Contents

Security

Secure Development

Building security into how software is written, built and shipped.

Backend Engineer track

Junior

Write correct code, ship small changes safely, ask good questions.

Core: start here

1 more junior concepts

Mid-level

Own a feature end to end without hand-holding.

Core: start here

8 more mid-level concepts
  • Attack SurfaceEvery point where an attacker could try to get in.
  • Audit LoggingRecording who did what and when, for accountability.
  • CVEA public identifier for a known vulnerability.
  • Defense in DepthSeveral layers of security, so one failure isn't fatal.
  • Dependency ScanningFinding known vulnerabilities in your dependencies.
  • SASTStatic analysis that looks for security bugs in source code.
  • TyposquattingMalicious packages named like popular ones.
  • Zero-DayA vulnerability exploited before a fix exists.

Senior

Own a system, its failure modes, and its trade-offs.

Core: start here

  • Threat ModelingSystematically asking what could go wrong and how to prevent it.
12 more senior concepts
  • Bug BountyPaying outside researchers to report vulnerabilities.
  • Container SecurityMinimal images, non-root users and image scanning.
  • CVSSA score rating how severe a vulnerability is.
  • DASTTesting a running app for vulnerabilities from the outside.
  • Penetration TestingAuthorized simulated attacks to find vulnerabilities.
  • Responsible DisclosureReporting vulnerabilities privately before going public.
  • SBOMA software bill of materials listing every component.
  • Secret RotationRegularly replacing credentials.
  • Security ReviewReviewing a design or change specifically for security risks.
  • Shift-Left SecurityFinding security issues early in development.
  • Software Supply Chain SecurityProtecting against compromised dependencies and build pipelines.
  • STRIDEA way to categorize threats: spoofing, tampering, repudiation, disclosure, denial of service, elevation.

Staff

Shape how many teams build, across systems.

Principal

Set technical direction for the organization.

Nothing here yet.

Data Engineer track

Junior

Build and fix pipelines from clear specs; write correct SQL.

Mid-level

Own pipelines and models end to end, including their quality.

  • Attack SurfaceEvery point where an attacker could try to get in.
  • Audit LoggingRecording who did what and when, for accountability.
  • CVEA public identifier for a known vulnerability.
  • Defense in DepthSeveral layers of security, so one failure isn't fatal.
  • Dependency ScanningFinding known vulnerabilities in your dependencies.
  • SASTStatic analysis that looks for security bugs in source code.
  • Secrets ManagementKeeping API keys and passwords in a vault, not in code.
  • TyposquattingMalicious packages named like popular ones.
  • Zero-DayA vulnerability exploited before a fix exists.

Senior

Design the platform's storage, processing and modeling choices.

  • Bug BountyPaying outside researchers to report vulnerabilities.
  • Container SecurityMinimal images, non-root users and image scanning.
  • CVSSA score rating how severe a vulnerability is.
  • DASTTesting a running app for vulnerabilities from the outside.
  • Penetration TestingAuthorized simulated attacks to find vulnerabilities.
  • Responsible DisclosureReporting vulnerabilities privately before going public.
  • SBOMA software bill of materials listing every component.
  • Secret RotationRegularly replacing credentials.
  • Security ReviewReviewing a design or change specifically for security risks.
  • Shift-Left SecurityFinding security issues early in development.
  • Software Supply Chain SecurityProtecting against compromised dependencies and build pipelines.
  • STRIDEA way to categorize threats: spoofing, tampering, repudiation, disclosure, denial of service, elevation.
  • Threat ModelingSystematically asking what could go wrong and how to prevent it.

Staff

Shape how the whole organization produces and uses data.

Principal

Set data strategy and architecture across the company.

Nothing here yet.

Frontend Engineer track

Junior

Build UI that works, ship small changes safely, ask good questions.

Mid-level

Own a feature end to end without hand-holding.

  • Attack SurfaceEvery point where an attacker could try to get in.
  • CVEA public identifier for a known vulnerability.
  • Defense in DepthSeveral layers of security, so one failure isn't fatal.
  • Dependency ScanningFinding known vulnerabilities in your dependencies.
  • SASTStatic analysis that looks for security bugs in source code.
  • Secrets ManagementKeeping API keys and passwords in a vault, not in code.
  • TyposquattingMalicious packages named like popular ones.
  • Zero-DayA vulnerability exploited before a fix exists.

Senior

Own an app's architecture, performance, and failure modes.

Core: start here

  • Threat ModelingSystematically asking what could go wrong and how to prevent it.
10 more senior concepts
  • Bug BountyPaying outside researchers to report vulnerabilities.
  • CVSSA score rating how severe a vulnerability is.
  • DASTTesting a running app for vulnerabilities from the outside.
  • Penetration TestingAuthorized simulated attacks to find vulnerabilities.
  • Responsible DisclosureReporting vulnerabilities privately before going public.
  • SBOMA software bill of materials listing every component.
  • Security ReviewReviewing a design or change specifically for security risks.
  • Shift-Left SecurityFinding security issues early in development.
  • Software Supply Chain SecurityProtecting against compromised dependencies and build pipelines.
  • STRIDEA way to categorize threats: spoofing, tampering, repudiation, disclosure, denial of service, elevation.

Staff

Shape how many teams build, across apps.

Principal

Set technical direction for the organization.

Nothing here yet.