This is where the second pass actually plays out, the last gate before an interview hits your
inbox. The recruiter slows down right here, and even then your current role still drives
around 95% of the decision.
Makes sense: nothing tells a hiring team what you can run in production right now the way your
current job does. To clear that "yes", this section has to walk the full
AppSec Engineer role profile, one bullet per slot you listed in Domain
Expertise above. Every bullet has to come off something you actually held in production,
not a Jira card that wandered past your queue.
1
Threat Modeling & Secure Design Review
You catch design flaws in a feature before a line is written. A flaw baked into the design is the
priciest kind to fix later, so hiring managers want the reviews you ran at design time. Talk about how
you used abuse-case modeling and design reviews, mapped to the NIST SSDF, to catch flaws before build
and cut rework.
Techniques
STRIDE, PASTA, LINDDUN
Architecture review boards
Abuse-case stories
Defense-in-depth design
Tools
Threagile, IriusRisk
OWASP ASVS, NIST SSDF
Confluence, Lucidchart
Metrics
Services reviewed
High-risk findings closed
Coverage of tier-0 services
2
SAST, DAST & SCA in CI
You wire code scanning into CI so bugs die at the pull request. Scanners drown teams in false positives,
so hiring managers want gates that block the real bugs, not everything. Show them how you used SAST and
DAST with custom rules, in Semgrep and GitHub Advanced Security, to block high-sev findings at the PR
and cut false positives.
Techniques
PR-blocking gates
Severity-based policy
Custom rule authoring
Auto-remediation PRs
Tools
Semgrep, SonarQube, Checkmarx
Snyk Code, GitHub Advanced Security
Burp Suite, OWASP ZAP, Tinfoil
Metrics
Coverage across services
False-positive rate down
High-sev findings blocked at PR
3
Secure Code Review & AppSec Champions
You turn everyday engineers into a security champions network. You can't review every PR yourself,
so building champions tells a hiring manager you scale security across the org. Point out how you used
risk-tiered code reviews and a champions program, against OWASP ASVS, to grow the program and catch
findings pre-merge.
Techniques
Risk-tiered code reviews
Champions enablement
Secure-coding standard
Office hours
Tools
GitHub PR review, Gerrit
Confluence, Notion, Slack
OWASP ASVS, Top 10
Metrics
Engineers in program
PRs reviewed/quarter
Findings caught pre-merge
4
Bug Bounty & Vulnerability Triage
You run the bug bounty and turn reports into fixes. Triage SLA and valid submissions are numbers, so
hiring managers want a program you ran, not "monitored HackerOne". Mention how you used bounty
scoping and fast triage, on HackerOne and Bugcrowd, to hold the triage SLA and ship critical fixes.
Techniques
Scope & bounty design
Triage and validation
Researcher relations
Disclosure programs
Tools
HackerOne, Bugcrowd, Intigriti
YesWeHack, GitHub Security Advisories
Jira, ServiceNow case mgmt
Metrics
Triage SLA
Valid submissions/quarter
Critical fixes shipped
5
Dependency & Supply-Chain Security
You lock down what your builds pull in. Two things ride on it for a hiring manager: known-vulnerable
dependencies caught, and artifacts you can prove are yours. Walk them through how you used SBOM
generation and artifact signing, with Syft and Cosign, to close high-sev CVEs and sign artifacts at
admission.
Techniques
SBOM generation
Artifact signing & provenance
License + vuln policies
SLSA / in-toto
Tools
Dependabot, Renovate, Mend
Syft, SPDX, CycloneDX
Cosign, Sigstore, in-toto
Metrics
Repos under SBOM
High-sev CVEs closed
Signed artifacts at admission
6
Secrets Management
You stop secrets from ever reaching a commit. A leaked key is a direct path in, so hiring managers want
pre-commit scanning and retirement you enforced. Lay out how you used pre-commit scanning and
secret-class retirement, with Gitleaks and GitGuardian, to catch leaks before commit and retire whole
secret classes.
Techniques
Pre-commit secret scanning
Dynamic credentials
Rotation policy
Secret-class retirement
Tools
HashiCorp Vault
Gitleaks, TruffleHog, GitGuardian
AWS Secrets Manager, Doppler
Metrics
Repos under secret-scanning
Leaks caught pre-commit
Rotation compliance
7
API & Authentication Security
You harden the APIs and the auth behind them. Hiring managers look here to see whether object-level auth
holds, or whether one user can read another's data. Spell out how you used OAuth patterns and
object-auth checks, with 42Crunch and Burp Pro, to close BOLA cases and block auth bypasses.
Techniques
OAuth 2.0 / OIDC patterns
JWT validation library
BOLA / object-auth checks
Rate-limit standard
Tools
OWASP API Top 10
Postman, Insomnia, Burp Pro
42Crunch, Salt, Noname
Metrics
API endpoints inventoried
BOLA cases closed
Auth bypasses blocked
8
Tooling & Workflow
You hand developers secure defaults they don't have to think about. Security that relies on
developers remembering fails, so hiring managers read secure defaults as security that sticks. Tell them
how you shipped secure-by-default templates and self-serve docs, in Git with Backstage, to make the
secure path the default one.
Techniques
Secure-by-default templates
Internal CLI / runbooks
Inner sourcing
Self-serve docs
Tools
Git, GitHub
Bash, Python, Go
Backstage TechDocs
Metrics
Templates maintained
PR cycle time
Secure-onboarding ramp cut