← Back to the catalogue
Domain 05 . Security

DevSecOps

25
Hours of teaching
Advanced
Level
8
Modules
Classroom . Online . Hybrid
Mode
Course overview

A security-in-pipeline course: threat modelling, scanning, secrets management and compliance evidence. Security controls are added to a working pipeline stage by stage dependency scanning, static and dynamic analysis, image scanning, policy as code and secrets management with each control tuned to keep build times workable.

The course follows the twelve-session structure delivered inside the Cloud & DevOps master programme.

Who it is for
  • DevOps and platform engineers
  • Security engineers joining delivery teams
  • Developers responsible for secure code
  • Compliance and audit staff
Prerequisites
Git, Docker, one Cl tool and basic Linux security knowledge.
How it runs
Learn → Practise → Build → Experience → Demonstrate, ending in a capstone. Delivered by practitioners from the engineering bench, in Madurai, Coimbatore and online.
Final project
Secure Pipeline with Full Evidence Pack

Programme sheet

The printed sheet carries the full module breakdown, labs, project work and certification path. Fees, dates and formats for the next intake are confirmed by the education team on enquiry.

Learning outcomes

01
Model threats before code is written.
02
Gate builds on dependency and code scanning.
03
Scan and harden container images.
04
Manage secrets centrally with rotation.
05
Secure a Kubernetes cluster with RBAC and policies.
06
Apply cloud IAM and logging baselines.
07
Assemble audit evidence for ISO 27001, SOC 2 and PCI DSS.

Module structure

8 modules
Module 01

DevSecOps Foundations

DevOps vs DevSecOps . Shift-left security . Shared responsibility . Security culture . Pipeline overview
Lab
Secure Toolchain Setup
Module 02

Secure SDLC

Requirements . Secure design . Threat modelling . Secure coding standards . Risk assessment
Lab
Threat Model
Module 03

Vulnerability Management

Assessment methodology . Baselines . Remediation workflow
Tools — OpenCV, Nmap, Nikto
Module 04

Secrets Management

Secret types . Storage . Rotation . Least privilege . Pipeline injection
Tools — HashiCorp Vault, AWS Secrets Manager, Azure Key Vault
Module 05

Dependency and Supply Chain

Third-party risk . SBOM . License compliance . Pinning and updates
Tools — Snyk, Trivy, Dependabot
Module 06

SAST and DAST

Static analysis . OWASP Top 10 . Runtime scanning . API testing . Triage of findings
Tools — SonarQube, Semgrep, OWASP ZAP
Module 07

Container and Kubernetes Security

Image hardening . Signing . Runtime security . RBAC . Network policies . Admission control
Tools — Trivy, Kube-bench, Falco, Kyverno
Module 08

Cloud, Compliance and Integration

IAM baselines . Encryption and keys . Logging . Zero trust . ISO 27001 . SOC 2 . PCI DSS . Security gates in Cl/CD

Assessment & certification

Module assignments and labs
25%
Internal assessments
15%
Mini projects
20%
Final project and review
40%

Learners who complete all modules, submit the final project and clear the review receive a course completion certificate from Kaizen Infinities Private Limited. Project work is documented for the learner's portfolio, and interview preparation is included in the closing sessions.

Career outcomes . Roles this programme prepares for
DevSecOps EngineerApplication Security EngineerCloud Security EngineerCompliance EngineerPlatform Security Lead
Enquire or apply →Programme sheet (PDF)Institutions can commission a cohort

Also in Security