Contact Sales
Contact Sales
UPDATED

SEC540: Cloud Native Security and DevSecOps Automation

SEC540Cloud Security
  • 5 Days (Instructor-Led)
  • 38 Hours (Self-Paced)
Course authored by:
Eric JohnsonBen AllenFrank Kim
Eric Johnson, Ben Allen & Frank Kim
SEC540: Cloud Security and DevSecOps Automation
Course authored by:
Eric JohnsonBen AllenFrank Kim
Eric Johnson, Ben Allen & Frank Kim
  • GIAC Cloud Security Automation (GCSA)
  • 38 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 19 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Gain the skills and methodology to secure modern Cloud Native, DevSecOps, and Kubernetes environments through hands-on labs using security controls in CI/CD pipelines for cloud systems.

Course Overview

The SANS SEC540 DevSecOps training course prepares security professionals to secure cloud-native and DevOps environments by implementing security controls in automated pipelines. It addresses challenges like insecure CI/CD pipelines, container misconfigurations, software supply chain weaknesses, and Kubernetes vulnerabilities while providing hands-on labs to develop practical skills. The course equips students with the DevSecOps mindset needed to secure cloud native environments.

What You'll Learn

  • Understand DevOps principles for secure workflows
  • Integrate AI security tools into developer environments and CI/CD pipelines
  • Manage secrets and automate infrastructure with IaC
  • Harden and monitor containers and Kubernetes workloads
  • Secure software supply chain with SBOMs and artifact signing
  • Defend microservices using cloud native identity provider and API Gateway services
  • Automate compliance with policy guardrails and remediation

Business Takeaways

  • Build a security team skilled in DevSecOps, AI, and cloud-native security
  • Collaborate with DevOps to integrate security and AI guardrails early in development
  • Utilize cloud-native services for deployment, hardening, and monitoring
  • Prepare for container and Kubernetes migrations with adaptability
  • Enhance security with API Gateway and cloud native observability services
  • Implement centralized audit pipelines and policy-as-code

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC540: Cloud Native Security and DevSecOps Automation.

Section 1DevOps Security Automation

This section introduces DevOps practices by analyzing and securing a vulnerable Version Control and Continuous Integration (CI) system, teaching students to configure AI agents that help identify risks and run DevOps tools that harden workflows, automate code analysis, and securely manage secrets.

Topics covered

  • DevOps and Security Challenges
  • DevOps Toolchain
  • Pre-Commit Security Controls
  • Pre-Merge Security Controls
  • Secrets Management

Labs

  • Attacking the DevOps Toolchain 
  • Configuring Pre-Commit Security Controls
  • AI-Assisted Merge Request Reviews
  • Protecting Secrets with Vault 
  • CloudWars Bonus Challenges

Section 2Cloud Infrastructure Security

In section two, students deploy cloud infrastructure with Terraform, harden network configurations, automate configuration management with Packer and Ansible, and secure container images for Kubernetes by managing misconfigurations, scanning for vulnerabilities, and securing the software supply chain with SBOMs and artifact signing.

Topics covered

  • Cloud Infrastructure as Code
  • Configuration Management as Code
  • Container Security Lifecycle
  • Software Supply Chain Security

Labs

  • Infrastructure as Code Network Hardening 
  • Gold Image Creation
  • Container Image Hardening
  • Container Software Supply Chain Security
  • CloudWars Bonus Challenges

Section 3Cloud Native Security Operations

In section three, students start by learning the Kubernetes control plane, the kubectl command line interface, and how to use AI to interact with clusters hosted in cloud services like AWS EKS and Azure AKS. Then, harden the cluster using security controls such as RBAC, workload identity, and admission control.

Topics covered

  • Kubernetes Architecture, Resources, and Kubectl
  • Kubernetes Risks and Security Controls
  • Kubernetes Workload Security 
  • Kubernetes Runtime Security 
  • Continuous Security Monitoring 

Labs

  • Kubectl and AI Assistants
  • Kubernetes Role-Based Access Control
  • Kubernetes Workload Identity
  • Kubernetes Admission Control
  • CloudWars Bonus Challenges

Section 4Microservice Security

In section four, students learn how security changes with microservices and how to implement centralized microservice security controls. We establish edge authentication and authorization with cloud native tooling, build network policy to govern service to service communication, deploy microservice patches with zero downtime, and enable OpenTelemetry.

Topics covered

  • Microservice Fundamentals
  • Microservice User Interface and Identity Providers
  • Microservice API Gateways
  • Kubernetes Deployment Orchestration
  • Cloud Native Security Observability

Labs

  • Keycloak Identity and Access Management
  • Kong Kubernetes Ingress Controller
  • Kubernetes Blue/Green Deployments
  • OpenTelemetry Observability
  • CloudWars Bonus Challenges

Section 5Continuous Compliance

In section five, students learn to automate cloud security and Kubernetes compliance, aggregate and correlate vulnerabilities, and implement policy as code to stop deployments and auto remediate configuration drift.

Topics covered

  • Compliance as Code
  • Policy as Code
  • Automated Remediation 

Labs

  • Cloud and Kubernetes Compliance
  • Vulnerability Aggregation and Correlation
  • Automated Remediation
  • CloudWars Bonus Challenges

Things You Need To Know

Relevant Job Roles

Systems Security Analyst (DCWF 461)

DoD 8140: Software Engineering

Ensures systems and software security from development to maintenance by analyzing and improving security across all lifecycle phases.

Explore learning path

Cloud Security Engineer Training, Salary, and Career Path

Cloud Security

Cloud Security Engineers integrate advanced security measures into cloud and cloud-native environments, maximize security automation within DevOps workflows, and proactively mitigate threats to safeguard modern cloud infrastructures.

Explore learning path

Systems Developer (DCWF 632)

DoD 8140: Cyber IT

Oversees full lifecycle of information systems from design through evaluation, ensuring alignment with functional and operational goals.

Explore learning path

Vulnerability Assessment Analyst (DCWF 541)

DoD 8140: Cybersecurity

Assesses systems and networks to ensure compliance with policies and identify vulnerabilities in support of secure and resilient operations.

Explore learning path

Technology Research and Development (OPM 661)

NICE: Design and Development

Responsible for conducting software and systems engineering and software systems research to develop new capabilities with fully integrated cybersecurity. Conducts comprehensive technology research to evaluate potential vulnerabilities in cyberspace systems.

Explore learning path

IT Investment/Portfolio Manager (DCWF 804)

DoD 8140: Cyber Enablers

Oversees a portfolio of IT capabilities aligned to enterprise goals, prioritizing needs, solutions, and value delivery to the organization.

Explore learning path

Communications Security (COMSEC) Management (OPM 723)

NICE: Oversight and Governance

Responsible for managing the Communications Security (COMSEC) resources of an organization.

Explore learning path

Information Systems Security Developer (DCWF 631)

DoD 8140: Cybersecurity

Designs and evaluates information system security throughout the software lifecycle to ensure confidentiality, integrity, and availability.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $8,780 USD*Prices exclude applicable local taxesBuy now for access on Mar 27. Use code Presale10 for 10% off course price!
    Registration Options
  • Location & instructor

    SANS 2026

    Orlando, FL, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Rocky Mountain 2026

    Denver, CO, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Security West 2026

    San Diego, CA, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Amsterdam May 2026

    Amsterdam, NL & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €8,230 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Chicago 2026

    Chicago, IL, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Riyadh June 2026

    Riyadh, SA & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,900 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Cyber Defence Singapore 2026

    Singapore, SG & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    S$11,390 SGD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANSFIRE 2026

    Washington, DC, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Cloud Security Exchange Summit & Training 2026

    San Francisco, CA, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
Showing 10 of 17

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources