This course takes you from securing CI/CD pipelines and application code to protecting containers, infrastructure, and secrets, building practical skills to integrate security controls throughout modern DevSecOps workflows.
You'll begin with CI/CD security, learning how pipeline stages work and where security controls can be integrated across the software delivery process. You'll explore static code analysis, security findings, and dependency vulnerability risks, along with techniques for identifying weaknesses in source code and third-party components. From there, the course moves into repository and application security. You'll learn how software composition analysis helps identify vulnerable dependencies and how secrets detection helps prevent sensitive information from being exposed in repositories. You'll then explore Dynamic Application Security Testing (DAST), including scan scope, targets, exclusions, and different scan modes for testing running applications. The course then advances into container security, where you'll examine common container threats and learn how image and dependency scanning can identify vulnerabilities. You'll apply these techniques to strengthen application and container protection within CI/CD workflows. Finally, you'll focus on Infrastructure as Code and secrets security. You'll identify infrastructure attack surfaces and common misconfigurations, validate infrastructure before provisioning, and apply IaC scanning and policy enforcement. You'll also explore secrets management, access policies, and secret lifecycles to protect sensitive information across DevSecOps environments. By the end of this course, you will be able to: • Explain CI/CD pipeline stages, security architecture, and security control placement. • Analyze source code and dependencies to identify vulnerabilities and supply chain risks. • Implement repository security practices to detect exposed secrets. • Perform dynamic security testing to identify application vulnerabilities. • Scan container images and dependencies to identify security vulnerabilities. • Apply IaC scanning and policy enforcement to secure infrastructure configurations. • Manage secrets, access policies, and secret lifecycles across DevSecOps environments. Designed for DevOps professionals, software developers, cloud professionals, and security professionals, this course provides a structured path from CI/CD security fundamentals to practical application, container, infrastructure, and secrets protection. To be successful here, you should have a basic understanding of DevSecOps foundations, CI/CD concepts, Git, containers, software development, and command-line operations. Prior experience with advanced security tools or practices is not required, as the course introduces them through guided practical activities. Build the skills to secure software delivery from code to infrastructure, protecting applications, containers, repositories, and secrets across modern DevSecOps environments.












