paul78 wrote: » Unfortunately, GWAPT doesn't really go into defensive secure development practices. But it's probably relevant after you have a little more experience. The most relevant cert based on your description is probably CSSLP. Check out www.isc2.org. I think Security+ may be interesting but given your experience it's not likely to be relevant. What type of code do you test? Maybe a mod can move this thread to the general security certification forum, may get more traction on this topic.