Secure Development Training

We don’t expect developers to become security experts. Instead, we aim to evolve internal definitions of “QA” to integrate security expectations seamlessly into development practices, making security a natural and essential part of the development process.

Created for Developers, By Developers

O ur interactive, two-day course combines lectures, hands-on security testing, manual code review, and remediation of common application vulnerabilities. Participants will learn how to design and code secure web solutions using defense-based code samples, third-party security libraries, and secure design review principles. Led by seasoned security practitioners with extensive multi-platform development experience, this secure development training expands awareness and establishes standards to effectively address critical, avoidable business risks.

Key Learning Objectives

  • Gain an understanding of top web application vulnerabilities and how to defend against them.
  • Learn secure password storage techniques.
  • Implement effective injection mitigation techniques.
  • Understand the limitations of HTTPS and how to mitigate risks.
  • Develop modern access controls for multi-tenancy environments.
  • Build a secure authentication mechanism.
  • Apply modern security headers in your applications.
  • Implement robust symmetric cryptographic storage solutions.
  • Use modern asymmetric cryptography effectively.
  • Design injection-safe user interfaces and server-side applications.
  • Master input validation and output encoding techniques.
  • Deploy multi-layered defenses against CSRF and clickjacking attacks.

This comprehensive training equips developers with the skills to integrate security seamlessly into their applications, reducing vulnerabilities and enhancing overall security posture.