CyberSecurity & DevSecOps Expert: Develop, PenTest, and Deploy Secure Applications

CyberSecurity & DevSecOps Expert: Develop, PenTest, and Deploy Secure Applications

Ilaria Digital School
País Itália
Géneros Educação, Cursos
Idioma EN-US
Episódios 171
Último 01.09.2026

This podcast presents the content of a CyberSecurity & DevSecOps course, aimed at developers and security professionals. It covers understanding application risks, performing authorized web and API penetration tests, and identifying major vulnerabilities such as authentication failures, access control issues, injections, and CSRF. Listeners are introduced to tools like Nmap, Wireshark, Metasploit, and Python scripting, and to the process of fixing flaws and setting up regression tests. Later episodes focus on producing vulnerability reports and building a secure delivery chain with CI/CD, SAST, DAST, SCA, and container security.

Episódios

  • Welcome, objectives and chapter journey 24.03.2026 15min
    Welcome to the course 'CyberSecurity and DevSecOps Expert: Develop, Pentest, and Deploy Secure Applications'. This introductory chapter is your starting point. Before diving into technical tools, attack techniques, or secure deployment pipelines, it ...
  • Essential vocabulary: security, threat, vulnerability, risk 24.03.2026 15min
    Welcome to this first foundational lesson. Before diving into technical tools, penetration testing techniques, or secure development practices, you need to master the vocabulary that structures all of cybersecurity. These words — security, threat, vu...
  • Guided workshop: associate each term with a concrete case 25.03.2026 15min
    **Theoretical Recap** Before diving into the workshop, let's consolidate the four core vocabulary terms you encountered in the previous lesson. A **threat** is any potential event or actor that could cause harm to a system — for example, a hacker att...
  • The CIA pillars: confidentiality, integrity, availability 26.03.2026 15min
    Before diving into the technical world of cybersecurity and secure application development, every professional in this field must internalize a fundamental framework: the three pillars known as the CIA triad. These three pillars are Confidentiality, ...
  • Guided workshop: identifying the CIA pillar under threat 26.03.2026 15min
    **Theoretical Recap** Before diving into the workshop, let's consolidate the essential framework you need. The CIA Triad is the cornerstone model of information security, composed of three pillars: Confidentiality, Integrity, and Availability. Confid...
  • Variation workshop: creating your own threat examples 27.03.2026 15min
    THEORETICAL RECAP Before diving into the workshop, let's consolidate what you have covered so far. Four core concepts form the backbone of cybersecurity thinking: security (the overall state of protection of systems and data), threat (any potential e...
  • Common web threats presented simply 28.03.2026 15min
    In the previous activities, you built a solid foundation: you mastered the core vocabulary of cybersecurity (security, threat, vulnerability, risk), and you explored the three fundamental pillars that any security approach must protect: confidentiali...
  • Guided workshop: recognize the threat on a screenshot 29.03.2026 15min
    **Theoretical Recap** Before diving into the workshop, let's consolidate what you have covered so far. In cybersecurity, a threat is any potential event or action that could exploit a vulnerability to cause harm to an information system. A vulnerabil...
  • Intermediate visual summary: mental map of concepts 31.03.2026 15min
    At this stage of your learning journey, you have covered a significant amount of foundational material. You have explored the core vocabulary of cybersecurity, discovered the three pillars known as the CIA triad, and encountered the most common web t...
  • Introduction to DevOps and the DevSecOps concept 31.03.2026 15min
    Before diving into the world of security within development pipelines, it is essential to understand what DevOps is, why it was created, and how the concept of DevSecOps grew out of it. You have already explored the foundational pillars of cybersecur...
  • Guided workshop: visualizing a simplified CI/CD pipeline 01.04.2026 15min
    **Theoretical Recap** CI/CD stands for Continuous Integration and Continuous Delivery (or Deployment). It is the backbone of modern DevOps — and by extension, DevSecOps — workflows. Continuous Integration means that every time a developer pushes code...
  • The role of safety at every stage of the pipeline 02.04.2026 15min
    When we talk about a software delivery pipeline, we are referring to the full chain of automated steps that transforms source code written by developers into a running application available to end users. In a traditional DevOps approach, this chain i...
  • Guided workshop: placing security checks in an imaginary pipeline 02.04.2026 15min
    THEORETICAL RECAP A CI/CD pipeline (Continuous Integration / Continuous Delivery) is the automated chain that takes source code from a developer's commit all the way to a running application in production. In a DevSecOps approach, security is not a f...
  • Variation workshop: adapting a secure pipeline to an e-commerce project 03.04.2026 15min
    THEORETICAL RECAP A CI/CD pipeline (Continuous Integration / Continuous Delivery) is an automated sequence of steps that takes source code from a developer's commit all the way to a production deployment. In a standard DevOps pipeline, the typical st...
  • Pipeline checkpoints and artifacts 06.04.2026 15min
    In the previous activities, you explored what a Continuous Integration and Continuous Delivery pipeline looks like, and you practiced placing security checks at various stages of an imaginary pipeline. You also adapted a secure pipeline to an e-comme...
  • Storyboard: Incident avoided with DevSecOps 06.04.2026 15min
    Introduction: Why a storyboard approach? Throughout the previous activities, you have explored what DevSecOps means, how a Continuous Integration and Continuous Delivery pipeline works, where security checks fit in at each stage, and how artifacts an...
  • mini-project: writing a security-oriented user story 07.04.2026 15min
    ## Mini-Project: Writing a Security-Oriented User Story ### Project Overview Building on your understanding of DevSecOps principles, the CI/CD pipeline, and the CIA triad, this mini-project challenges you to write a complete set of security-oriented ...
  • Entry ramp summary and personal checklist 08.04.2026 15min
    You have now completed the introductory section of this course on CyberSecurity and DevSecOps. Before moving on to more technical and specialized content, this chapter serves a double purpose: consolidating everything you have learned so far and givi...
  • Prepare your secure test environment (VM, accounts, browser) 09.04.2026 15min
    Before performing any security test, penetration test, or vulnerability analysis, you must set up a dedicated, isolated, and controlled environment. This is not optional. Working directly on your personal machine, using your real accounts, or testing...
  • Workshop: installing and verifying the lab virtual machine 09.04.2026 15min
    **Theoretical Recap** A virtual machine (VM) is a software emulation of a physical computer. It runs an operating system and applications in an isolated environment, completely separated from your host system. This isolation is fundamental in cyberse...

Popular em

Este podcast também aparece nas paradas de podcasts destes países.