Course Outline
1. DevSecOps Foundations: Security by Design
Explore core DevSecOps principles & secure SDLC
Demo: Comparative analysis of legacy vs modern secure pipelines
Lab: Construct your first DevSecOps-enabled pipeline template
2. OWASP ZAP Security Testing Bootcamp
Breach Simulation:
- Deploy a vulnerable application featuring SQLi & XSS
- Leverage OWASP ZAP to identify and neutralize threats
Defense Tactics:
- Automated scanning utilizing ZAP
- CI/CD integration via ZAP API
Lab: Customize ZAP baseline scans + attack rules
Challenge: “Locate the concealed admin panel in 10 minutes”
3. Dependency Hell: Supply Chain Defense
Breach Simulation:
- Inject a malicious npm package containing CVEs
Defense Tactics:
- Track vulnerabilities using OWASP Dependency-Track
- Apply policy gates that reject builds on critical CVEs
Lab: Establish vulnerability policies & alert workflows
Shocking Demo: “How a single flawed dependency can compromise your entire infrastructure”
4. Vulnerability Management War Room
Breach Simulation:
- Exploit unpatched container vulnerabilities
Defense Tactics:
- Centralize reporting via OWASP DefectDojo
- Scan containers with Trivy
Lab: Develop real-time dashboards for CISO/executive reporting
Competition: “Triage 50 findings faster than your rivals”
5. Secrets & Configuration Fire Drill
Breach Simulation:
- Exfiltrate secrets from Git history using truffleHog
Defense Tactics:
- Pre-commit hooks to block patterns like
password=.* - Utilize ZAP’s config spider to reveal dangerous settings
Lab: Deploy GitHub Actions secrets scanning
Reality Check: “Your database password is exposed in Slack right now”
6. Wrap-Up: DevSecOps Battle Plan
OWASP Integration Roadmap:
- Plan the adoption of DefectDojo, Dependency-Track, and ZAP
Personal Action Plan:
- Outline your 30-day security checklist
- Define your DevSecOps KPIs & reporting dashboards
Requirements
Basic software and SDLC experience
Audience
DevOps, Security & Cloud Engineers who are frustrated by theoretical security discussions
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer