This course takes you from the foundations of DevSecOps and shift-left security to Secure SDLC, application security testing, and software supply chain security, building a strong foundation for integrating security throughout software development.
You'll begin with DevSecOps foundations, exploring the security challenges associated with traditional DevOps and how DevSecOps brings security into development and operations. You'll learn about shared responsibility, core DevSecOps principles, Security as Code, shift-left security, and the role of automation in supporting consistent security practices. From there, the course moves into the Secure Software Development Lifecycle. You'll explore how security can be integrated across SDLC phases, how earlier security feedback can reduce late-stage issues, and why the timing of security activities matters. You'll also examine Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) and how they contribute to application security at different stages of development. The course then focuses on application security risks, including common vulnerability types and the OWASP Top 10. You'll explore how vulnerability identification standards provide a consistent way to describe and track security weaknesses and how these concepts support application security practices. Finally, you'll explore software supply chain and dependency security, including the risks introduced through open-source components and third-party dependencies. You'll learn how Software Composition Analysis helps identify vulnerable components, examine relevant vulnerability information, and support appropriate remediation decisions. By the end of this course, you will be able to: - Explain DevSecOps principles, shared responsibility, shift-left security, and Security as Code. - Describe how security practices and feedback mechanisms integrate across the Secure SDLC. - Discuss the roles of SAST and DAST across the software development lifecycle. - Perform static security scanning to identify vulnerabilities and security issues in application code. - Identify common application vulnerabilities, OWASP Top 10 risks, and vulnerability standards. - Outline how Software Composition Analysis supports dependency vulnerability identification and secure software development. Designed for aspiring DevOps professionals, software developers, and security professionals, this course provides a structured path from DevSecOps principles and Secure SDLC practices to application and software supply chain security. To be successful here, you should have familiarity with software development concepts, DevOps practices, CI/CD fundamentals, Git, and Linux shell commands. Prior experience with application security testing or specialized security tools is not required, as the relevant concepts and techniques are introduced throughout the course. Build the foundation to integrate security throughout software development, identify application and dependency risks earlier, and support secure software delivery through DevSecOps and Secure SDLC practices.












