Cloud Security for DevSecOps Engineers: From Security Models to API Protection

Cloud Security for DevSecOps Engineers: From Security Models to API Protection

2h 35mBeginner2025-10-08

Authors

Damien Burks

Damien Burks

Course details

Designed for new and early-career DevSecOps engineers, this course introduces cloud security through a DevSecOps lens. Get started by learning the fundamentals of cloud computing, service models, and the shared responsibility model. Explore the importance of key security services and control types, such as identity and access management (IAM), encryption, logging, and network segmentation, as well as API security fundamentals in cloud-native environments. Along the way, instructor Damien Burks dives into the essentials of infrastructure as code (IaC), showing you how to identify common risks, enforce compliance with policy as code, and automate security checks at scale using tools like Trivy. By the end of this course, you’ll be prepared to effectively apply key DevSecOps principles and concepts within the cloud security space.

Learning objectives
Describe your security responsibilities across software-as-a-service, platform-as-a-service, and infrastructure-as-a-service models.
Identify key cloud-native security controls in any environment.
Apply security best practices to infrastructure as code.
Recognize common API vulnerabilities and how to prevent them.
Embrace a DevSecOps mindset focused on automation and collaboration.

Skills covered

Cloud SecurityDevOps FoundationsNetwork SecurityDevOpsCybersecurityCloud ComputingOne-Off

Concepts

Introduction

  • From risk to resilience - Securing the cloud without slowing down
  • What you should know before continuing

Understanding the Cloud and Foundational Security Risks

  • What is cloud computing
  • Cloud deployment types
  • SaaS, PaaS, and IaaS explained
  • The shared responsibility model
  • Security implications for SaaS, PaaS, and IaaS

Cloud Security Essentials for DevSecOps

  • Risks in public cloud
  • Understanding cloud security controls
  • Controlling access to cloud resources using IAM
  • Protecting data at rest and in transit
  • Protecting data with encryption and secrets management
  • Logging and monitoring fundamentals
  • Network security explained
  • Tagging, labels, and governance

Securing APIs in Cloud-Native Environments

  • APIs in the cloud - What they are and why they matter
  • API risks and OWASP API Top 10 overview
  • Securing APIs with authentication and authorization
  • Input validation and response hardening
  • Logging and monitoring for API security
  • API rate limiting and abuse prevention
  • API security testing

Building Secure Infrastructure as Code

  • Getting set up in GitHub Codespaces
  • What is infrastructure as code (IaC)
  • Common security risks with IaC
  • Policy-as-code basics
  • IaC scanning basics
  • Scan misconfigured IaC files and report findings using Trivy
  • Purpose of automating IaC security scans
  • GitHub Actions IaC scanning with Trivy

Conclusion

  • Next steps
80,000 Toman