Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates
In this advanced-level course, you will learn to embed security directly into the software development lifecycle, transforming how your organization builds and deploys applications. You'll move beyond traditional development practices to automate security by gating Infrastructure-as-Code (IaC) pipelines, embedding SAST/DAST scanning, and continuously monitoring control baselines to ensure ongoing compliance. You'll leverage generative AI and manual frameworks to lead comprehensive threat-modeling workshops, identifying potential attack vectors before they impact production. You'll also engineer secure containerized and Kubernetes environments, aligning workload protection and orchestration controls with established cloud landing zones, and design AI-enhanced security gates within Jenkins and GitHub Actions to prevent AI-related attack vectors throughout the software delivery lifecycle.
This course is for security engineers, DevOps professionals, and software architects with familiarity with the SDLC, basic CI/CD pipeline automation, and introductory experience with application or infrastructure security testing. By the end of this course, you will be able to lead threat-modeling workshops to derive security requirements and structure control gates across complex systems; operationalize SAST, DAST, SCA, and secret-scanning within CI/CD and IaC pipelines to enforce risk-based gating; engineer secure containerized and Kubernetes environments aligned with established cloud landing zones; and design AI-enhanced security gates within Jenkins and GitHub Actions to prevent AI-related attack vectors across the software delivery lifecycle.
This course works with tools across the DevSecOps ecosystem, including GitHub Advanced Security for secret scanning and code analysis, the free Microsoft Threat Modeling Tool which are available for public repositories. GitHub Advanced Security features, including Code Security and Secret Protection, require a paid license for private repositories.