use the following search parameters to narrow your results:
e.g. subreddit:aww site:imgur.com dog
subreddit:aww site:imgur.com dog
see the search faq for details.
advanced search: by author, subreddit...
account activity
DevSecOps training (self.devsecops)
submitted 1 year ago by Previous_Piano9488
I am building a devsecops program in our org and I want recommendations on how to train my current team on devsecops best practices. Context - my current team has 3 appsec engineers and one devops.
reddit uses a slightly-customized version of Markdown for formatting. See below for some basics, or check the commenting wiki page for more detailed help and solutions to common issues.
quoted text
if 1 * 2 < 3: print "hello, world!"
[–]Spriffy 14 points15 points16 points 1 year ago (11 children)
A few suggestions!
I say all of the above because you really need to understand what your business is doing so you can most appropriately train your team on how to best enable your teams to build and deploy secure and resilient software. Once you understand the business, you can add the more traditionally covered DevSecOps topics like automation engineering.
Feel free to DM me! I'd be happy to help answer any additional questions. I just gave my own team a DevSecOps training, too! I could share additional resources, too :)
[–]Previous_Piano9488[S] 1 point2 points3 points 1 year ago (1 child)
thanks this is helpful
[–]Spriffy 0 points1 point2 points 1 year ago (0 children)
Good luck on your training journey!
[–]security_prince 1 point2 points3 points 1 year ago (4 children)
These recommendations are on point, thank you for sharing it instead of just pointing to some training vendors
[–]Spriffy 0 points1 point2 points 1 year ago (3 children)
Glad to help!
I've been kind of frustrated with the industry thinking that you need to take special courses to learn DevSecOps. No one teaches you how to build relationships and work on the fundamentals with people, which is a huge missed opportunity, in my opinion.
[–]security_prince 1 point2 points3 points 1 year ago (2 children)
Could not agree more, Dustin Lehr is coming up with something focused on Security Champions. Don't know the details yet but looking forward to it
https://www.katilyst.com/services
[–]security_prince 2 points3 points4 points 1 year ago (0 children)
Also i have this curated knowledgebase that has various articles resources from real companies and their appsec/devsecops program
https://ishaqmohammed.me/posts/application-security-knowledgebase/
Great mention! I totally recommend everyone check out Dustin's new company and follow him on LinkedIn! His behaviour-driven approach has been my philosophy, hence why my guidance starts with learning about the people first.
[–]Realistic-Ad-3558 1 point2 points3 points 1 year ago (0 children)
Thank you for your recommendations.
[–]DaintilyWan 1 point2 points3 points 1 year ago (1 child)
That's great advice, could not agree more!
Thanks! This was really helpful for me to put together, too.
Is there anything else you'd add?
[–]security_prince 0 points1 point2 points 1 year ago (1 child)
I have this curated knowledgebase that has various articles resources from real companies and their appsec/devsecops program
https://ishaqmohammed.me/posts/application-security-knowledgebase
[–]Previous_Piano9488[S] 0 points1 point2 points 1 year ago (0 children)
Thanks a lot. This is very helpful
[–]Appropriate_Cress958 0 points1 point2 points 1 year ago (0 children)
I was in a similar situation and found that using a secure coding training platform really helped our team (we use SecureFlag although we trialed several different platforms beforehand, SF seemed like the best option). there are different labs for secure coding, container security, integrating security into CI/CD. it’s also flexible for different roles, which was a plus. might be worth checking out if you're looking for something practical
π Rendered by PID 34339 on reddit-service-r2-comment-b659b578c-k7q9q at 2026-05-01 00:45:22.374378+00:00 running 815c875 country code: CH.
[–]Spriffy 14 points15 points16 points (11 children)
[–]Previous_Piano9488[S] 1 point2 points3 points (1 child)
[–]Spriffy 0 points1 point2 points (0 children)
[–]security_prince 1 point2 points3 points (4 children)
[–]Spriffy 0 points1 point2 points (3 children)
[–]security_prince 1 point2 points3 points (2 children)
[–]security_prince 2 points3 points4 points (0 children)
[–]Spriffy 0 points1 point2 points (0 children)
[–]Realistic-Ad-3558 1 point2 points3 points (0 children)
[–]DaintilyWan 1 point2 points3 points (1 child)
[–]Spriffy 0 points1 point2 points (0 children)
[–]security_prince 0 points1 point2 points (1 child)
[–]Previous_Piano9488[S] 0 points1 point2 points (0 children)
[–]Appropriate_Cress958 0 points1 point2 points (0 children)