Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Advanced

Cloud Native Security and DevSecOps Automation

DevSecOps training in Canada for engineers who own a pipeline and are expected to make it safe without slowing it to a crawl. The course treats security as something you automate, not something you review at the end.

Ten weeks across build pipelines, infrastructure as code scanning, container images, Kubernetes clusters, secrets handling and runtime protection. You leave with a pipeline that fails on the right things and stays quiet on the rest.

Duration
10 weeks
Format
Live online, instructor-led
Prerequisites
Cloud Security Essentials
Class size
Capped at 12 learners
Cloud Native Security and DevSecOps Automation

What you will be able to do

  • Add security gates to a CI/CD pipeline that developers accept rather than bypass
  • Scan Terraform and Kubernetes manifests before they reach an environment
  • Build minimal container images and cut vulnerability counts at the source
  • Configure Kubernetes RBAC, network policy and pod security controls
  • Run admission control that blocks non compliant workloads at deploy time
  • Manage secrets without static credentials in code or environment files
  • Deploy runtime detection for container behaviour and respond to its alerts
  • Tune scanner output so the findings that reach a team are actionable

Course outline

6 modules

  • Threat modelling the pipeline itself, not just what it builds
  • Build system identity, credentials and permissions
  • Where to place each gate in the build sequence
  • Failing a build responsibly and handling exceptions
  • Measuring whether a control is actually catching anything

What you need before you start

  • Cloud Security Essentials or equivalent practical cloud experience
  • Working knowledge of Docker and at least one CI/CD system
  • Comfort with YAML, Git and the command line
  • A machine able to run Docker and connect to a remote Kubernetes cluster

Who this course is for

  • DevOps and platform engineers asked to own security in the pipeline
  • Cloud security engineers supporting development teams
  • Site reliability engineers running Kubernetes in production
  • Application security engineers extending into infrastructure and delivery
  • Technical leads deciding which controls belong in the build process

Where this leads

Prepares you for

CCSP

Awarded by ISC2

The cloud platform and application security domains of the ISC2 CCSP overlap with this course, though the automation depth here goes further. The CCSP credential comes from ISC2 through its own exam process, not from completing this course.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.