DevSecOps Training in Netherlands

  • Learn via: Classroom / Virtual Classroom / Online
  • Duration: 2 Days
  • Level: Fundamentals
  • Price: Please contact for booking options

This hands-on course introduces participants to integrating security within modern DevOps practices,
including CI/CD, Continuous Monitoring, and Infrastructure as Code (IaC).

Regulatory Note for Financial Institutions:
In compliance with the Regulation on Banks’ Information Systems and Electronic Banking Services (Articles 16–25),
DevSecOps pipelines in financial institutions must ensure secure development, continuous vulnerability monitoring,
and traceable audit mechanisms for all deployments and code changes.

Participants will receive a fully functional DevSecOps Lab VM (Vagrant + Ansible) preloaded with open-source tools
such as OWASP ZAP, HashiCorp Vault, and Semgrep to simulate real-world security automation pipelines.

We can organize this training at your preferred date and location. Contact Us!

Who Should Attend

Ideal for developers, DevOps engineers, and IT managers in banks, financial institutions, and regulated enterprises.

What You Will Learn

Delegates will be able to:

  • Automate security in CI/CD pipelines.

  • Deploy and secure tools like Vault, ZAP, OpenVAS, and Semgrep.

  • Align DevSecOps processes with BDDK Article 23 compliance (secure software lifecycle and traceability).

  • Build resilient, auditable, and regulation-ready DevOps environments.

  • Act as Security Champions within agile teams.


By the end of this course, participants will confidently build secure, compliant, and automated DevSecOps pipelines
fully aligned with both global best practices and BDDK banking regulations.


Training Outline

Day 1

Lab Setup

  • Online Lab Setup
  • Offline Lab Instructions

Introduction to DevOps

  • What is DevOps?
  • Lab : DevOps Pipeline

Introduction to DevSecOps

  • Challenges for Security in DevOps
  • DevOps Threat Model
  • DevSecOps – Why, What and How?
  • Vulnerability Management

Continuous Integration

Pre-Commit Hooks

  • Introduction to Talisman
    • Lab : Running Talisman
    • Lab : Create your own regexes for Talisman

Secrets Management

  • Introduction to HashiCorp Vault
  • Demo : Vault Commands

Continuous Delivery

  • Software Composition Analysis (SCA)
    • Introduction to Dependency-Check
    • Lab : Run Dependency-Check pipeline
    • Lab : Fix issues reported by Dependency-Check
  • Static Analysis Security Testing (SAST)
    • Introduction to Semgrep
    • Lab : Run Semgrep pipeline
    • Lab : Create your own Semgrep Rules
    • Lab : Fix Issues reported by Semgrep
  • Dynamic Analysis Security Testing (DAST)
    • Introduction to OWASP ZAP
    • Demo : Creating ZAP Context File
    • Lab : Run ZAP in pipeline

Day 2

Infrastructure As Code

  • Vulnerability Assessment (VA)
    • Introduction to OpenVAS
    • Lab : Run OpenVAS pipeline
  • Container Security (CS)
    • Introduction to Trivy
    • Lab : Run Trivy in Pipeline
    • Lab : Improvise Docker base image
  • Compliance as Code (CaC)
    • Introduction to Inspec
    • Lab : Run Inspec in Pipeline
    • Lab : Improvise Docker compliancy controls

Continuous Monitoring

  • Logging
    • Introduction to the ELK Stack
    • Lab : View Logs in Kibana
  • Alerting
    • Introduction to ElastAlert and ModSecurity
    • Lab : View Alerts in Kibana
  • Monitoring
    • Lab : Create Attack Dashboards in Kibana

DevSecOps in AWS

  • DevOps on Cloud Native AWS
  • AWS Threat Landscape
  • DevSecOps in Cloud Native AWS

DevSecOps Challenges and Enablers

  • Challenges with DevSecOps
  • Building DevSecOps Culture
  • Security Champions
  • Case Studies
  • Where do we Begin?
  • DevSecOps Maturity Model
Training Reviews


Contact us for more detail about our trainings and for all other enquiries!

Avaible Training Dates

Join our public courses in our Netherlands facilities. Private class trainings will be organized at the location of your preference, according to your schedule.

We can organize this training at your preferred date and location.
08 februari 2026 (2 Days)
Amsterdam, Rotterdam
15 februari 2026 (2 Days)
Amsterdam, Rotterdam
02 maart 2026 (2 Days)
Amsterdam, Rotterdam
03 april 2026 (2 Days)
Amsterdam, Rotterdam
19 april 2026 (2 Days)
Amsterdam, Rotterdam
21 april 2026 (2 Days)
Amsterdam, Rotterdam
21 april 2026 (2 Days)
Amsterdam, Rotterdam
21 april 2026 (2 Days)
Amsterdam, Rotterdam

Related Trainings

By using this website you agree to let us use cookies. For further information about our use of cookies, check out our Cookie Policy.