Application security engineering is the responsibility of system designers who have to design security into the system that reflects the security requirements and policies of the system procurer.

Infrastructure security engineering is the responsibility of system managers or administrators whose job is to configure the existing infrastructure software (operating systems, databases, middleware, etc.) to ensure that it conforms to the security policies of the organisation that uses the infrastructure.
