Application Security: Web Apps, APIs and Microservices
Application security training in Toronto written for the people who fix the code, not the ones who find the bugs. You work through the OWASP Top 10 from the defensive side: what the flaw is, why the usual patch fails, and what actually closes it.
The course covers web applications, REST and GraphQL APIs, and service to service communication in microservice architectures. You finish able to threat model a design and defend the decisions you made in it.
- Duration
- 10 weeks
- Format
- Live online, instructor-led
- Prerequisites
- None required
- Class size
- Capped at 12 learners

What you will be able to do
- Defend against each OWASP Top 10 category at the code and design level
- Design authentication and session handling that resists takeover attempts
- Secure REST and GraphQL APIs, including authorisation at object level
- Validate and encode input correctly for the context it lands in
- Configure security headers and content security policy without breaking the app
- Secure service to service calls with mutual TLS and scoped tokens
- Threat model a feature before it is built and record the decisions
- Review a pull request for security impact and explain findings to the author
Course outline
6 modules
- Reading the OWASP Top 10 as a defender rather than a checklist
- Trust boundaries in a modern application stack
- Where frameworks help and where they quietly do not
- CVE and CVSS in context: judging whether a finding matters to you
- Setting up the vulnerable reference application
What you need before you start
- Ability to read code in at least one of Python, JavaScript, Java or C#
- Understanding of HTTP, TLS and how a web request reaches a database
- Experience working with or alongside a software development team
- A local development environment with Docker available
Who this course is for
- Software developers who have been made responsible for security in their team
- Application security engineers formalising knowledge picked up on the job
- Cloud and platform engineers running services they did not write
- Security analysts who need to speak credibly to developers
- Technical leads who approve designs and want to catch problems earlier
Where this leads
Prepares you for
CSSLP
Awarded by ISC2
The material maps to several domains of the ISC2 Certified Secure Software Lifecycle Professional. ISC2 issues that certification following its own exam and experience verification. Completing this course is not certification and does not shorten the ISC2 process.
Questions about this course
More in cloud security
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



