| Title | Author | Rating | Notes |
|---|---|---|---|
| The Art of Software Security Assessment: Identifying and Preventing Software Vulnerabilities | Mark Dowd, John McDonald, Justin Schuh | ★★★★★ | |
| The Tangled Web: A Guide to Securing Modern Web Applications | Michał Zalewski | ★★★★★ | |
| Web Application Obfuscation | Mario Heiderich, Eduardo Alberto Vela Nava, Gareth Heyes, David Lindsay | ★★★★★ | |
| Building Secure and Reliable Systems | Heather Adkins et al., Google | ★★★★★ | |
| The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws | Dafydd Stuttard, Marcus Pinto | ★★★★★ | |
| Hacking: The Art of Exploitation, 2nd ed. | Jon Erickson | ★★★★★ | |
| How to Solve It | George Pólya | ★★★★★ | |
| Securing DevOps: Security in the Cloud | Julien Vehent | ★★★★☆ | |
| OAuth 2 in Action | Justin Richer, Antonio Sanso | ★★★★☆ | Quick read; gives concrete terminology and mental models for OAuth 2. |
| The Phoenix Project | Gene Kim, Kevin Behr, George Spafford | ★★★★☆ | Big-picture view of how technology and business move together with DevOps. No technical depth. It pokes fun at security teams that block developers over trivial things, which still makes me laugh, and is worth remembering when we are the blocker. |
| Algorithms to Live By: The Computer Science of Human Decisions | Brian Christian, Tom Griffiths | ★★★★☆ | |
| Surely You're Joking, Mr. Feynman! | Richard Feynman | ★★★★☆ | |
| iOS Hacker's Handbook | Charlie Miller et al. | not rated | |
| Permanent Record | Edward Snowden | not rated |
Ratings are personal.