| Nivo: | For IT professionals |
| Prodajalec: | EC-Council |
| Teme: | Security, Developer |
| Trajanje (dni): | 3 |
| Ur/dan: | 8 |
| Tip učenja: | Preko spleta |
| Cena: | 2.350 € + DDV |
EC-Council’s Certified DevSecOps Engineer (ECDE) course covers both application and infrastructure security across on-premises environments and leading cloud-native platforms. It features the latest DevSecOps concepts, AI-powered tools, and practices, addressing security considerations across all 8 stages of the DevOps lifecycle. With 70% hands-on labs (100+ online and offline labs), this program aligns with the real-world roles and responsibilities of a DevSecOps
engineer. It helps professionals effectively mitigate cybersecurity risks while shifting left and securing development pipelines in AWS, Azure, and GCP.
Who should attend
This program is designed to build in-demand skills for the following job roles:
-
DevSecOps Engineer / Senior DevSecOps Engineer
-
Cloud DevSecOps Engineer (Azure / AWS)
-
DevSecOps Analyst / Specialist
-
DevSecOps Systems Administrator / System Engineer
-
DevSecOps Consultant
-
DevSecOps CI/CD Engineer
-
Infrastructure DevSecOps Engineer
-
Application Security Professionals and DevOps Engineers
What will you learn
-
AI-Powered Tools: Leverage AI-driven tools for the DevOps/DevSecOps pipeline, secure code review, and SAST.
-
Security Across 8 DevOps Stages: Integrate security into the plan, code, build, test, deploy, release, operate, and monitor stages.
-
On-Premises & Cloud-Native Security: Build expertise in security native development and deployment across internal IT infrastructure and public clouds (AWS, Azure, GCP).
-
Automated Security Testing: Implement automated testing methods including SAST (Snyk, SonarQube, Checkmarx), DAST (StackHawk, OWASP ZAP, Invicti), IAST (CxFlow, Invicti Shark), and RASP (Contrast Security, Datadog, Dynatrace).
-
Software Composition Analysis (SCA): Utilize tools like Debricked, Mend, and OWASP Dependency-Check.
-
Pipeline Integration: Integrate Eclipse, GitHub, Jira, and Confluence with Jenkins to create secure CI/CD pipelines.
-
Threat Modeling: Align security practices with workflows using tools like Threat Dragon, ThreatModeler, and Threatspec.
-
Continuous Scanning & Penetration Testing: Use Nessus, Amazon Macie, Probely, GitGraber, Gitleaks, and GitMiner to detect and remediate vulnerabilities early.
Course Objectives
-
Master DevSecOps Culture: Understand DevOps principles and foster collaboration between Dev, Sec, and Ops teams.
-
Implement "Shift-Left" Security: Seamlessly embed security controls across all 8 stages of the DevOps lifecycle.
-
Build Secure CI/CD Pipelines: Integrate threat modeling, secure code reviews, and automated workflows.
-
Automate Security Testing: Apply SAST, DAST, IAST, and SCA tools to detect and mitigate vulnerabilities early.
-
Secure Cloud & Infrastructure: Protect on-premises and cloud environments (AWS, Azure, GCP) using Infrastructure as Code (IaC) and container security.
-
Enable Continuous Monitoring: Deploy RASP and automated vulnerability scanners for real-time application protection.
Key Features and Critical Components of the ECDE Program
-
70% Hands-on Labs: Over 100 practical exercises simulating real-world CI/CD pipeline security.
-
AI-Powered Tools: Leveraging AI for intelligent secure code reviews and automated vulnerability detection.
-
Full 8-Stage Lifecycle: Seamless security integration across all DevOps phases (Plan, Code, Build, Test, Release, Deploy, Operate, Monitor).
-
App & Infra Security: Securing both the application source code and the underlying container/server environments.
-
Cloud & On-Premises: Native security deployment across AWS, Azure, GCP, and internal IT infrastructures.
-
Automated Security Testing: Practical implementation of SAST, DAST, IAST, RASP, and SCA methodologies.
Course Content
MODULE 01: Understanding DevOps Culture
-
DevOps Fundamentals
-
Understanding CI/CD pipeline concepts and operations
-
DevOps Maturity Models
-
Benefits and challenges of DevOps implementation and DevOps in cloud environments
-
The importance of collaboration culture, communication, and feedback loops for faster and more reliable software delivery
MODULE 02: Introduction to DevSecOps
-
Security challenges in DevOps environments
-
Integrating security into DevOps (Shift-Left approach and principles)
-
Establishing a DevSecOps culture within an organization
-
Components of the DevSecOps pipeline (automation, monitoring, feedback)
-
Deployment strategies, tools, and models (e.g., Blue-Green Deployment)
MODULE 03: DevSecOps Pipeline—Plan Stage
-
Identifying security requirements and security-focused planning
-
Threat Modeling Concepts
-
Continuous Integration and Pre-Commit code evaluation
-
Secret Management Tools
-
Collaboration between development, security, and operations teams (Dev, Sec, Ops)
MODULE 04: DevSecOps Pipeline—Code Stage
-
Reviewing and scanning code repositories
-
Implementing security controls within Integrated Development Environments (IDEs)
-
Secure coding guidelines according to industry best practices
-
Developer extensions and plugins (tools for identifying vulnerabilities during the coding process)
MODULE 05: DevSecOps Pipeline—Build and Test Stage
-
"Security by Design" concepts and Code Review Strategies
-
Integrating code repositories with security tools
-
SAST (Static Application Security Testing) concepts and tools (e.g., Snyk, SonarQube)
-
DAST (Dynamic Application Security Testing) concepts and tools
-
IAST (Interactive Application Security Testing)
-
SCA (Software Composition Analysis) for analyzing open-source components and dependencies
MODULE 06: DevSecOps Pipeline—Release and Deploy Stage
-
RASP (Runtime Application Self-Protection) concepts and tool capabilities
-
Vulnerability Assessment and Penetration Testing (VAPT) strategies
-
Infrastructure as Code (IaC) concepts and tools (Ansible, Terraform, etc.)
-
Containerization concepts (Docker, Kubernetes) and container security challenges
-
Security best practices for secure application deployment to production environments
MODULE 07: DevSecOps Pipeline—Operate and Monitor Stage
-
Logging concepts and Continuous Monitoring
-
Incident detection and rapid response
-
Compliance as Code Tools
-
Continuous security monitoring using SIEM (Security Information and Event Management) tools
-
Integrating alerting tools and improving the efficiency of security operations
Prerequisites
-
Intermediate application security knowledge. Participants should have a foundational understanding of DevOps principles, cloud concepts, and general cybersecurity practices before attending this specialist-level program.
Location: Housing Pearson Vue test center Ljubljana and Zagreb
Enrollement: at Housing EC-Council test center via email
Official web page: eccouncil.org
Price: The certificate is included in the course fee.
About Exam
The ECDE certification exam validates your practical expertise in implementing a security-first approach across modern software development pipelines. Passing the exam proves your capability to build secure and resilient applications from the ground up.
-
Format: 100 Multiple-Choice Questions
-
Duration: 4 Hours
-
Passing Score: 70%
-
Location & Enrollment: Online via the EC-Council Exam (ECC) Center
Mane Piperevski
About
Mane is an Experienced Information Technology Expert with extensive experience in Cyber Security. Over 20 years in IT industry and 15 years experience in field of Cyber Security. With a breadth of technology skills, including networks, operating systems, databases and application development, Mane has provided penetration testing and IT forensics services in various industry sectors such as banking, electronic payment services, transportation, software development
companies, utilities, pension and disability insurance and state courts. As experienced Microsoft Certified Trainer and Certified EC-Council Instructor, Mane has conducted training classes in Cyber security and Microsoft Products for over 1500 students in last 12 years. He is regular speaker at Cyber Security International Conferences and community events, leader and founder of OWASP Macedonian Chapter.
He is also AlienVault Certified Security Engineer (ACSE) capable for implementing, supporting and managing AlienVault USM solution.
As Security Expert he understands and knows how to look for the weaknesses and vulnerabilities in systems, how they work, how to investigate them and exploit for Proof of Concept.
Social Media
Kontakt z nami v živo