Introduction
Welcome to the DevSecOps course! This course will guide you through the fundamentals and advanced concepts of DevSecOps.
Welcome to the DevSecOps course! This course will guide you through the fundamentals and advanced concepts of DevSecOps.
Learn the difference between DevSecOps and DevOps, and why integrating security into the DevOps pipeline is crucial.
Understand the roles and responsibilities of a DevSecOps Engineer, including key skills and day-to-day tasks.
Learn about Static Application Security Testing (SAST) and tools like SonarQube, Fortify, and Checkmarx.
Watch a demo of how to perform SAST scans using popular tools.
Learn about Software Bill of Materials (SBOM) and Software Composition Analysis (SCA) tools like Snyk and Dependency-Check.
Watch a demo of how to perform SCA scans using popular tools.
Learn about Dynamic Application Security Testing (DAST) and tools like OWASP ZAP and Burp Suite.
Watch a demo of how to perform DAST scans using popular tools.
Learn about container security and tools like Trivy, Anchore, and Clair.
Watch a demo of how to secure container images using popular tools.
Learn about Infrastructure as Code (IAC) security and tools like Checkov and Terraform.
Watch a demo of how to secure IAC using popular tools.
Learn about Common Weakness Enumeration (CWE), Common Vulnerabilities and Exposures (CVE), and Common Vulnerability Scoring System (CVSS).
Learn about FPA (First Party Access) and its importance in security.
Watch a demo of how to implement FPA in your security practices.
Learn how to report security vulnerabilities in JIRA.
Understand the DevSecOps Maturity Model and how to assess your organization's maturity level.
Learn the basics of Docker and containerization.
Watch a demo of how to perform SAST scans using Docker.
Learn the basics of Git and GitHub for version control.
Learn about IDE plugins for security, such as SonarLint and Snyk.
Watch a demo of how to use Git for version control.
Watch a demo of how to use two popular IDE plugins for security.
Learn the basics of CI/CD tools like Jenkins, GitHub Actions, and GitLab CI.
Learn how to install and set up a popular CI/CD tool.
Learn how to implement a complete DevSecOps pipeline using GitHub Actions and GitOps with ArgoCD.
Learn tips and strategies for finding a security job in the market.
Learn how to create a professional CV for security jobs.
Explore additional resources and bonus content to enhance your DevSecOps skills.