Get in Touch

Course Outline

Overview of the Software Development Life Cycle (SDLC) and Secure SDLC Frameworks

Implementation of SDLC Automation through Continuous Delivery/Continuous Deployment (CD/CD) Methodologies

Alignment of SDLC with DevOps Integration Strategies

Automated, Integrated, and Secured SDLC Processes via DevSecOps Practices

Application of OWASP Tools within the DevSecOps Ecosystem

Threat Modeling Utilizing OWASP Threat Dragon

SBOM Implementation via OWASP CycloneDX

Automated Vulnerability Detection Using OWASP Dependency-Track

Management of the Vulnerability Lifecycle Through OWASP DefectDojo

Integration of Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) into Software Delivery Pipelines

The curriculum incorporates practical application with industry-standard tools designed to support secure SDLC and DevSecOps for government and public sector operations, including:

  • Threat Modeling: OWASP Threat Dragon
  • Software Bill of Materials (SBOM): OWASP CycloneDX
  • Vulnerability Assessment: OWASP Dependency-Track
  • Vulnerability Lifecycle Management: OWASP DefectDojo
  • CI/CD Pipeline Platforms: Jenkins, GitHub Actions, and GitLab CI/CD
  • Security Testing Solutions: Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) technologies

This program offers several core advantages, supporting professionals seeking to advance their capabilities in secure software engineering:

Strengthened Security Competency – Develop expertise in embedding security controls throughout the SDLC, DevOps, and CI/CD environments.
Practical Application – Engage with leading OWASP tools to facilitate security automation and effective vulnerability management for government initiatives.
Professional Advancement – Acquire high-demand skills in Secure SDLC and DevSecOps to expand career opportunities within the public sector.
Regulatory Compliance and Risk Reduction – Learn to implement security measures that align with standards such as ISO 27001, NIST, and GDPR.
Operational Efficiency – Automate security verification processes to minimize manual workload while enhancing overall application security posture.
Strategic Advantage – Enable organizations to identify and mitigate vulnerabilities early in the development lifecycle, reducing costs and delays associated with late-stage remediation.

This training represents a strategic investment for professionals and agencies aiming to establish secure, resilient, and compliant software solutions for government use.

Requirements

To ensure maximum benefit from this curriculum, attendees must meet the following baseline requirements:

  1. A foundational grasp of software engineering lifecycle principles and development processes.
  2. Working knowledge of DevOps frameworks and continuous integration/continuous deployment (CI/CD) workflows.
  3. Familiarity with core cybersecurity tenets and industry-standard security protocols.
  4. While not mandatory, prior practical experience with cloud-native or on-premises development setups is advantageous.

To actively participate in the laboratory exercises and tool integration modules, users must maintain access to the following services:

  • GitHub or GitLab (Free tier) – Necessary for establishing CI/CD workflows and DevSecOps automation tasks.
  • Cloud-based DevOps Infrastructure (optional) – Such as AWS, Azure, or GCP, if the curriculum includes cloud deployment scenarios.
  • Docker (optional) – Required only if local containerized environments are utilized.

This program is tailored for personnel responsible for software engineering, information security, and DevOps operations, including:

  • Software Developers – To embed security controls within the coding lifecycle.
  • DevOps Engineers – To automate security enforcement within CI/CD pipelines.
  • Security Engineers – To deploy and supervise secure development operations.
  • Application Security Specialists – To improve security testing and vulnerability remediation capabilities.
  • QA Engineers – To incorporate security validations into automated test suites.
  • IT Leaders & Architects – To design and govern secure software delivery processes, particularly for government
 28 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories