Get in Touch
 Duration 7 hours

Course Outline

1. DevSecOps Fundamentals: Security by Design

Learn: Core DevSecOps principles & secure SDLC

Demo: Comparative analysis of legacy vs modern secure pipelines

Lab: Construct your initial DevSecOps-enabled pipeline template

2. OWASP ZAP Security Testing Intensive

Breach Simulation:

  • Deploy a vulnerable app containing SQLi & XSS
  • Leverage OWASP ZAP to detect and mitigate threats

Defense Tactics:

  • Automated scanning utilizing ZAP
  • CI/CD integration via ZAP API

Lab: Tailor ZAP baseline scans + attack rules

Challenge: “Locate the hidden admin panel within 10 minutes”

3. Dependency Risks: Supply Chain Security

Breach Simulation:

  • Introduce a malicious npm package with CVEs

Defense Tactics:

  • Track vulnerabilities using OWASP Dependency-Track
  • Implement policy gates that fail builds upon critical CVEs

Lab: Establish vulnerability policies & alert workflows

Impactful Demo: “How a single flawed dependency can compromise your infrastructure”

4. Vulnerability Management Command Center

Breach Simulation:

  • Exploit unpatched container vulnerabilities

Defense Tactics:

  • Centralize reporting with OWASP DefectDojo
  • Scan containers with Trivy 

Lab: Develop real-time dashboards for CISO/executive reporting

Competition: “Resolve 50 findings quicker than your peers”

5. Secrets & Configuration Emergency Drill

Breach Simulation:

  • Exfiltrate secrets from Git history using truffleHog

Defense Tactics:

  • Pre-commit hooks to block patterns like password=.*
  • Utilize ZAP’s config spider to uncover dangerous settings

Lab: Deploy GitHub Actions secrets scanning

Reality Check: “Your database password is currently in Slack”

6. Conclusion: DevSecOps Strategic Plan

OWASP Integration Roadmap:

  • Plan the adoption of DefectDojo, Dependency-Track, and ZAP

Personal Action Plan:

  • Formulate your 30-day security checklist
  • Define your DevSecOps KPIs & reporting dashboards

Requirements

Basic software and SDLC experience

Target Audience

DevOps, Security & Cloud Engineers who dislike theoretical security lectures

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories