<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="32309" language="fr" source="https://portal.flane.ch/swisscom/fr/xml-course/ec-ecde" lastchanged="2025-10-06T10:17:28+02:00" parent="https://portal.flane.ch/swisscom/fr/xml-courses"><title>EC-Council Certified DevSecOps Engineer</title><productcode>ECDE</productcode><vendorcode>EC</vendorcode><vendorname>EC-Council</vendorname><fullproductcode>EC-ECDE</fullproductcode><version>1.0</version><objective>&lt;ul&gt;
&lt;li&gt;Understand DevOps security bottlenecks and discover how the culture, philosophy, practices, and tools of DevSecOps can enhance collaboration and communication across development and operations teams.&lt;/li&gt;&lt;li&gt;Understand the DevSecOps toolchain and how to include security controls in automated DevOps pipelines.&lt;/li&gt;&lt;li&gt;Integrate Eclipse and GitHub with Jenkins to build applications.&lt;/li&gt;&lt;li&gt;Align security practices like security requirement gathering, threat modeling, and secure code reviews with development workflows.&lt;/li&gt;&lt;li&gt;Integrate threat modeling tools like Threat Dragon, ThreatModeler, and Threatspec; manage security requirements with Jira and Confluence; and use Jenkins to create a secure CI/CD pipeline.&lt;/li&gt;&lt;li&gt;Understand and implement continuous security testing with static, dynamic, and interactive application security testing and SCA tools (e.g., Snyk, SonarQube, StackHawk, Checkmarx SAST, Debricked, WhiteSource Bolt).&lt;/li&gt;&lt;li&gt;Integrate runtime application selfprotection tools like Hdiv, Sqreen, and Dynatrace that protect applications during runtime with fewer false positives and remediate known vulnerabilities.&lt;/li&gt;&lt;li&gt;Integrate SonarLint with the Eclipse and Visual Studio Code IDEs.&lt;/li&gt;&lt;li&gt;Implement tools like the JFrog IDE plugin and the Codacy platform.&lt;/li&gt;&lt;li&gt;Integrate automated security testing into a CI/CD pipeline using Amazon CloudWatch; Amazon Elastic Container Registry; and AWS CodeCommit, CodeBuild, CodePipeline, Lambda, and Security Hub.&lt;/li&gt;&lt;li&gt;Implement various automation tools and practices, including Jenkins, Bamboo, TeamCity, and Gradle.&lt;/li&gt;&lt;li&gt;Perform continuous vulnerability scans on data and product builds using automated tools like Nessus, SonarCloud, Amazon Macie, and Probely.&lt;/li&gt;&lt;li&gt;Implement penetration testing tools like gitGraber and GitMiner to secure CI/CD pipelines.&lt;/li&gt;&lt;li&gt;Use AWS and Azure tools to secure applications.&lt;/li&gt;&lt;li&gt;Integrate automated tools to identify security misconfigurations that could expose sensitive information and result in attacks.&lt;/li&gt;&lt;li&gt;Understand the concept of infrastructure as code and provision and configure infrastructure using tools like Ansible, Puppet, and Chef.&lt;/li&gt;&lt;li&gt;Audit code pushes, pipelines, and compliance using logging and monitoring tools like Sumo Logic, Datadog, Splunk, the ELK stack, and Nagios.&lt;/li&gt;&lt;li&gt;Use automated monitoring and alerting tools (e.g., Splunk, Azure Monitor, Nagios) and create a real-time alert and control system.&lt;/li&gt;&lt;li&gt;Integrate compliance-as-code tools like Cloud Custodian and the DevSec framework to ensure that organizational regulatory or compliance requirements are met without hindering production.&lt;/li&gt;&lt;li&gt;Scan and secure infrastructure using container and image scanners (Trivy and Qualys) and infrastructure security scanners (Bridgecrew and Checkov).&lt;/li&gt;&lt;li&gt;Integrate tools and practices to build continuous feedback into the DevSecOps pipeline using Jenkins and Microsoft Teams email notifications.&lt;/li&gt;&lt;li&gt;Integrate alerting tools like Opsgenie with log management and monitoring tools to enhance operations performance and security.&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;Students should have an understanding of application security concepts.&lt;/p&gt;</essentials><audience>&lt;ul&gt;
&lt;li&gt;C|ASE-certified professionals&lt;/li&gt;&lt;li&gt;Application security professionals&lt;/li&gt;&lt;li&gt;DevOps engineers&lt;/li&gt;&lt;li&gt;Software engineers and testers&lt;/li&gt;&lt;li&gt;IT security professionals&lt;/li&gt;&lt;li&gt;Cybersecurity engineers and analysts&lt;/li&gt;&lt;li&gt;Anyone with prior knowledge of application security who wants to build their career in DevSecOps&lt;/li&gt;&lt;/ul&gt;</audience><contents>&lt;ul&gt;
&lt;li&gt;Understanding DevOps Culture&lt;/li&gt;&lt;li&gt;Introduction to DevSecOps&lt;/li&gt;&lt;li&gt;DevSecOps Pipeline&amp;mdash;Plan Stage&lt;/li&gt;&lt;li&gt;DevSecOps Pipeline&amp;mdash;Code Stage&lt;/li&gt;&lt;li&gt;DevSecOps Pipeline&amp;mdash;Build and Test Stage&lt;/li&gt;&lt;li&gt;DevSecOps Pipeline&amp;mdash;Release and Deploy Stage&lt;/li&gt;&lt;li&gt;DevSecOps Pipeline&amp;mdash;Operate and Monitor Stage&lt;/li&gt;&lt;/ul&gt;</contents><objective_plain>- Understand DevOps security bottlenecks and discover how the culture, philosophy, practices, and tools of DevSecOps can enhance collaboration and communication across development and operations teams.
- Understand the DevSecOps toolchain and how to include security controls in automated DevOps pipelines.
- Integrate Eclipse and GitHub with Jenkins to build applications.
- Align security practices like security requirement gathering, threat modeling, and secure code reviews with development workflows.
- Integrate threat modeling tools like Threat Dragon, ThreatModeler, and Threatspec; manage security requirements with Jira and Confluence; and use Jenkins to create a secure CI/CD pipeline.
- Understand and implement continuous security testing with static, dynamic, and interactive application security testing and SCA tools (e.g., Snyk, SonarQube, StackHawk, Checkmarx SAST, Debricked, WhiteSource Bolt).
- Integrate runtime application selfprotection tools like Hdiv, Sqreen, and Dynatrace that protect applications during runtime with fewer false positives and remediate known vulnerabilities.
- Integrate SonarLint with the Eclipse and Visual Studio Code IDEs.
- Implement tools like the JFrog IDE plugin and the Codacy platform.
- Integrate automated security testing into a CI/CD pipeline using Amazon CloudWatch; Amazon Elastic Container Registry; and AWS CodeCommit, CodeBuild, CodePipeline, Lambda, and Security Hub.
- Implement various automation tools and practices, including Jenkins, Bamboo, TeamCity, and Gradle.
- Perform continuous vulnerability scans on data and product builds using automated tools like Nessus, SonarCloud, Amazon Macie, and Probely.
- Implement penetration testing tools like gitGraber and GitMiner to secure CI/CD pipelines.
- Use AWS and Azure tools to secure applications.
- Integrate automated tools to identify security misconfigurations that could expose sensitive information and result in attacks.
- Understand the concept of infrastructure as code and provision and configure infrastructure using tools like Ansible, Puppet, and Chef.
- Audit code pushes, pipelines, and compliance using logging and monitoring tools like Sumo Logic, Datadog, Splunk, the ELK stack, and Nagios.
- Use automated monitoring and alerting tools (e.g., Splunk, Azure Monitor, Nagios) and create a real-time alert and control system.
- Integrate compliance-as-code tools like Cloud Custodian and the DevSec framework to ensure that organizational regulatory or compliance requirements are met without hindering production.
- Scan and secure infrastructure using container and image scanners (Trivy and Qualys) and infrastructure security scanners (Bridgecrew and Checkov).
- Integrate tools and practices to build continuous feedback into the DevSecOps pipeline using Jenkins and Microsoft Teams email notifications.
- Integrate alerting tools like Opsgenie with log management and monitoring tools to enhance operations performance and security.</objective_plain><essentials_plain>Students should have an understanding of application security concepts.</essentials_plain><audience_plain>- C|ASE-certified professionals
- Application security professionals
- DevOps engineers
- Software engineers and testers
- IT security professionals
- Cybersecurity engineers and analysts
- Anyone with prior knowledge of application security who wants to build their career in DevSecOps</audience_plain><contents_plain>- Understanding DevOps Culture
- Introduction to DevSecOps
- DevSecOps Pipeline—Plan Stage
- DevSecOps Pipeline—Code Stage
- DevSecOps Pipeline—Build and Test Stage
- DevSecOps Pipeline—Release and Deploy Stage
- DevSecOps Pipeline—Operate and Monitor Stage</contents_plain><duration unit="d" days="3">3 jours</duration><pricelist><price country="DE" currency="EUR">2950.00</price><price country="AT" currency="EUR">2950.00</price><price country="SE" currency="EUR">2950.00</price><price country="CH" currency="CHF">3300.00</price><price country="NL" currency="EUR">2950.00</price><price country="IT" currency="EUR">2950.00</price><price country="SI" currency="EUR">2950.00</price></pricelist><miles/></course>