DevSecOps

DevSecOps

Step by step guide to becoming a DevSecOps Expert in @currentYear@

This page is a visitor-friendly snapshot of how William currently sees this area: what feels strong, what is still being refined, and where the evidence is still partial.

0

Done

7

Learning

0

Target

0

Skipped

93

Tracked

Status meanings

Done: enough evidence to present this area as a solid strength.

Learning: an area of active development with growing confidence.

Target: relevant and intentional, but still earlier in the journey.

Skipped: not a current priority relative to other areas.

How the estimates are formed

Profile and manual review: 0

Evidence from project experience: 0

Competency mapping alignment: 7

Quiz-backed updates: 0

These signals help estimate progress, but they are still best treated as directional rather than perfectly complete.

Areas currently being strengthened

Introduction

This is actively developing and would benefit from more practice, proof, or recent examples.

OWASP Top 10

This is actively developing and would benefit from more practice, proof, or recent examples.

Secure API Design

This is actively developing and would benefit from more practice, proof, or recent examples.

Build Pipeline Hardening

This is actively developing and would benefit from more practice, proof, or recent examples.

Secure Coding

This is actively developing and would benefit from more practice, proof, or recent examples.

Threat Modeling

This is actively developing and would benefit from more practice, proof, or recent examples.

Introduction

Learning
Competency mapping

DevSecOps vs DevOps

Untracked

CIA Triad

Untracked

Authentication

Untracked

OWASP Top 10

Learning
Competency mapping

Symmetric

Untracked

Asymmetric

Untracked

Encryption

Untracked

Firewalls

Untracked

DNS

Untracked

ACLs

Untracked

HTTP

Untracked

VLANs

Untracked

TLS

Untracked

Network Segmentation

Untracked

Networking Basics

Untracked

SQL Injection Prevention

Untracked

XSS Prevention

Untracked

Role Based Access

Untracked

Least Privilege

Untracked

Alert Types

Untracked

SIEM

Untracked

Burp Suite

Untracked

Wireshark basics

Untracked

Nmap basics

Untracked

CSPM

Untracked

Key Management Service

Untracked

IAM

Untracked

Cloud Security

Untracked

Defense in Depth Concepts

Untracked

Secure API Design

Learning
Competency mapping

Zero Trust Concepts

Untracked

Forensics

Untracked

Containment

Untracked

Root Cause Analysis

Untracked

Incident Response

Untracked

IR Lifecycle

Untracked

Multi Region Security Planning

Untracked

Large Scale Identity Strategy

Untracked

Certificate Lifecycle

Untracked

PKI Design and Failover

Untracked

Cryptographic Hashing

Untracked

IDS

Untracked

SBOMS

Untracked

DDoS Miligation Strategy

Untracked

Build Pipeline Hardening

Learning
Competency mapping

Secure Network Zoning

Untracked

Dependency Risk Management

Untracked

Supply Chain Security

Untracked

Enterprise Operations

Untracked

SOAR Automation

Untracked

Endpoint Detection

Untracked

Response Strategy

Untracked

Audit & Compliance Mapping

Untracked

Risk Quantification

Untracked

Learn a Programming Language

Untracked

Python

Untracked

Go

Untracked

JavaScript / Node.js

Untracked

Scripting Knowledge

Untracked

Ruby

Untracked

Rust

Untracked

Bash

Untracked

PowerShell

Untracked

Vim / Nano / Emacs

Untracked

Authorization

Untracked

Secure Coding

Learning
Competency mapping

Input Validation Patterns

Untracked

Identity Basics

Untracked

IAM

Untracked

Monitoring

Untracked

Log Analysis

Untracked

PASTA

Untracked

STRIDE

Untracked

Threat Modeling Workflows

Untracked

Threat Modeling

Learning
Competency mapping

Attack Surface Mapping

Untracked

Image Scanning

Untracked

Kubernetes

Untracked

Docker

Untracked

Container Security

Learning
Competency mapping

SOAR Concepts

Untracked

Automated Patching

Untracked

Nessus

Untracked

Nmap

Untracked

OpenVAS

Untracked

Qualys

Untracked

IPS

Untracked

bcrypt

Untracked

SHA 256

Untracked

SOC 2

Untracked

ISO 27001

Untracked

NIST

Untracked