Cloud & DevSecOps Security
By Wanderson Leandro de Oliveira
Cloud and DevSecOps security is not a separate discipline bolted onto engineering — it is engineering, applied with an adversary in mind. This course walks through the full lifecycle of a modern cloud-native application: who is responsible for what in the cloud, how to grant the least privilege necessary, how secrets and configuration should (and should not) flow through your systems, how to harden containers and the images they run from, how to bake security gates into CI/CD without grinding delivery to a halt, how infrastructure as code changes the security conversation, and how to detect and respond when something goes wrong anyway. Every lesson pairs a real risk with a real, production-grade control — the same build → test → lint → audit discipline the DARE method's Ralph Loop enforces, just applied to infrastructure and pipelines instead of application code. The course closes with two practical projects: building a secure CI pipeline checklist and auditing a real Terraform configuration for security issues.
Course content
Cloud security fundamentals
- 🔒 The shared responsibility model text
- 🔒 Cloud IAM and least privilege text
- 🔒 Securing cloud storage buckets text
Secrets and configuration
- 🔒 Secrets management in the cloud text
- 🔒 Avoiding hardcoded credentials text
- 🔒 Environment and config security text
Container security
- 🔒 Container security basics text
- 🔒 Writing secure Dockerfiles text
- 🔒 Scanning images for vulnerabilities text
CI/CD security
- 🔒 Securing the CI/CD pipeline text
- 🔒 SAST: static analysis essentials text
- 🔒 DAST and dependency scanning text
Infrastructure as code and observability
- 🔒 Infrastructure as code security basics text
- 🔒 Security monitoring and alerting text
- 🔒 Incident response in the cloud text
Practical project
- 🔒 Building a secure CI pipeline checklist text
- 🔒 Auditing a Terraform config for security issues text
- 🔒 Practical project: a DevSecOps pipeline text