[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fds-shift-left-security-culture":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","ds-shift-left-security-culture","Ds Shift Left Security Culture","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,51,54,57,60,63,66,69,72,75,78,81,84,85,88,91,94,97,100,103,106,109,112,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":40,"name":41,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":43,"name":44,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":46,"name":47,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":49,"name":50,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":52,"name":53,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":55,"name":56,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":58,"name":59,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":61,"name":62,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":64,"name":65,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":67,"name":68,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":70,"name":71,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":73,"name":74,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":76,"name":77,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":79,"name":80,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":82,"name":83,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":8,"name":9,"count":11},{"key":86,"name":87,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":89,"name":90,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":92,"name":93,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":95,"name":96,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":98,"name":99,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":101,"name":102,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":104,"name":105,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":107,"name":108,"count":11},"security-authn-authz","Security Authn Authz",{"key":110,"name":111,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":113,"name":114,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,180,193,206,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":154,"explanation":165},"019fab8f-ce48-71bd-9c30-ef006cbe3f14",1,"What does \"shift-left security\" mean in software delivery?",[153,156,159,162],{"key":154,"text":155},"a","Introducing security activities earlier in the lifecycle, starting at design and coding",{"key":157,"text":158},"b","Moving all security testing to a dedicated team right before the production release date",{"key":160,"text":161},"c","Relocating the security team's office closer to the operations team for faster incident response",{"key":163,"text":164},"d","Replacing manual code review entirely with automated scanning tools in the CI pipeline","Shift-left means moving security work earlier in the lifecycle (requirements, design, coding) instead of concentrating it right before release. It is about timing of activities, not about team location or fully replacing manual review with tooling.",{"id":167,"topic":9,"difficulty":168,"body":169,"options":170,"correct_key":154,"explanation":179},"019fab8f-ce48-7e7f-905f-b3d55993c63c",2,"Why is finding a design-level security flaw during sprint planning generally cheaper than finding the same flaw after release?",[171,173,175,177],{"key":154,"text":172},"Because the design can still be changed without rework on already-built and deployed code",{"key":157,"text":174},"Because production incidents are always caused by design flaws rather than coding mistakes",{"key":160,"text":176},"Because sprint planning meetings automatically include a dedicated penetration tester",{"key":163,"text":178},"Because compliance auditors only review findings that are reported during planning meetings","The earlier a flaw is caught, the less has been built on top of the flawed assumption. Catching it at design time means changing a diagram or a story; catching it after release means reworking deployed code, migrating data, and possibly handling an incident.",{"id":181,"topic":9,"difficulty":150,"body":182,"options":183,"correct_key":160,"explanation":192},"019fab8f-ce49-7996-8a88-ecf95d2be0bf","In a security champion program, what is the primary role of a \"security champion\"?",[184,186,188,190],{"key":154,"text":185},"An external consultant hired only during compliance audit season to sign off on controls",{"key":157,"text":187},"A full-time member of the central security team who audits every pull request across the company",{"key":160,"text":189},"An engineer embedded in a product team who keeps their regular engineering job while acting as the local point of contact and advocate for security",{"key":163,"text":191},"A manager who approves security budget requests without doing any hands-on technical work","A security champion is embedded in a product team, keeps doing their regular engineering job, and acts as the local point of contact and advocate for security practices, bridging the team and the central security function.",{"id":194,"topic":9,"difficulty":168,"body":195,"options":196,"correct_key":163,"explanation":205},"019fab8f-ce4a-740a-89d5-98054ab08afd","A team is writing a user story for a new feature that will let users upload profile photos. When should the team first think about what could go wrong from a security perspective?",[197,199,201,203],{"key":154,"text":198},"Only after a customer reports that they were able to upload an unexpected file type",{"key":157,"text":200},"During the final regression test pass, right before the release is tagged",{"key":160,"text":202},"Never, because profile photo upload is considered too minor a feature to warrant it",{"key":163,"text":204},"While writing and refining the story itself, before implementation starts","Lightweight threat consideration belongs in story writing and refinement, before code is written. Waiting for a customer report or the final regression pass means the risky design decisions (file type validation, storage, size limits) are already baked in.",{"id":207,"topic":9,"difficulty":150,"body":208,"options":209,"correct_key":157,"explanation":218},"019fab8f-ce4a-7da4-ae9f-cb38fb531946","What is \"security debt\" in the context of a product backlog?",[210,212,214,216],{"key":154,"text":211},"The total amount of money a company owes to a third-party security vendor for annual licenses",{"key":157,"text":213},"A known, accepted weakness tracked as a backlog item to be fixed later, not right now",{"key":160,"text":215},"A fine imposed by a regulator after a data breach is discovered and reported",{"key":163,"text":217},"The interest rate applied to a company's cyber-insurance premium each renewal cycle","Security debt is the security equivalent of technical debt: a known weakness that the team consciously decides not to fix right now, tracked explicitly so it is not forgotten and can be prioritized later.",{"id":220,"topic":9,"difficulty":168,"body":221,"options":222,"correct_key":160,"explanation":231},"019fab8f-ce4b-759a-833e-e3d9f013859c","A company rolls out a mandatory annual security awareness training video for all developers. Why might completion rate alone be a poor measure of the training's effectiveness?",[223,225,227,229],{"key":154,"text":224},"Completion rate cannot be measured automatically by any learning management system",{"key":157,"text":226},"Annual trainings are always illegal under most data protection regulations",{"key":160,"text":228},"Completion only shows the video was watched, not that code-writing behavior changed afterward",{"key":163,"text":230},"Developers are legally required to skip the training if it takes longer than one hour","Completion is a process metric: it tells you people clicked through the material. It says nothing about whether behavior changed, such as fewer recurring vulnerability classes in code review or SAST results after the training.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":168,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]