DevSecOps in Action: Securing and Governing Multicloud Infrastructures
1h 42mIntermediate2025-12-05
Authors
Emmanuel Chebukati
Certified cloud security engineer and cofounder of Hepta Analytics
Course details
Organizations are increasingly adopting multicloud strategies for performance, reliability, and cost efficiency—but this creates challenges in security, visibility, and governance. In this course, Emmanuel Chebukati, a certified cloud security engineer, demonstrates practical DevSecOps approaches for AWS and Azure. Topics include deploying applications with Terraform, automating resources across clouds, enabling zero trust access, managing secrets with Doppler, monitoring dependency risks with Dependabot, and setting up incident responses. Emmanuel also covers how to enforce policy guardrails using Open Policy Agent and track compliance through automated systems. Designed for cloud security strategists, senior cloud architects, DevOps team leads, and directors managing cloud initiatives, this course offers hands-on demos and real-world simulations to help you apply these practices to secure, monitor, and govern multicloud environments effectively.
Learning objectives
Explain how to deploy a multicloud application in AWS and Azure.
Implement a firm foundation for DevSecOps across clouds.
Apply testing methodologies throughout the software development lifecycle.
Discuss how to monitor and enforce compliance across platforms centrally.
Learning objectives
Explain how to deploy a multicloud application in AWS and Azure.
Implement a firm foundation for DevSecOps across clouds.
Apply testing methodologies throughout the software development lifecycle.
Discuss how to monitor and enforce compliance across platforms centrally.
Concepts
Introduction
- Getting started with multicloud DevSecOps
- Deploy a multicloud application with infrastructure as code
- Deploying resources to Azure and AWS
- Setting up Terraform
- Finishing our tech setup
Building a Secure Multicloud Foundation
- Automating identity federation across clouds
- Enabling zero trust access with Twingate
- Managing multicloud secrets with Doppler
Securing Multicloud Developer Workflows
- Detect credentials leaks with GitGuardian
- Monitor dependency risks with Dependabot
- Run multicloud static application security testing (SAST)
Runtime Security
- Dynamically test internal deployments
- Set up a multicloud penetration test
- Simulate and respond to a multicloud incident
Multicloud Observability and Compliance
- Centralize multicloud logs and metrics
- Enforce policy guardrails with Open Policy Agent
- Track security controls through compliance automation
Conclusion
- Cleaning up cloud resources
Related courses
- Learning the OWASP Top 10 (2025 Version)
- Google Cloud Professional Cloud Architect Cert Prep: 5 Managing Implementation
- Microservices Security Workshop: From Build to Production
- Building a Multicloud Security Program: Strategy, Implementation, and Emerging Trends
- Application Security in DevSecOps (2019)
- Application Security in DevSecOps
- Building Your First DevSecOps Pipeline in AWS
- Learning Static Code Analysis