- Technology
- Cloud Computing
- Amazon Web Services (AWS)
- AWS Containers
- Amazon Elastic Container Registry (ECR)
- Technology
- Cloud Computing
- Amazon Web Services (AWS)
- AWS Security, Identity & Compliance
- AWS Identity and Access Management
- Technology
- Cloud Computing
- Amazon Web Services (AWS)
- AWS Security, Identity & Compliance
- Amazon Inspector
DevSecOps: Secure CI/CD Pipelines and Cloud Security
Edureka via Coursera Specialization
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
A security review at the end of a release finds problems when they cost the most to fix. This Specialization covers DevSecOps as engineering rather than policy: controls automated inside the pipeline, running on every commit. It spans code, dependencies, containers, infrastructure, cloud, and runtime.
You start with shift-left principles and Security as Code, then run SAST with SonarQube and Semgrep, DAST with OWASP ZAP, and dependency scanning. You add container scanning with Trivy, infrastructure scanning with Checkov, policy enforcement with OPA, and secrets in Vault, then secure an AWS pipeline and add Falco detection and AIOps monitoring.
By the end of this Specialization, you will be able to:
• Apply shift-left security and Security as Code in the SDLC.
• Run SAST, DAST, and dependency scanning in CI/CD.
• Scan containers and infrastructure code with Trivy and Checkov.
• Enforce policy as code with OPA and manage secrets in Vault.
• Secure AWS delivery with IAM, ECR, and Inspector.
• Detect runtime threats with Falco and flag anomalies.
This Specialization suits DevOps engineers, security engineers, cloud engineers, platform engineers, and developers who own delivery pipelines, plus SREs adding security controls. It assumes Git, CI/CD, and Linux familiarity, and no prior security tooling experience.
Enroll now to automate security into every stage of your pipeline.
Syllabus
- Course 1: DevSecOps Foundations and Application Security
- Course 2: Container and Infrastructure Security Automation
- Course 3: Cloud-Native Security and AIOps for DevSecOps
Courses
-
Build practical skills to secure cloud-native DevSecOps environments, detect runtime threats, verify software artifact integrity, and apply AIOps for intelligent monitoring and incident response. You will work with AWS IAM, Secrets Manager, Terraform, Checkov, Amazon ECR, Inspector, Falco, Syft, Cosign, Prometheus, Grafana, Elasticsearch, and Python-based AI techniques. The course progresses from securing cloud identities, secrets, infrastructure, and container images to monitoring runtime behavior and validating trusted software artifacts. You will then apply anomaly detection, log analysis, security-event correlation, predictive monitoring, and Generative AI to support DevSecOps operations. Hands-on demonstrations help you investigate abnormal behavior, forecast emerging reliability issues, correlate operational and security evidence, and generate evidence-based remediation recommendations. By the end of the course, you will be able to combine preventive security, runtime detection, software supply chain protection, and AI-assisted operations into an integrated DevSecOps security workflow.
-
This course takes you from securing CI/CD pipelines and application code to protecting containers, infrastructure, and secrets, building practical skills to integrate security controls throughout modern DevSecOps workflows. You'll begin with CI/CD security, learning how pipeline stages work and where security controls can be integrated across the software delivery process. You'll explore static code analysis, security findings, and dependency vulnerability risks, along with techniques for identifying weaknesses in source code and third-party components. From there, the course moves into repository and application security. You'll learn how software composition analysis helps identify vulnerable dependencies and how secrets detection helps prevent sensitive information from being exposed in repositories. You'll then explore Dynamic Application Security Testing (DAST), including scan scope, targets, exclusions, and different scan modes for testing running applications. The course then advances into container security, where you'll examine common container threats and learn how image and dependency scanning can identify vulnerabilities. You'll apply these techniques to strengthen application and container protection within CI/CD workflows. Finally, you'll focus on Infrastructure as Code and secrets security. You'll identify infrastructure attack surfaces and common misconfigurations, validate infrastructure before provisioning, and apply IaC scanning and policy enforcement. You'll also explore secrets management, access policies, and secret lifecycles to protect sensitive information across DevSecOps environments. By the end of this course, you will be able to: • Explain CI/CD pipeline stages, security architecture, and security control placement. • Analyze source code and dependencies to identify vulnerabilities and supply chain risks. • Implement repository security practices to detect exposed secrets. • Perform dynamic security testing to identify application vulnerabilities. • Scan container images and dependencies to identify security vulnerabilities. • Apply IaC scanning and policy enforcement to secure infrastructure configurations. • Manage secrets, access policies, and secret lifecycles across DevSecOps environments. Designed for DevOps professionals, software developers, cloud professionals, and security professionals, this course provides a structured path from CI/CD security fundamentals to practical application, container, infrastructure, and secrets protection. To be successful here, you should have a basic understanding of DevSecOps foundations, CI/CD concepts, Git, containers, software development, and command-line operations. Prior experience with advanced security tools or practices is not required, as the course introduces them through guided practical activities. Build the skills to secure software delivery from code to infrastructure, protecting applications, containers, repositories, and secrets across modern DevSecOps environments.
-
This course takes you from the foundations of DevSecOps and shift-left security to Secure SDLC, application security testing, and software supply chain security, building a strong foundation for integrating security throughout software development. You'll begin with DevSecOps foundations, exploring the security challenges associated with traditional DevOps and how DevSecOps brings security into development and operations. You'll learn about shared responsibility, core DevSecOps principles, Security as Code, shift-left security, and the role of automation in supporting consistent security practices. From there, the course moves into the Secure Software Development Lifecycle. You'll explore how security can be integrated across SDLC phases, how earlier security feedback can reduce late-stage issues, and why the timing of security activities matters. You'll also examine Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) and how they contribute to application security at different stages of development. The course then focuses on application security risks, including common vulnerability types and the OWASP Top 10. You'll explore how vulnerability identification standards provide a consistent way to describe and track security weaknesses and how these concepts support application security practices. Finally, you'll explore software supply chain and dependency security, including the risks introduced through open-source components and third-party dependencies. You'll learn how Software Composition Analysis helps identify vulnerable components, examine relevant vulnerability information, and support appropriate remediation decisions. By the end of this course, you will be able to: - Explain DevSecOps principles, shared responsibility, shift-left security, and Security as Code. - Describe how security practices and feedback mechanisms integrate across the Secure SDLC. - Discuss the roles of SAST and DAST across the software development lifecycle. - Perform static security scanning to identify vulnerabilities and security issues in application code. - Identify common application vulnerabilities, OWASP Top 10 risks, and vulnerability standards. - Outline how Software Composition Analysis supports dependency vulnerability identification and secure software development. Designed for aspiring DevOps professionals, software developers, and security professionals, this course provides a structured path from DevSecOps principles and Secure SDLC practices to application and software supply chain security. To be successful here, you should have familiarity with software development concepts, DevOps practices, CI/CD fundamentals, Git, and Linux shell commands. Prior experience with application security testing or specialized security tools is not required, as the relevant concepts and techniques are introduced throughout the course. Build the foundation to integrate security throughout software development, identify application and dependency risks earlier, and support secure software delivery through DevSecOps and Secure SDLC practices.
Taught by
Edureka