Skip to main content
CYB-0336ExpertCurrent Intake
XASE

XASE: Xcademia Application Security Engineer

6-Day Instructor-Led Programme

The XASE Certification Programme is the practitioner standard for application security engineers who secure software throughout the development lifecycle, from threat modelling and secure code review through to DevSecOps pipeline hardening and API security testing. Assessed on Day 6 through a supervised code review, threat model, and AppSec assessment exercise. No MCQs. No exam.

Duration

6 Days

Price

$4,995

XASE: Xcademia Application Security Engineer
Duration
6 Days
Complete in 6 days
Learning Style
Mentor-led, practical and scenario-based
Guided walkthroughs, real-world examples, and applied skills for the workplace.

Course Overview

Insecure software is the root cause of the majority of enterprise breaches. Organisations need application security engineers who can identify vulnerabilities in code, integrate security into CI/CD pipelines, and work alongside development teams to build security in from the start rather than bolt it on at the end. XASE is built for security engineers, developers moving into security, and application security consultants who need to demonstrate practical AppSec capability.

Across six instructor-led days, participants build competency from secure development foundations through to advanced techniques: threat modelling with STRIDE and MITRE ATT&CK, secure code review across multiple languages, OWASP Top 10 and ASVS application, API security testing, mobile application security, software supply chain security, and DevSecOps pipeline integration with SAST, DAST, and SCA tooling. Every session uses real code, real vulnerabilities, and real remediation.

On Day 6, participants conduct a supervised AppSec assessment including a code review of a vulnerable application, threat model development, and API security test. The senior practitioner observes methodology, technical depth, and communication quality. XASE certificate and Practitioner Assessment Report issued together. Aligned with OWASP Top 10 2025, OWASP ASVS, NIST SP 800-218 SSDF, NCSC Secure Development guidelines, CWE/SANS Top 25, and SLSA supply chain framework.

Hands-On Learning

Hands-on secure code review across Python, JavaScript, Java, and Go, SAST and DAST tool integration in CI/CD pipelines, threat modelling with STRIDE and ATT&CK, API security testing, and a supervised AppSec assessment on Day 6

Mentor-Led Sessions

Mentor-led sessions reviewing real-world vulnerability patterns, secure design principles, and how AppSec integrates into engineering culture when working alongside development teams.

Career-Ready Skills

Identify, assess, and remediate application security vulnerabilities across the full SDLC, integrate security tooling into DevSecOps pipelines, and communicate AppSec risk to engineering leadership.

Learning Outcomes

Conduct structured secure code reviews across multiple programming languages using SAST tooling and manual taint analysis methodology

Apply OWASP Top 10 2025 and OWASP ASVS to identify and remediate application security vulnerabilities in real codebases

Design threat models using STRIDE, MITRE ATT&CK, and PASTA methodology for complex application architectures

Integrate SAST, DAST, and SCA security tooling into CI/CD pipelines as part of a DevSecOps programme

Assess API security including REST, GraphQL, and OAuth 2.0 implementations against OWASP API Top 10

Communicate application security risk to engineering teams and leadership with actionable remediation guidance

Prerequisites

1

Minimum 12 months in a software development, security engineering, or penetration testing role

2

Working knowledge of at least one programming language: Python, JavaScript, Java, Go, or C#

3

Basic familiarity with web application architecture, HTTP, and API design concepts

Detailed Syllabus

Organized by professional domains with comprehensive coverage

Topics Covered:
  • Secure development lifecycle models: Microsoft SDL, BSIMM, and SAMM maturity assessment
  • Security requirements engineering: translating compliance and threat data into developer stories
  • Security gates in Agile sprints: where security activities sit in the sprint lifecycle
  • Security debt management: tracking, prioritising, and reducing accumulated vulnerability backlog
  • AppSec programme KPIs: vulnerability discovery rate, MTTD, MTTR, and coverage metrics
Stage 5Final Capstone

XASE: Xcademia Application Security Engineer — Capstone Project

On Day 6, participants conduct a supervised AppSec assessment against a provided vulnerable application. They perform a structured code review identifying security vulnerabilities, develop a threat model using STRIDE methodology, and conduct an API security test against a connected REST API. The senior practitioner observes methodology, reviews findings documentation, and assesses both technical depth and communication quality. The XASE certificate and Practitioner Assessment Report are issued together on passing standard.

Assessed by a senior Xcademia practitioner

Framework Alignment

This course is mapped directly onto the standards your organisation already answers to. No invented frameworks, no proprietary jargon.

  • OWASP Top 10 2025

    Global

    Full 2025 edition: primary application vulnerability reference throughout all domains with code examples

  • OWASP ASVS

    Global

    Application Security Verification Standard Levels 1 to 3: used as assessment framework and requirements source

  • OWASP API Top 10

    Global

    API security testing and design review aligned to OWASP API Top 10 throughout

  • NIST SP 800-218 SSDF

    Global

    Secure Software Development Framework: DevSecOps and secure SDLC alignment throughout

  • NCSC Secure Development

    Global

    UK government secure coding guidance: developer security practice alignment

  • CWE/SANS Top 25

    Global

    Most Dangerous Software Weaknesses: vulnerability classification and remediation patterns

  • SLSA Framework

    Global

    Supply Chain Levels for Software Artefacts: CI/CD pipeline integrity and supply chain security

  • BSIMM / SAMM

    Global

    Software Assurance Maturity Model: AppSec programme design and maturity measurement

Skills You'll Gain

Master these in-demand skills through hands-on practice

Secure code reviewOWASP Top 10 2025OWASP ASVSThreat ModellingSAST ToolingDAST (OWASP ZAP)API security TestingDevSecOps pipeline integrationSBOM and supply chain securityMobile securityCryptography application securitySecurity champion programme design

Career Progression

A clear view of the roles this programme supports, what typically comes next, and where learners progress over time

Application Security EngineerSecurity EngineerDevSecOps EngineerPenetration TesterSecure Code ReviewerPlatform Security Engineer
Flexible Delivery Options

Ways to Learn

Choose the learning format that works best for you and your team

Book Now

Live Online

Instructor-Led Training

Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.

6 Days
Small cohorts
  • Live instructor interaction (real-time)
  • Trainer-led walkthroughs and real examples
  • Guided resources and session notes provided
  • Structured Q&A and practical discussion

Price per person

$4,995+ VAT

Group enrolments and early planning options available.

All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.

Premium Training Option

Prefer a Faster, Personalised Route into IT?

Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.

Personalised XASE: Xcademia Application Security Engineer learning plan
Tailored to your pace and goals
Live 1-to-1 sessions
With an experienced mentor
Real-world troubleshooting
Practice, not just exam theory
Flexible scheduling
To fit around work, study, or family

"Many learners choose 1-to-1 when they want understanding, not memorisation."

Exam & Certification Information

Everything you need to know about the certification exams

Xcademia Certification Programme

Xcademia Certification Programme

On successful completion of XASE: Xcademia Application Security Engineer, learners are assessed on the final day through a supervised practitioner scenario. Three outcomes are possible, Certificate Awarded, Certificate Deferred, or Not Awarded. The Practitioner Assessment Report and certificate are issued together. Verified at xcademia.com/verify.

Certificate Awarded

Assessed competent on the final day.

Certificate Deferred

Resit available on a future cohort.

Not Awarded

Attendance record issued. Reassessment possible.

Frequently Asked Questions

Everything you need to know about this course

CASE exists in two separate versions (.NET and Java) and both are MCQ exams. You pay twice for two separate certifications covering one language each. XASE is a single 6-day programme covering secure code review across Python, JavaScript, Java, Go, and C#, plus threat modelling, API security, mobile security, and DevSecOps integration. Assessed by a practitioner who reviews your actual code analysis and threat model, not your MCQ answers.

Share:

Ready to Start Your Learning Journey?

Take the next step in your professional development

Digital certificate upon completion
Comprehensive course materials
Expert instructor support
Flexible learning options