Syllabus
Balancing security and usability-User authentication mechanisms, Zero Trust Architecture, Identity and Access Management (IAM). Target environment hardening and secure application deployment. Threat Modeling -STRIDE, PASTA. Risk Assessment – CVSS v4.0, Attack trees. Security Testing – Common Vulnerabilities and Exploits, Application Security Testing- SAST, DAST, IAST, RASP, AI-Augmented Security: Using LLMs for code review vs. risks of AI-generated code, Fuzzing techniques-(Coverage-guided, Structure-aware). Software security economics-logging/monitoring and operational security aspects. Infrastructure Security-Infrastructure as Code (IaC- Terraform/CloudFormation/K8s manifests) Security, Container (Docker) Security, Cluster (Kubernetes) Security, eBPF for runtime protection. Software Supply Chain Security – SBOM (SPDX, CycloneDX), VEX, SCA, OSS Licensing Models, Policy-as-Code. Enhance Detection Engineering with Agile DevSecOps – SOC tech stack, EDR, SOAR, XDR, MDR, Chaos Engineering for resilience.