Contents

Security

Web Application Security

The vulnerabilities attackers actually exploit in web apps, and how to prevent them.

Backend Engineer track

Junior

Write correct code, ship small changes safely, ask good questions.

Core: start here

  • Cross-Site Scripting (XSS)Injecting scripts into pages other users view.
  • IDORReaching other users' data by changing an ID; a missing authorization check.
  • Input ValidationChecking every input at the boundary before using it.
  • Never Trust the ClientAnything from the browser can be forged, so validate on the server.
  • SQL InjectionAttackers running SQL through unescaped input; prevented with parameterized queries.
3 more junior concepts

Mid-level

Own a feature end to end without hand-holding.

Core: start here

  • CORSCross-Origin Resource Sharing: how a server lets browsers call it from other origins.
  • CSRFCross-Site Request Forgery: tricking a logged-in browser into sending a request the user didn't intend.
  • OWASP Top 10The ten most critical web application security risks.
  • Rate LimitingLimiting how many requests a client can make.
18 more mid-level concepts

Senior

Own a system, its failure modes, and its trade-offs.

  • Business Logic VulnerabilitiesAbusing legitimate features in unintended ways.
  • Insecure DeserializationDeserializing untrusted data in a way that executes code.
  • ReDoSRegular expressions that take exponential time on crafted input.
  • SSRFTricking a server into making requests to internal systems.
  • XXEXML parsers fetching external entities and leaking files.

Staff

Shape how many teams build, across systems.

Nothing here yet.

Principal

Set technical direction for the organization.

Nothing here yet.

Data Analyst track

Junior

Write correct SQL, build trusted dashboards, ask good questions.

Nothing here yet.

Mid-level

Own an analysis end to end, from vague question to recommendation.

  • Parameterized QueryPassing values separately from SQL so they can't change its meaning.
  • Rate LimitingLimiting how many requests a client can make.
  • SQL InjectionAttackers running SQL through unescaped input; prevented with parameterized queries.

Senior

Own experimentation and metrics design; call out bad numbers.

Nothing here yet.

Staff

Shape how the organization measures and decides.

Nothing here yet.

Principal

Set measurement strategy across the company.

Nothing here yet.

Data Engineer track

Junior

Build and fix pipelines from clear specs; write correct SQL.

Nothing here yet.

Mid-level

Own pipelines and models end to end, including their quality.

Senior

Design the platform's storage, processing and modeling choices.

Nothing here yet.

Staff

Shape how the whole organization produces and uses data.

Nothing here yet.

Principal

Set data strategy and architecture across the company.

Nothing here yet.

Frontend Engineer track

Junior

Build UI that works, ship small changes safely, ask good questions.

Core: start here

5 more junior concepts
  • IDORReaching other users' data by changing an ID; a missing authorization check.
  • Input SanitizationCleaning untrusted input, and why validation and escaping matter more.
  • Input ValidationChecking every input at the boundary before using it.
  • Output Encoding / EscapingEscaping data for the context it's inserted into.
  • SQL InjectionAttackers running SQL through unescaped input; prevented with parameterized queries.

Mid-level

Own a feature end to end without hand-holding.

Core: start here

  • Content Security PolicyA header restricting which scripts and resources a page may load.
  • CSRFCross-Site Request Forgery: tricking a logged-in browser into sending a request the user didn't intend.
14 more mid-level concepts

Senior

Own an app's architecture, performance, and failure modes.

Staff

Shape how many teams build, across apps.

Nothing here yet.

Principal

Set technical direction for the organization.

Nothing here yet.