Six modules, one continuous defense.
Each module answers a different question a real engineering org asks about security — read them in order the first time, then use any one on its own after that.
Use this map as the connective tissue between modules — it's worth returning to.
Module 1
Fundamentals
Shift-left, threat modeling, STRIDE, shared responsibility, security as code.
Module 2
SAST · DAST · SCA
Catching code, runtime, and dependency vulnerabilities before they ship.
Module 3
Containers & K8s
Image hardening, RBAC, network policy, admission control, runtime detection.
Module 4
Secrets & IAM
The highest-stakes category — dynamic secrets, least privilege, workload identity.
Module 5
CI/CD & Supply Chain
The pipeline itself as a target — SBOM, signing, SLSA.
Module 6
Compliance
How everything above maps to SOC 2, ISO 27001, PCI-DSS, GDPR.
The narrative arc
1. Thinklike an attacker, before building.
2. Automatescanning at every stage.
3. Hardenwhat actually runs.
4. Protectthe pipeline itself.
5. Proveit to an auditor.