Course Outline
1. DevSecOps Essentials: Security by Design
Key Concepts: Fundamental DevSecOps principles and secure SDLC practices
Demonstration: Comparative analysis of legacy versus modern secure pipelines
Hands-On: Constructing your initial DevSecOps-enabled pipeline template
2. OWASP ZAP Security Testing Intensive
Breach Simulation:
- Deployment of a vulnerable application featuring SQLi and XSS
- Utilization of OWASP ZAP for threat detection and mitigation
Defense Strategies:
- Implementation of automated scanning using ZAP
- CI/CD integration via the ZAP API
Hands-On: Customizing ZAP baseline scans and attack rules
Challenge: “Locate the hidden admin panel within 10 minutes”
3. Supply Chain Resilience: Tackling Dependency Risks
Breach Simulation:
- Injection of a malicious npm package containing CVEs
Defense Strategies:
- Vulnerability monitoring via OWASP Dependency-Track
- Implementation of policy gates that halt builds upon critical CVEs
Hands-On: Developing vulnerability policies and alert workflows
Illustrative Demo: “How a single flawed dependency can compromise your infrastructure”
4. Vulnerability Management Command Center
Breach Simulation:
- Exploitation of unpatched container vulnerabilities
Defense Strategies:
- Centralization of reporting using OWASP DefectDojo
- Container scanning with Trivy
Hands-On: Creating real-time dashboards for CISO/executive reporting
Competition: “Triage 50 findings more efficiently than your competitors”
5. Secrets and Configuration Emergency Protocol
Breach Simulation:
- Exfiltration of secrets from Git history using truffleHog
Defense Strategies:
- Pre-commit hooks to block patterns like
password=.* - Use of ZAP’s config spider to identify dangerous settings
Hands-On: Implementation of GitHub Actions secrets scanning
Reality Check: “Your database password is currently exposed in Slack”
6. Conclusion: DevSecOps Strategic Roadmap
OWASP Integration Plan:
- Planning the adoption of DefectDojo, Dependency-Track, and ZAP
Personal Action Plan:
- Drafting a 30-day security checklist
- Defining DevSecOps KPIs and reporting dashboards
Requirements
Essential knowledge of software development and the SDLC
Target Audience
DevOps, Security, and Cloud Engineers who prefer practical, no-nonsense security training
Testimonials (2)
The knowledge and experience of the consultant, as theoretical topics are addressed by applying them to the reality of processes. The course contains a highly valuable program in information technology management.
Luis Castro Gamboa - Cooperativa De Ahorro Y Credito Ande No. 1 R.L.
Course - Site Reliability Engineering (SRE) Foundation®
Machine Translated
That it was very clear in each specification
Ricardo Ramirez - AMX CONTENIDO
Course - DevOps Leader (DOL)®
Machine Translated