Hello everyone. I’ve been reading posts here for a few weeks and finally decided to register. I’m coming from a customer support and CRM background, so application security is a completely new field for me. My company is starting to look into SAST tools, and Veracode’s name comes up a lot.
I’m trying to understand if it’s a good platform for someone with my background to learn appsec fundamentals, or if its scale and complexity would be counterproductive. In my past work with ticketing systems, I’ve seen how a tool with too many options can actually slow down a team that’s just getting started.
From what I’ve read, Veracode seems very powerful. But I’m nervous about two things. First, will the initial setup and results be something a beginner can parse and act on, or will it just produce a flood of findings I won’t know how to prioritize? Second, is the learning curve more about understanding the tool itself, or about learning security concepts through it?
I’m determined to get up to speed, but I want to make sure I’m starting on a path that builds understanding rather than just generating a report I can’t contextualize. For those of you who started with limited appsec knowledge, did Veracode help you learn, or did you find you needed a lot of prior knowledge just to use it effectively? Any insights on the onboarding experience would be really helpful.