Secure Software Development Lifecycle (SSDLC) with Hands-On Coding
Security bolted on at the end of a project is expensive, fragile, and too late. In this 4.5-hour hands-on workshop you will learn to build security into every phase of the software development lifecycle — and prove it with working code.
🔓 Open access, self-paced. All workshop materials — the syllabus, the full textbook, the presentation deck, and the knowledge check — are freely available. No purchase or enrollment required.
Who Is It For?
Software developers, security engineers, QA testers, and IT professionals with working familiarity with at least one programming language and basic web application concepts.
What You Will Do
- Analyze real-world breaches — the MOVEit file-transfer breach and the T-Mobile data breach — and pinpoint the lifecycle phase where each vulnerability was introduced.
- Build a threat model for a realistic e-commerce system and propose prioritized mitigations.
- Find and fix SQL injection, XSS, CSRF, and buffer overflows in live code.
- Run OWASP ZAP, Burp Suite, and SonarQube against a deliberately vulnerable application.
- Design a DevSecOps pipeline that makes security continuous rather than episodic.
What’s Included
- Course syllabus — full academic syllabus, also available as a designed PDF.
- Workshop textbook — ten chapters covering the complete lifecycle, with code examples, real-world cases, and a terminology appendix.
- Presentation deck — the complete 19-slide workshop deck, viewable and downloadable.
- Hands-on labs — threat modeling, a secure coding challenge, and a security testing lab.
- Knowledge check — a final quiz covering every phase of the SSDLC.
Course Details
| Duration | 4.5 hours across six sessions |
| Language | English |
| Format | Self-paced study, or instructor-led delivery for companies and organizations |
| Prerequisites | Working familiarity with at least one programming language and basic web application concepts |
| Tools covered | OWASP ZAP, Burp Suite, SonarQube, Microsoft Threat Modeling Tool, OWASP Threat Dragon, Dependabot |
Delivering this workshop in your organization? The course is also available as an instructor-led session for companies and teams. Contact Cyber School for details.