Professional development

Infosec Skills author teaches people-process-technology approach for “secure software development”

January 15, 2021 by Shreya Verma

Infosec Skills instructor John Prathab learned the importance of education and development early in his IT career.

“In IT, we call it a people-process-technology approach, where technology is as good as the processes implemented around it, and processes are as good as the people who execute them,” John said. “Realizing this, I invested in my education and career development heavily. It helped close my skills gaps and increased my productivity at work.”

He carried that same approach throughout 12 years of his experience while doing lab experiments, earning certifications and building his new Infosec Skills learning path. John’s Secure Software Development Life Cycle (SDLC) Learning Path is a foundational course designed to give you hands-on experience in developing or establishing proactive and reactive security controls across your organization.

Secure Software Development Life Cycle

The journey from a software developer to security architect

“I started as a software developer and my role entailed coding security, which got me interested in the cybersecurity field,” said John. “There was no stopping then. I started learning more through certifications, training courses and self-study. I got my hands dirty with CEH (Certified Ethical Hacker) and CHFI (Computer Hacking Forensic Investigator) certifications and was able to apply that hands-on-experience in my security consultant job.” 

Learning and earning different cybersecurity certifications, John eventually moved up to Senior Cybersecurity Architect at VISA. This was only possible because of continuous learning and development through these 12 years.

Developing practical cybersecurity skills

The Secure Software Development Life Cycle Learning Path focuses on the three phases of secure software development: Secure design, secure build and secure validation. “In the path, we learn the concepts and polish our basics, then implement these concepts through the project,” John said. One of the project’s challenges is “static application security testing using codebase and VCG tool, which is a direct application of security validation.”

The hands-on project John created is designed to reinforce key concepts from his course, provide practical experience and help students develop their skills.

John said he designed the SDLC Learning Path to be as applicable as possible. He wants students to walk away with a strong foundational knowledge of SDLC, which they can use as a base to develop advanced skills like pentesting, creating their own scripts for network security and much more.

Selecting the right certificates

Professionals in many fields benefit from pursuing industry certifications. Getting certified helps IT pros get hired and advance their careers while showing dedication to professional development and learning. Certificates help verify a person’s skill and assist current professionals in moving forward in their careers. Of course, not just any certificate will do. 

“It is important to choose certificates that best fit your career goals. That is why I pursued CEH and CHFI certifications. I gained hands-on experience in subjects relevant to my career goals, which I can apply in my day-to-day job,” said John. “If your goal is to move into management, certifications like the CISM can help you learn more about IT management and prove you’re qualified for the role.”

That’s why no matter your reasons for pursuing certification, John stresses the importance of choosing a certificate that matches your career goals.

John’s motivation is mentoring

“When I started in cybersecurity, I had no mentor and didn’t know where to start,” John recalled. “It motivated me to share my knowledge and experience with people new to the field.”

John started his career as a software developer but switched his focus to cybersecurity in 2007 when he joined Information Security System (ISS), an IBM subsidiary. He has spent the last 12 years doing cybersecurity research and development on securing software development life cycle, security contours, security analysis and security architecture.

“I started as a security analyst and currently work as a senior security architect. I have learned a lot during this 12-year journey,” John said. That led to consulting for many companies to meeting new people who are just starting out in cybersecurity to becoming an Infosec Skills instructor.

Contributing to the cybersecurity community

John encourages everyone to give back to the cybersecurity community. A thriving community teaches, mentors and energizes its members. It serves as a platform to share and benefit from each other’s experiences and learnings.

“Contributing to the community is a two-way street,” said John. You gain as much as you give.”

So how can you contribute to the cybersecurity community? Here are just a few ideas.

  • Mentoring people who are new to the field
  • Donation to communities that empower people in the field
  • Participate in security challenges and conferences
  • Conduct webinars to raise cybersecurity awareness

Learn more about John Prathab courses

See John's Courses

About John Prathab
John Prathab has a master’s degree in software engineering and more than a decade of IT experience, with 12 years in application security and three years in software development.

His primary responsibilities are in Secure SDLC, including but not limited to threat modeling, secure DevOps, web application firewalls, static and dynamic application security testing, RASP, pentesting and red teaming to safeguard information and hold people accountable for security. He’s interested in active learning, innovation and mentorship and is certified in ethical hacking, computer hacking and forensic investigation. He holds CEH, CHFI, SANS GMOB and Data Virtualization Architect certificates.

Posted: January 15, 2021
Articles Author
Shreya Verma
View Profile

Shreya is a Product Marketing Specialist for Infosec.