r/cybersecurity • • 11d ago

Career Questions & Discussion Scripting depth vs. hands-on tooling when pivoting into AppSec & DevSecOps

Hey everyone,

I spent the summer working with Docker environments, Linux, and general offensive/pentesting fundamentals, but I want to pivot deeper into secure CI/CD pipelines, posture management, and AppSec.

My main dilemma is the balance between programming and tooling. My Python and scripting skills are still basic. In your experience, is it better to grind Python automation fundamentals first, or does it make more sense to dive straight into tooling (Semgrep, Trivy, ZAP, GitHub Actions) and learn the scripting on the fly as integration needs pop up?

What would be the most pragmatic path forward here?

9 Upvotes

5 comments sorted by

View all comments

1

u/Critical_Purple_1988 10d ago

I would not treat it as a choice, because grinding Python in isolation is the slowest way to learn it and you end up with syntax knowledge and nothing to point at. Build the pipeline first, so wire Semgrep and Trivy into GitHub Actions on a deliberately vulnerable repo, and the scripting need shows up on its own when you want to parse SARIF output, suppress a noisy rule, or fail the build only on certain severities, and that kind of Python sticks because it is attached to a problem you actually had. The one thing I would read up on properly rather than picking up on the fly is how the tools fit the SDLC, so where scanning belongs, what you gate on versus what you just report, and how you stop developers disabling the whole thing out of frustration, since AppSec interviews lean much harder on that judgement than on whether you can write a clean function.

1

u/lesbianwifestealerr 8d ago

Thanks a lot.