Cloud Native Security and DevSecOps Automation
DevSecOps training in Canada for engineers who own a pipeline and are expected to make it safe without slowing it to a crawl. The course treats security as something you automate, not something you review at the end.
Ten weeks across build pipelines, infrastructure as code scanning, container images, Kubernetes clusters, secrets handling and runtime protection. You leave with a pipeline that fails on the right things and stays quiet on the rest.
- Duration
- 10 weeks
- Format
- Live online, instructor-led
- Prerequisites
- Cloud Security Essentials
- Class size
- Capped at 12 learners

What you will be able to do
- Add security gates to a CI/CD pipeline that developers accept rather than bypass
- Scan Terraform and Kubernetes manifests before they reach an environment
- Build minimal container images and cut vulnerability counts at the source
- Configure Kubernetes RBAC, network policy and pod security controls
- Run admission control that blocks non compliant workloads at deploy time
- Manage secrets without static credentials in code or environment files
- Deploy runtime detection for container behaviour and respond to its alerts
- Tune scanner output so the findings that reach a team are actionable
Course outline
6 modules
- Threat modelling the pipeline itself, not just what it builds
- Build system identity, credentials and permissions
- Where to place each gate in the build sequence
- Failing a build responsibly and handling exceptions
- Measuring whether a control is actually catching anything
What you need before you start
- Cloud Security Essentials or equivalent practical cloud experience
- Working knowledge of Docker and at least one CI/CD system
- Comfort with YAML, Git and the command line
- A machine able to run Docker and connect to a remote Kubernetes cluster
Who this course is for
- DevOps and platform engineers asked to own security in the pipeline
- Cloud security engineers supporting development teams
- Site reliability engineers running Kubernetes in production
- Application security engineers extending into infrastructure and delivery
- Technical leads deciding which controls belong in the build process
Where this leads
Prepares you for
CCSP
Awarded by ISC2
The cloud platform and application security domains of the ISC2 CCSP overlap with this course, though the automation depth here goes further. The CCSP credential comes from ISC2 through its own exam process, not from completing this course.
Questions about this course
More in cloud security
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



