DevSecOps Fundamental Bootcamp Fundamental · DevOps experience required

Catch it at the commit,not in the breach.

Every commit goes through the scanner. Learn to build the gates: secret scanning, SAST, dependency and image scanning, policy as code, Vault, AWS and Kubernetes hardening, and to judge which of the hundreds of findings actually matter.

€359 €640 −44% One-time payment
Lifetime access
See the curriculum
Self-paced, writtenMentor Bob in every section3 capstones + portfolio
LANE 2 · PR #418 · payments-api → main
Scanning Reading 5 changed files…

Five scanners, five chapters. Pick a filter to see what each one is looking for.

0Core lessons
0Chapters
0Written sections
0Practice sets
0Assessment questions
0Capstone case files
0Portfolio modules
0Words, code included

Counted from the lesson files: 100 chapter assessments × 30 questions. Plus a 12-chapter software installation guide.

Gate 01What the job is

Scanners find. Engineers decide.

Turning on a scanner takes an afternoon. The job is what comes after: a quarterly scan at a fintech returns 847 findings, and someone has to say which one gets fixed first, and why. Here are five of them, from the practice exercise in Chapter 9.5. Add each signal and watch the order change.

FinVault · B2B payments · AWS · PCI-DSS v4.0, GDPR, SOC 2Fix order ↓

Findings, EPSS and KEV values and the reference order are from Chapter 9.5's Practice, Task 2. Weights here: exploitability 37.5%, asset 27.5%, CVSS 20%, business impact 15%, inside the ranges its reference guidance gives. The chapter has you design and defend your own.

A normal week, and where each part is taught

Mon

Triage the weekend's scan results by risk, not by CVSS.

Ch 9.5 · Prioritization and Triage
Tue

Review a Terraform PR; the policy check flags a public bucket.

Ch 5.4 IaC Scanning · 5.5 Policy as Code
Wed

A token shows up in CI logs. Rotate it, then check CloudTrail for use.

Ch 2.10 Secrets Detection · 3.7 AWS Logging
Thu

Replace a service account's cluster-admin binding with a namespace Role.

Ch 4.2 · Kubernetes RBAC
Fri

Roll out a new pod security policy in audit mode before enforcing it.

Ch 4.3 · Pod Security Standards
Gate 02Where it takes you

Six badges. One skill set.

Companies hire for the same core skills under different job titles. Each badge lists the lessons that give it its access.

This is a Fundamental-tier bootcamp for people coming from DevOps. Expect these titles at their first level, with the senior versions coming from the experience you build on top.

Gate 03Who it's for

Pre-screening. Be honest.

This bootcamp adds the security layer on top of DevOps skills you already have. It doesn't teach Docker or CI/CD from scratch. Tick what you've actually done.

Clearance questionnaire

Used, not just read about.

CHECKS PASSED 0 / 6

Cleared for this bootcamp

  • You run CI/CD, containers or cloud infrastructure and want security to stop being someone else's department
  • You work in, or want to move into, regulated industries (fintech, healthcare, public sector) where audits are routine
  • You want to know how attacks work, so your controls aren't just checkbox compliance
  • You want written reference material you'll reopen on the job, and capstones you can show a hiring manager
  • You want to learn at your own pace, without a weekly class schedule

Not this lane

  • You've never worked with DevOps or cloud tooling. Start with DevOps Beginner
  • You want a SOC analyst course. This is engineering, not alert-queue blue-teaming
  • You want exam prep for CISSP, CEH or similar. It teaches the skills behind them, not the exam
  • You need a live instructor, a cohort or video lectures. Everything here is written and self-paced
Gate 04Curriculum

The coverage matrix. 104 chapters.

Ten lessons, one column each, one cell per chapter, laid out like the threat-coverage matrices security teams use. Click any chapter to see its sections, or run an incident to see which chapters defend against it.

Run an incident:

No incident running. Every chapter is shown.

← Scroll the matrix sideways →

Lesson 11 · Installation guide

12 chapters setting up the toolchain on your machine, ending with Killercoda, a free browser sandbox for practising Kubernetes and container commands.

Lesson 12 · Capstones

Three case files, each worked through in three phases with a reference solution. Open them ↓

Lesson 13 · Portfolio

Eight modules that turn the capstones into case studies, diagrams and a threat model report you can publish.

A grey dot on a cell means that chapter has no 30-question assessment in the current files (4 of 104).

Gate 05Inside one chapter

One chapter, under the scanner.

Chapter 2.10, Secrets Detection in CI/CD, scanned layer by layer. Five written sections, a practice set and a 30-question assessment, with each bar sized to its real word count. Every chapter follows this structure.

Chapter 2.10 · 7 layers46,834 words

Bar length = words in that section (code examples included). Click a layer.

Gate 06Capstones

Three case files. No answer sheet.

Each capstone is a company with a real problem and real constraints. You work through it in three phases: current-state risk assessment, control and tooling design, rollout and validation. The reference solution compares reasoning, not a final answer: four decisions, each with the option chosen and the alternative rejected.

Lesson 13Evidence locker

Then turn the case files into a portfolio.

Eight modules take your capstone work and make it something a hiring manager can evaluate, with guidance on anonymising anything confidential before you publish it.

Gate 07Salaries

What the security layer is worth.

Gross annual base salary for DevSecOps roles, set against what a general DevOps engineer earns, since that's where most people taking this bootcamp start. Few salary sites track "DevSecOps" as its own title, so these bands combine sources and should be read as ranges, not promises.

Gate 08Mentor Bob

Stuck at 11pm? Ask Bob.

Self-paced doesn't mean on your own. Mentor Bob is an AI study assistant in the corner of every section. It has already read the section you're on, so you can ask about it in your own words.

  • Answers from the section you're reading, not from the whole internet
  • Explains a concept another way, or with a new example
  • There in every lesson, at any hour. Included, not an upsell
🔒 MENTOR BOBChapter 2.10 · Section C
Example conversations, written from the chapters they're set in.
Gate 09FAQ

Questions before boarding.

Do I need security experience?

No. You need DevOps experience: Git, a CI/CD pipeline, Docker, basic Kubernetes and AWS, the Linux command line. Security starts from first principles in Lesson 1 (threat modelling, compliance frameworks, IAM, incident response) and builds from there.

Is it only AWS?

Lesson 3 (Cloud Security) and the AWS parts of Lesson 8 are AWS-focused: IAM, VPC security, KMS, GuardDuty, Security Hub, Inspector, CloudTrail. Everything else is cloud-agnostic: Kubernetes, Terraform, Vault, container security and the CI/CD scanners work the same way on any provider.

Which tools does it cover?

Among others: Gitleaks, TruffleHog and GitGuardian for secrets; Semgrep and SonarQube for SAST; Snyk, Trivy and Grype for dependencies and images; Checkov, tfsec and Terrascan for IaC; OPA/Gatekeeper, Kyverno and Sentinel for policy as code; HashiCorp Vault; Cosign/Sigstore and SBOMs for supply chain; Falco for runtime detection; OWASP ZAP and Burp Suite for testing. The chapters compare tools rather than only teaching one.

Is it hands-on, or just reading?

It's written, but 101 chapters have a practice section built around a realistic scenario, with real commands and configuration to work through. Lesson 11 walks through installing the toolchain, and recommends Killercoda as a free, disposable browser sandbox for Kubernetes and container practice.

Will this prepare me for a certification?

It isn't exam prep and doesn't follow any certification's syllabus. It teaches the engineering skills that security certifications test, so it's useful background, but you'd still want a dedicated exam guide.

Does it cover penetration testing?

Lesson 10 covers security testing from the engineer's side: methodologies, web application, API, infrastructure and Kubernetes testing, security chaos engineering, red team operations and reporting. It's an introduction aimed at building better defences, not a pentester career track.

How long will it take?

It depends entirely on your pace and background, so we don't promise a number of weeks. For scale: one chapter, like 2.10, is around 47,000 words including its code examples. You keep access for life, so there's no deadline.

What happens after I pay?

Every lesson unlocks straight away in your dashboard, with Mentor Bob in each section. It's a one-time payment with lifetime access, so no subscription and no renewal.

Security clearance · DevSecOps Fundamental

Security is everyone's job now. Make it yours first.

All 10 lessons and 104 chapters, plus the installation guide, three capstones and the portfolio lessons, unlocked as soon as you enroll.

AccessLifetime
PaceYour own
MentorBob, 24/7
Cleared
Admit one
€359€640 · −44% · one-time