Secure SDLC
- NIST Secure SDF / SANS Cloud Architecture
- Security Quality Assurance / SQUARE Framework
- Secure Design Patterns / Threat Modeling
- Enterprise Security, Zero Trust, SDN, SDP
- Security Policies / Kubernetes Policies
- Service Mesh / Server Hardening
- (Linux, Apache, Tomcat, PostgreSQL, Mongo, MySQL, Redis)
DevOps & SRE
- DevOps Lean Thinking, SAST / DAST
- 5 Principles of DevOps / CALMS Framework
- SRE Implements DevOps / Shift Left
- Infrastructure as a Code / Observability
Security Controls & DevSecOps
- Application Security Controls
- Generic Controls
- HIPAA / PCI Controls
- DevSecOps
Java Application Vulnerabilities
- Cross-Site Scripting Vulnerability (XSS)
- Buffer Overflow Exploit
- Directory Traversal Exploit
- Command / Shell Injection Exploit
- Vulnerable and Outdated Components
- HTTP Response Split Vulnerability
- Parameter Manipulation Vulnerability
- SQL Injection Vulnerability
- XML Entity Injection / (XXE) Attack
- XPath Injection Attack
- Cross-Site Request Forgery (CSRF)
- Server-Side Request Forgery (SSRF