π Security Engineering (for backend engineers)
AppSec
- OWASP Top 10 (web) and OWASP API Security Top 10 β: injection, broken auth, BOLA/IDOR, SSRF, mass assignment
- OWASP Top 10 for LLM Applications: prompt injection, insecure output handling, excessive agency β
- Input validation, output encoding, parameterized queries
- AuthN/AuthZ β Spring Security: OAuth2/OIDC, JWT pitfalls (
alg=none, no expiry, secrets in the payload) - Authorization models: RBAC, ABAC, ReBAC (Google Zanzibar β OpenFGA/SpiceDB); policy engines (OPA)
- Session security, CSRF, CORS, security headers (CSP, HSTS)
- Rate limiting & abuse prevention (bots in flash sales!)
Crypto basics (conceptual)
- Hashing vs encryption vs encoding; salted password hashing (argon2/bcrypt)
- Symmetric (AES-GCM) vs asymmetric (RSA/ECDSA); signatures; HMAC
- TLS/mTLS, certificates, PKI; envelope encryption with KMS
- Post-quantum crypto (awareness: hybrid key exchange is being rolled out in TLS)
Infra & supply chain
- Secrets management (Vault, AWS Secrets Manager, External Secrets); never in git
- Least-privilege IAM; K8s RBAC; NetworkPolicies; Pod Security
- Dependency scanning (Dependabot, OWASP dependency-check,
govulncheck), SAST (Semgrep, CodeQL), image scanning (Trivy) - SBOM, signing (Sigstore/cosign), SLSA
- Zero-trust networking; mTLS via a mesh
Data & privacy
- PII handling, encryption at rest/in transit, data retention; GDPR and Indiaβs DPDP Act (awareness)
- Audit logging
- Payments: PCI-DSS awareness (use tokenized providers)
π§ͺ Labs (π’ warm-up β π‘ core β π΄ hard β β« boss)
- π’ PortSwigger labs: access control, JWT, SSRF, SQLi
- π‘ A cross-tenant attack suite against Orbit (BOLA/IDOR, key reuse, JWT tampering)
- π΄ SSRF protection for the
http_requesttool (allowlists, block private IP ranges, DNS rebinding) - π΄ A sandbox escape test suite for the
codestep - β« Red-Team Day (W22): prompt injection, exfiltration, excessive agency
π§ Cognitive tasks
- STRIDE threat model per Orbit version
- Transfer: map classic AppSec controls to agent/tool security
π°οΈ Orbit integration
- Security gates in CI; tenant isolation; the tool permission model
Go deeper
π§© Anti-Patterns & Code Smells Β· π€ Evals, Guardrails & LLMOps
Resources
- OWASP cheat sheets β Β· API Security in Action (Madden) Β· PortSwigger Academy Β· Security Engineering (Anderson, reference)