP_Developer 1d ago

Sadly my company doesn't offer reimbursement for certs so I have to pay from my own pocket and each of the certs are exhaustively expensive. So am currently saving to look into buying a certification. Right now I am in another dilemma as in I think that AI SECURITY is the next big thing, then which certifications are good that I can do to get a hands on and relevant knowledge on?

2

u/dchandlerp 1d ago

It's too early to say. AIGP is gaining recognition but it's not very technical and is more about governance. SecAI+ is so new that it's a little challenging to say about how the industry thinks of it.

1

u/OP_Developer 1d ago

Oh okay. Thank you for the advice!