Practical Security Engineering for Tech Teams : OWASP Top 10, Containers, DevSecOps, AWS Security & AI with Security Reviews
Overview
Security vulnerabilities slip into production faster than teams can catch them. This 2-day workshop teaches developers, DevOps engineers, SREs, and security engineers to identify and remediate vulnerabilities across web applications, containers, cloud infrastructure, and AI/LLM applications. Learn to attack OWASP Top 10 vulnerabilities, exploit containers and harden images, attack AWS misconfigurations across multiple cloud services, integrate automated security testing into CI/CD pipelines via GitHub Actions and Jenkins, secure LLM applications against prompt injection, and then apply threat modelling to realistic architectures.
This workshop takes a progressive, hands-on approach. You will learn to attack OWASP Top 10 vulnerabilities, perform secure code review, exploit container isolation weaknesses, harden container images and supply chains, attack and secure AWS cloud infrastructure, automate vulnerability scanning and static analysis, integrate security into CI/CD workflows, secure LLM systems against prompt injection and RAG pipeline poisoning, and apply STRIDE threat modelling to web, cloud, and AI architecture.
All labs run in a browser-based environment with no local installation required. You leave with the full mdbook, the session recording, a certificate of completion, and complete lab documentation for ongoing reference and practice.
Format
- Duration: 2 days
- Timings: 09:00 – 18:00
- Delivery: online, live instructor-led
Labs
- Browser-based, running in GitHub Codespaces
- No local Docker or tool installation required
- Full mdbook with theory and step-by-step labs provided for reference after the training
Prerequisites
- AWS access: where a lab needs AWS, we provide pre-created credentials and environments as per that lab's requirement.
- Access and kit: a GitHub account, a laptop with a modern browser (Chrome, Firefox, or Edge), at least 4GB RAM, and a stable internet connection. No local Docker or tool installation needed.
- Mindset: curiosity and the willingness to research when you get stuck. Trainers guide every lab, and the material stays with you to revisit and extend afterwards.
- Technical comfort: familiarity with the command line and following step-by-step instructions is enough. No prior pentesting or container experience required.
- Environment: on Windows or Mac, make sure endpoint security, antivirus, and VPN are not blocking browser access to GitHub.
- Codespace access verified before day 1, using the setup instructions sent after registration.
Who This Is For
- You write and ship code, and keep getting security findings you cannot reproduce locally.
- You own the pipeline and have been asked to "add security scanning" with no brief beyond that.
- You run AWS or Kubernetes in production and have never attacked your own environment.
- You are moving into security from dev, ops or SRE and need hands-on proof, not just theory.
- You already review designs and want the whole attack chain end to end, not one flaw at a time.
Day 1
1. OWASP Top 10 (2025) Pentesting
- Lab: Set up the vulnerable app in Codespaces
- Lab: Burp Suite Community usage
- Lab: A01 Broken Access Control
- Lab: A02 Cryptographic Failures
- Lab: A03 Injection
- Lab: A04 Insecure Design
- Lab: A05 Security Misconfiguration
- Lab: A06 Vulnerable and Outdated Components
- Lab: A07 Identification and Authentication Failures
- Lab: A08 Software and Data Integrity Failures
- Lab: A09 Security Logging and Monitoring Failures
- Lab: A10 Server-Side Request Forgery
- Lab: Clean up the vulnerable app
2. Secure Code Review
- Theory: Reading code for injection and SSRF flaws
- Lab: OS command injection in Maintenance
- Lab: Server-side request forgery in Maintenance
3. Automated Source Code Review
- Theory: Static analysis in the review workflow
- Lab: Scanning with Opengrep
4. Container Security
4.1 Container fundamentals
- Theory: Linux namespaces and isolation
- Lab: Exploring namespace isolation
- Theory: Control groups and resource limits
- Lab: Preventing resource exhaustion
4.2 Runtime and privilege security
- Theory: Privileged vs non-privileged containers
- Lab: Privilege escalation and container escape
- Theory: Root vs non-root execution
- Lab: Read-only root filesystem
- Theory: Linux capabilities and seccomp
- Lab: Dropping unnecessary capabilities
4.3 Image security
- Theory: Vulnerable vs secure base images
- Lab: Scanning images with Trivy
4.4 Secrets and image layers
- Theory: Secrets in image layers
- Lab: Extracting secrets from images
- Lab: Moving secrets from env vars to secure mounts
5. Infrastructure as Code and its benefits
- Lab: Static IaC scanning with Checkov
Day 2
6. Software Composition Analysis (SCA)
- Theory: Dependency risk and transitive vulnerabilities
- Lab: Software composition analysis in Python (pip-audit)
- Lab: Remediating insecure dependencies
- Lab: Container SBOM with Syft and Grype
- Lab: Transitive dependency analysis
7. DevSecOps
- Theory: CICD security with Jenkins
- Lab: Set up the pipeline and add a secret scanning stage
- Lab: Add a SAST stage
- Lab: Add an SCA stage
- Lab: Add a DAST stage with ZAP and OSS Vulnerability Management
8. AWS Cloud Security
- Theory: IAM policies, roles and privilege escalation paths
- Lab: Basics of IAM policies
- Lab: Overly permissive IAM policies
- Lab: Attacking S3 buckets
- Lab: Attacking AWS WAF
- Lab: EC2 & ALB security
- Lab: AWS misconfiguration challenges
9. AI Security
- Theory: Prompt injection
- Lab: AI prompt injection
- Lab: Defending prompt injection with LLM Guard
- Theory: RAG pipeline poisoning
- Lab: Poisoning a RAG pipeline
- Lab: RAG pipeline defence
- Theory: AI BOM
- Lab: Generating an AI BOM
10. Threat Modelling & Security Review
- Theory: Threat modelling and security review
- Lab: Threat modelling and security review of a FinTech application
- Lab: Assisted security review using Claude skills
Wrap-up
Why This Training
- Labs, not slides: 45 named labs across 10 sections. Theory appears where it is needed to do the next lab, not as a lecture block.
- Nothing to install: Everything runs in GitHub Codespaces in a browser. No Docker on your laptop, no VM, no corporate-laptop fight.
- Attack and then fix: Every exploited flaw is followed by the remediation, so you leave with both halves rather than a list of scary demos.
- You keep the book: The full mdbook stays with you after the training, so the labs are repeatable when you actually need them at work.
What This Training Does Not Cover
- A guaranteed job, promotion, or salary bump. The certificate proves you did the work; it does not replace doing the work at your job.
- A magic fix for your organisation's security posture. You leave with a working method, not a finished audit of your company.
- Coding from scratch or a data science course. Labs use realistic, deliberately vulnerable applications you attack and fix, not applications you build.
- One-on-one mentoring during the batch. Instructors run the room; book a 1:1 session separately for individual coaching.
Included with the training
- Certificate of completion: issued after you complete the training
- Full mdbook: theory and step-by-step labs, to keep and revisit
- Session recording
- Cloud security interview question repository
Free career and interview workshop for participants
A free workshop, once a month, open to anyone who has attended any Peachycloud Security training. Group format, not one-to-one. No expiry and no booking required. One session a month, whoever joins, joins.
The topic rotates each month, for example:
- Interview questions and discussion
- Resume and profile review
- Mock interview hot seat
- How to talk about your projects in an interview
One-to-one sessions are available separately, booked through Topmate.
Discount
- Early bird: 20% (first 10 seats)
- Group: 10% (3 or more booking together)
- Student / fresher: 50% (student id or <2 years experience)
Discounts do not stack. Where more than one applies, the lower price is used.
FAQ
- Do I need my own AWS account? No. The AWS labs run in environments we provide, and the rest runs in GitHub Codespaces. You need a GitHub account and a browser.
- Is it beginner-friendly? Yes, if you are comfortable on the command line and can follow step-by-step instructions. You do not need prior security experience: each section starts from the fundamentals before the labs get adversarial.
- What if I miss a day? You get the session recording and the full mdbook, so you can work through what you missed. We do not routinely reschedule or extend sessions.
- How long do I keep the recording and the book? The mdbook is yours to keep. The recording is shared after the batch and stays available to attendees.
- Can I get a refund? Fees are non-refundable. If you cannot attend for documented medical reasons you can request to transfer your seat to another person, chargeable at 10% of the fee and subject to written approval. Full terms are on the refund and cancellation policy page.
Will the batch definitely run? The batch runs with a minimum of 2 participants and is capped at 35. If it cannot run we contact you before the date.