Best of · 1970

Software Security,
ranked.

Books on application and web security, threat modeling, and secure engineering. For developers who want to ship code that holds up against real attackers, not just pass a checklist. 6 titles, ranked by 2,825+ reader reviews on Amazon and Goodreads, weighted for recency and depth.

The best software security book in 1970 is Security Engineering by Ross Anderson, rated 4.8★ from 265+ readers. Below, all 6 titles are ranked by aggregate ratings, with who each one is for and what to read first.

Methodology
Rankings combine Amazon star averages, Goodreads ratings, mention frequency on r/programming and HN, and recency weight (books older than 8 years lose 10% per year).
Reviews counted
3K+
01
Security Engineering
Ross Anderson · Wiley · 2020
Security Engineering
A Guide to Building Dependable Distributed Systems
security
Astonishing breadth; few books connect this many parts of security.
Enormous at over 1,200 pages; it is a reference, not a weekend read.
Best for: Engineers and architects who want the deepest, broadest security grounding
RATING
4.8
265 RATINGS
Check Price on Amazon →
02
Alice and Bob Learn Application Security
Tanya Janca · Wiley · 2020
Alice and Bob Learn Application Security
security
Friendly, encouraging tone that lowers the barrier to a hard topic.
Breadth over depth; each topic is an introduction rather than a deep dive.
Best for: Developers who want a structured, lifecycle-wide view of AppSec
RATING
4.7
225 RATINGS
Check Price on Amazon →
03
The Web Application Hacker's Handbook
Dafydd Stuttard, Marcus Pinto · Wiley · 2011
The Web Application Hacker's Handbook
Finding and Exploiting Security Flaws
security
The most thorough offensive web-security reference in print.
Published in 2011, so it predates modern single-page-app and API patterns.
Best for: People learning web penetration testing who want the canonical text
RATING
4.3
329 RATINGS
Check Price on Amazon →
04
Web Security for Developers
Malcolm McDonald · No Starch Press · 2020
Web Security for Developers
Real Threats, Practical Defense
security
Short and readable; you can finish it in a weekend and act on it.
Deliberately broad and shallow; specialists will find it basic.
Best for: Developers who want a first, friendly grounding in web security
RATING
4.6
108 RATINGS
Check Price on Amazon →
05
Threat Modeling
Adam Shostack · Wiley · 2014
Threat Modeling
Designing for Security
security
The definitive treatment of threat modeling from a field founder.
Long and dense at 624 pages; it reads like a reference, not a tutorial.
Best for: Architects and engineers who make design decisions with security stakes
RATING
4.5
339 RATINGS
Check Price on Amazon →
06
The Developer's Playbook for Large Language Model Security
Steve Wilson · O'Reilly Media · 2024
The Developer's Playbook for Large Language Model Security
Building Secure AI Applications
securityllm
The most practical single book on securing apps built with LLMs.
A fast-moving field, so some tools and attacks will keep evolving past print.
Best for: Developers adding LLM features who want a security baseline before shipping
RATING
4.6
29 RATINGS
Check Price on Amazon →
See also
Best Of
Engineering Practices & Culture
Books on how teams actually build software over time — code review, testing, version control, dependency management, and the practices behind long-lived codebases.
SEE THE RANKED LIST →
Best Of
System Design & Distributed Systems
Books on designing reliable, scalable, and maintainable backend systems. Storage, replication, consensus, streaming, and the trade-offs behind every architectural choice.
SEE THE RANKED LIST →
Best Of
Software Craft & Code Quality
Books on the daily craft of writing software — clean code, refactoring, design principles, and the habits that separate working code from code that lasts.
SEE THE RANKED LIST →