
Secure Software Engineering training
Secure Software Engineering Training gives developers the skills to build security into every phase of the software lifecycle — from design through deployment. You'll learn threat modelling, secure coding, security testing, and DevSecOps practices grounded in industry-standard frameworks. Stop treating security as someone else's job and start shipping software that's built to resist real-world attacks.
What you will learn:
This course covers the full spectrum of secure software engineering, starting with attacker mindset and vulnerability fundamentals and moving through threat modelling, secure design principles, and hands-on secure coding techniques. You'll learn how to apply SAST, DAST, and fuzz testing to catch flaws before they reach production. The curriculum also addresses supply chain risk, CI/CD pipeline security, and incident response. Supplementary modules cover cloud-native security, API and microservice protection, regulatory compliance, and AI system security. By the end, you'll have practical skills to integrate security across every stage of development.
How you study in practice Secure Software Engineering training
How you practise Secure Software Engineering training
For companies looking to train their team
With Dedika for businesses, the course includes exercises and examples tailored to your own business and the specific needs of your company.
Course content
8 Chapters • 41 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsFoundations of Secure Software Engineering
Foundations of Secure Software Engineering
Lesson 1 • Security in the Software Development Lifecycle
Maps security activities to each SDLC phase from requirements through deployment. Shows how early integration reduces cost and risk.
Lesson 2 • Security Goals and Core Principles
Defines confidentiality, integrity, and availability as engineering constraints. Connects these goals to design decisions made throughout the development lifecycle.
Lesson 3 • Attacker Mindset and Threat Concepts
Introduces adversarial thinking as a foundational engineering skill. Teaches how attackers identify and exploit weaknesses to inform defensive design.
Lesson 4 • Common Vulnerability Categories
Surveys the most prevalent software weakness classes using industry-standard taxonomies. Provides a shared vocabulary for identifying and discussing flaws.
Lesson 5 • Risk Fundamentals for Developers
Introduces likelihood, impact, and risk scoring as practical developer tools. Enables prioritization of security effort based on business context.
Chapter 2HideHide detailsSee detailsThreat Modeling and Security Requirements
Threat Modeling and Security Requirements
Lesson 1 • Identifying and Rating Threats
Applies STRIDE categories to DFD elements to enumerate threats systematically. Introduces DREAD and CVSS-style scoring to prioritise identified threats.
Lesson 2 • Threat Model Maintenance and Updates
Addresses how threat models evolve as systems change over time. Establishes triggers and processes for keeping models accurate and actionable.
Lesson 3 • Deriving Security Requirements
Converts threat model outputs into verifiable security requirements. Links each requirement to a specific threat to maintain traceability.
Lesson 4 • Threat Modeling Methodologies
Compares leading structured approaches to threat identification and analysis. Equips students to select the right methodology for a given project context.
Lesson 5 • Data Flow Diagrams for Security
Teaches construction of DFDs as the primary artifact for threat modeling. Students identify trust boundaries and data flows that expose attack opportunities.
Chapter 3HideHide detailsSee detailsSecure Design Principles and Patterns
Secure Design Principles and Patterns
Lesson 1 • Core Secure Design Principles
Covers least privilege, defence in depth, fail-safe defaults, and separation of duties. Students apply each principle to concrete design scenarios.
Lesson 2 • Cryptography Selection and Application
Guides selection of appropriate cryptographic primitives for common use cases. Covers symmetric, asymmetric, and hashing choices without requiring deep maths.
Lesson 3 • Authentication and Session Design
Designs robust authentication flows and secure session management mechanisms. Addresses credential storage, multi-factor patterns, and session lifecycle.
Lesson 4 • Secure API and Service Design
Applies secure design principles specifically to REST and service-oriented interfaces. Covers input validation, rate limiting, and secure error handling at the API layer.
Lesson 5 • Authorization and Access Control Models
Compares RBAC, ABAC, and policy-based access control for different system types. Students design access control schemes that enforce least privilege.
Chapter 4HideHide detailsSee detailsSecure Coding Techniques
Secure Coding Techniques
Lesson 1 • Secure Error Handling and Logging
Teaches error handling that prevents information leakage while supporting diagnostics. Covers secure logging practices that avoid capturing sensitive data.
Lesson 2 • Secure Concurrency and State Management
Identifies race conditions and time-of-check/time-of-use flaws in concurrent code. Applies synchronisation and atomic operations to eliminate state-based vulnerabilities.
Lesson 3 • Cross-Site Scripting Prevention
Covers reflected, stored, and DOM-based XSS with specific mitigation for each type. Introduces Content Security Policy as a defence-in-depth control.
Lesson 4 • Memory Safety and Resource Management
Addresses buffer overflows, use-after-free, and resource exhaustion in systems code. Applies safe memory patterns and resource lifecycle controls.
Lesson 5 • Injection Attack Prevention
Addresses SQL, command, LDAP, and XML injection through parameterisation and safe APIs. Students refactor vulnerable code to eliminate injection vectors.
Lesson 6 • Input Validation and Output Encoding
Establishes validation and encoding as the primary defence against injection attacks. Covers allowlist validation, canonicalisation, and context-aware output encoding.
Chapter 5HideHide detailsSee detailsSecurity Testing Fundamentals
Security Testing Fundamentals
Lesson 1 • Fuzz Testing and Property-Based Testing
Applies fuzzing to discover unexpected input handling failures and crashes. Introduces property-based testing as a complement to example-based security tests.
Lesson 2 • Security Testing Strategy and Planning
Defines the scope, objectives, and methods for a security testing programme. Aligns testing effort with threat model outputs and risk priorities.
Lesson 3 • Dynamic Application Security Testing
Uses DAST tools to probe running applications for exploitable vulnerabilities. Covers authenticated scanning, spider configuration, and result interpretation.
Lesson 4 • Penetration Testing Concepts
Introduces structured penetration testing methodology from reconnaissance to reporting. Distinguishes developer-focused pen testing from full red team engagements.
Lesson 5 • Static Application Security Testing
Applies SAST tools to detect vulnerabilities in source code without execution. Covers tool configuration, triage of findings, and suppression of false positives.
Chapter 6HideHide detailsSee detailsDependency and Supply Chain Security
Dependency and Supply Chain Security
Lesson 1 • Secure Build and Artifact Integrity
Applies signing, hashing, and provenance tracking to build artifacts. Ensures that what is deployed matches what was reviewed and approved.
Lesson 2 • Dependency Management Best Practices
Establishes policies for selecting, pinning, and updating third-party dependencies. Reduces attack surface through minimal dependency footprint.
Lesson 3 • Software Composition Analysis
Uses SCA tools to inventory open-source components and detect known vulnerabilities. Covers licence compliance as a parallel concern alongside security.
Lesson 4 • Understanding Software Supply Chain Risk
Maps the modern software supply chain and identifies attack vectors at each stage. Establishes why transitive dependencies amplify risk beyond direct dependencies.
Lesson 5 • Responding to Dependency Vulnerabilities
Defines a structured process for triaging and remediating disclosed dependency flaws. Covers patching, forking, and temporary mitigation strategies.
Chapter 7HideHide detailsSee detailsDevSecOps and Secure CI/CD Pipelines
DevSecOps and Secure CI/CD Pipelines
Lesson 1 • Container and Image Security
Secures container images from base image selection through runtime deployment. Covers image scanning, minimal base images, and runtime security controls.
Lesson 2 • DevSecOps Principles and Culture
Defines the shift-left philosophy and shared security responsibility model. Addresses cultural barriers to security adoption in fast-moving development teams.
Lesson 3 • Secrets Management in Pipelines
Prevents hardcoded credentials by integrating secrets vaults into build and deploy workflows. Covers secret rotation, access scoping, and audit logging.
Lesson 4 • Automating Security in CI Pipelines
Embeds SAST, SCA, and secret scanning as automated pipeline stages. Configures quality gates that block builds on critical security findings.
Lesson 5 • Infrastructure as Code Security
Scans IaC templates for misconfigurations before provisioning cloud resources. Applies policy-as-code to enforce security baselines across environments.
Chapter 8HideHide detailsSee detailsIncident Response and Secure Operations
Incident Response and Secure Operations
Lesson 1 • Resilience and Recovery Design
Designs software systems to degrade gracefully and recover quickly after attacks. Covers backup strategies, failover patterns, and chaos engineering basics.
Lesson 2 • Post-Incident Analysis and Learning
Applies blameless post-mortems to extract security lessons from incidents. Converts findings into concrete code and process improvements.
Lesson 3 • Incident Response Fundamentals
Introduces the incident response lifecycle and the developer's role within it. Covers preparation, detection, containment, eradication, and recovery phases.
Lesson 4 • Vulnerability Disclosure and Patch Management
Establishes processes for receiving, triaging, and remediating reported vulnerabilities. Covers coordinated disclosure, patch timelines, and customer communication.
Lesson 5 • Security Observability by Design
Builds security-relevant logging and monitoring into applications from the start. Defines what events must be captured to support effective incident detection.
Your valid completion certificate
This course is for you:
Software developers who want security to become second nature in their work.
Backend engineers tired of patching vulnerabilities discovered after deployment.
DevOps practitioners looking to embed security controls directly into pipelines.
Computer science graduates entering roles where secure coding is expected immediately.
Career changers from IT support who are moving into software development roles.
Technical leads responsible for setting security standards across their development teams.
What our students say
Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos help a lot with learning.

Top trainings
FAQ
Who is Dedika?
Is the certificate valid in Nigeria?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















