DevSecOps
DevSecOps Engineering: Secure CI/CD Pipelines
Put security controls inside the pipeline, not after the release.
- 12 modules
- 18 labs
- ~26 hours
- Intermediate

- Hands-on Labs
- Projects
- Certificate
Course overview
You build a working CI/CD pipeline and progressively harden it: dependency scanning, static analysis, secret detection, container scanning, IaC checks and signed artifacts.
The focus is on failing builds for the right reasons — actionable findings, sensible thresholds and developer-friendly feedback.
What you will be able to do
- Build a CI/CD pipeline with security gates that developers accept
- Integrate SAST, SCA, secret and IaC scanning
- Harden container images and build environments
- Manage pipeline secrets and least-privilege runners
- Produce a supply-chain security baseline
Curriculum
- 1
DevSecOps Principles
Shift left without shifting pain.
- Pipeline threat model
- Gate design
- Developer experience
- 2
Build Your Pipeline
A real repo, a real pipeline.
- Repo and workflow setup
- Runner security
- Environment separation
- 3
Code & Dependency Security
Catch it before it ships.
- SAST integration
- SCA and SBOM generation
- Triaging findings
- Suppression policy
- 4
Secrets & Credentials
Stop leaking the keys.
- Secret scanning
- Vault-backed injection
- Rotation and revocation
- 5
Container & IaC Security
Harden what you deploy.
- Image hardening
- Container scanning
- Terraform policy checks
- Kubernetes manifests
- 6
Supply Chain & Release Integrity
Trust what you ship.
- Artifact signing
- Provenance
- Release approval gates
- Pipeline monitoring
Labs you will build
PrimeSec does not hand you a pre-built machine. You get professional lab guides and build the environment yourself — that is where the skill comes from.
- Create a pipeline that builds and tests a sample app
- Add SAST and triage the first findings
- Generate an SBOM and flag vulnerable dependencies
- Enable secret scanning and remediate a planted secret
- Scan and harden a container image
- Block a non-compliant Terraform change
- Sign a build artifact and verify it
Portfolio projects
- A hardened reference pipeline repository with documentation
- A security gate policy defining thresholds and exceptions
- A supply-chain security assessment of your own pipeline
Frequently asked questions
Do you provide the lab environment?
No — and that is intentional. PrimeSec gives you professional lab guides that teach you to build and configure the environment yourself using your own machine, Hyper-V, VMware, VirtualBox, Docker, or a cloud free tier. Building and troubleshooting the environment is part of the skill.
Is this course self-paced?
DevSecOps Engineering is self-paced. Lessons, knowledge checks, labs and projects unlock in order so you always know what to do next.
Do I get a certificate?
You receive a PrimeSec course completion certificate once every module, lab and project requirement is met. It demonstrates completion and practical work — not an accredited industry certification.
Will cloud labs cost me money?
Labs are designed around free tiers and local virtualisation wherever possible, and every cloud lab includes cleanup steps so you do not leave billable resources running.
Related courses
Cloud Security
Cloud Security Engineer Bootcamp
Intermediate · 14 modules · 22 labs
AI Security
AI Security Fundamentals: Protecting AI Systems
Intermediate · 10 modules · 16 labs
IAM & Identity
Entra ID & Identity Security Mastery
Intermediate · 9 modules · 14 labs
