STARWEAVER

Fundamentals of Secure Software Design

STARWEAVER

Fundamentals of Secure Software Design

Aseem Singhal
Professionals in the Industry

Instructors: Aseem Singhal

Included with Coursera PlusLearn more

Ask Coursera

Gain insight into a topic and learn the fundamentals.
Intermediate level

Recommended experience

9 hours to complete
Flexible schedule
Learn at your own pace
Gain insight into a topic and learn the fundamentals.
Intermediate level

Recommended experience

9 hours to complete
Flexible schedule
Learn at your own pace

What you'll learn

  • Apply security-first principles including CIA Triad and Zero Trust, and conduct threat modeling using STRIDE/DREAD with GenAI support.

  • Identify and mitigate OWASP Top 10 and API security vulnerabilities using secure coding, input validation, OAuth 2.0, JWT, and encryption.

  • Write secure code using OWASP practices, refactor insecure patterns, integrate SAST/DAST/SCA into CI/CD, and use GenAI for code review.

  • Design secure APIs, microservices, and cloud architectures while applying NIST SSDF, ISO 27001, and enterprise security governance practices.

Details to know

Shareable certificate

Add to your LinkedIn profile

Recently updated!

August 2026

Assessments

4 assignments

Taught in English

See how employees at top companies are mastering in-demand skills

 logos of Petrobras, TATA, Danone, Capgemini, P&G and L'Oreal

There are 4 modules in this course

This module establishes foundational security principles and defensive thinking required for secure software design. Learners examine real-world breaches to understand why software gets hacked, master core security principles (CIA Triad, Least Privilege, Zero Trust), and conduct hands-on threat modeling using STRIDE and DREAD frameworks. GenAI tools augment threat identification by generating comprehensive attack scenarios. Students leave with practical skills to identify vulnerabilities before writing code.

What's included

11 videos2 readings1 assignment1 peer review2 discussion prompts

This module dives into the most critical security flaws plaguing modern applications through the OWASP Top 10 framework. Learners identify and mitigate injection attacks, broken access control, XSS, CSRF, and authentication vulnerabilities through hands-on code analysis and remediation. Students implement secure authentication flows, password storage, OAuth 2.0, secrets management, and encryption for data protection. Each lesson combines vulnerability exploitation understanding with practical secure coding techniques in Python and JavaScript, ensuring students can both recognize and prevent these flaws in production code.

What's included

10 videos1 reading1 assignment1 peer review2 discussion prompts

This module focuses on practical secure coding techniques and automated security testing integration. Learners apply OWASP Secure Coding Practices across multiple languages, identify and refactor common anti-patterns like insecure deserialization and hardcoded credentials, and implement secure error handling and logging. Students integrate automated security testing tools (SAST, DAST, SCA) into CI/CD pipelines using Bandit, Semgrep, OWASP ZAP, and Snyk. The module culminates with leveraging GenAI for intelligent code review, vulnerability detection, and security test generation while understanding AI limitations and risks.

What's included

10 videos1 reading1 assignment1 peer review2 discussion prompts

This module prepares students for enterprise-level secure software design by covering API security, cloud and container deployments, and cybersecurity governance. Learners apply OWASP API Security Top 10 principles to design secure RESTful and GraphQL APIs with proper authentication, rate limiting, and versioning. Students learn cloud shared responsibility models, container hardening, and Infrastructure as Code security. The module concludes with cybersecurity governance frameworks (NIST SSDF, ISO 27001), policy development, and complete secure architecture blueprints for real-world applications. Capstone project integrates all course concepts into comprehensive secure application design.

What's included

11 videos1 reading1 assignment2 peer reviews2 discussion prompts

Instructors

Aseem Singhal
14 Courses9,661 learners

Offered by

STARWEAVER

Why people choose Coursera for their career

Felipe M.

Learner since 2018
"To be able to take courses at my own pace and rhythm has been an amazing experience. I can learn whenever it fits my schedule and mood."

Jennifer J.

Learner since 2020
"I directly applied the concepts and skills I learned from my courses to an exciting new project at work."

Larry W.

Learner since 2021
"When I need courses on topics that my university doesn't offer, Coursera is one of the best places to go."

Chaitanya A.

"Learning isn't just about being better at your job: it's so much more than that. Coursera allows me to learn without limits."

Frequently asked questions