A security engineer writes in whatever the product is written in. Python is named most, for the scanners, tools and automation that security work runs on, and it leads in cloud security. Java is close behind, because the login systems and large applications being secured are often Java, and it leads in identity work and at the banks' GCCs. Go is third and marks the cloud and platform end: the security companies that build network and cloud protection, and the operating-system and cloud companies, ask for it most. C/C++ is fourth and marks the deepest work, in application security at the chip makers and in big tech, where the code being secured runs close to the hardware. JavaScript and TypeScript appear where the product has a web front, and Ruby in a handful of job posts at the security and cloud companies. Linux is named in a fair share, with Ubuntu, Debian, FreeBSD and CentOS as the versions, and PowerShell and Windows Server where the estate includes Windows.
The largest single family of skills in the role is the set of standards for proving who someone is and what they may do. OAuth 2.0 is the most-named, the standard that lets an application act on a user's behalf, with OpenID Connect on top of it for signing in and SAML as the older standard that enterprise single sign-on still runs on. JWT is the token that carries the result. SCIM keeps user accounts in step between systems, and LDAP, Active Directory, Entra ID and Kerberos are where a company's staff accounts live. Together these are the identity and access job posts, and they are concentrated at the identity companies, the IT-management tool companies, whose products hold the keys to every customer's machines, and the retailers' and banks' GCCs.
The products in this space are named too. Okta, Ping Identity, Auth0, ForgeRock and Keycloak are the sign-in platforms, SailPoint governs who has access to what, and CyberArk guards the most privileged accounts. SailPoint and Okta are named most in the mid-sized IT services firms, where the work is implementing these products for clients. The concepts behind them, single sign-on, multi-factor login, role-based access and zero trust, are described in the text of job posts rather than named.
Application security is the largest kind of job post, and it is the work of making sure the software itself cannot be attacked. It means reviewing code for weaknesses, modelling how an attacker would approach a feature, designing APIs that cannot be misused, and running tools that scan code and running applications. OWASP is the body whose list of common weaknesses every application security engineer knows, and CWE is the catalogue of weakness types. Burp Suite and OWASP ZAP are the tools for probing a running web application, and SonarQube, Checkmarx, Snyk and Black Duck scan code and its dependencies inside the build pipeline, which is what SAST and DAST mean in a job post. Metasploit and Nmap appear in the few job posts that include penetration testing. Application security is heaviest in big tech, where Microsoft and Google secure their own platforms, at the payment networks and medical-device companies, where regulators require it, and at the banks' GCCs.
Cloud security is the second kind of job post, and it is where security meets the cloud and DevOps role. The work is making sure the cloud accounts, containers, clusters and infrastructure code are set up safely, that secrets are kept out of code, and that security checks run inside the pipeline so nothing insecure reaches production. Terraform is named in a fair share of these job posts, because the engineer secures the infrastructure by reading and writing the code that builds it, with CloudFormation, CDK and Ansible behind it. Prisma Cloud is the most-named security product in the whole role, the platform that watches cloud accounts and containers for misconfiguration, and Qualys, Wiz, Nessus and Trivy appear as the scanners. HashiCorp Vault, AWS KMS, AWS Secrets Manager and Azure Key Vault keep secrets and keys. Cloud security is heaviest at the network and cloud security companies, whose products sit in the path of customers' traffic, and at the vulnerability-management companies that build the scanners.
The smallest kind of job post is network security, and it is the closest to traditional infrastructure. Firewalls is its most-named skill, with IDS for detecting intrusions, VPN and IPSec for securing traffic, and the protocols underneath: TCP/IP, IP, DNS, HTTP/HTTPS, NAT, DHCP, SMTP, SSH and SNMP. Wireshark inspects the traffic. These job posts are concentrated at the network security and networking equipment companies, where the firewall or the gateway is the product, and they ask for C/C++ and Linux more than the other kinds.
Two further skills cut across all four kinds. Cryptography is tagged on a fair share of job posts, and on most at the operating-system and cloud companies. FIPS is the standard that governs which encryption may be used in government and regulated work, and OpenSSL, PKI and SSL/TLS are the tools and concepts behind it. Compliance is tagged on a smaller share, and it names the rules the product must meet: PCI DSS for payments, HIPAA for health data, SOC 2 and FedRAMP for selling to companies and governments, and GDPR for privacy. Compliance is heaviest at the platform companies and the payment and medical-device companies, where a certificate is a condition of sale.
A fair share of job posts ask for security monitoring, which means collecting logs and events and spotting the signs of an attack in them. Splunk is the tool named most, with Datadog, Sumo Logic, the ELK Stack, Grafana, Prometheus and OpenTelemetry behind it, and PagerDuty to raise the alarm. Monitoring is heaviest at the security product companies and the payment networks.
Database security is tagged on a fair share of job posts, most at the security companies and the GCCs, and it means controlling who may read the data and encrypting it where it rests. PostgreSQL, MySQL, Redis, MongoDB, Elasticsearch, Cassandra, Oracle, SQL Server and DynamoDB are named in small shares, and SQL in a fair share. The application overlap is the most common extra ask in the whole role, on most job posts, and it is highest in big tech, at the payment networks and at the security companies, where the security engineer is also building the product. JavaScript, TypeScript, HTML and CSS appear where that product has a web front.
Underneath all of it sits the ordinary craft of building software in a team: Git for source control, pull requests and reviews, and a pipeline that runs the security checks on every change. Job posts count these as given and rarely list them as skills.
A security software engineer who writes Python or Java well, understands OAuth 2.0, OpenID Connect and SAML, knows the OWASP weaknesses and can use Burp Suite and a code scanner, can read and secure Terraform and a Kubernetes cluster, keeps secrets in HashiCorp Vault or the cloud's own store, and is at home on Linux, meets the core of nearly every job post. The variations belong to the employer. The security companies want engineers who build the protection itself, in Go and Python, with Prisma Cloud, Firewalls and the identity standards, and the most monitoring. The operating-system, cloud and chip companies want application and platform security in Go and C/C++, with the most cryptography and FIPS. The payment networks and medical-device companies want application security with PCI DSS and the compliance that regulators demand. The banks' and retailers' GCCs want identity and access above all, in Java, with SailPoint, CyberArk and Active Directory, and application security beside it. Big tech wants application security for its own platforms, in C/C++ and Java. Across all of them, the engineer who can build software and then break it is the one every job post describes.