Course Outline
1. DevSecOps Fundamentals: Security by Design
Explore: Core DevSecOps principles & secure SDLC
Demonstration: Direct comparison of legacy vs modern secure pipelines
Hands-on: Create your initial DevSecOps-enabled pipeline template
2. OWASP ZAP Security Testing Intensive
Attack Simulation:
- Deploy a vulnerable application containing SQLi & XSS
- Leverage OWASP ZAP to identify and address threats
Defensive Strategies:
- Automated scanning using ZAP
- CI/CD integration through the ZAP API
Hands-on: Tailor ZAP baseline scans + attack rules
Challenge: “Locate the hidden admin panel within 10 minutes”
3. Dependency Risks: Supply Chain Protection
Attack Simulation:
- Introduce a malicious npm package containing CVEs
Defensive Strategies:
- Track vulnerabilities using OWASP Dependency-Track
- Implement policy gates that fail builds on critical CVEs
Hands-on: Establish vulnerability policies & alert workflows
Key Demonstration: “How a single flawed dependency can compromise your infrastructure”
4. Vulnerability Management Command Center
Attack Simulation:
- Exploit unpatched container vulnerabilities
Defensive Strategies:
- Centralize reporting with OWASP DefectDojo
- Scan containers using Trivy
Hands-on: Develop real dashboards for CISO/executive reporting
Competition: “Triage 50 findings faster than your peers”
5. Secrets & Configuration Emergency Response
Attack Simulation:
- Extract secrets from Git history using truffleHog
Defensive Strategies:
- Pre-commit hooks to block patterns like
password=.* - Leverage ZAP’s config spider to expose dangerous settings
Hands-on: Implement GitHub Actions secrets scanning
Reality Check: “Your database password is in Slack right now”
6. Conclusion: DevSecOps Action Plan
OWASP Integration Strategy:
- Map out the adoption of DefectDojo, Dependency-Track, and ZAP
Individual Action Plan:
- Prepare your 30-day security checklist
- Define your DevSecOps KPIs & reporting dashboards
Requirements
Essential software and SDLC experience
Target Audience
DevOps, Security & Cloud Engineers who prefer practical over theoretical security discussions
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer