Complete the 6-Month DevOps Roadmap first.
- OWASP Top 10
- CIA Triad, defense in depth
- Threat modeling basics
- Security in SDLC
Milestone: Complete threat model for sample app
- SAST fundamentals (Semgrep, CodeQL)
- SCA/Dependency scanning (Trivy, Snyk)
- Secret detection (Gitleaks)
- Integrating into CI/CD
Milestone: Security scanning pipeline
- IaC scanning (Checkov, tfsec)
- Container scanning
- Kubernetes security basics
- Network security
Milestone: Secure Terraform + K8s deployment
- HashiCorp Vault
- AWS Secrets Manager
- SOPS for GitOps
- External Secrets Operator
Milestone: Vault-integrated application
- Pipeline hardening
- OIDC authentication
- Signed commits
- Artifact signing (Cosign)
Milestone: Fully secured CI/CD pipeline
- Falco
- Network Policies
- Pod Security Standards
- OPA/Gatekeeper
Milestone: Runtime-protected K8s cluster
- SLSA framework
- SBOM generation
- Dependency verification
- Image attestations
Milestone: SLSA Level 2 compliance
- Policy as Code
- Compliance frameworks (SOC2, PCI)
- Audit logging
- Reporting
Milestone: Compliance dashboard
- Complete secure microservices platform
- Full DevSecOps pipeline
- Security documentation
- DevSecOps interview questions
- Scenario-based practice
- Portfolio finalization
Next: See 6-Month AI SecOps roadmap.