Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Coursera

Fundamentals of Secure Software Design

Starweaver via Coursera

Overview

Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates
Master secure software development with this hands-on application security training course built on OWASP best practices, threat modeling, and AI-powered security automation. Designed for developers, security engineers, tech leads, and architects, it teaches you to shift security left across the secure SDLC — starting with security-first principles (CIA Triad, Least Privilege, Zero Trust) and threat modeling using the STRIDE framework and DREAD scoring with GenAI-generated attack scenarios. You will apply OWASP Top 10 vulnerability prevention through SQL injection prevention, XSS prevention techniques, CSRF protection, and access control fixes, plus secure authentication patterns including OAuth 2.0 implementation, JWT security, bcrypt password hashing, secrets management best practices, and encryption, all through practical Python secure coding and JavaScript security labs. You will then build DevSecOps automation and enterprise secure software architecture skills: integrating SAST, DAST, and SCA tools (Bandit, Semgrep, OWASP ZAP, Snyk) into CI/CD security pipelines, refactoring insecure anti-patterns, and using GenAI for AI-powered code review and security test generation. Final modules cover OWASP API security, secure API design, microservices security, container security with Docker hardening, cloud security architecture, and cybersecurity governance through NIST SSDF training and ISO 27001 compliance. Every module includes vulnerable code labs and real breach analysis, culminating in a capstone secure architecture blueprint — so you leave with deployable secure coding patterns, pipeline configs, and policy templates, not just theory.

Syllabus

  • Security-First Engineering Mindset & Foundations
    • This module establishes foundational security principles and defensive thinking required for secure software design. Learners examine real-world breaches to understand why software gets hacked, master core security principles (CIA Triad, Least Privilege, Zero Trust), and conduct hands-on threat modeling using STRIDE and DREAD frameworks. GenAI tools augment threat identification by generating comprehensive attack scenarios. Students leave with practical skills to identify vulnerabilities before writing code.
  • Common Vulnerabilities & Secure Application Components
    • This module dives into the most critical security flaws plaguing modern applications through the OWASP Top 10 framework. Learners identify and mitigate injection attacks, broken access control, XSS, CSRF, and authentication vulnerabilities through hands-on code analysis and remediation. Students implement secure authentication flows, password storage, OAuth 2.0, secrets management, and encryption for data protection. Each lesson combines vulnerability exploitation understanding with practical secure coding techniques in Python and JavaScript, ensuring students can both recognize and prevent these flaws in production code.
  • Secure Coding, Testing & DevSecOps Automation
    • This module focuses on practical secure coding techniques and automated security testing integration. Learners apply OWASP Secure Coding Practices across multiple languages, identify and refactor common anti-patterns like insecure deserialization and hardcoded credentials, and implement secure error handling and logging. Students integrate automated security testing tools (SAST, DAST, SCA) into CI/CD pipelines using Bandit, Semgrep, OWASP ZAP, and Snyk. The module culminates with leveraging GenAI for intelligent code review, vulnerability detection, and security test generation while understanding AI limitations and risks.
  • Secure Architecture, Governance & Real-World Application
    • This module prepares students for enterprise-level secure software design by covering API security, cloud and container deployments, and cybersecurity governance. Learners apply OWASP API Security Top 10 principles to design secure RESTful and GraphQL APIs with proper authentication, rate limiting, and versioning. Students learn cloud shared responsibility models, container hardening, and Infrastructure as Code security. The module concludes with cybersecurity governance frameworks (NIST SSDF, ISO 27001), policy development, and complete secure architecture blueprints for real-world applications. Capstone project integrates all course concepts into comprehensive secure application design.

Taught by

Aseem Singhal and Professionals in the Industry

Reviews

Start your review of Fundamentals of Secure Software Design

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.