LAB · SUPPLY CHAIN
Know what you ship
Generate an SBOM for a real build and trace one dependency to its origin.
> Security · DevOpsSchool Training
Live online batches timed for ET (UTC−5), or corporate onsite across United States — every session a live demo in a real lab, not slides.
★ 4.8 / 5 from 2,300+ ratings18,000+ engineers certifiedTrained teams at JPMorgan Chase, Verizon, Nokia, World Bank
# upcoming batches
Times shown in ET (UTC−5). New cohorts start on the 1st of every month.
| Starts | Days & time | Timezone | Mode | Duration | Seats | Enrol |
|---|---|---|---|---|---|---|
| —Most popular | Weekend · Sat · Sun 10:00 AM – 1:00 PM | ET (UTC−5) | Live online · Corporate onsite | 5 weekends | — of 10 left | Reserve |
| — | Weekday · Mon · Wed · Fri 8:00 – 10:00 PM | ET (UTC−5) | Live online · Corporate onsite | 5 weeks | — of 10 left | Reserve |
Batches are capped at 10 learners by design. We do not run a classroom in United States — sessions here are live online, or onsite at your office for corporate batches.Need a date that isn't listed? Talk to us about a private batch →
# how you attend
Individuals, anywhere
Scheduled instructor-led batch. Every session is a live demo in a real lab, and every session is recorded.
Reserve my seatTeams of 8–30
Custom agenda built from your stack, delivered at your office or online, in your timezone. NDA-friendly, invoiced against a PO.
Request a quoteSelf-starters
The full recorded curriculum plus a year of the entire LMS — 20+ courses and 50+ tools, not just this one.
Enroll now# private batches
We start with a discovery call, map your stack to the modules below, and drop anything your team already runs in production. Delivery is at your office, online, or hybrid — in your timezone, scheduled around your release calendar.
Send us the tools, the team size and a rough window. You'll get an agenda and a quote back, not a sales call.
# united states
DevSecOps training in United States is taken mostly by DevOps engineers adding security to existing pipelines and Security engineers working with delivery teams. Sessions run live online in ET (UTC−5), or onsite at your office — there is no United States classroom. Teams here often pair it with our DataOps and DevOps training, and a corporate batch can cover more than one in a single engagement. A United States-wide cohort spans four domestic timezones and, more importantly, several different hiring markets. The expectations of a platform engineer in a coastal product company and one in a midwestern insurance carrier are not the same, and a session that assumes either will lose the other. We handle that by teaching the reasoning rather than the house style, and by keeping the labs realistic for both. The common thread across US teams is cost scrutiny. Cloud spend has moved from a growth line to a reviewed line, and engineers are increasingly expected to explain a bill as fluently as an architecture diagram. That is now a substantial part of what a US cohort actually asks about. There is no US classroom. Sessions are live online, and the timezone offset from IST is significant — most US learners rely on recordings for part of the cohort, with mentor hours scheduled in US working time. Corporate batches are run entirely within your own hours and invoiced in USD.
We do not run a classroom in United States. Batches here are live online, or onsite at your office for corporate cohorts.
Our two classrooms are in Bengaluru and Hyderabad.
# the subject
DevSecOps means the security work happens where the change happens: dependency and container scanning in the pipeline, static and dynamic analysis on every merge request, secrets kept out of source control by construction, infrastructure policy evaluated before apply, and a software bill of materials produced for every release. The design problem is signal. A pipeline that fails on every medium-severity finding gets bypassed within a week. The practice that works is failing the build on a narrow, defensible set of conditions and reporting the rest.
Supply-chain attacks and regulation have moved security from a pre-release gate to a continuous property of the pipeline, and the people who can implement that without destroying delivery speed are genuinely scarce. Employers are looking for engineers who can hold both concerns at once rather than specialists in either.
# outcomes
# curriculum
Every module follows the same shape: 5 hrs · 2 assignments · 1 capstone.
What is DevSecOps?, DevSecOps as part of DevOps, Static Code Analysis, Dynamic Code Analysis, Secure Code Review, Defect Classifications, OWASP open web application security project, CWE common weakness enumeration
DevOps and CI/CD Refresher, DevOps Basics, Principles of DevOps, DevOps Benefits, Continuous Integration, Continuous Deployment, Continuous Delivery, Typical CI/CD pipeline
Deployment strategies, Tooling, Maven, Docker, Kubernetes, Jenkins, Bitbucket, Travis
OWASP ZAP/, Ansible/Chef, Inspec, Terraform, Secure SDLC, What is Secure SDLC, Secure SDLC Activities and Security Gates, Requirements, Design, Implementation and Testing
Deployment and Maintenance, Embedding Security as part of CI/CD pipeline, DevSecOps and challenges with Pentesting and Vulnerability Assessment., DevSecOps Maturity Model (DSOMM), Maturity levels and tasks involved, 4-axes in DSOMM, Going from Maturity Level 1 to Maturity Level 4, Maturity level specific practices and challenges
Software Component Analysis (SCA), What is Software Component Analysis., SCA Solutions, Embedding SCA tools into the pipeline, SCA Tool - Blackduck, Sonatype Nexus Lifecycle, JFrog Xray, Snyk, SAST (Static Analysis Security Testing), What is Static Application Security Testing., Embedding SAST tools in the pipeline.
Preventing secrets exposure in the code., SAST Tool - Checkmarx, Veracode, Fortify, Coverity etc, DAST (Dynamic Analysis Security Testing), What is Dynamic Application Security Testing?, Session management & AJAX Crawling, DAST tools, SSL misconfiguration testing, Creating baseline scans for DAST.
Scan frequencies, DAST Tool - Burp, AppScan, OWASP ZAP, Infrastructure as Code (IaaC), What is Infrastructure as Code?, Benefits of Infrastructure as Code, Building Blocks, Configuration Management Systems, Ansible
Modules, tasks, roles and Playbooks, Compliance as code, Handling Compliance Requirements, Using configuration management to achieve compliance., Inspec / OpenScap, Vulnerability Management, Managing vulnerabilities in the organization., Defect Dojo, RiskSense
What is Software Development, What is SDLC, SDLC Models, Agile Model, Waterfall Model, Issues in traditional way, What is DevOps
Open-book, scenario-based, taken in the LMS. Two free re-attempts and detailed feedback.
# hands-on
We don't hand out a sandbox that expires. You provision your own free-tier environment with our guidance, so the setup skill goes with you.
LAB · SUPPLY CHAIN
Generate an SBOM for a real build and trace one dependency to its origin.
LAB · SECRETS
Find committed secrets in history, remove them and rotate what leaked.
LAB · POLICY
Write policy that blocks a non-compliant infrastructure change at plan time.
# toolchain
# pricing
₹833/mo
billed yearly ₹9,996
All recorded sessions, labs and the full LMS — at your own pace.
₹34,999₹49,999SAVE 30%
works out to ₹2,917/moIllustrative monthly equivalent. The full amount is charged once at enrolment; we do not offer instalments.
5-week live cohort plus the complete LMS bundle.
₹99,999
works out to ₹8,333/moIllustrative monthly equivalent. The full amount is charged once at enrolment; we do not offer instalments.
A dedicated senior practitioner. Pace, schedule and labs tailored to you.
+ 18% tax / VAT as applicable · Prices are charged in INR.
If we cancel or postpone a cohort and you decline the rescheduled session, you get a 100% refund within 15 days. Refund policy →
Recordings, slides and lab repos are licensed to you for your own learning. Terms →
We don't share your details with third parties. Privacy →
# who teaches it
Twenty years across DevOps, SRE and security, in principal and architect roles at PayPay, SoftwareAG, ServiceNow, Intuit, Adobe and IBM. Has personally trained more than 10,000 engineers at JPMorgan Chase, Verizon, Nokia, the World Bank and dozens more. He teaches what he runs, not what he reads.







# the credential
Certificate of Completion
Your Name
DevSecOps Training in United States
DS-DEVSEC-XXXX-XXXX
# reviews
4.8 / 5 from 2,300+ ratings.
Reviews for this program are being collected from public sources. Every review shown here links to the original.
# alternatives
| What matters | YouTube + blogs | Generic online course | Local training institute | DevOpsSchool |
|---|---|---|---|---|
| Teaching method | Unstructured, no sequence | Pre-recorded slides | Slide-led classroom | Live demos in a real lab |
| Batch size | n/a | Unlimited | 30–60 | Capped at 10 |
| Lab environment | Yours to figure out | Shared sandbox that expires | Shared lab | You build your own — the skill goes with you |
| Per-tool structure | None | Video only | Varies | 5 hrs · 2 assignments · 1 capstone |
| Assessment | None | Quiz | Attendance | 3 hours · online · open-book · scenario-based |
| Certificate | None | Auto-issued | Attendance certificate | Industry-recognised, verifiable |
| Corporate invoicing | No | Card only | Sometimes | PO, tax invoice, NDA |
| Post-training support | None | Forum for 30 days | None | Lifetime forum support |
| Total cost | Free, and it costs you months | Low, low completion | High | One fee, LMS included |
# questions
No. We do not have a training centre in United States, and we would rather say so than let you plan a commute. Batches here run live online, or onsite at your own office for corporate cohorts. Our two classrooms are in Bengaluru and Hyderabad.
Our instructors teach from India, so sessions are converted into ET (UTC−5) on the batch table above rather than quoted in IST. The weekday cohort lands more conveniently for United States than the weekend one, and every session is recorded the same day. For a corporate batch we schedule entirely inside ET (UTC−5) working hours instead.
The curriculum is the same everywhere — it is the same course, and pretending otherwise would be dishonest. What changes for United States is delivery: the batch times are set for ET (UTC−5), fees are shown in USD, and delivery is live online or onsite at your office rather than in a classroom. The examples our instructors reach for also tend to follow what United States teams actually run.
No, and that is deliberate. You build the labs on your own free-tier account, and we walk through the setup and the cost guardrails in week one. A sandbox that expires when the course ends teaches you nothing you keep; your own environment does.
Every session is recorded and available in the LMS the same day, and you keep access for a year. You can also sit the missed session again with the next cohort at no extra cost.
Comfortable with Git and a CI pipeline; Understanding of how your software is built and deployed; Basic Linux and networking. If you are unsure whether you are ready, tell us what you work on now and we will give you a straight answer rather than a sales one.
You get an industry-recognised DevOpsSchool certificate after the three-hour open-book exam. Most people find the capstone repositories carry more weight in an interview than the certificate itself, which is why the labs are built to be shown.
Yes. We build the agenda from your stack after a discovery call and drop anything your team already runs in production. Teams of 8 to 30 work best; larger groups split into parallel batches.
If we cancel or postpone a cohort and you decline the rescheduled session, you get a full refund within 15 days. We do not offer a general money-back guarantee, and taxes and gateway fees are not refunded.
No. The fee is charged once at enrolment. Where we show a monthly figure it is arithmetic to help you size the cost against a budget, not a payment plan.
# elsewhere
# keep learning
Everything below is open and free — no enrolment needed.
# in the room








# ready when you are