Become an Application Security Engineer | Roadmap

แชร์
ฝัง
  • เผยแพร่เมื่อ 3 ส.ค. 2024
  • In this video I clarify the confusion around Application Security and I share with you how you can become an Application Security (AppSec) Speclialist or an Application Security Engineer.

ความคิดเห็น • 90

  • @victorboyi6383
    @victorboyi6383 11 หลายเดือนก่อน +27

    Protect this guy at all costs

    • @UnixGuy
      @UnixGuy  11 หลายเดือนก่อน +1

      lmao thanks man

    • @tobby_fabulous
      @tobby_fabulous 10 หลายเดือนก่อน

      He's doing well 😊

    • @King_Prodigy
      @King_Prodigy 2 หลายเดือนก่อน

      I'm in a full stack bootcamp and wanted to get into application security engineer. I don't have a degree but I'm working on getting my security plus cert. This video helped alot but wanted to know if I'm going in the right direction

    • @abdulvakeel2150
      @abdulvakeel2150 26 วันที่ผ่านมา

      Seriously Dude.. He's the best.

  • @muyideenkazeemoluwadare3720
    @muyideenkazeemoluwadare3720 10 หลายเดือนก่อน +5

    Thank you Sir, I passed my CySa+ exam today(16-09-2023). I thank you so much for your help and guidance. God continue to bless you

    • @UnixGuy
      @UnixGuy  10 หลายเดือนก่อน

      🙏🏻

  • @vrunsidhu5707
    @vrunsidhu5707 ปีที่แล้ว +6

    hey i just want to thank you for making these videos. recently, due to a medical issue i was rejected from joining my countries military. i had been planning my since i was 7 or 8 to join the army, i felt lost and didn't know where to go. eventually, i settled on cyber security and your videos have really helped me narrow it down and plan a solid road map.

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +2

      Glad I was able to help Vrun, all the best my friend

    • @toddh3704
      @toddh3704 10 หลายเดือนก่อน

      ​@@UnixGuythank you for making the video. It is very interesting. Do you know if the IBM certification for Application Security Engineer is worth it?

    • @UnixGuy
      @UnixGuy  10 หลายเดือนก่อน +1

      @@toddh3704 yes its ok

    • @toddh3704
      @toddh3704 10 หลายเดือนก่อน

      @@UnixGuy thank you. We all greatly appreciate all your videos. I just started watching today.

  • @greysonbennett6788
    @greysonbennett6788 ปีที่แล้ว +1

    I was just given advice about this by a person in the industry as well; thanks for this well structured video.

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +1

      Awesome! There is a huge demand for AppSec, are u thinking of getting into it?

    • @greysonbennett6788
      @greysonbennett6788 ปีที่แล้ว +1

      @@UnixGuy yes initially I was thinking of heading to study for the AWS solutions architect cert but decided to veer off in another direction. There is someone I know that works in the field and he mentioned it'd be a better idea to start around here and then if I want to do cloud security to switch after.

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +1

      @@greysonbennett6788 no reason why you can’t do both, cloud skills will always be handy

  • @BobBob-qm2bm
    @BobBob-qm2bm ปีที่แล้ว +10

    Thank you for explaining the Application Security landscape. INE has updated eJPT to version 2 with more industry relevant content. Several streamers have mentioned a shortage of qualified people for the AppSec field. Please share your thoughts on this issue. Also, keep on rocking the content U.G!

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +4

      Hey Bob, I agree there is a big shortage of ‘GOOD’ AppSec specialists! Key word is good, so if someone is really good in this area they’re gonna have an excellent career

    • @BobBob-qm2bm
      @BobBob-qm2bm ปีที่แล้ว +1

      @@UnixGuyThank you. Being good is key! Also, finding that good training to become a 'GOOD' AppSec specialist. 👍

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว

      @@BobBob-qm2bm 100%

    • @Damo_LowEnd_or_NoEnd
      @Damo_LowEnd_or_NoEnd 10 หลายเดือนก่อน

      Question how can u get the experience you need in this field with no background knowledge

  • @muyideenkazeemoluwadare3720
    @muyideenkazeemoluwadare3720 11 หลายเดือนก่อน +1

    Thank you so much. I am sending you this short message as an appreciation to you. I was able to get 4 certification (Comptia Security+, SC-200, AZ-104, SC-100) in 4 months with your motivation and encouragement. Even though I have not landed my first job but I believe I will soon. Keep up the good work. God continue to bless you and your entire household.

    • @UnixGuy
      @UnixGuy  11 หลายเดือนก่อน

      so glad to hear it! congrats and I’m sure you will land a job soon if you keep applying’l!

  • @viq234
    @viq234 ปีที่แล้ว +4

    I'll like to mention DAST, SAST and IAST. These are point and shoot type scanners
    That you can use throughout the SDLC

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +1

      Excellent points, agreed.

  • @TaelurAlexis
    @TaelurAlexis ปีที่แล้ว +1

    You hit the nail on the head! My mentor is a DevSecOps engineer and a lot of what he does is cloud security, container security and integrating security into the CI/CD pipeline which is alot of what I’ve seen in appsec postings lol he just doesn’t know how to code. Whereas I just got hired as an appsec analyst work where I’ll be doing lots of code review and working on a SAST tool however lol. These terms are really vague and inconsistent lol 😅. Would you say cloud certs would be relevant for me on top of Portswigger and pentesting certs? Because I do want to ultimately be an appsec engineer.

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +1

      focus on portswigger / pentest and if u have time for sure cloud is helpful

  • @hectorvasquez6128
    @hectorvasquez6128 ปีที่แล้ว +1

    Love the vids bro, would you recommend WGU University for B.S Cybersecurity & Info assurance? Thanks!

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว

      I certainly do, talked briefly about it here: Western Governonre University (WGU) Degrees | Cyber Security
      th-cam.com/users/shortsWJs-oh1IIJc?feature=share

  • @haxguy0
    @haxguy0 ปีที่แล้ว +3

    I'm the only app sec analyst at my company and I'm expected to build out the app sec program. I feel a bit lost and overwhelmed. I'm attempting to slowly make changes that will move everything to be more secure

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +2

      Hey Charles, it’s not uncommon to be the only AppSec person unfortunately, as I said in the video people generally don’t understand this field very well.
      I recommend you start by ensuring there are checks against OWASP top 10, and secure coding reviews are conducted before going to prod
      good luck!

  • @primebore
    @primebore ปีที่แล้ว +1

    Dear UnixGuy, I really enjoy your career pathway videos a lot but there are still fields out there that you haven't covered like IAM, security architecture and DevSecOps. Could you do a video on these sometime? Appreciate it!

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +1

      hey mate, security architecture is coming in the near future!
      Regarding IAM and DevSecOps there aren’t exactly certifications, its something you learn from broad certs and doing on the job tasks, but I might summarise them at one point

    • @primebore
      @primebore ปีที่แล้ว

      @@UnixGuy OK looking forward to it! I missed security engineering, would it be possible for you to cover what's it like to be a security engineer as well? Thanks.

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +1

      @@primebore security ‘engineer’ can mean a lot of things in different companies, so much so that the title is meaningless now, but the closest is a SOC anlyst/engineer:
      th-cam.com/video/HohIYcNd_VM/w-d-xo.html

    • @primebore
      @primebore ปีที่แล้ว

      @@UnixGuy That's interesting, wouldn't a SOC analyst be more focussed on the DFIR side rather than working with security architecture? I read online that security engineer roles tend to be a step up from SOC roles, but just beneath the architect role.

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว

      @@primebore some do some don’t, titles are all over the place unfortunately. A SOC engineer can also create detection rules for eg,

  • @SavageScientist
    @SavageScientist ปีที่แล้ว +2

    Great video, i in a dev sec ops position and i mostly do secure code reviews. I have fun but would enjoy red team operations more, but breaking apps is fun. The pay is great too 100k.

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว

      Sounds great!

    • @squid13579
      @squid13579 11 หลายเดือนก่อน +3

      How much coding required for this job ? And what kind of resources did you have ? Free or purchase ?

    • @SavageScientist
      @SavageScientist 11 หลายเดือนก่อน

      @@squid13579 , currently its not much writing code but it is a lot of reviewing and correcting code. I have a Masters in Computer science and the CSSLP certification. On my youtube channel savage scientist i will start covering things i do as a security analyst.

  • @willownot
    @willownot ปีที่แล้ว +2

    Hello, I just arrived at this channel, I'm starting in cybersecurity, but I have 3 questions, can you help me? 1: Is it better to go after these certifications soon? comptia, CSSP, EC-COUNCIL...
    2: Are there really these 300,400k a year salaries?
    3: Are AIs or this tech bubble that burst ending or could they end up with jobs in the area?

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว

      Hey mate, I answered this comment in another video

  • @frankshorts6322
    @frankshorts6322 ปีที่แล้ว +1

    What is the main language used as a cybersecurity analyst and consultant?
    What languages are taught in Macquarie's bachelor of cybersecurity. And is the degree heavy on discrete maths and etc. Thanks, great info😍

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว

      Hey mate, there is no ‘main language’ , it depends on the environment. This video explains what a SOC Analyst actually does:
      th-cam.com/video/HohIYcNd_VM/w-d-xo.html
      As for Macquaire, I reviewed their degrees a year ago: th-cam.com/video/jLHHwHzqaEI/w-d-xo.html

  • @tobby_fabulous
    @tobby_fabulous 10 หลายเดือนก่อน

    eJPT noted ✅️ 👌 😊

    • @UnixGuy
      @UnixGuy  10 หลายเดือนก่อน +1

      👍

  • @JosephAluko
    @JosephAluko ปีที่แล้ว

    What cyber security jobs can you do, if you like to do system management but do not want to learn programs languages or coding

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว

      What do you mean by ‘system management’ ? System administration? you need some basic scripting fir that, but it’s not a cyber job per se. there are many cyber jobs that doesn’t need programming. I recommend you watch this playlist and select a path that you like: Cyber Security Specialisations
      th-cam.com/play/PLdI5VHN89i7XgaT-dWsthpAKOmjAF3gCR.html

  • @everything-om3zx
    @everything-om3zx ปีที่แล้ว +3

    Hey UnixGuy, '
    can recommend some SOC certifications that can land me a job pleas. i have eJPT, Security +, and i studied Cyber security bootcamp in one of US Universities. i looked up the SANS GSOC which is very expensive to me, i cant pay for it. i would really appreciate it if you give me some information.
    Thank You.

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +1

      The recommendations that you’re looking for are all in this video:
      th-cam.com/video/HohIYcNd_VM/w-d-xo.html

    • @everything-om3zx
      @everything-om3zx ปีที่แล้ว

      @@UnixGuy Your content is Golden Sir,
      Thank You so much.

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว

      @@everything-om3zx you’re welcome mate, once you watvh the video, let me know if you have any further questions :)

  • @Rekke_yt
    @Rekke_yt ปีที่แล้ว +1

    Hi Unixguy, what do you think of Cybersecurity Course (Cert IV) in TAFE Australia? Already have Bachelor of IT + 3 years of System Engineer work history. Planning to do certs as per your other video but saw TAFE course is free and course syllabus looks very interesting

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +2

      Hey Rekke, I like that Cert IV because it’s free (i think in victoria) and I hired two people who did it.
      It’s content heavy but you will get out of it what you put in. It’s going to be part of your learning journey so it’s just another avenue fir you to learn. But since you already have experience and degree, going straight to certs might be faster - depending on quick you are and how well you do self-learning, some people prefer the structure of a degree/tafe,
      Many paths and options are out there, whichever you choose work hard at it and be patient and good things will happen

    • @Rekke_yt
      @Rekke_yt ปีที่แล้ว

      @@UnixGuy Thank you so much for your response! I would love to see some content on the different cyber security roles and pathways that System Admin/IT Roles can pivot into for career changes :)

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +1

      @@Rekke_yt system admins can pivot to literally any specialisation. I strongly recommend the vidoes in this playlist, I go through each specialisation in detail: Cyber Security Specialisations
      th-cam.com/play/PLdI5VHN89i7XgaT-dWsthpAKOmjAF3gCR.html

  • @sandyc1868
    @sandyc1868 ปีที่แล้ว

    I have been contemplating about CASE Java Certification by EC Council. I am still not sure if I can go for it. Neither is the course content available on their website nor are any demo videos. I have been a typical Java developer with no exposure to security coding, whatsoever.
    Kindly share your opining about this CASE Java training and Certification by EC Council.

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +1

      Im not a fan of that training, do basic cyber security training like this: th-cam.com/video/6LIUhx95MCU/w-d-xo.html
      and supplement with some pentesting courses:
      th-cam.com/video/OR8G_Vi5B1U/w-d-xo.html

  • @aruha2847
    @aruha2847 ปีที่แล้ว +2

    Hi, I am from software development trying to get into cyber security. I have worked in front end for 2 years. Is it possible for me to get into app sec as a beginner in cyber security?

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +2

      yes you have the perfect background for it! You can even supplement with some certification to boost your profile. Start here:
      th-cam.com/video/jtLfX5_Lu84/w-d-xo.html

    • @aruha2847
      @aruha2847 ปีที่แล้ว

      @@UnixGuy Thank you so much for your answer

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +1

      @@aruha2847 🫡

  • @abhiraj4528
    @abhiraj4528 ปีที่แล้ว

    Can you help me please.
    Needed a review about EC-COUNCIL. When i searched on reddit.
    I can see that reddit users aren't happy with the EC-Council and their cources.
    Some are comparing C|EH with OSCP instead of C|PENT.
    I came to know that there's an offline institution that had partnered with EC-Council and give training offline instead of online. (It's make it easier to learn I guess)
    They offer C|EH, C|SCU, C|ND, C|SCE, C|PENT, C|HFI
    I'm curious about C|HFI.
    I'm an absolute beginner and never got an exposure into ethical hacking or cyber security.
    The fee is 3 lakhs INR ($4000)
    And i can't afford it and must take a loan to take the course.
    What's your opinion about this, and any suggestions?
    Thanks :)

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +1

      I’m gonna have to agree with reddit. If you want to be a penetration tester, save your money and do the courses I recommend in this video instead: th-cam.com/video/OR8G_Vi5B1U/w-d-xo.html

    • @abhiraj4528
      @abhiraj4528 ปีที่แล้ว +1

      @@UnixGuy thanks. Appreciate it!

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว

      @@abhiraj4528 u welcome

  • @headlights-go-up
    @headlights-go-up 8 หลายเดือนก่อน

    will ai impact appsec jobs more than other cybersecurity positions? for example, do you think that ai will eventually produce more secure code thus reducing the need for appsec engineers? or do you think it will be the opposite?

    • @UnixGuy
      @UnixGuy  8 หลายเดือนก่อน

      the answer is here:
      th-cam.com/video/5sCrHjDMsiU/w-d-xo.html

    • @headlights-go-up
      @headlights-go-up 7 หลายเดือนก่อน +1

      @@UnixGuy Oh! You responded so quickly I didnt even notice lol. Thank you, I will go watch now!

  • @jay2004r
    @jay2004r 8 หลายเดือนก่อน

    Quick Question, can vulnerability management be a pathway to becoming a application security engineer ?

    • @UnixGuy
      @UnixGuy  8 หลายเดือนก่อน

      Unlikely! If you want to become Application Security Engineer follow this:
      th-cam.com/video/shgKU-zjOmw/w-d-xo.html

  • @knox1
    @knox1 ปีที่แล้ว

    can you become software engineer with cyber security courses?

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +1

      Do software engineering courses if you want to become a software engineer, watch this:
      th-cam.com/video/ys-_xQHaYAc/w-d-xo.html

  • @MichaelOseiAppiah
    @MichaelOseiAppiah 3 หลายเดือนก่อน

    Hello Abed:
    Is there a training you know that I can enroll in to be an appsec engineer?

    • @UnixGuy
      @UnixGuy  3 หลายเดือนก่อน

      yes all explained in this video:
      th-cam.com/video/shgKU-zjOmw/w-d-xo.html

  • @GIMFCFX
    @GIMFCFX 3 หลายเดือนก่อน +1

    I am late to the party! I want to become an Application Security Engineer. Can someone provide a roadmap for such a field?

    • @UnixGuy
      @UnixGuy  3 หลายเดือนก่อน

      yes this video has it:
      th-cam.com/video/shgKU-zjOmw/w-d-xo.html

  • @raymondakoson5165
    @raymondakoson5165 9 หลายเดือนก่อน

    With the coming of DevSecOps, what's the future of AppSec engineers?

    • @UnixGuy
      @UnixGuy  9 หลายเดือนก่อน

      the future is good!

  • @MichaelOseiAppiah
    @MichaelOseiAppiah 2 หลายเดือนก่อน

    Can you recommend any links to study appsec.

    • @UnixGuy
      @UnixGuy  2 หลายเดือนก่อน

      yes watch this:
      th-cam.com/video/shgKU-zjOmw/w-d-xo.html

    • @MichaelOseiAppiah
      @MichaelOseiAppiah 2 หลายเดือนก่อน

      @@UnixGuy Thank you.

  • @krusty07
    @krusty07 ปีที่แล้ว

    sir can share us your linkedin or some verification proof of your work

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +1

      No, I don’t share my private LinkedIn information publicly.

    • @krusty07
      @krusty07 ปีที่แล้ว

      @@UnixGuy Sir you seems like a genuine guy but i like to cross check the information but there are no credentials like LinkedIn or twitter or GitHub or showcase of you

    • @UnixGuy
      @UnixGuy  ปีที่แล้ว +3

      @@krusty07 I have no obligation to prove anything to you my friend, I’m putting out my personal views online for free, take it or leave it.

    • @krusty07
      @krusty07 ปีที่แล้ว

      @@UnixGuy alright sir