Fortifying systems against threats while navigating enterprise requirements, this class integrates security, governance, and compliance into the software development lifecycle (DevSecOps). Students will learn core security principles including identity and access management (IAM), encryption (at rest and in transit), network security (firewalls, VPCs), vulnerability scanning, and threat modeling. Enterprise tools covered include SIEM platforms (Splunk, Sentinel), secret management (HashiCorp Vault), SAST/DAST scanning (SonarQube, Snyk), and policy-as-code (Open Policy Agent). The compliance module addresses frameworks such as SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS—including audit trails, data retention, and incident response planning. By the end, learners will be able to build secure, audit-ready systems that meet regulatory standards—preparing them for DevSecOps, security engineer, or compliance analyst roles.
Explore the full learning path section by section and preview what is included in this program.