Security CareerJun 13, 2022
IBMtVik58

Application Security Engineer vs. DevSecOps Engineer

I've been interviewing for both of these roles recently and I swear, even after a good amount of interviews, they appear to be so similar. In a traditional sense, what truly is the difference? Which one is a better choice for pay/future demand? Blind Tax: 12 exp/250k

SAP tronics Jun 13, 2022

App security is focused on vulnerabilities in source code whereas devsecops focuses on securing the infrastructure where the application will be hosted in.

Goldman Sachs jmfF73 Jun 13, 2022

DevSecOps is also concerned with source code (SAST), and is only marginally concerned with infrastructure (as it relates or applies to continuous deployment). AppSec is an umbrella term which contains DevSecOps.

Goldman Sachs jmfF73 Jun 13, 2022

AppSec is better for future pay—easier to move from general AppSec (pentesting, code/design review, PM, cloud infra) to DevSecOps than the other way around.

IBM tVik58 OP Jun 13, 2022

valid points