What is the equivalent for the security realm that would be worthy of a mention on a resume?
for offensive security, it boils down to discover (and get credited) vulnerabilities in other services, or to have certifications (which IMO are unworthy, but as you said "worthy of a mention on a resume"...).
for application security, you can follow the same example you already mentioned, but focus on security topics. Work on authentication and authorization, secure communications, etc.
for blue team, it's hard to have something worth of mention on a resume, unless you have some talks, a podcast, blogs, etc on this topic.