Answer summary
To learn about Application Security Engineering, follow industry leaders, researchers, and organizations that focus on secure coding, vulnerability research, and shifting security left into the development lifecycle. Influential practitioners include Tanya Janca, James Kettle, and Corey Ball, among others. Essential organizations and resources include OWASP and PortSwigger Research.
Sign in to check whether you are mentioned or cited in this prompt.
Where each engine placed them
What the models searched first
The sub-queries each engine actually searched before answering.
Unlock the full picture
The sub-queries each engine actually searched before answering.
Your tracked entities
Save a voice, brand or tool and see where it stands on this question.
Full responses
4 of 4 engines that answered. Full stored text as captured, with dashes shown as hyphens. Nothing is summarised.
ChatGPT3,943 characters · September 13, 2026
If you want to learn **Application Security Engineering (AppSec)** seriously, I’d follow a mix of practitioners, researchers, educators, and communities. AppSec is broad: secure coding, threat modeling, architecture reviews, cloud security, CI/CD security, vulnerability research, and developer enablement. [OWASP Foundation - The Open Source Foundation for Application Security](https://owasp.org/?utm_source=chatgpt.com) ## People to follow ### Foundational AppSec / secure design - Jim Manico - Great for secure coding practices, OWASP guidance, and developer-focused security. - Tanya Janca - Excellent for learning how AppSec programs work inside organizations, security champions, and secure development culture. - Chris Romeo - Strong focus on threat modeling, security champions, and practical AppSec leadership. [Authors](https://appsec.beehiiv.com/authors/?utm_source=chatgpt.com) ### Threat modeling and architecture - Adam Shostack - One of the most recognized voices in threat modeling; his work around practical threat modeling is foundational. - Evan Gilman - Useful for modern identity, infrastructure, and security engineering perspectives. ### Web security / offensive AppSec - PortSwigger Research Team - Follow their research if you want to understand real vulnerabilities and exploitation techniques. - Dafydd Stuttard - Author of The Web Application Hacker's Handbook and a major influence in web application testing. - Nicolas Waisman - Good for vulnerability research and modern AppSec topics. ### Cloud-native AppSec / DevSecOps - Liz Rice - Excellent for containers, Kubernetes, and cloud security concepts. - Kelsey Hightower - Not strictly AppSec, but invaluable for understanding the systems AppSec engineers secure. ### Vulnerability research and secure coding - Katie Moussouris - Great for vulnerability management and security ecosystem topics. - Alex Stamos - Broader security leadership and industry context. ## Communities and resources worth following - OWASP - Probably the best starting point. Follow projects like: - OWASP Top 10 - OWASP Application Security Verification Standard (ASVS) - OWASP Cheat Sheet Series - OWASP Juice Shop for hands-on practice [OWASP Foundation - The Open Source Foundation for Application Security](https://owasp.org/?utm_source=chatgpt.com) - PortSwigger - Their Web Security Academy is one of the best free ways to practice web exploitation and defenses. - SANS Institute - Useful for structured security training. - Cloud Security Alliance - Helpful if you want to combine AppSec with cloud security. ## Newsletters / podcasts - Application Security Weekly - Industry discussions and interviews. - The Secure Developer - Developer-oriented security discussions. - TL;DR Sec - Short security news updates. ## A good learning path 1. **Learn how software is built** - HTTP, APIs, databases, authentication, authorization - One backend language deeply (Java, Python, Go, JavaScript/TypeScript) 2. **Master common vulnerabilities** - OWASP Top 10 - SQL injection - XSS - SSRF - CSRF - Broken access control - Deserialization - Authentication flaws 3. **Learn secure engineering practices** - Threat modeling - Secure code review - Security requirements - CI/CD security - Dependency management 4. **Practice** - OWASP Juice Shop - PortSwigger Web Security Academy - Capture-the-flag challenges A strong AppSec engineer is usually someone who can sit with developers, understand the code and architecture, identify realistic risks, and help ship safer software - not just someone who finds vulnerabilities. [AppSec Engineer Career Guide | CyberWithJohann](https://cyberwithjohann.com/blog/appsec-engineer-guide/?utm_source=chatgpt.com) If you tell me your background (developer, pentester, sysadmin, student, etc.), I can suggest a more targeted AppSec follow list and learning roadmap.
Copilot4,352 characters · September 13, 2026
**To learn about Application Security Engineering, you should follow security engineers, researchers, and thought leaders who specialize in software security, vulnerability management, and secure development practices. Some of the most influential voices today include Parisa Tabriz (Google), Troy Hunt (Have I Been Pwned), and Daniel Miessler (security researcher and educator).** ## 🔑 Key Experts in Application Security Engineering Name| Role / Focus| Why Follow Them ---|---|--- **Parisa Tabriz**| Director of Engineering at Google, known as “Security Princess”| Leads Chrome security team, advocates for secure software design, shares insights on large-scale application security. [Top Cybersecurity Leaders of 2026 | The Industry Leaders](https://www.theindustryleaders.org/leaders/top-25-cybersecurity-leaders-2026) **Troy Hunt**| Founder of _Have I Been Pwned_| Practical guidance on web app security, data breaches, password management, and developer-friendly security practices. [Top Cybersecurity Leaders of 2026 | The Industry Leaders](https://www.theindustryleaders.org/leaders/top-25-cybersecurity-leaders-2026) **Daniel Miessler**| Security researcher, writer of _Unsupervised Learning_| Focuses on application security, threat modeling, and human risk factors; excellent educational content. [Top Cybersecurity Leaders of 2026 | The Industry Leaders](https://www.theindustryleaders.org/leaders/top-25-cybersecurity-leaders-2026) **Heather Adkins**| VP of Security Engineering at Google| Co-author of _Building Secure and Reliable Systems_ , deep expertise in secure software engineering. [50 CISOs and Cybersecurity Leaders Making an Impact in 2026](https://secureframe.com/blog/cybersecurity-leaders-2026) **Feross Aboukhadijeh**| Founder of Socket| Specializes in open-source supply chain security, preventing malicious packages in applications. [50 CISOs and Cybersecurity Leaders Making an Impact in 2026](https://secureframe.com/blog/cybersecurity-leaders-2026) **Katie Moussouris**| CEO of Luta Security| Pioneer in vulnerability disclosure and bug bounty programs, shaping modern app security practices. [Top Cybersecurity Leaders of 2026 | The Industry Leaders](https://www.theindustryleaders.org/leaders/top-25-cybersecurity-leaders-2026) **Matthew Rosenquist**| CISO & Advisor| Translates complex application risks into business-focused strategies, strong on secure design thinking. [Top 10: Cybersecurity Influencers | Cyber Magazine](https://cybermagazine.com/top10/top-10-cybersecurity-influencers) **Chuck Brooks**| Cybersecurity advisor & Georgetown professor| Offers broad insights into policy, risk management, and secure technology adoption. [16 Top Cybersecurity Influencers to Follow in 2026](https://www.acecloudhosting.com/blog/top-cybersecurity-influencers/) ## 📌 How to Use These Voices * **Twitter/X & LinkedIn**: Most of these experts share real-time insights, vulnerability disclosures, and best practices. * **Blogs & Newsletters**: Troy Hunt’s blog, Daniel Miessler’s _Unsupervised Learning_ , and Bruce Schneier’s _Schneier on Security_ are excellent for staying current. * **Talks & Courses**: Parisa Tabriz and Heather Adkins often speak at conferences (Black Hat, RSA, Google events). Katie Moussouris frequently discusses vulnerability disclosure frameworks. ## ⚠️ Risks & Considerations * **Hype vs. Reality** : Cybersecurity influencers sometimes amplify trends (like AI-driven attacks) that may not apply directly to application security engineering. Always cross-check with technical documentation. * **Vendor Bias** : Some leaders are tied to companies (Google, Microsoft, Socket). Their advice is valuable but may lean toward their ecosystem. * **Rapid Change** : Application security evolves quickly (e.g., supply chain attacks, AI-driven vulnerabilities). Following multiple voices ensures balanced perspectives. 👉 If you’re starting out, I’d recommend **Troy Hunt for practical developer-focused security** , **Parisa Tabriz for large-scale engineering insights** , and **Daniel Miessler for conceptual frameworks and continuous learning**. Would you like me to build a **structured learning path** (books, blogs, courses, and communities) around these experts so you can go from beginner to advanced in application security engineering?
Gemini4,101 characters · September 13, 2026
Learning Application Security (AppSec) engineering requires looking past traditional perimeter defense and diving into code, architecture, build pipelines, and attacker psychology. [AppSec Engineers: Responsibilities, Salary, Career Progression - Wiz](https://www.wiz.io/academy/application-security/appsec-engineers#:~:text=Education%20and%20credentials.%20Most%20AppSec%20engineers%20come,layering%20security%20knowledge%20onto%20their%20coding%20skills.) The industry's most influential practitioners, researchers, educators, and platforms share deep insights into AppSec, DevSecOps, and secure software design: ### AppSec Researchers & Technical Thought Leaders * **James Kettle (PortSwigger):** Director of Research at PortSwigger and a legendary figure in web application security. Follow his work and conference talks (like Black Hat) for bleeding-edge research on web vulnerabilities, HTTP request smuggling, and the intersection of AI and security testing. * **Tanya Janca (We Hack Purple):** A powerhouse in AppSec education, Tanya focuses heavily on teaching developers and organizations how to build secure software from the ground up. She runs the _We Hack Purple_ community and podcast. [Top 10 AppSec Experts You Should Follow - GitGuardian Blog](https://blog.gitguardian.com/top-10-appsec-experts-you-should-follow/#:~:text=Anshuman%20was%20recently%20a%20guest%20on%20Tanya,latest%20posts%20here.%20*%204.%20Renaud%20Deraison.) * **Clint Gibler:** Known for his incredible curation skills, Clint publishes _TL;DR Sec_ , a must-read weekly newsletter that filters through the noise of the security industry to highlight practical AppSec, cloud security, and software supply chain tools and research. * **Corey Ball:** An absolute authority on **API Security** and author of _Hacking APIs_. If you want to understand how modern application endpoints break and how to secure them, his content is essential. [PortSwigger - Web security tools, training and research](https://portswigger.net/#:~:text=A%20community%20like%20no%20other%20*%20%F0%9F%87%BA%F0%9F%87%B8,%400xTib3rius%20%C2%B7%20USA.%20Pentester%20%2F%20content%20creator.) ### Practical Engineering & Newsletters (Substack) * **Chris Hughes (_Resilient Cyber_):** Focuses heavily on software supply chain security, DevSecOps, and the intersection of policy and application security engineering. [The top AppSec Substacks to follow | RL Blog - ReversingLabs](https://www.reversinglabs.com/blog/appsec-substacks-you-should-follow#:~:text=The%20Resilient%20Cyber%20Substack%2C%20by%20Chris%20Hughes%2C,security%2C%20DevSecOps%2C%20and%20software%20supply%20chain%20security.) * **Derek Fisher (_Securely Built_):** Explores structured product security, threat modeling, and embedding security seamlessly into the software development lifecycle (SDLC). * **Daniel Miessler:** A security leader who regularly writes about the philosophy of security, AI integration, and practical vulnerability management for engineers. [15 Cybersecurity Experts To Follow on LinkedIn | Cato Networks](https://www.catonetworks.com/blog/15-cybersecurity-experts-to-follow-on-linkedin/#:~:text=Head%20of%20Vulnerability%20Management%20and%20AppSec%20at,a%20regular%20basis%20via%20his%20website%2C%20danielmiessler.com.) ### Essential Platforms & Organizations * **PortSwigger Web Security Academy:** While not a single person, this is widely considered the gold standard free resource for anyone learning AppSec. Created by the makers of Burp Suite, it offers labs ranging from beginner to advanced on virtually every web vulnerability class. [PortSwigger - Web security tools, training and research](https://portswigger.net/) * **OWASP (Open Worldwide Application Security Project):** Following OWASP leaders and checking out their flagship projects (like the OWASP Top Ten and the Application Security Verification Standard - ASVS) is mandatory for any aspiring AppSec engineer. What specific area of AppSec are you hoping to focus on first - such as secure code review, API security, or DevSecOps pipeline automation?
Google AI Mode2,178 characters · September 13, 2026
To learn application security (AppSec) engineering, you should follow **industry leaders, researchers, and organizations that focus specifically on secure coding, vulnerability research, and shifting security left into the development lifecycle****.** [Application Security Engineering: Responsibilities, Required](https://www.reddit.com/r/hackthebox/comments/1tvguob/application_security_engineering_responsibilities/) Top AppSec Experts and Practitioners * * ** _Troy Hunt_ :** Creator of _Have I Been Pwned_ and an expert in web application security and developer education. Excellent for understanding real-world data breaches and API/web vulnerabilities. * ** _Tanya Janca_ (SheHacksPurple):** Founder of Our Cyber Security Club, focused heavily on application security, secure coding, and building AppSec programs from scratch. * **Zack Fasano / AppSec-focused researchers on X/LinkedIn:** Following active contributors in the [OWASP](https://owasp.org/) community gives you immediate breakdowns of modern injection flaws, supply chain risks, and container security. * Essential Organizations and Resources * * **OWASP (Open Web Application Security Project) :** The gold standard baseline for application security. Follow their main accounts and local chapter leads for deep dives into the OWASP Top 10, cheat sheets, and secure coding practices. [Application Security Engineer: Roles, Skills & Career Path](https://www.hackerone.com/knowledge-center/application-security-engineer) * **[PortSwigger Research](https://portswigger.net/research) :** Home of Burp Suite and the best free web security academy available. Following their research team provides masterclass-level breakdowns of bleeding-edge web vulnerabilities. [What Is an Application Security Engineer? | Huntress](https://www.huntress.com/cybersecurity-101/topic/application-security-engineer) * If you want to tailor this, let me know: * * Your **current programming or IT background** * Whether you want to focus on **offensive AppSec (pentesting)** or **defensive AppSec (engineering & automation)** * I can recommend specific learning paths or starter projects.