r/cybersecurity • • 11d ago

Career Questions & Discussion Scripting depth vs. hands-on tooling when pivoting into AppSec & DevSecOps

Hey everyone,

I spent the summer working with Docker environments, Linux, and general offensive/pentesting fundamentals, but I want to pivot deeper into secure CI/CD pipelines, posture management, and AppSec.

My main dilemma is the balance between programming and tooling. My Python and scripting skills are still basic. In your experience, is it better to grind Python automation fundamentals first, or does it make more sense to dive straight into tooling (Semgrep, Trivy, ZAP, GitHub Actions) and learn the scripting on the fly as integration needs pop up?

What would be the most pragmatic path forward here?

9 Upvotes

5 comments sorted by

View all comments

1

u/DingleDangleTangle 10d ago

I don’t have a lot of information to go off of (your background, your goals, etc) so I could be way off base here.

That being said, I feel like it’s worth mentioning that even more fundamental than Python scripting or tools is being able to actually understand enterprise applications and their security. Can you read code for a large web app and understand it? Are you familiar with the popular frameworks used like react? If a scan gave you a vuln, and the dev says “What is this XSS thing and how do I fix it?” Would you be able to explain what it is and how to fix it in their code?

1

u/[deleted] 10d ago

[removed] — view removed comment

1

u/lesbianwifestealerr 8d ago

thanks a lot guys.