Role track: Application Developer

Role overview

Build and ship secure containerized applications. Focus on fundamentals, trusted images, secrets, least privilege, and integrating baseline security into delivery.

Core responsibilities (framework):

  • Lightweight threat modeling for applications and workloads

  • Service accounts and RBAC for secure access

  • Safe secret usage and encryption awareness

  • Vulnerability scanning and testing in the build pipeline

  • Current dependencies and base images

  • Non-root / least-privilege workload design

  • Minimal, reproducible images with basic signing in the build workflow

Out of scope for this track: platform governance, runtime detection tuning, and security policy exceptions (Platform Operator, DevSecOps, or Architect).

No Advanced labs are assigned to this role—grow into the DevSecOps or Security Architect track.