Project Management

DevSecOps for Managers & Leaders

DevOps is the combination of cultural philosophies, practices, and tools that increases an organization’s ability to delivery applications and services at high velocity. Under a DevOps model, a development and operations teams are no longer “siloed”. Quality assurance team also becomes more tightly integrated with development and operations and throughout the application lifecycle.

The shift to DevSecOps has become essential as organizations prioritize secure software delivery without sacrificing speed. Integrating security practices into the DevOps workflow is critical to reducing vulnerabilities early in the development lifecycle, ensuring compliance, and managing risk proactively.

This course provides managers, project leads, analysts, and others involved in enterprise software development projects with a comprehensive understanding of the principles and practices of modern DevSecOps product development, deployment and maintenance.

3 days

Who Should Take This Course


  • Leaders who are or will be designing and leading a DevOps practice in their team, department, or organization
  • Staff who are or will be participating in DevOps projects and are looking for a comprehensive, end-to-end understanding of the processes they will be supporting
  • This course is not intended for individuals looking for hands-on or specific technical training; other courses are available to meet specific technical needs


One year or more of enterprise IT experience with software and systems.

Course Outline

• What is DevOps?
• Why DevOps Matters for the Enterprise
• Cultural Shifts in DevOps
• DevOps and Leadership
• The DevOps Lifecycle
• From Development to Operations: Understanding the Flow
• Building a DevOps Strategy
• Measuring the ROI of DevOps
• Data-Driven Decision Making in DevOps
• Future Trends in DevOps
• Introduction to DevSecOps
• Static Application Security Testing (SAST)
• Coding for Security
• Dynamic Application Security Testing (DAST)
• Vulnerability Scanning and Software Composition Analysis (SCA)
• Security Policy and Compliance
• Interactive Application Security Testing (IAST)
• Security Orchestration and Automation
• Threat Modeling and Continuous Improvement
• Implementing SAST in a CI/CD Pipeline
• Refactoring Code for Security
• Integrating ZAP into CI/CD Pipelines
• Analyzing Open-Source Dependencies
• Compliance Automation
• Running and Interpreting IAST Results
• Building an Automated Security Pipeline
• Threat Modeling

