Get in Touch
 Duration 7 hours

Course Outline

1. DevSecOps Foundations: Security by Design

 Acquisition of Knowledge: Core DevSecOps principles & secure SDLC

Demonstration: Side-by-side comparison of legacy vs modern secure pipelines

Practical Exercise: Build your first DevSecOps-enabled pipeline template

2. OWASP ZAP Security Testing Bootcamp

Breach Simulation:

  • Deploy a vulnerable app with SQLi & XSS
  • Use OWASP ZAP to detect and mitigate threats

Defense Tactics:

  • Automated scanning with ZAP
  • CI/CD integration via ZAP API

 Practical Exercise: Customize ZAP baseline scans + attack rules

 Challenge: “Find the hidden admin panel in 10 minutes”

3. Dependency Hell: Supply Chain Defense

Breach Simulation:

  • Inject malicious npm package with CVEs

Defense Tactics:

  • Monitor vulnerabilities with OWASP Dependency-Track
  • Enforce policy gates that fail builds on critical CVEs

Practical Exercise: Create vulnerability policies & alert workflows

Shocking Demo: “How one bad dependency can own your infrastructure”

4. Vulnerability Management War Room

Breach Simulation:

  • Exploit unpatched container vulnerabilities

Defense Tactics:

  • Centralize reporting with OWASP DefectDojo
  • Scan containers with Trivy 

Practical Exercise: Build real dashboards for CISO/executive reporting

Competition: “Triage 50 findings faster than your rivals”

5. Secrets & Configuration Fire Drill

Breach Simulation:

  • Exfiltrate secrets from Git history using truffleHog

Defense Tactics:

  • Pre-commit hooks to block patterns like password=.*
  • Use ZAP’s config spider to surface dangerous settings

Practical Exercise: Implement GitHub Actions secrets scanning

Reality Check: “Your database password is in Slack right now”

6. Wrap-Up: DevSecOps Battle Plan

OWASP Integration Roadmap:

  • Plan your DefectDojo, Dependency-Track, and ZAP adoption

Personal Action Plan:

  • Draft your 30-day security checklist
  • Define your DevSecOps KPIs & reporting dashboards

Requirements

Foundational knowledge of software development and SDLC

Audience

DevOps, Security & Cloud Engineers who dread theoretical security discussions

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories