Course Duration
2 Days

Cyber
Authorized Training

IT

Course cost:
was £1,575 + VAT
£1,418 + VAT

IT Certification Overview

This practical course builds expertise in enterprise-scale AI-powered DevSecOps practices for modern software delivery environments. Delegates will learn to build secure DevSecOps pipelines with AI integrated from the start, using the Model Context Protocol (MCP) to enrich findings and streamline triage. The course covers supply chain security, automation, and the most effective tools used in production, helping learners overcome common DevSecOps challenges and scale security across enterprise environments. Hands-on labs and guidance from experienced security professionals ensure practical skills and real-world application.

Newto Training Reviews

What Our Happy Alumni Say About Us

Prerequisites

Anybody with a background in IT or related to software development whether a developer or a manager can attend this course to get an insight about DevOps and DevSecOps.

Target audience

  • DevOps and DevSecOps engineers
  • Application security engineers
  • Developers and technical leads
  • Enterprise and solution architects
  • Operations teams
  • CISOs

Learning Objectives

This course uses a Defence by Offense methodology based on real-world offensive research (not theory). That means everything we teach has been tried and tested, either in a live environment or in our labs, and can be applied (by you) once the course is over.

Delegates will learn how to:

  • Focus on supply chain security to harden CI/CD pipelines.
  • Exactly where to start when shifting from DevOps to DevSecOps.
  • Understand the role of Asset registry, security onboarding, vulnerability management, and supply chain security.
  • See how AI agents, connected via the Model Context Protocol (MCP), enrich and triage findings directly inside your DevSecOps pipeline.
  • Learn how to automate security into a fast-paced DevOps environment using various open-source tools and scripts that don’t slow down delivery.
  • Master the ability to craft custom rules for SAST, WAF, and Compliance as Code (CaC) to strengthen application security, enforce policies at scale, and proactively defend against evolving threats.
  • Hands-on experience in managing Application Security Posture Management(ASPM) systems and remediating issues to reduce the attack surface.
  • How to secure the pipeline from supply chain attacks using provenance and SBOM.
  • How to secure your methodology for managing and delivering Infrastructure as Code (IaC).
  • How to use Wazuh to monitor your application’s behaviours with logs and alerts.
  • How AI-assisted pentesting complements traditional DAST scanning.
  • What challenges to expect when moving to a DevSecOps model and how to overcome them.
  • How to mature your DevSecOps approach over time.

DevSecOps Course Content

Lab setup

  • Introduction to online lab setup and GitHub CI/CD

Introduction to DevOps

  • Overview of industry standards and practices
  • Continuous Integration (CI)
  • Continuous Delivery (CD)
  • Infrastructure as Code (IaC)
  • Continuous Monitoring

Introduction to DevSecOps

  • Integrating security into the software development lifecycle
  • Shift Left
  • DevSecOps lifecycle
  • Vulnerability management

Role of version control

  • Git as central version control
  • GitHub platform and actions ecosystem
  • Pull requests and merge requests

Supply chain security

  • Ensuring trusted and verified components
  • Creating security artifacts like provenance
  • Pushing results into ASPM
  • SLSA levels and AIBOM

Continuous integration

  • Identifying and remediating issues early
  • Pre-commit hooks and frameworks
  • Secrets management and credential handling
  • Tools: GitHub actions, GitHub Secrets, Talisman, Trufflehog, Defect Dojo

Software composition analysis (SCA)

  • Conducting SCA scans locally and in pipelines
  • Integrating with ASPM
  • Remediation strategies
  • Tools: Dependency-check

Enabling AI using MCP

  • Fundamentals of Model Context Protocol (MCP)
  • Building and deploying MCP server
  • Reducing token costs
  • Tools: MCP Server, MCP Client, GitHub Actions

SAST

  • Running and integrating SAST scans
  • Customising SAST rules
  • False positive analysis in ASPM
  • AI enrichment of findings
  • Tools: Opengrepo MCP Tool

AI Pen-testing and DAST

  • Configuring DAST for continuous testing
  • AI-driven Pen testing agents
  • Using OWASP ZAP and AI-assisted tools
  • Tools: AI Pentest tool, MCP Tool, OWASP ZAP

Continuous deployment

  • Embedding security controls in deployment pipelines
  • Using SBOM as a deployment gate
  • Fixing flagged components and dependency issues
  • Assessing infrastructure security
  • Tools: CycloneDX, Docker, MCP Tool

Continuous monitoring

  • Logging and monitoring applications and infrastructure
  • Setting up logging and monitoring
  • Firewalls and SIEM
  • Custom firewall rules
  • Tools: ModSecurity, Wazuh

DevSecOps challenges and enablers

  • Overcoming organisational and cultural challenges
  • Creating security champions
  • Case study discussions

Exams and assessments

Certificate of completion and Continuing Professional Education (CPE) credits awarded. Learning pack provided. Missing information provided for this section.

Hands-on learning

  • Running tools and testing against realistic use cases in dedicated labs
  • Automating code reviews for vulnerability and supply chain security
  • Implementing Defence in Depth and Secure by Design environments
  • Embedding human and cultural aspects of DevSecOps
  • Connecting MCP server to pipelines and using AI agents for enrichment, triage, and remediation

Upcoming Dates

Dates and locations are available on request. Please contact us for the latest schedule.

Advance Your Career with DevSecOps

Gain the skills you need to succeed. Enrol in DevSecOps with Newto Training today.