Group Purchasing
Group Purchasing

SEC522 Live Online February

  • Mon, Feb 8 - Fri, Feb 12, 2027
  • 1 Course
  • English
Virtual (ET)
SEC522: Application Security: Securing Web Applications, APIs, and Microservices
  • 5-Day Course: February 8 – 12, 2027

    Earn 30 CPEs.

  • GIAC Certified Web Application Defender
  • Advanced Skill Level

    Course material is geared for cybersecurity professionals with hands-on experience.

  • 17 Hands-On Labs

    Apply what you learn with hands-on exercises and labs.

SEC522: Application Security: Securing Web Applications, APIs, and Microservices - Live Online

HTTP stopped being a website protocol a long time ago. It is now the connective tissue between cloud services, microservices, API gateways, and AI inference endpoints, and a flaw in one of those paths rarely stays contained to one application.

SEC522 teaches defense across that whole surface, virtually in real-time, with your questions answered as they come up. The lab environment is a running application rather than a slide deck: you attack it, defend it, then see what your control blocked. The course is programming-language agnostic, so the patterns hold whether your stack is Java, Python, .NET, or something newer.

During the Week, You'll Work Through

  • 17 hands-on labs
  • A competitive Defend the Flag capstone
  • SQL injection, XSS, CSRF, Unicode, and file upload handling
  • OAuth and access control, session fixation, and TLS traffic inspection
  • Content Security Policy, clickjacking, and cross-domain request defenses
  • GraphQL, API gateway, and JSON security exercises
  • Securing AI Endpoints and APIs

Securing AI Endpoints and APIs

The course closes its API and microservices section with securing AI components inside modern applications, including how AI inference endpoints inherit the same weaknesses as anything else built on HTTP. You’ll get 30 CPE credits for this course, and it’s aligned to the GIAC Certified Web Application Defender (GWEB) certification.

Who Should Take This Course?

Application security analysts and managers, application architects, technical leads of development teams, auditors who need to evaluate web defenses rather than just check for them, penetration testers who want the defensive side, and teams working under PCI DSS requirements. A basic working knowledge of HTML, JavaScript, and SQL is assumed.

Download the Course Syllabus or Letter to Justify this Training to Your Manager

To learn more about SEC522, business takeaways, laptop requirements and more, please visit the course page.

Early Bird Offer

Save $750 USD using the code "EarlyBirdNA" and pay for any 4-6 day course (excluding Beta Courses and 300 Level Courses) by October 20, 2026.

Courses

Looking for Group Purchasing? Contact Sales

Featured Speaker

Dr. Johannes Ullrich
Dr. Johannes Ullrich

Dr. Johannes Ullrich

Dean of Research at SANS Technology Institute

Dr. Johannes Ullrich is the Dean of Research for SANS Technology Institute, a SANS Faculty Fellow, and founder of the Internet Storm Center (DShield.org) which provides a free analysis and warning service to thousands of Internet users and organizations.

Read more about Dr. Johannes Ullrich

Three Reasons to Train Virtually

  • Ultimate Convenience

    Eliminate the hassle of daily commutes and wasted travel time. You’ll have everything you need right from your home.

  • Personalization

    Hands-on learning with the opportunity to ask questions and receive instant feedback from world-renowned experts. Afterward, reinforce your skills with 4-months of access to daily course lecture archives.

  • Hands-On Labs

    Learn cutting-edge cybersecurity knowledge with hands-on labs that provide you with techniques you can immediately use in your organization.

Woman at Laptop