Choose your language
Secure Software Engineering training
Over 2 million learners across the globe

Secure Software Engineering training

Secure Software Engineering Training gives developers the skills to build security into every phase of the software lifecycle — from design through deployment. You'll learn threat modelling, secure coding, security testing, and DevSecOps practices grounded in industry-standard frameworks. Stop treating security as someone else's job and start shipping software that's built to resist real-world attacks.

Dedika for businesses

What you will learn:

This course covers the full spectrum of secure software engineering, starting with attacker mindset and vulnerability fundamentals and moving through threat modelling, secure design principles, and hands-on secure coding techniques. You'll learn how to apply SAST, DAST, and fuzz testing to catch flaws before they reach production. The curriculum also addresses supply chain risk, CI/CD pipeline security, and incident response. Supplementary modules cover cloud-native security, API and microservice protection, regulatory compliance, and AI system security. By the end, you'll have practical skills to integrate security across every stage of development.

How you study practically Secure Software Engineering training

How you practise Secure Software Engineering training

For companies looking to train their teams

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course content

8 Chapters • 41 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Secure Software Engineering

  • Lesson 1 • Security in the Software Development Lifecycle

    Maps security activities to each SDLC phase from requirements through deployment. Shows how early integration reduces cost and risk.

  • Lesson 2 • Security Goals and Core Principles

    Defines confidentiality, integrity, and availability as engineering constraints. Connects these goals to design decisions made throughout the development lifecycle.

  • Lesson 3 • Attacker Mindset and Threat Concepts

    Introduces adversarial thinking as a foundational engineering skill. Teaches how attackers identify and exploit weaknesses to inform defensive design.

  • Lesson 4 • Common Vulnerability Categories

    Surveys the most prevalent software weakness classes using industry-standard taxonomies. Provides a shared vocabulary for identifying and discussing flaws.

  • Lesson 5 • Risk Fundamentals for Developers

    Introduces likelihood, impact, and risk scoring as practical developer tools. Enables prioritization of security effort based on business context.

Chapter 2See details

Threat Modeling and Security Requirements

  • Lesson 1 • Identifying and Rating Threats

    Applies STRIDE categories to DFD elements to enumerate threats systematically. Introduces DREAD and CVSS-style scoring to prioritise identified threats.

  • Lesson 2 • Threat Model Maintenance and Updates

    Addresses how threat models evolve as systems change over time. Establishes triggers and processes for keeping models accurate and actionable.

  • Lesson 3 • Deriving Security Requirements

    Converts threat model outputs into verifiable security requirements. Links each requirement to a specific threat to maintain traceability.

  • Lesson 4 • Threat Modeling Methodologies

    Compares leading structured approaches to threat identification and analysis. Equips students to select the right methodology for a given project context.

  • Lesson 5 • Data Flow Diagrams for Security

    Teaches construction of DFDs as the primary artifact for threat modeling. Students identify trust boundaries and data flows that expose attack opportunities.

Chapter 3See details

Secure Design Principles and Patterns

  • Lesson 1 • Core Secure Design Principles

    Covers least privilege, defence in depth, fail-safe defaults, and separation of duties. Students apply each principle to concrete design scenarios.

  • Lesson 2 • Cryptography Selection and Application

    Guides selection of appropriate cryptographic primitives for common use cases. Covers symmetric, asymmetric, and hashing choices without requiring deep maths.

  • Lesson 3 • Authentication and Session Design

    Designs robust authentication flows and secure session management mechanisms. Addresses credential storage, multi-factor patterns, and session lifecycle.

  • Lesson 4 • Secure API and Service Design

    Applies secure design principles specifically to REST and service-oriented interfaces. Covers input validation, rate limiting, and secure error handling at the API layer.

  • Lesson 5 • Authorization and Access Control Models

    Compares RBAC, ABAC, and policy-based access control for different system types. Students design access control schemes that enforce least privilege.

Chapter 4See details

Secure Coding Techniques

  • Lesson 1 • Secure Error Handling and Logging

    Teaches error handling that prevents information leakage while supporting diagnostics. Covers secure logging practices that avoid capturing sensitive data.

  • Lesson 2 • Secure Concurrency and State Management

    Identifies race conditions and time-of-check/time-of-use flaws in concurrent code. Applies synchronisation and atomic operations to eliminate state-based vulnerabilities.

  • Lesson 3 • Cross-Site Scripting Prevention

    Covers reflected, stored, and DOM-based XSS with specific mitigation for each type. Introduces Content Security Policy as a defence-in-depth control.

  • Lesson 4 • Memory Safety and Resource Management

    Addresses buffer overflows, use-after-free, and resource exhaustion in systems code. Applies safe memory patterns and resource lifecycle controls.

  • Lesson 5 • Injection Attack Prevention

    Addresses SQL, command, LDAP, and XML injection through parameterisation and safe APIs. Students refactor vulnerable code to eliminate injection vectors.

  • Lesson 6 • Input Validation and Output Encoding

    Establishes validation and encoding as the primary defence against injection attacks. Covers allowlist validation, canonicalisation, and context-aware output encoding.

Chapter 5See details

Security Testing Fundamentals

  • Lesson 1 • Fuzz Testing and Property-Based Testing

    Applies fuzzing to discover unexpected input handling failures and crashes. Introduces property-based testing as a complement to example-based security tests.

  • Lesson 2 • Security Testing Strategy and Planning

    Defines the scope, objectives, and methods for a security testing programme. Aligns testing effort with threat model outputs and risk priorities.

  • Lesson 3 • Dynamic Application Security Testing

    Uses DAST tools to probe running applications for exploitable vulnerabilities. Covers authenticated scanning, spider configuration, and result interpretation.

  • Lesson 4 • Penetration Testing Concepts

    Introduces structured penetration testing methodology from reconnaissance to reporting. Distinguishes developer-focused pen testing from full red team engagements.

  • Lesson 5 • Static Application Security Testing

    Applies SAST tools to detect vulnerabilities in source code without execution. Covers tool configuration, triage of findings, and suppression of false positives.

Chapter 6See details

Dependency and Supply Chain Security

  • Lesson 1 • Secure Build and Artifact Integrity

    Applies signing, hashing, and provenance tracking to build artifacts. Ensures that what is deployed matches what was reviewed and approved.

  • Lesson 2 • Dependency Management Best Practices

    Establishes policies for selecting, pinning, and updating third-party dependencies. Reduces attack surface through minimal dependency footprint.

  • Lesson 3 • Software Composition Analysis

    Uses SCA tools to inventory open-source components and detect known vulnerabilities. Covers licence compliance as a parallel concern alongside security.

  • Lesson 4 • Understanding Software Supply Chain Risk

    Maps the modern software supply chain and identifies attack vectors at each stage. Establishes why transitive dependencies amplify risk beyond direct dependencies.

  • Lesson 5 • Responding to Dependency Vulnerabilities

    Defines a structured process for triaging and remediating disclosed dependency flaws. Covers patching, forking, and temporary mitigation strategies.

Chapter 7See details

DevSecOps and Secure CI/CD Pipelines

  • Lesson 1 • Container and Image Security

    Secures container images from base image selection through runtime deployment. Covers image scanning, minimal base images, and runtime security controls.

  • Lesson 2 • DevSecOps Principles and Culture

    Defines the shift-left philosophy and shared security responsibility model. Addresses cultural barriers to security adoption in fast-moving development teams.

  • Lesson 3 • Secrets Management in Pipelines

    Prevents hardcoded credentials by integrating secrets vaults into build and deploy workflows. Covers secret rotation, access scoping, and audit logging.

  • Lesson 4 • Automating Security in CI Pipelines

    Embeds SAST, SCA, and secret scanning as automated pipeline stages. Configures quality gates that block builds on critical security findings.

  • Lesson 5 • Infrastructure as Code Security

    Scans IaC templates for misconfigurations before provisioning cloud resources. Applies policy-as-code to enforce security baselines across environments.

Chapter 8See details

Incident Response and Secure Operations

  • Lesson 1 • Resilience and Recovery Design

    Designs software systems to degrade gracefully and recover quickly after attacks. Covers backup strategies, failover patterns, and chaos engineering basics.

  • Lesson 2 • Post-Incident Analysis and Learning

    Applies blameless post-mortems to extract security lessons from incidents. Converts findings into concrete code and process improvements.

  • Lesson 3 • Incident Response Fundamentals

    Introduces the incident response lifecycle and the developer's role within it. Covers preparation, detection, containment, eradication, and recovery phases.

  • Lesson 4 • Vulnerability Disclosure and Patch Management

    Establishes processes for receiving, triaging, and remediating reported vulnerabilities. Covers coordinated disclosure, patch timelines, and customer communication.

  • Lesson 5 • Security Observability by Design

    Builds security-relevant logging and monitoring into applications from the start. Defines what events must be captured to support effective incident detection.

Certification

Your valid completion certificate

This course is for you:

  • Software developers who want security to become second nature in their work.

  • Backend engineers tired of patching vulnerabilities discovered after deployment.

  • DevOps practitioners looking to embed security controls directly into pipelines.

  • Computer science graduates entering roles where secure coding is expected immediately.

  • Career changers from IT support who are moving into software development roles.

  • Technical leads responsible for setting security standards across their development teams.

What our students say

Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos help a lot with learning.
André Felipe
André FelipePrompt Engineering Student

Top training programmes

FAQ

Who is Dedika?

Is the certificate valid in Kenya?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course