
Begin a hands-on, end-to-end DevSecOps journey on Google Cloud, learning the target audience, DevSecOps basics, cloud build YAML, SAST, SCA, DAST, and code coverage in SonarCloud via a Java project.
Explain why this devsecops course matters for freshers, IT professionals, and security professionals, and highlight the high demand and upskilling toward secure CI/CD on Google Cloud.
Define DevSecOps and explain how security integrates into development and operations through shift-left practices, secure coding checks, source-code security tools, container registry controls, and automated compliance scans.
Learn to implement devsecops in GCP by connecting Google Cloud Source Repository to Google Cloud Build, triggering automated security and code quality tools, and storing reports in Google Cloud Storage.
Create GCP Account and Enable Free Tier. Please use Firefox Browser if you are facing issues while creating account using Google Chrome.
Create a cloud source repository in GCP and clone it to your local system with Git, a private source code repository service provided by GCP for secure DevSecOps workflows.
Learn to write a cloud build YAML file defining pipeline steps—from building code and running tests to deployment—using a docker image, and push changes to a GCP cloud source repository.
Create a Google Cloud Build trigger to automatically build on code pushes to the master branch, using Cloud Source Repo, Cloud Builder steps, and a cloud build file.
Create a SonarCloud account by signing in with GitHub, Bitbucket, GitLab, or a DevOps account, then explore the SonarCloud dashboard and prepare for project setup on Google Cloud.
Create an organization and a project in SonarCloud to analyze GCP source code for a secure DevSecOps pipeline, then configure keys and a cloud build YAML.
Identify prerequisites for integrating SonarCloud with the GCP DevSecOps pipeline, including organization and project keys. Generate and securely store the security token, then prepare to configure SonarCloud with GCP repos.
Move security tokens from a code file to GCP Cloud Build substitution variables in Cloud Build triggers, replacing credentials with ${_TOKEN} and keeping secrets in a secure location.
Create a snyk security token and store it as a substitution variable in a GCP cloud build trigger, enabling secure integration into your devsecops pipeline.
Learn to integrate software composition analysis into a google cloud platform cloud build pipeline using cloud-build.yaml and pom.xml, install maven, and run the sca check with maven.
Discover OWASP ZAP, the open source web application security scanner, and how it identifies security issues in web apps and API specifications in the DevSecOps with GCP course.
Create a Google Cloud Storage bucket to store DAST HTML reports from security scans and download artifacts later.
Integrate OWASP ZAP DAST into a GCP DevSecOps pipeline using Cloud Build YAML; run ZAP proxy on Ubuntu, generate a report, and store it in a GCS bucket.
Explore end-to-end DevSecOps in Google Cloud Platform by understanding Java project requirements and implementing a secure ci/cd pipeline with Maven, SonarCloud, Snyk, and OWASP ZAP.
Explore end-to-end devsecops in GCP by building a cloudbuild.yaml that runs SAST, SCA, and DAST for a Java project using Maven, Sneak, and OWASP ZAP.
Implement pom.xml changes to enable sast, sca, and dast within a gcp devsecops pipeline for a java project, and integrate unit test coverage reporting to the cloud dashboard using snyk.
Report a high-severity command injection security issue from SonarCloud in Jira by creating a bug, detailing the vulnerable file path, function, line number, and remediation references.
Learn to report sca security issues identified by Snyk in Jira, detailing vulnerabilities, vulnerable path, and fixes like upgrading Morgan from 1.9.0 to 1.9.1 to resolve injection risk.
Identify and report a medium-severity dast finding from owasp zap in jira, detailing the x-frame-options header issue on example dot com, then follow devsecops workflow to fix, retest, and close.
Explore information security career paths from devsecops and cloud penetration testing to continuous security, security architecture and design, web and mobile testing, and cloud security and compliance including GDPR.
This lecture has a sample DevSecOps engineer CV and it helps to create your CV as a DevSecOps Engineer and provides an idea on the technologies to be included in the CV.
Course Updates:
v 9.0 - May 2024
Added DevSecOps Handbook document in Section 9
v 3.0 - January 2024
Updated GitHub Repos in all SonarCloud sections to install Java 17 and to use sonar.token instead of sonar.login
Update GitHub repos to upgrade OWASP ZAP from 2.11 to 2.14.0
v 2.0 - October 2022
Updated course lectures with tool changes
v 1.0 - June 2022
Updated course with newer videos on End to End GCP DevSecOps Pipeline for a Java Project in Section 7
Added Quizzes to the course
Who shall take this course?
This "DevSecOps in Google Cloud Platform" course is designed for Security Engineers, DevOps Engineers, SRE, QA Professionals and Freshers looking to find a job in the field of security. This is a focused GCP DevSecOps course with a special focus on integrating SAST/SCA/DAST tools in Build pipeline.
Learn and implement security in DevOps pipeline, get Hands On experience in using Security tools & technologies.
This course is for:
Developers
DevOps
Security Engineers
Aspiring professional in the Security domain
Quality Assurance Engineers
InfoSec/AppSec Professional
DevSecOps being the hot skill, will help you to secure a high-salaried job and stay informed on the latest market trends.
Why purchase this course?
This is only practical hands-on course available on the internet till now.
DevSecOps enables rapid application development with agility, at the same time it secures your application with automated security checks integrated within the pipeline. It helps to increase productivity and security by integrating security stages in the pipeline.
Also, we have included practical examples to implement security in the DevOps pipeline through various tools.
By the end of the course, you will be able to successfully implement DevOps or DevSecOps pipeline and lead initiatives to create, build and maintain security pipelines in your project.
No Action required before taking this course. For any question or concerns, Please post your comments on discussions tab
Disclaimer: English subtitles are auto-generated so please ignore any grammar mistakes