Lead Application Security Manager.
Lead Application Security Manager training allows you to develop the knowledge and skills necessary to establish, implement, maintain and continuously improve your application security program. During this training, you will gain an understanding of Secure Software Development Life Cycle (Secure SDLC) best practices. You will learn how to integrate security activities at every stage of application development, from design and coding to testing and deployment, to minimize vulnerabilities and protect against attacks.
Issues
-
Application security
-
Secure SDLC
-
Threat modeling
-
Safe design
-
Secure coding
-
Security testing
-
Code reviews
-
Vectors of attacks on applications
-
Defense methods
-
Responding to incidents
-
Application security program
-
Vulnerability management
Benefits
- Master the concepts and principles of application security
- Gain the skills to implement and manage a Secure SDLC program
- They will learn how to perform threat modeling and code reviews for security
- Of popular application attack vectors and defense methods will be deepened
Who is this training for?
Prerequisites
- Basic knowledge of software development
- Knowledge of the software development life cycle
- Programming experience (preferred)
- IT security basics
Training program
Day 1: Introduction to Application Security and Secure SDLC
- Introduction to application security — threat landscape, vulnerability statistics, cost of remediation at different SDLC stages
- Secure SDLC — security integration at every lifecycle stage (requirements, design, coding, testing, deployment, maintenance)
- Application security frameworks — OWASP SAMM (Software Assurance Maturity Model), BSIMM, Microsoft SDL, NIST SSDF
- Application security program — establishment, structure, roles (Security Champions), metrics, budget, board reporting
- Security requirements — requirements identification, abuse cases, security user stories, data classification
- Exercises: application security maturity assessment (OWASP SAMM), security user stories development
Day 2: Threat Modeling and Secure Design
- Threat modeling — methodologies (STRIDE, DREAD, PASTA, Attack Trees), threat identification, risk assessment
- Secure design patterns — defense in depth, least privilege, fail secure, separation of duties, secure by default
- Secure architecture — authentication and authorization (OAuth 2.0, OIDC, RBAC), session management, cryptography
- OWASP Top 10 — analysis of the most common vulnerabilities (injection, broken authentication, XSS, SSRF, insecure deserialization)
- OWASP API Security Top 10 — API-specific threats (BOLA, broken authentication, excessive data exposure)
- Exercises: conducting threat modeling (STRIDE) for a web application, identifying mitigations
Day 3: Secure Coding and Security Testing
- Secure coding — practices (input validation, output encoding, parameterized queries, error handling, logging)
- Security code reviews — manual code review, checklists, common vulnerability patterns in code
- Static Application Security Testing (SAST) — tools, IDE and CI/CD integration, results analysis, false positives
- Dynamic Application Security Testing (DAST) — scanning, configuration, crawling, fuzzing, report interpretation
- Interactive Application Security Testing (IAST) and Software Composition Analysis (SCA) — dependency analysis, CVE, licenses
- Exercises: security code review, SAST results analysis, identifying vulnerable dependencies (SCA)
Day 4: Vulnerability Management and DevSecOps
- Vulnerability management — process (identification, CVSS classification, prioritization, remediation, verification)
- Application penetration testing — methodology, scope, rules of engagement, reporting, retesting
- DevSecOps — security integration in CI/CD pipeline, Security Gates, security test automation
- Application security incident response — identification, containment, eradication, recovery, lessons learned
- AppSec program metrics — MTTR, density of vulnerabilities, coverage, training metrics, trend analysis
- Exercises: developing a DevSecOps pipeline with security gates, vulnerability classification (CVSS), remediation plan
Day 5: PECB Exam Preparation
- Application security program summary — review of key concepts and practices
- Building a security culture — Security Champions program, developer training, gamification, internal CTFs
- Case studies — AppSec program analysis in organizations (fintech, e-commerce, SaaS)
- PECB certification preparation — exam format, question types, passing strategies
- Practice exam — PECB Certified Lead Application Security Manager exam simulation
- PECB certification exam (optional) — written exam leading to PECB Certified Lead Application Security Manager certificate
Delivery Methods
Online
- Convenience of participating from anywhere
- Interactive live sessions with trainer
- Materials available for 30 days
- No travel costs
On-site
- Direct contact with trainer and group
- Intensive hands-on workshops
- Networking with other participants
- Full focus on learning
Frequently asked questions
Who is the Lead Application Security Manager. training for?
This training is designed for professionals looking to develop skills in lead application security manager.. Required level: intermediate.
How long is the Lead Application Security Manager. training?
The training lasts 5. Available in online or on-site format.
Will I receive a certificate?
Yes — every participant receives a completion certificate confirming acquired competencies. EITT holds ISO 9001 accreditation.
Can this training be conducted for a closed group?
Yes — we offer dedicated closed trainings for companies. We customize the program to your team's needs. Contact us for an individual quote.
Request a quote
Funding Options
Check funding options for your company
Development Services Database
Up to 80% funding for SMEs from EU funds
Check availabilityNational Training Fund
Up to 100% funding for employers
Learn moreTrusted by
We train teams at Poland's largest companies
Interested in this training?
Contact us - we'll prepare an offer tailored to your organization's needs.