ORIGINAL REDDIT POST
Wanted to get into product security / AppSec role at product based companies
Can you suggest what product-based companies are looking for in a candidate? my background: i have 1 yoe in offensive security (web & android). I'm also interested in securing a product - not just finding issues. please suggest me something. What sort of…
Can you suggest what product-based companies are looking for in a candidate? my background: i have 1 yoe in offensive security (web & android). I'm also interested in securing a product - not just finding issues. please suggest me something. What sort of skill set should I have.
Collected discussion
With 1 year of offensive security experience, you already have a good foundation. For product-based companies, I think the biggest difference is moving from just finding vulnerabilities to understanding how products are built and secured. I'd focus on secure SDLC, threat modeling, code review basics, API security, cloud security, and learning how developers actually design and deploy applications. Knowing how to communicate risks and suggest practical fixes is also a big advantage.
Since early in career. How much cloud security knowledge is required ? Like I'm familiar with aws (iam,vpc,ec2,security group, s3,rds, and basic of their security recommendations)
You could focus on getting some certifications, they really go crazy over them but ofc you still need to know your stuff. It's already great if you have offensive security background, you could send me over your resume as well.
Go do a pile of white-box testing, as that's going to give you the stuff you need to know when it comes to secure code review and is more representative of the triaging process for vulnerabilities surfaced by scanners.