B7-3 standard-with-variation — logo home, mixed middle routes, contact as clay button

Security

Secure CI/CD with policy gates

Shift-left controls that security teams accept and developers do not bypass silently.

Duration
5 weeks · 28h live
Format
Hybrid evenings (GMT+9)
Level
Advanced
Career track
Security engineering

₩1,350,000 · Certificate of completion

Course visual for Secure CI/CD with policy gates

Program narrative

Combine SBOM diffing, secret scanning, and admission policies with developer-friendly feedback loops. Includes bilingual policy summaries for compliance reviewers.

What is included

  • · Policy-as-code with reviewable bundles
  • · Artifact signing flows
  • · Human-readable deny messages
  • · Exception workflows with expiry
  • · Dependency update cadence design
  • · Threat modeling for pipelines
  • · Audit log correlation exercises

Outcomes you can show

  1. Ship a policy bundle with documented exceptions
  2. Reduce false positives via tuned rules
  3. Align security sign-off with sprint cadence

Lead mentor

Avatar for Kyungseo Han

Kyungseo Han

AppSec coach for B2B SaaS selling into regulated buyers.

FAQ

Experience notes

“Policy deny messages are now Korean + English; auditors stopped pinging us nightly.”
Eunbi · Health data startup
“Positive overall; would like a deeper SBOM diff lab—mentor sent extra exercises after.”
Taeyang