Security
Secure CI/CD with policy gates
Shift-left controls that security teams accept and developers do not bypass silently.
- Duration
- 5 weeks · 28h live
- Format
- Hybrid evenings (GMT+9)
- Level
- Advanced
- Career track
- Security engineering
₩1,350,000 · Certificate of completion
Program narrative
Combine SBOM diffing, secret scanning, and admission policies with developer-friendly feedback loops. Includes bilingual policy summaries for compliance reviewers.
What is included
- · Policy-as-code with reviewable bundles
- · Artifact signing flows
- · Human-readable deny messages
- · Exception workflows with expiry
- · Dependency update cadence design
- · Threat modeling for pipelines
- · Audit log correlation exercises
Outcomes you can show
- Ship a policy bundle with documented exceptions
- Reduce false positives via tuned rules
- Align security sign-off with sprint cadence
Lead mentor
Kyungseo Han
AppSec coach for B2B SaaS selling into regulated buyers.
FAQ
Experience notes
“Policy deny messages are now Korean + English; auditors stopped pinging us nightly.”
“Positive overall; would like a deeper SBOM diff lab—mentor sent extra exercises after.”