This practical course builds expertise in enterprise-scale AI-powered DevSecOps practices for modern software delivery environments. Delegates will learn to build secure DevSecOps pipelines with AI integrated from the start, using the Model [...]
  • QADEVSECOPS-QA
  • Cena na vyžádání

This practical course builds expertise in enterprise-scale AI-powered DevSecOps practices for modern software delivery environments. Delegates will learn to build secure DevSecOps pipelines with AI integrated from the start, using the Model Context Protocol (MCP) to enrich findings and streamline triage. The course covers supply chain security, automation, and the most effective tools used in production, helping learners overcome common DevSecOps challenges and scale security across enterprise environments. Hands-on labs and guidance from experienced security professionals ensure practical skills and real-world application.

  • Focus on supply chain security to harden CI/CD pipelines.
  • Exactly where to start when shifting from DevOps to DevSecOps.
  • Understand the role of Asset registry, security onboarding, vulnerability management, and supply chain security.
  • See how AI agents, connected via the Model Context Protocol (MCP), enrich and triage findings directly inside your DevSecOps pipeline.
  • Learn how to automate security into a fast-paced DevOps environment using various open-source tools and scripts that don’t slow down delivery.
  • Master the ability to craft custom rules for SAST, WAF, and Compliance as Code (CaC) to strengthen application security, enforce policies at scale, and proactively defend against evolving threats.
  • Hands-on experience in managing Application Security Posture Management(ASPM) systems and remediating issues to reduce the attack surface.
  • How to secure the pipeline from supply chain attacks using provenance and SBOM.
  • How to secure your methodology for managing and delivering Infrastructure as Code (IaC).
  • How to use Wazuh to monitor your application’s behaviours with logs and alerts.
  • How AI-assisted pentesting complements traditional DAST scanning.
  • What challenges to expect when moving to a DevSecOps model and how to overcome them.
  • How to mature your DevSecOps approach over time.

Mám zájem o vybraný QA kurz