Build the expertise to design, develop, and maintain secure applications and infrastructure across modern cloud environments.

EC-Council’s Certified DevSecOps Engineer (E|CDE) v2 is a practical, lab intensive course covering AI powered DevSecOps, application security, infrastructure security, and secure development across on premises environments and AWS, Azure, and GCP.

  • Why get trained: Learn to build secure CI/CD pipelines, apply Shift Left security, integrate threat modeling and security testing tools, perform SAST, DAST, IAST, and SCA, secure containers and infrastructure, implement Infrastructure as Code, and strengthen monitoring, compliance, and incident response.
  • Why it matters: Integrating security throughout the development lifecycle helps organizations identify vulnerabilities earlier, automate security controls, protect applications and infrastructure, and maintain secure and efficient delivery pipelines.
  • Who should attend: DevOps Engineers, Application Security Professionals, Software Engineers, Testers, IT Security Professionals, Cybersecurity Engineers, Cybersecurity Analysts, and CASE Certified Professionals.

Build hands on DevSecOps capabilities and develop the skills to integrate security across applications, infrastructure, cloud platforms, and CI/CD environments. HRD Corp Claimable.

Overview

According to Verified Market Research, the DevSecOps market was valued at USD 8.15 billion in 2024 and is projected to reach USD 58.32 Billion by 2031, ascending at a CAGR of 30.76% from 2024 to 2031.

The growth of the DevSecOps market is fueled by a surge in sophisticated cyberattacks, increasing the need for quick delivery of secure applications. Organizations are looking for certified DevSecOps engineers, with competitive salaries for freshers as well as experienced professionals, to help them with developing quick and secure software products. However, due to a lack of skilled DevSecOps professionals, most of the organizations are unable to find suitable candidates and the position remains vacant for years.

EC-Council’s Certified DevSecOps Engineer (E|CDE) v2 is a lab-intensive, practical course that incorporates the use of AI in DevSecOps and equips professionals with relevant skills to design, develop, and maintain secure applications and infrastructure. It covers both application and infrastructure in on-premises and the top 3 cloud-native platforms—AWS, Azure, and GCP.

Skills Covered

  • Learn to integrate Eclipse and GitHub with Jenkins to streamline application development and build processes
  • Learn to integrate threat modeling tools like Threat Dragon, ThreatModeler, and Threatspec
  • Integrate Jira and Confluence to effectively manage security requirements throughout the development lifecycle
  • Learn to integrate security plugins, scanners, and software composition analysis (SCA) tools within IDEs to detect and mitigate vulnerabilities early in development, following a Shift-Left security approach
  • Use Jenkins to create and manage secure CI/CD pipelines
  • Gain expertise in using various SAST (Snyk, SonarQube, and Checkmarx), DAST (Stackhawk, OWASP ZAP, and Invicti), IAST (CxFlow IAST and Invicti Shark), and SCA (Debricked, Mend, and OWASP Dependency-Check) tools for comprehensive security testing
  • Integrate RASP tools like Contrast Security, Datadog, and Dynatrace to protect applications during runtime with minimal false positives and effective vulnerability remediation
  • Learn to integrate tools like SonarLint with Eclipse, Visual Studio, and VS Code to enhance code quality and security within the development environment
  • Implement tools such as JFrog Security IDE Plugin, Snyk ID, and Codacy to automate security testing within the CI/CD pipeline
  • Conduct continuous vulnerability scans on product builds using automated scanning tools like Nessus, SonarQube, SonarCloud, Amazon Macie, and Probely Vulnerability Scanning
  • Use penetration testing tools like GitGraber, Gitleaks, and GitMiner to secure the CI/CD pipeline against vulnerabilities
  • Provision and configure infrastructure using infrastructure as code (IaC) tools like Ansible, Puppet, and Chef
  • Implement comprehensive logging and monitoring using tools like Sumo Logic, Datadog, Splunk, ELK, and Nagios to audit everything from code pushes to compliance activities
  • Use automated monitoring and alerting tools such as Splunk, Paessler PRTG, and Nagios to build real-time alerting and control systems
  • Integrate Compliance as Code (CaC) tools like Cloud Custodian and DevSec to meet regulatory requirements without disrupting production
  • Learn to scan and secure infrastructure using container and image scanners (Trivy, Qualys) and infrastructure security scanners (Prisma Cloud, Checkov)
  • Integrate continuous feedback mechanisms into the DevSecOps pipeline using tools like email notifications in Jenkins and Microsoft Teams
  • Integrate alerting tools like OpsGenie with log management and monitoring tools to improve operational performance and security
  • Integrate tools like Incident.io, PagerDuty, and Splunk for effective incident response within the DevSecOps pipeline

Prerequisites

Students should have an understanding of application security concepts.

Target Audience

Anyone with prior knowledge of application security, who wants to build a career in DevSecOps.

The intended professionals for the course are:

  • CASE Certified Professionals
  • Application Security Professionals
  • DevOps Engineers
  • Software Engineers/ Testers
  • IT Security Professionals
  • Cybersecurity Engineers/ Analysts

Course Curriculum

Module 1: Understanding DevOps Culture

Module 2: Introduction to DevSecOps

Module 3: DevSecOps Pipeline – Plan Stage

Module 4: DevSecOps Pipeline – Code Stage

Module 5: DevSecOps Pipeline – Build and Test Stage

Module 6: DevSecOps Pipeline – Release and Deploy Stage

Module 7: DevSecOps Pipeline – Operate and Monitor Stage

Dates & Locations

Let’s make it work for you

Can’t find a date that fits? Need to train your whole team? Looking for a discount?
Speak to one of our learning experts today.

January 11, 2027 - January 13, 2027

Location: Kuala Lumpur
Modal: ILT
Availability: TBC
Exam:
Included

January 11, 2027 - January 13, 2027

Location: Online
Modal: VILT
Availability: TBC
Exam:
Included

April 6, 2027 - April 8, 2027

Location: Kuala Lumpur
Modal: ILT
Availability: TBC
Exam:
Included

April 6, 2027 - April 8, 2027

Location: Online
Modal: VILT
Availability: TBC
Exam:
Included

August 24, 2027 - August 26, 2027

Location: Kuala Lumpur
Modal: ILT
Availability: TBC
Exam:
Included

August 24, 2027 - August 26, 2027

Location: Online
Modal: VILT
Availability: TBC
Exam:
Included

November 17, 2027 - November 19, 2027

Location: Kuala Lumpur
Modal: ILT
Availability: TBC
Exam:
Included

November 17, 2027 - November 19, 2027

Location: Online
Modal: VILT
Availability: TBC
Exam:
Included
Trainocate exam and cert

Exam & Certification

Certified DevSecOps Engineer (E|CDE) v2

The course is lab-intensive and hands-on, covering the complete DevSecOps pipeline, from planning and coding through build, testing, release, deployment, operation, and monitoring. Participants gain practical exposure to security practices across on-premises environments and AWS, Azure, and GCP.

The certification validates the ability to apply key DevSecOps practices, including Shift Left security, threat modeling, SAST, DAST, IAST, SCA, container security, Infrastructure as Code (IaC), security automation, monitoring, compliance, and incident response.

By earning the Certified DevSecOps Engineer (E|CDE) v2 certification, professionals demonstrate their ability to integrate security throughout the software development lifecycle and help organizations build, deploy, and maintain secure applications and infrastructure across modern cloud environments.

Training & Certification Guide

Exam Number: 312-97
Questions: 100
Passing Score: 70%
Duration: 4 hours
Test format: Multiple-Choice
Passing score: 70%

Frequently Asked Questions

DevSecOps is a trending practice in application security that involves introducing security earlier in the software
development life cycle (SDLC).

Itrequires a change in culture, process, and tools across these core functional teams and makes security a shared
responsibility.

“Shifting Left” means that the organization includes security throughout the entire software development life cycle.

“Shifting Left” from DevOps to DevSecOps aims to prioritize security by automating parts of the development lifecycle to improve a company’s security posture.

  • DevSecOps Engineer/Senior DevSecOps Engineer
  • Cloud DevSecOps Engineer
  • Azure DevSecOps Engineer
  • AWS DevSecOps Engineer
  • DevSecOps Analyst
  • DevSecOps Specialist
  • DevSecOps Systems Administrator
  • DevSecOps System Engineer
  • DevSecOps Consultant
  • DevSecOps CI/CD Engineer
  • Infrastructure DevSecOps Engineer

ECDE Covers Both On-Premises and Cloud-native DevSecOps Practices

On-premise DevSecOps

  • It refers to implementing DevSecOps practices within an organization’s internal IT infrastructure.
  • In an on-premises DevSecOps, DevSecOps engineers various open-source or commercial thirparty tools to build, integrate, and execute devsecops pipelines.

Cloud-native DevSecOps

  • It refers to implementing DevSecOps practices within a public cloud environment, such as Amazon Web Services, Microsoft Azure, Google Cloud Platform.
  • In cloud-native DevSecOps, DevSecOps engineers can leverage cloud-native tools, services, and platforms to help them integrate development, security, and operations more tightly.

Speak to a Training Consultant

All courses are HRD Claimable.
Get in touch with our team via the form or WhatsApp us on +6011-5119 6631

Preferred mode of training
Checkboxes