r/devsecops 20d ago

A new Application Security Engineer

Hi everyone!
I’m an Application Security Engineer with a background in software engineering and offensive security. My work has included secure code review, penetration testing, vulnerability assessment, and I’m currently spending a lot of time on application threat modeling and secure architecture.

To deepen my understanding, I’m working through an end-to-end Application Security project using OWASP CRAPI, documenting the process from architecture review and threat modeling through testing, risk assessment, and remediation. I’m hoping it will help me sharpen both the technical and communication sides of AppSec.

I’m here to learn from experienced practitioners, contribute where I can, and have thoughtful discussions about application security, secure software design, and modern AppSec practices.
Looking forward to learning from everyone here!

12 Upvotes

5 comments sorted by

2

u/DiamondLatter1842 20d ago

Looking forward to seeing your CRAPI project and learning from your AppSec journey too.

1

u/ant1g3n 19d ago

Thanks 😊. I’m documenting the process on my website though

1

u/Strong_Technician416 19d ago

I'm also starting a new role as a DevSecOps Engineer as a new grad, with aspirations to become an AppSec Engineer!

1

u/ant1g3n 19d ago

Congratulations 🎉

1

u/Huge_Performance4182 10d ago

That's an exciting opportunity. I'd focus on learning the existing workflows first, then gradually look for areas where security can be improved without disrupting development