Application security careers have bright future

Application security careers have bright future

I have recently joined a company and become a trainee in application security, which includes vulnerability assessment, pen testing, reporting and secure coding. Can you please tell me about the future of this career?

    Requires Free Membership to View

    When you register, you'll receive targeted emails designed to keep you informed of the most relevant information on Agile development, application security, testing & QA, software requirements, and more.

    Hannah Smalltree, Editorial Director

    By submitting your registration information to SearchSoftwareQuality.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSoftwareQuality.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

I think the future of this career field is very solid. Up until this point, security has not been a priority of development teams. With compliance requirements such as PCI DSS and new regulatory requirements from groups such as the OCC, this has changed. Developers who understand secure design and development will become the norm rather than the exception, and getting an early start is always good.

Software security resources:
PCI DSS compliance: Web application firewall or code review?

The most effective time to do security testing

How to address application security from a holistic perspective

In addition, skills such as penetration testing, application assessment and code review will increasingly be in demand. Again -- regulatory and compliance pressures mandate that application level testing be performed, so there will be a need for more capable individuals. Over time, though, these areas will be commoditized and the really valuable skills will be more process-focused. The ability to lead development teams in secure development efforts as well as the ability to help integrate security into the software development lifecycle (SDLC) will become more important than the testing of individual applications.

This was first published in June 2008