Scott Norberg’s Post

View profile for Scott Norberg, graphic

ASP.NET Security Consultant, Author, Researcher, and Speaker - CISSP, CCSP, MBA, MCTS (Web Development), MCTS (SQL Server)

A have a question about #AppSec Engineers: More and more, I'm seeing the expectation that #ApplicationSecurity folks know how to secure infrastructure along with being able to dig into code to help software developers. This strikes me as an odd combination of skills. Securing infrastructure is not at all like securing code. And most people I've met who were really good at one were, um, less good at the other. Am I wrong? Crazy? Or, as someone who has dug through the source code of ASP.NET Core (and subsequently written a book), is my expectation of what "good" is too high?

If we talk about the AppSec role, in theory, you should be good at doing code review as well as knowing about infrastructure. However, to achieve this or: 1) You are really good and skilled that you quickly abstract knowledge in a short time. 2) you have years of experience, a lot of experience. In any case, in my opinion, I believe that the fundamental role is to facilitate/enable security and must work alongside dev teams. Security should not be the one who, exclusively, must solve all problems, on the contrary, be accompanied by the dev team. While AppSec may not be the code expert, it better knows code and can give practical and usable solutions. It must be the benchmark in security and equalize it.

Jacob Ivester, MBA

GitLab | Passionate about Success + Curious about Process

1y

Let’s first be honest, #DevSecOps is more slogan than practice. I think that as the core tenets are better defined and adopted, there will be intentional experience ration with specialized roles. Much like it took government regulatory bodies and car manufactures decades to formalize safety standards and test crashing, I expect the same will happen in the software industry for development, operations, and security.

James Warren

US Cybersecurity Headhunter | We build world class Cybersecurity teams

1y

Yes I’ve noticed this as well. Core AppSec skill set: MSCR, SAST, DAST AppSec Engs with Infra skills as well (container security etc.) used to be known as Product Security Engineers. Now that expectation has started to get wrapped up into AppSec jobs. Similarly CloudSec Engineers are increasingly expected to automate SAST/DAST testing in CI/CD pipelines.

See more comments

To view or add a comment, sign in

Explore topics