Ship Secure, Scalable and Sellable Software with DevSecOps
Combine the forces of development, security, and operations to achieve proactive security and resource effectiveness.
The Upskilling Roadmap
Curriculum crafted to enable expertise and experience with each module
Understand the impact and implement security practices for protecting the organisation against breaches. Familiarize yourself with OWASP's top 10 vulnerabilities.
Get introduced to DevSecOps, its roles and key responsibilities.
Build a CI pipeline and use GitLeaks for secret scanning and fixing security vulnerabilities.
Generate automated security scan reports and learn to fix security issues.
Learn to perform software composition analysis and fix security issues in application dependencies.
Integrate secure CI/CD pipelines with cloud environments using GitLab Runner and Docker.
Analyze & fix issues with containers and images using best security practices in Docker.
Understanding IAM services in opted cloud (AWS/Azure/GCP) and configuring secure access from CI/CD pipelines.
Securely configure and automate server access using AWS Systems Manager (SSM), IAM roles, and short-lived credentials. Explore dynamic application security testing (DAST) and its integration into CI/CD pipelines.
Automate infrastructure provisioning using Terraform and GitOps principles. Learn to implement remote state, automated security scans, and the "cattle vs pets" concept to enhance security in DevSecOps workflows.
Gain hands-on experience configuring AWS CloudTrail, CloudWatch, and alarms for key security events.
Explore fundamental Kubernetes security concepts and best practices, with a focus on provisioning secure AWS EKS clusters.
Implement Role-Based Access Control (RBAC) in Kubernetes and test access to ensure secure cluster management.
Configure secure authentication using GitLab OIDC and build a secure IaC pipeline for provisioning AWS EKS clusters with Terraform.
Get familiar with EKS Blueprints and configure add-ons for bootstrapping clusters. Learn troubleshooting techniques and manage access token expiration for cluster autoscalers.
Master the setup and configuration of ArgoCD for continuous application deployment in Kubernetes, integrating GitOps principles and Kustomize.
Define and enforce security policies using Open Policy Agent (OPA) and Gatekeeper.
Master the setup and configuration of ArgoCD for continuous application deployment in Kubernetes, integrating GitOps principles and Kustomize.
Implement a service mesh using Istio in Kubernetes, focusing on secure traffic routing, mTLS, and authorization policies.
Understand the importance of Compliance as Code and automate compliance checks using AWS Config and CIS Benchmarks.
Learn the strategic challenges and best practices for adopting DevSecOps in organizations, with a focus on overcoming resistance and implementing security from the ground up.
Work on real-world case studies and capstone projects to put acquired skills and best practices to work.
Understand the impact and implement security practices for protecting the organisation against breaches. Familiarize yourself with OWASP's top 10 vulnerabilities.
Get introduced to DevSecOps, its roles and key responsibilities.
Build a CI pipeline and use GitLeaks for secret scanning and fixing security vulnerabilities.
Generate automated security scan reports and learn to fix security issues.
Learn to perform software composition analysis and fix security issues in application dependencies.
Integrate secure CI/CD pipelines with cloud environments using GitLab Runner and Docker.
Analyze & fix issues with containers and images using best security practices in Docker.
Understanding IAM services in opted cloud (AWS/Azure/GCP) and configuring secure access from CI/CD pipelines.
Securely configure and automate server access using AWS Systems Manager (SSM), IAM roles, and short-lived credentials. Explore dynamic application security testing (DAST) and its integration into CI/CD pipelines.
Automate infrastructure provisioning using Terraform and GitOps principles. Learn to implement remote state, automated security scans, and the "cattle vs pets" concept to enhance security in DevSecOps workflows.
Gain hands-on experience configuring AWS CloudTrail, CloudWatch, and alarms for key security events.
Explore fundamental Kubernetes security concepts and best practices, with a focus on provisioning secure AWS EKS clusters.
Implement Role-Based Access Control (RBAC) in Kubernetes and test access to ensure secure cluster management.
Configure secure authentication using GitLab OIDC and build a secure IaC pipeline for provisioning AWS EKS clusters with Terraform.
Get familiar with EKS Blueprints and configure add-ons for bootstrapping clusters. Learn troubleshooting techniques and manage access token expiration for cluster autoscalers.
Master the setup and configuration of ArgoCD for continuous application deployment in Kubernetes, integrating GitOps principles and Kustomize.
Define and enforce security policies using Open Policy Agent (OPA) and Gatekeeper.
Understand the importance secrets management in Kubernetes and the use of tools like Vault and AWS Secrets Manager. Learn to deploy and manage secrets using the External Secrets Operator and integrate them securely into microservices.
Implement a service mesh using Istio in Kubernetes, focusing on secure traffic routing, mTLS, and authorization policies.
Understand the importance of Compliance as Code and automate compliance checks using AWS Config and CIS Benchmarks.
Learn the strategic challenges and best practices for adopting DevSecOps in organizations, with a focus on overcoming resistance and implementing security from the ground up.
Work on real-world case studies and capstone projects to put acquired skills and best practices to work.
The training that translates into real results.
*exclusive of official training content or certification. The program covers learning topics to appear for these exams.
Ready for the DevSecOps transformation?
Curious to know more?
Let’s talk about your team, your goals and how we can pave the way to achieve them.
Book Free ConsultationFrequently Asked Questions
We know training your team in DevSecOps is a profitable investment, but it should also be an informed one. Here’s the answer to some of the quick questions you might have:
DevSecOps can be critical in improving your time-to-market and security by detecting vulnerabilities early in the cycle and proactively fixing them, reducing bottlenecks in development and resulting in faster lead time and ensuring scalability of applications.
This program is a value-add for developers, DevOps engineers, Security engineers, Cloud engineers, Kubernetes administrators, Site Reliability Engineers, IT Managers and Infrastructure Engineers.
The foremost objective of this boot camp is to make your team production-ready. To do that, we collaborate closely with you to understand your current practices, IT environment, team skill level, and desired business outcomes.
These set the foundation for our experts to curate the right curriculum, include the most suitable tech stack, create a delivery plan, and design content consisting of relevant case studies and practice labs.
Through our assignments, assessments and hands-on projects at frequent checkpoints in the training, you will be able to analyse the progress of your team in terms of their conceptual understanding and application-ready skills.
The long-term impact of the Bootcamp will also reflect in important metrics such as Mean Time to Detection, Mean Time to Remediation, Mean Time to Recover, Deployment Frequency, Patch/Update Lead Time, and more.
Yes, all the participants receive duly verified certificates from Uptut acknowledging the skills they have acquired. Participants can also opt for professional certifications.
The Bootcamp is designed to be 15 weeks long, but the exact duration will depend on the unique curriculum and delivery schedule you opt for. The program is flexible to cater to the availability of your team
We have an incredible team of subject matter experts to solve doubts in case your team needs further assistance. We also support you with consulting to help your team apply concepts on projects and solve challenges.