Secure Development
Building security into how software is written, built and shipped.
Backend Engineer track
Junior
Write correct code, ship small changes safely, ask good questions.
Core: start here
- Keeping Sensitive Data Out of LogsNever logging passwords, tokens or personal data.
- Principle of Least PrivilegeGive every user and service only the access it needs.
1 more junior concepts
- Phishing and Social EngineeringAttacks that trick people instead of breaking code.
Mid-level
Own a feature end to end without hand-holding.
Core: start here
- Secrets ManagementKeeping API keys and passwords in a vault, not in code.
8 more mid-level concepts
- Attack SurfaceEvery point where an attacker could try to get in.
- Audit LoggingRecording who did what and when, for accountability.
- CVEA public identifier for a known vulnerability.
- Defense in DepthSeveral layers of security, so one failure isn't fatal.
- Dependency ScanningFinding known vulnerabilities in your dependencies.
- SASTStatic analysis that looks for security bugs in source code.
- TyposquattingMalicious packages named like popular ones.
- Zero-DayA vulnerability exploited before a fix exists.
Senior
Own a system, its failure modes, and its trade-offs.
Core: start here
- Threat ModelingSystematically asking what could go wrong and how to prevent it.
12 more senior concepts
- Bug BountyPaying outside researchers to report vulnerabilities.
- Container SecurityMinimal images, non-root users and image scanning.
- CVSSA score rating how severe a vulnerability is.
- DASTTesting a running app for vulnerabilities from the outside.
- Penetration TestingAuthorized simulated attacks to find vulnerabilities.
- Responsible DisclosureReporting vulnerabilities privately before going public.
- SBOMA software bill of materials listing every component.
- Secret RotationRegularly replacing credentials.
- Security ReviewReviewing a design or change specifically for security risks.
- Shift-Left SecurityFinding security issues early in development.
- Software Supply Chain SecurityProtecting against compromised dependencies and build pipelines.
- STRIDEA way to categorize threats: spoofing, tampering, repudiation, disclosure, denial of service, elevation.
Staff
Shape how many teams build, across systems.
- Security ChampionAn engineer on each team who advocates for security.
Principal
Set technical direction for the organization.
Nothing here yet.
Data Engineer track
Junior
Build and fix pipelines from clear specs; write correct SQL.
- Keeping Sensitive Data Out of LogsNever logging passwords, tokens or personal data.
- Phishing and Social EngineeringAttacks that trick people instead of breaking code.
- Principle of Least PrivilegeGive every user and service only the access it needs.
Mid-level
Own pipelines and models end to end, including their quality.
- Attack SurfaceEvery point where an attacker could try to get in.
- Audit LoggingRecording who did what and when, for accountability.
- CVEA public identifier for a known vulnerability.
- Defense in DepthSeveral layers of security, so one failure isn't fatal.
- Dependency ScanningFinding known vulnerabilities in your dependencies.
- SASTStatic analysis that looks for security bugs in source code.
- Secrets ManagementKeeping API keys and passwords in a vault, not in code.
- TyposquattingMalicious packages named like popular ones.
- Zero-DayA vulnerability exploited before a fix exists.
Senior
Design the platform's storage, processing and modeling choices.
- Bug BountyPaying outside researchers to report vulnerabilities.
- Container SecurityMinimal images, non-root users and image scanning.
- CVSSA score rating how severe a vulnerability is.
- DASTTesting a running app for vulnerabilities from the outside.
- Penetration TestingAuthorized simulated attacks to find vulnerabilities.
- Responsible DisclosureReporting vulnerabilities privately before going public.
- SBOMA software bill of materials listing every component.
- Secret RotationRegularly replacing credentials.
- Security ReviewReviewing a design or change specifically for security risks.
- Shift-Left SecurityFinding security issues early in development.
- Software Supply Chain SecurityProtecting against compromised dependencies and build pipelines.
- STRIDEA way to categorize threats: spoofing, tampering, repudiation, disclosure, denial of service, elevation.
- Threat ModelingSystematically asking what could go wrong and how to prevent it.
Staff
Shape how the whole organization produces and uses data.
- Security ChampionAn engineer on each team who advocates for security.
Principal
Set data strategy and architecture across the company.
Nothing here yet.
Frontend Engineer track
Junior
Build UI that works, ship small changes safely, ask good questions.
- Keeping Sensitive Data Out of LogsNever logging passwords, tokens or personal data.
- Phishing and Social EngineeringAttacks that trick people instead of breaking code.
- Principle of Least PrivilegeGive every user and service only the access it needs.
Mid-level
Own a feature end to end without hand-holding.
- Attack SurfaceEvery point where an attacker could try to get in.
- CVEA public identifier for a known vulnerability.
- Defense in DepthSeveral layers of security, so one failure isn't fatal.
- Dependency ScanningFinding known vulnerabilities in your dependencies.
- SASTStatic analysis that looks for security bugs in source code.
- Secrets ManagementKeeping API keys and passwords in a vault, not in code.
- TyposquattingMalicious packages named like popular ones.
- Zero-DayA vulnerability exploited before a fix exists.
Senior
Own an app's architecture, performance, and failure modes.
Core: start here
- Threat ModelingSystematically asking what could go wrong and how to prevent it.
10 more senior concepts
- Bug BountyPaying outside researchers to report vulnerabilities.
- CVSSA score rating how severe a vulnerability is.
- DASTTesting a running app for vulnerabilities from the outside.
- Penetration TestingAuthorized simulated attacks to find vulnerabilities.
- Responsible DisclosureReporting vulnerabilities privately before going public.
- SBOMA software bill of materials listing every component.
- Security ReviewReviewing a design or change specifically for security risks.
- Shift-Left SecurityFinding security issues early in development.
- Software Supply Chain SecurityProtecting against compromised dependencies and build pipelines.
- STRIDEA way to categorize threats: spoofing, tampering, repudiation, disclosure, denial of service, elevation.
Staff
Shape how many teams build, across apps.
- Security ChampionAn engineer on each team who advocates for security.
Principal
Set technical direction for the organization.
Nothing here yet.