# Building an Application Security Team

DevFeed: [Building an Application Security Team](<https://devfeed.tech/articles/building-an-application-security-team-36672.md>)

Original publisher: [Read original article](<https://shostack.org/blog/application-security-team/>)

Author: Jonathan Marcil

Published: 2017-10-15T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [critical](<https://devfeed.tech/tags/critical.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [red-team](<https://devfeed.tech/tags/red-team.md>), [security](<https://devfeed.tech/tags/security.md>), [team](<https://devfeed.tech/tags/team.md>), [teams](<https://devfeed.tech/tags/teams.md>)

## AI overview

The article discusses how to build an application security team and why the role requires both broad and specialized skills. It contrasts product-based security tools with penetration testing services, comparing their coverage, accuracy, false positives, creativity, and technical depth. It also describes the evolution of penetration testing toward Red Team operations.

## Source excerpt

[no description provided]