Building an AppSec Program
Stop firefighting vulnerabilities. Build an application security program that scales.
Tuition
$399
Advanced
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
10 hours
Estimated time
What you will be able to do
- Assess your organization's application security maturity against a recognized model and turn the gaps into a realistic, risk-based roadmap.
- Shift security left by embedding threat modeling and secure design reviews into the software development lifecycle (SDLC) before code is written.
- Recruit, charter, and sustain a security champions network that extends your reach into every engineering team without adding headcount.
- Wire automated security testing into your CI/CD pipelines, covering static and dynamic scanning, dependency checks, secrets detection, and infrastructure as code review.
- Design security gates that stop genuine risk while protecting developer trust and release speed.
- Triage and prioritize vulnerabilities at scale using severity, exploitability, and business context so teams fix what matters first.
- Build a metrics dashboard and an executive narrative that prove the program is reducing risk over time.
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
AppSec Program Foundations and Shifting Left
A program scales only when it rests on strategy, not on heroics. In this module you will size up your current state against maturity models such as the Software Assurance Maturity Model (SAMM) from the Open Worldwide Application Security Project (OWASP) and the Building Security In Maturity Model (BSIMM), then set risk-based priorities. You will also learn to shift security left by moving threat modeling and secure design upstream, so problems are caught before a single line of vulnerable code ships.
2 lessons · 5 quiz questions
- 02
Security Champions and Scaling Secure Development
You cannot personally review every design and every pull request, so scaling application security means multiplying your influence instead of your hours. This module shows you how to design a security champions program that developers actually want to join: how to recruit champions, give them a clear charter, reward the work, and keep them engaged. You will also learn to build paved roads (the safe, well-supported defaults developers reach for first), write secure coding standards people actually use, and deliver training that helps hundreds of developers make safer choices without slowing down.
2 lessons · 5 quiz questions · assignment
- 03
CI/CD Security Gates and Automation
Automation is how application security keeps pace with modern release speed. This module assembles the testing layers that belong in a continuous integration and continuous delivery (CI/CD) pipeline (static and dynamic testing, software composition analysis, secrets detection, and infrastructure as code scanning), then shows how to turn those tools into gates that block genuine risk while keeping false positives and broken builds low enough that developers keep trusting the pipeline.
2 lessons · 5 quiz questions
- 04
Vulnerability Triage at Scale and Program Metrics
Every scanner you add produces more findings than any team can fix, so triage is where a program lives or dies. This module teaches you to deduplicate, route, and prioritize vulnerabilities using severity, exploitability, and business context, drawing on the Common Vulnerability Scoring System (CVSS) and the Exploit Prediction Scoring System (EPSS), and to hold remediation to fair service level agreements (SLAs). You then build the metrics and the executive story, from mean time to remediate (MTTR) to risk burndown, that prove the program is actually reducing risk.
2 lessons · 5 quiz questions · assignment