Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Advanced

Application Security: Web Apps, APIs and Microservices

Application security training in Toronto written for the people who fix the code, not the ones who find the bugs. You work through the OWASP Top 10 from the defensive side: what the flaw is, why the usual patch fails, and what actually closes it.

The course covers web applications, REST and GraphQL APIs, and service to service communication in microservice architectures. You finish able to threat model a design and defend the decisions you made in it.

Duration
10 weeks
Format
Live online, instructor-led
Prerequisites
None required
Class size
Capped at 12 learners
Application Security: Web Apps, APIs and Microservices

What you will be able to do

  • Defend against each OWASP Top 10 category at the code and design level
  • Design authentication and session handling that resists takeover attempts
  • Secure REST and GraphQL APIs, including authorisation at object level
  • Validate and encode input correctly for the context it lands in
  • Configure security headers and content security policy without breaking the app
  • Secure service to service calls with mutual TLS and scoped tokens
  • Threat model a feature before it is built and record the decisions
  • Review a pull request for security impact and explain findings to the author

Course outline

6 modules

  • Reading the OWASP Top 10 as a defender rather than a checklist
  • Trust boundaries in a modern application stack
  • Where frameworks help and where they quietly do not
  • CVE and CVSS in context: judging whether a finding matters to you
  • Setting up the vulnerable reference application

What you need before you start

  • Ability to read code in at least one of Python, JavaScript, Java or C#
  • Understanding of HTTP, TLS and how a web request reaches a database
  • Experience working with or alongside a software development team
  • A local development environment with Docker available

Who this course is for

  • Software developers who have been made responsible for security in their team
  • Application security engineers formalising knowledge picked up on the job
  • Cloud and platform engineers running services they did not write
  • Security analysts who need to speak credibly to developers
  • Technical leads who approve designs and want to catch problems earlier

Where this leads

Prepares you for

CSSLP

Awarded by ISC2

The material maps to several domains of the ISC2 Certified Secure Software Lifecycle Professional. ISC2 issues that certification following its own exam and experience verification. Completing this course is not certification and does not shorten the ISC2 process.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.