James O’Brien
OSWE, GWAPT

13 years focused on application security and secure software development. Has conducted assessments for web applications, mobile apps, and APIs across banking, e-commerce, and healthcare sectors.
James O’Brien is an Application Security Instructor at GICCT, focused on helping developers and security professionals find and fix the vulnerabilities that matter most in modern web applications and APIs. His work sits at the meeting point of secure development and offensive testing, and he teaches students to see applications from both perspectives at once.
Background and career
James came to application security through a path that gave him a foot in both camps: he understands how applications are built and how they are broken. That dual fluency is the foundation of his effectiveness, allowing him to speak credibly to developers about the realities of shipping code while also demonstrating, concretely, how the flaws they introduce are exploited in practice.
He has assessed and hardened applications for organisations ranging from startups to large enterprises, developing a deep understanding of how vulnerabilities are introduced, discovered, and remediated in real codebases. He has seen the same categories of flaw appear again and again across very different organisations, and he has formed clear, practical views on what actually works to prevent them — views he brings directly into his teaching.
Areas of expertise
James’s expertise centres on the OWASP Top 10, secure coding, security testing, and code review across modern web stacks and APIs. He has particular depth in the practical mechanics of finding vulnerabilities — the methodical testing, the creative probing, and the understanding of how applications fail that separates effective security testing from superficial scanning.
He is equally strong on the defensive side, able to guide development teams in fixing the flaws he finds properly rather than merely patching symptoms. He understands that the goal of application security is not to produce impressive vulnerability reports but to produce more secure software, and he keeps that outcome firmly in view.
Teaching philosophy
James teaches application security from both sides of the keyboard. His students attack deliberately vulnerable applications, experiencing firsthand how a vulnerability is actually exploited, and then learn to build defences against the very flaws they have just used. He finds this dual perspective makes the lessons stick and transfer directly to real projects in a way that one-sided instruction never achieves.
He emphasises developing a security mindset over memorising rules — the habit of constantly asking how something could be misused. His goal is graduates who carry that instinct into their daily work, catching problems as they write code rather than relying solely on later testing to find them.
A practitioner’s perspective
James’s teaching reflects the reality that most application vulnerabilities are not novel but familiar, recurring because their underlying causes are organisational and human as much as technical. He helps students understand why this cycle persists and what genuinely breaks it, rather than offering superficial fixes that fail to address the root causes.
He keeps current with an ever-shifting landscape, from the security challenges of modern front-end frameworks to the rapid proliferation of APIs and the new attack surfaces they expose. He frames these developments in terms of lasting principles, helping students build knowledge that adapts as specific technologies rise and fall.
His students appreciate that he treats application security as a craft to be developed rather than a checklist to be completed. He encourages them to be curious, to probe and experiment, and to build the deep, intuitive understanding of how applications work that ultimately makes the difference between a competent tester and an exceptional one.
At GICCT
At the institute, James leads the Web Application Security program. He is a strong advocate for shifting security earlier in development, regularly reminding students that a flaw caught while writing code costs a fraction of one found after release. For developers wanting to write more secure software, and for security professionals specialising in applications, his courses offer a rigorous and genuinely practical grounding.