Course map
6 modules
02 / 38

Six modules, one continuous defense.

Each module answers a different question a real engineering org asks about security — read them in order the first time, then use any one on its own after that.

Use this map as the connective tissue between modules — it's worth returning to.

Module 1

Fundamentals

Shift-left, threat modeling, STRIDE, shared responsibility, security as code.

Module 2

SAST · DAST · SCA

Catching code, runtime, and dependency vulnerabilities before they ship.

Module 3

Containers & K8s

Image hardening, RBAC, network policy, admission control, runtime detection.

Module 4

Secrets & IAM

The highest-stakes category — dynamic secrets, least privilege, workload identity.

Module 5

CI/CD & Supply Chain

The pipeline itself as a target — SBOM, signing, SLSA.

Module 6

Compliance

How everything above maps to SOC 2, ISO 27001, PCI-DSS, GDPR.

The narrative arc

1. Thinklike an attacker, before building.
2. Automatescanning at every stage.
3. Hardenwhat actually runs.
4. Protectthe pipeline itself.
5. Proveit to an auditor.