Get in Touch

Course Outline

Introduction to DevSecOps and the ECDE Framework

  • Foundations and principles of DevSecOps
  • Security challenges within DevOps environments
  • Overview of the ECDE exam and its domains

Building a Secure DevOps Culture and Mindset

  • Security as a shared responsibility
  • Shifting security left in the SDLC
  • Stakeholder alignment and team roles

Integrating Security into CI/CD Pipelines

  • Securing Jenkins, GitLab CI, and Azure DevOps pipelines
  • Managing secrets and configuring environments
  • Securing container builds and performing image scanning

Application Security within DevSecOps

  • Static and dynamic application security testing (SAST/DAST)
  • Scanning open-source dependencies using SCA tools
  • Conducting secure code reviews and adopting secure coding practices

Infrastructure as Code and Cloud Security

  • Securing configurations for Terraform, Ansible, and Kubernetes
  • Implementing IAM and policy-as-code
  • Applying DevSecOps in hybrid and multi-cloud environments

Monitoring, Compliance, and Incident Readiness

  • Implementing security monitoring and logging in CI/CD
  • Automating compliance (e.g., NIST, ISO, SOC 2)
  • Setting up automated remediation and incident response workflows

ECDE Exam Preparation and Final Lab

  • Understanding the ECDE exam structure and preparation tips
  • Completing a capstone DevSecOps pipeline lab
  • Conducting knowledge checks and readiness assessments

Summary and Next Steps

Requirements

  • A solid understanding of basic DevOps workflows and tools
  • Familiarity with the software development lifecycle (SDLC)
  • Knowledge of application security principles is advantageous

Target Audience

  • DevOps engineers
  • Application security professionals
  • Software developers integrating security into pipelines
 28 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories