Camp Fire Academy
Learning path
Complete UI/UX Masterclass UI/UX Design Foundations UI/UX Design Intermediate Advanced UX Strategy
Specialisations
Fintech & Banking UI/UX UI/UX with AI Training UX for Leaders Design Thinking Figma Training
Most requested
AI for Workplace Productivity Excel for Business Power BI & Business Intelligence Cybersecurity Awareness PDPA Compliance Data Protection Officer Browse the full catalogue →
For teams
Corporate & In-House Training LMS & Self-Paced Learning Events
Company
About Contact Verify Certificate WhatsApp

DevSecOps & Cloud Security Hardening

Security added at the end of a delivery cycle arrives too late to change anything and gets overruled by the release date. Moving it earlier only works if the checks are fast, accurate enough to be trusted, and attached to something a developer can fix. This programme covers both halves: building security into the pipeline without stalling delivery, and hardening the cloud environment against the specific misconfigurations that account for most real breaches.

Programme Agenda

Threat Modelling Without Ceremony

A lightweight approach that fits into design work rather than replacing it. Identifying what an attacker would go for, and letting that drive where the effort goes.

Securing the Pipeline Itself

The pipeline holds credentials to production, which makes it a target. Scoping runner permissions, protecting branches, signing artefacts, and preventing a pull request from executing privileged workflows.

Static Analysis and Secret Scanning

Placing code scanning where it will be acted on, tuning out the noise that causes teams to ignore results, and scanning history for credentials already committed.

Dependency and Supply Chain Risk

Software composition analysis, lockfiles, transitive dependency exposure, and a workable policy for a critical vulnerability in a package you do not control. Generating and using a software bill of materials.

Container Image Security

Base image choice and update cadence, image scanning in the pipeline, running as a non-root user, and admission control that stops an unscanned image reaching the cluster.

Secrets Management

Getting credentials out of code, environment files and pipeline variables into a managed secret store. Dynamic and short-lived credentials, rotation, and workload identity as the better answer.

Cloud Hardening

The misconfiguration categories behind most cloud incidents: public storage, over-permissive identity, exposed management ports, absent logging, and unencrypted data. Detective controls and posture management.

Detection and Incident Readiness

Logging what an investigation will need, alerting on identity and configuration change rather than only on traffic, and rehearsing a compromised-credential scenario end to end.

Learning Outcomes:
Run a lightweight threat model as part of ordinary design work
Harden a delivery pipeline against use as an attack path into production
Place code and secret scanning where results are actually acted on
Set a workable policy for dependency vulnerabilities and produce an SBOM
Secure container images from base selection through admission control
Move credentials into a managed secret store with rotation or short lifetimes
Close the cloud misconfigurations that account for most real breaches
Log and alert on what an incident investigation will need

Duration: 2 Days (16 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: All levels
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included

Frequently Asked Questions

DevOps and platform engineers, developers, cloud architects, and security engineers moving into a cloud-native environment. Security teams and delivery teams attending together get noticeably more out of it.

Familiarity with a CI/CD pipeline and a cloud platform. Participants without either should take CI/CD and DevOps Culture or Cloud Engineering Foundations first.

Cloud Security Fundamentals covers the shared responsibility model and cloud controls from a security practitioner's angle. This programme is delivery-focused: pipeline security, supply chain, secrets and the engineering practice around hardening. Some organisations run both.

No. Open source and commonly available tools are used in the exercises, and the material concentrates on where a control belongs and how to tune it rather than on any vendor's interface.

Yes, this programme is HRD Corp SBL-KHAS claimable. Our team can assist your HR department with the documentation required for the grant application.

Yes. Any programme can be booked as a team day. Everyone works the same brief together, so your people come away having built something and knowing each other better.

If you are claiming under HRD Corp, the session has to fall at least 14 days after your HRD Corp approval. If you are not claiming, the date is flexible and we work around your calendar.

Put them on the self-paced e-learning instead. Your team works through the modules on our LMS in their own time, sits the assessment, and earns the same certificate, so nobody has to clear a full day together.

More in Cloud, DevOps and Platform Engineering