Download Full Outline
Course
DevSecOps in Action: Building Secure, Scalable Workflows
CompTIA Certified Badge
Master practical DevSecOps skills to secure your code, pipelines, containers, and cloud infrastructure.
ID:TTDV8400
Duration:5 Days
Level:Intermediate
Format:

Upcoming Public Course Dates

Class Schedule
Group Training
Special Offers
Course Schedule Available By Request - Contact Us

Group training options will be displayed here. Contact us for more information about group training opportunities.

Special offers will be displayed here. Check back later for promotional deals and special pricing.

What You'll Learn

Overview
Objectives
Audience
Pre-Reqs
Agenda
Follow On
Related
Expand All

Overview

CompTIA Authorized Partner Badge

DevSecOps gives you the ability to build and deliver software that is secure from the start. This expert-led course is for professionals who already understand the basics of CI/CD, containers, and cloud platforms and want to grow their skills by bringing security into every part of the development process. Over five days, you will learn how to catch risks earlier, automate the right security checks, and reduce manual effort by setting up smarter workflows. You will work with tools like SonarQube, Trivy, OWASP ZAP, Terraform, and Kubernetes, but more importantly, you will learn how to make them work together in real-world scenarios. Everything is ready for you in our fully prepared lab environment so you can focus on building skills instead of setting up tools.

This course is about fifty percent hands-on and guided by an expert who has helped real teams solve security challenges in live environments. You will not just see how tools work but understand where they fit, why they matter, and how to use them to make your own processes stronger. You will gain experience building policies into pipelines, securing Kubernetes clusters, scanning infrastructure code, and improving visibility across your cloud environments. You will also explore how to meet common compliance goals without adding extra overhead. Whether your focus is personal growth or helping your team work more securely and efficiently, this course will give you practical skills you can put to use right away.

Objectives

The goal of this course is to help you feel confident adding security into your development and deployment workflows without slowing things down. You will leave with practical, hands-on experience and a clear understanding of how to apply what you have learned in your own environment.

Here are six key skills you will build during the course:

  • Build secure pipelines by adding automated checks and scanners into your CI/CD tools like GitHub Actions and Jenkins.
  • Find and fix code vulnerabilities early using tools like SonarQube, OWASP ZAP, and Trivy in a repeatable and efficient way.
  • Harden containers and Kubernetes by setting up access controls, network policies, and runtime monitoring that protect your workloads.
  • Secure infrastructure as code using Terraform with scanning tools like Checkov and Tfsec to catch misconfigurations before deployment.
  • Improve visibility and response by setting up security monitoring with tools like AWS Config, GuardDuty, and Kubernetes log analysis.
  • Support compliance goals with practical ways to align your workflows to frameworks like NIST, ISO 27001, and OWASP Top 10 without adding extra work.

Throughout the course, you will get to apply these skills in real examples with everything already set up and ready to go, so you can focus on learning and practicing.

Audience

This course is designed for professionals who are already comfortable with modern DevOps workflows and are ready to start applying security practices throughout the software development lifecycle. It is a great fit for DevOps engineers, cloud engineers, developers, and security professionals who want to build real-world DevSecOps skills. You should be familiar with CI/CD tools, container basics, and working in cloud environments.

To get the most out of this course, you should already know how to:

  • Work with Git and understand basic version control workflows
  • Use Docker to build and run containers
  • Navigate Linux environments and write simple scripts in Bash or Python

Pre-Requisites

This course is designed for professionals who are already comfortable with modern DevOps workflows and are ready to start applying security practices throughout the software development lifecycle. It is a great fit for DevOps engineers, cloud engineers, developers, and security professionals who want to build real-world DevSecOps skills. You should be familiar with CI/CD tools, container basics, and working in cloud environments.

To get the most out of this course, you should already know how to:

  • Work with Git and understand basic version control workflows
  • Use Docker to build and run containers
  • Navigate Linux environments and write simple scripts in Bash or Python

Take Before: In order to gain the most from this course, you should have incoming skills equivalent to those in the course listed below, or should have attended this as a prerequisite:

Introduction to GitHub for Developers
Introduction to Linux / Linux Essentials

Agenda

Please note that this list of topics is based on our standard course offering, evolved from current industry uses and trends. We will work with you to tune this course and level of coverage to target the skills you need most. Course agenda, topics and labs are subject to adjust during live delivery in response to student skill level, interests and participation. The course tools, topics, use cases and hands-on labs can be adjusted to suit your specific needs, goals or requirements.

1: Introduction to DevSecOps and Secure Development Practices

Learn the foundations of DevSecOps and how to build security into your coding practices from day one.

  • Understand core DevSecOps principles
  • Explore secure SDLC and team culture
  • Review top security risks (OWASP Top 10)
  • Apply threat modeling and secure coding basics
  • Lab: Scan dependencies using OWASP Dependency-Check
  • Lab: Run static code analysis with SonarQube

2: CI/CD Pipeline Security and Automated Testing

Secure your pipelines by embedding automated testing and scanning tools into CI/CD workflows.

  • Design secure CI/CD pipelines
  • Implement SAST and DAST tools
  • Use SonarQube, Snyk, Trivy, and OWASP ZAP
  • Add security checks to pipeline stages
  • Lab: Add SAST to Jenkins or GitHub Actions
  • Lab: Run DAST scans with OWASP ZAP

3: Container Security and Kubernetes Hardening

Learn how to secure containerized apps and strengthen Kubernetes security.

  • Identify container security risks
  • Scan Docker images for vulnerabilities
  • Configure RBAC and network policies in Kubernetes
  • Monitor workloads with Falco and Sysdig
  • Lab: Scan containers using Trivy and Anchore
  • Lab: Apply Kubernetes RBAC and policies

4: Infrastructure-as-Code and Cloud Security Best Practices

Secure cloud environments using code and apply monitoring across platforms.

  • Scan Terraform with Checkov and Tfsec
  • Apply cloud security best practices (AWS, GCP, Azure)
  • Set up logging and alerts
  • Enforce policies using Sentinel or OPA
  • Lab: Secure Terraform deployments
  • Lab: Monitor cloud resources with AWS tools

5: Incident Response, Compliance, and Governance

Prepare for incidents, align with compliance, and automate policy enforcement.

  • Build incident response workflows
  • Use forensics and audit-ready logging
  • Map workflows to NIST, ISO 27001, SOC 2
  • Explore Zero Trust and maturity models
  • Lab: Respond to a simulated security incident
  • Lab: Enforce policies with Open Policy Agent

Connect with us

Tailor your learning experience with Trivera Tech. Whether you need a custom course offering or want to schedule a specific date and time for corporate training, we are here to help. Our team works with you to design a solution that fits your organization's unique needs; whether that is enrolling a small team or your entire department. Simply let us know how many participants you'd like to enroll and the skills you want to develop, and we will provide a detailed quote tailored to your request.

Contact Trivera Today to discuss how we can deliver personalized training that equips your team with the critical skills needed to succeed!