
Develop secure pipelines with TeamCity by learning DevSecOps fundamentals, and integrate SonarCloud, software composition analysis, and OWASP testing for automated builds and secure deployments from GitHub.
Learn why this devsecops course matters for beginners, identify the target audience—freshers in security engineering and it professionals—and explain the high demand and opportunities in the field.
Meet Harry Singh, a lead devsecops engineer with 11+ years in information security, specializing in cloud security, automation across the sdlc lifecycle, and helping students land jobs.
Explore key security terms used in DevSecOps, including SAST, SCA, DAST, IEC, infrastructure as code testing, and API security, and learn how they guide manual and automated risk checks.
Explore DevSecOps by integrating security early in the software development lifecycle, applying shift-left practices, secure coding checklists, automation, and PCI, DSS standards across infrastructure and container workflows.
Explore enterprise devsecops tooling, from git secrets and ide security plugins to sast, dynamic application security testing, sca, iac, and container security, plus build and cloud posture tools.
Implement DevSecOps in TeamCity by importing GitHub code, creating a project, and configuring a pipeline with static, dynamic, and software composition analysis, plus artifacts and tokens moved to environment variables.
Create a TeamCity cloud account using GitHub for a 14-day trial, and explore cloud versus self-hosted options, including Professional and Enterprise plans with build agents and credits.
Create a TeamCity project by connecting a GitHub repo, auto-detect build steps, and review project overview and changelog as you prepare to implement a desktop Java pipeline.
Learn how sonar cloud, a software as a service platform, keeps your source code free from quality and security issues, defines custom quality gates, and uses default 80% code coverage.
Create a SonarCloud account by signing in with GitHub, review the dashboard, and understand how to set up projects as a foundation for SAST in a DevSecOps pipeline.
Integrate SonarCloud within a TeamCity DevSecOps pipeline using a manual build configuration, including Maven steps, SonarCloud analysis, and organization, project keys, and token setup.
Install a GitHub webhook from TeamCity to automatically trigger builds when commits are pushed, enabling real-time CI/CD for the DevSecOps Java vulnerable application.
Clean up the TeamCity project by removing extra build configurations and keeping the DevSecOps build pipeline configuration. Observe how triggers now initiate builds from the single remaining configuration.
Enable a version control system (VCS) trigger in TeamCity to automatically trigger the DevSecOps build pipeline when code changes are pushed to GitHub.
Discover how Snyk provides cloud-based security tools to secure source code with sast, scan open source libraries, secure containers, and guard infrastructure as code with CloudFormation and Terraform.
Create an account with Snyk and learn to run a software composition analysis scan to identify security issues in third-party libraries like log4j within a DevSecOps pipeline.
Integrate Snyk into a TeamCity DevSecOps pipeline by adding a command line build step for software composition analysis, configuring a token, and running maven with Snyk test to reveal vulnerabilities.
Explore OWASP ZAP, the open source web application security scanner, and learn how its Z attack proxy identifies security issues in web apps and API specifications, including enterprise use.
Integrate OWASP ZAP into a TeamCity devsecops pipeline to perform dynamic application security testing (DAST) for web apps and APIs, generating a ZAP report HTML artifact.
Create a free Jira account with Atlassian to report security issues to the development team, set up a Jira site, and start a DevSecOps project for fixing security bugs.
Identify a high-severity command injection flaw found by SonarCloud during SAST and report it in Jira as a bug with scan details to guide devs in sprint one.
Demonstrate reporting a sca security issue found by snyk in jira, detailing an injection vulnerability in Morgan Library 1.9.0 and its fix to 1.9.1, with scan data and workflow.
Discover how to report a DAST security issue found by OWASP ZAP in JIRA within a DevSecOps workflow, including a medium severity finding and remediation steps.
Integrate SonarCloud with Jira to auto-create tickets with one-click, mapping bugs, vulnerabilities, code smells, and security hotspots from the SonarCloud dashboard into Jira issues.
Discover career paths in information security, from devsecops and cloud penetration testing to container security, security architecture and design, and cloud compliance.
Course Updates:
v 3.0 - May 2024
Added DevSecOps Handbook document in Section 9
v 2.0 - March 2024
Updated lecture 12 with JDK 17 changes for SonarCloud
v 1.0 - Feb 2023
Updated course with newer videos on Integrate JIRA with SonarCloud/SonarQube
Who shall take this course?
This "DevSecOps with TeamCity" course is designed for Security Engineers, DevOps Engineers, SRE, QA Professionals and Freshers looking to find a job in the field of security. This is a focused GitLab DevSecOps course with a special focus on integrating SAST/SCA/DAST tools in Build pipeline.
Learn and implement security in DevOps pipeline, get Hands On experience in using Security tools & technologies.
This course is for:
Developers
DevOps
Security Engineers
Aspiring professional in the Security domain
Quality Assurance Engineers
InfoSec/AppSec Professional
DevSecOps being the hot skill, will help you to secure a high-salaried job and stay informed on the latest market trends.
Why purchase this course?
This is only practical hands-on course available on the internet till now.
DevSecOps enables rapid application development with agility, at the same time it secures your application with automated security checks integrated within the pipeline. It helps to increase productivity and security by integrating security stages in the pipeline.
Also, we have included practical examples to implement security in the DevOps pipeline through various tools.
By the end of the course, you will be able to successfully implement DevOps or DevSecOps pipeline and lead initiatives to create, build and maintain security pipelines in your project.
No Action required before taking this course. For any question or concerns, Please post your comments on discussions tab
Disclaimer: English subtitles are auto-generated so please ignore any grammar mistakes