← Back to the catalogueDevSecOps
Classroom . Online . Hybrid
Mode
Course overview
A security-in-pipeline course: threat modelling, scanning, secrets management and compliance evidence. Security controls are added to a working pipeline stage by stage dependency scanning, static and dynamic analysis, image scanning, policy as code and secrets management with each control tuned to keep build times workable.
The course follows the twelve-session structure delivered inside the Cloud & DevOps master programme.
Who it is for
- DevOps and platform engineers
- Security engineers joining delivery teams
- Developers responsible for secure code
- Compliance and audit staff
Prerequisites
Git, Docker, one Cl tool and basic Linux security knowledge.
How it runs
Learn → Practise → Build → Experience → Demonstrate, ending in a capstone. Delivered by practitioners from the engineering bench, in Madurai, Coimbatore and online.
Final project
Secure Pipeline with Full Evidence Pack
Programme sheet
The printed sheet carries the full module breakdown, labs, project work and certification path. Fees, dates and formats for the next intake are confirmed by the education team on enquiry.
Learning outcomes
01
Model threats before code is written.
02
Gate builds on dependency and code scanning.
03
Scan and harden container images.
04
Manage secrets centrally with rotation.
05
Secure a Kubernetes cluster with RBAC and policies.
06
Apply cloud IAM and logging baselines.
07
Assemble audit evidence for ISO 27001, SOC 2 and PCI DSS.
Module structure
8 modulesModule 01
DevSecOps Foundations
DevOps vs DevSecOps . Shift-left security . Shared responsibility . Security culture . Pipeline overview
Lab
Secure Toolchain Setup
Requirements . Secure design . Threat modelling . Secure coding standards . Risk assessment
Module 03
Vulnerability Management
Assessment methodology . Baselines . Remediation workflow
Tools — OpenCV, Nmap, Nikto
Module 04
Secrets Management
Secret types . Storage . Rotation . Least privilege . Pipeline injection
Tools — HashiCorp Vault, AWS Secrets Manager, Azure Key Vault
Module 05
Dependency and Supply Chain
Third-party risk . SBOM . License compliance . Pinning and updates
Tools — Snyk, Trivy, Dependabot
Static analysis . OWASP Top 10 . Runtime scanning . API testing . Triage of findings
Tools — SonarQube, Semgrep, OWASP ZAP
Module 07
Container and Kubernetes Security
Image hardening . Signing . Runtime security . RBAC . Network policies . Admission control
Tools — Trivy, Kube-bench, Falco, Kyverno
Module 08
Cloud, Compliance and Integration
IAM baselines . Encryption and keys . Logging . Zero trust . ISO 27001 . SOC 2 . PCI DSS . Security gates in Cl/CD
Assessment & certification
Module assignments and labs
25%
Final project and review
40%
Learners who complete all modules, submit the final project and clear the review receive a course completion certificate from Kaizen Infinities Private Limited. Project work is documented for the learner's portfolio, and interview preparation is included in the closing sessions.
Career outcomes . Roles this programme prepares for
DevSecOps EngineerApplication Security EngineerCloud Security EngineerCompliance EngineerPlatform Security Lead