Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Microsoft

Application and DevSecOps

Microsoft via Coursera

Overview

Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates
In this advanced-level course, you will learn to embed security directly into the software development lifecycle, transforming how your organization builds and deploys applications. You'll move beyond traditional development practices to automate security by gating Infrastructure-as-Code (IaC) pipelines, embedding SAST/DAST scanning, and continuously monitoring control baselines to ensure ongoing compliance. You'll leverage generative AI and manual frameworks to lead comprehensive threat-modeling workshops, identifying potential attack vectors before they impact production. You'll also engineer secure containerized and Kubernetes environments, aligning workload protection and orchestration controls with established cloud landing zones, and design AI-enhanced security gates within Jenkins and GitHub Actions to prevent AI-related attack vectors throughout the software delivery lifecycle. This course is for security engineers, DevOps professionals, and software architects with familiarity with the SDLC, basic CI/CD pipeline automation, and introductory experience with application or infrastructure security testing. By the end of this course, you will be able to lead threat-modeling workshops to derive security requirements and structure control gates across complex systems; operationalize SAST, DAST, SCA, and secret-scanning within CI/CD and IaC pipelines to enforce risk-based gating; engineer secure containerized and Kubernetes environments aligned with established cloud landing zones; and design AI-enhanced security gates within Jenkins and GitHub Actions to prevent AI-related attack vectors across the software delivery lifecycle. This course works with tools across the DevSecOps ecosystem, including GitHub Advanced Security for secret scanning and code analysis, the free Microsoft Threat Modeling Tool which are available for public repositories. GitHub Advanced Security features, including Code Security and Secret Protection, require a paid license for private repositories.

Syllabus

  • Threat Modeling: Operationalize Secure Design
    • Before modeling a specific threat, an architect must establish the baseline security requirements for the enterprise. Learn how to define and operationalize secure-by-design principles that apply to all new software projects.
  • Threat Modeling: Scope and Methodology
    • A threat modeling session without a clear scope is guaranteed to fail. Learn to gather the right stakeholders, define the boundaries of the system being modeled, and select the appropriate methodology.
  • Threat Modeling: Spearhead Workshops
    • Put theory into practice. Learn to use the Microsoft Threat Modeling Tool (TMT) to draw Data Flow Diagrams, define trust boundaries, and automatically generate a matrix of architectural threats.
  • DevSecOps: Embed SAST and DAST
    • Learn the difference between Static, Dynamic, and Software Composition Analysis, and how to embed them into GitHub Actions to automatically scan pull requests for vulnerabilities.
  • DevSecOps: Secure Container Environments
    • Container security spans both the pipeline and runtime. Learn to design architectures that scan images in the registry and enforce admission control policies in Kubernetes.
  • DevSecOps: Gate IaC Pipelines
    • Infrastructure is now code, meaning cloud misconfigurations and leaked secrets can be deployed instantly. Learn to scan Terraform templates and block exposed keys directly at the commit level.
  • GenAI Module: The Danger of Prompt Injection
    • Generative AI introduces new application data flows and trust boundaries. In this module, you will update your Secure-by-Design standards to account for the OWASP Top 10 for LLMs. You will threat model an internal Copilot application to identify Prompt Injection vulnerabilities, and then architect the solution by mandating the integration of Azure AI Content Safety (Prompt Shields) into the application request path before LLM invocation, such as the API gateway or orchestration layer, alongside strict CI/CD pipeline validation gates.
  • Project Module: DevSecOps Pipeline
    • Synthesize your knowledge of threat modeling, SAST/DAST, strategic DAST placement, containers, and automated gating to design a secure DevSecOps pipeline architecture. You will document where security validation and control gates must be enforced across the Software Development Lifecycle (SDLC) to mitigate risks while minimizing unnecessary friction with engineering.

Taught by

Microsoft

Reviews

Start your review of Application and DevSecOps

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.