DevSecOps Crash Course

Shramik Awale

profile
Best Seller
DevSecOps Crash Course
profile
Courses

📘 DevSecOps Crash Course

Duration: 8–10 Weeks (40–50 Hours)

Level: Beginner

🗓️ Week 1 – DevSecOps Foundations

Theory

  1. DevOps vs DevSecOps
  2. Secure SDLC & Shift-Left security
  3. CIA Triad, Least Privilege, Defense in Depth
  4. OWASP Top 10 overview

Hands-On

  1. Install Git, Docker, Python, VS Code
  2. Linux VM or AWS EC2 setup
  3. GitHub repo creation

Outcome

  1. Understand DevSecOps mindset & security basics

🗓️ Week 2 – Programming & Automation for Security

Theory

  1. Python basics for security automation
  2. Bash scripting fundamentals
  3. Secure Git workflows

Hands-On

  1. Python password strength checker
  2. Bash security audit script
  3. Git secret scanning with Gitleaks
  4. Pre-commit hooks setup

Outcome

  1. Automate basic security checks

🗓️ Week 3 – Networking & Infrastructure Security

Theory

  1. TCP/IP, DNS, HTTP vs HTTPS
  2. TLS & certificates
  3. Firewalls & network segmentation

Hands-On

  1. Network scanning with Nmap
  2. Packet analysis with Wireshark
  3. Linux firewall (UFW) & AWS Security Groups

Outcome

  1. Identify & secure network attack surfaces

🗓️ Week 4 – Application Security

Theory

  1. OWASP Top 10 deep dive
  2. Secure coding practices
  3. Encryption & hashing basics

Hands-On

  1. Vulnerable app testing (OWASP Juice Shop)
  2. DAST using OWASP ZAP
  3. Fix common web vulnerabilities

Outcome

  1. Secure applications against common attacks

🗓️ Week 5 – Container & Kubernetes Security

Theory

  1. Docker & container security risks
  2. Kubernetes security architecture
  3. RBAC & Pod Security

Hands-On

  1. Secure Dockerfile creation
  2. Image scanning with Trivy
  3. Kubernetes security checks (kube-bench, kube-hunter)

Outcome

  1. Secure containerized workloads

🗓️ Week 6 – AWS Cloud Security

Theory

  1. AWS Shared Responsibility Model
  2. IAM, MFA & Least Privilege
  3. Zero Trust concepts

Hands-On

  1. IAM roles & policies
  2. Enable CloudTrail
  3. AWS security audit using Prowler / ScoutSuite
  4. S3 encryption

Outcome

  1. Secure AWS cloud environments

🗓️ Week 7 – CI/CD Pipeline Security

Theory

  1. CI/CD concepts
  2. Supply chain security
  3. SBOM importance

Hands-On

  1. GitHub Actions pipeline
  2. SAST (Semgrep)
  3. SCA (OWASP Dependency-Check)
  4. Secrets scanning (Gitleaks)
  5. SBOM generation (Syft)

Outcome

  1. Build secure CI/CD pipelines

🗓️ Week 8 – Threat Modeling & Risk Management

Theory

  1. STRIDE threat modeling
  2. Risk assessment & CVSS
  3. Vulnerability management lifecycle

Hands-On

  1. Threat modeling using OWASP Threat Dragon
  2. Vulnerability scan with OpenVAS
  3. Risk prioritization report

Outcome

  1. Identify & manage security risks

🗓️ Week 9 – Monitoring & Incident Response

Theory

  1. SIEM concepts
  2. Incident Response lifecycle
  3. Security automation (SOAR basics)

Hands-On

  1. Wazuh agent deployment
  2. Log analysis & alert simulation
  3. Incident response playbook

Outcome

  1. Detect & respond to security incidents

🗓️ Week 10 – Governance, Compliance & Capstone

Theory

  1. NIST CSF & CIS Benchmarks
  2. Security policies & governance
  3. DevSecOps career roadmap

Hands-On

  1. CIS benchmark mapping
  2. Policy documentation
  3. Final project demo:
  4. Secure app
  5. CI/CD security
  6. AWS deployment
  7. Monitoring & reports

Outcome

  1. Job-ready DevSecOps skillset + portfolio

🎓 Final Deliverables

  1. Secure application
  2. CI/CD pipeline with security gates
  3. AWS security audit report
  4. Incident response plan
  5. GitHub portfolio
$500