RESOLV

Resolv Academy · Programme

Secure Development

Writing, reviewing and testing software that passes security review, with practice on real vulnerable code.

Length
6 weeks
Level
Intermediate
Format
Instructor-led, live online or on-site, with code review and exploitation labs
Certification
Aligned to the objectives of the OWASP Top 10 and CSSLP-style secure software lifecycle practice.

Who it is for

  • Software developers and technical leads
  • Quality assurance engineers
  • Developers working on regulated or sensitive systems

Prerequisites

  • Professional experience in at least one programming language
  • Familiarity with web applications and APIs

You will be able to

  • Recognise and fix the most common classes of web vulnerability
  • Threat-model a feature before building it
  • Write security tests that fail before the fix is applied
  • Review code for security defects
  • Integrate security checks into a delivery pipeline

Syllabus

Module by module.

  1. Module 01

    Secure design

    • Threat modelling
    • Trust boundaries
    • Security requirements
  2. Module 02

    Common vulnerabilities

    • Injection
    • Broken access control
    • Cross-site scripting
    • Server-side request forgery
  3. Module 03

    Authentication and sessions

    • Password storage
    • Multi-factor authentication
    • Session management
    • Token handling
  4. Module 04

    Data protection

    • Encryption in transit and at rest
    • Secrets management
    • Data minimisation in code
    • Logging without leaking
  5. Module 05

    Security testing

    • Red-first security tests
    • Static and dynamic analysis
    • Dependency scanning
    • Mutation testing of security controls

Hands-on labs

Learning by operating real systems.

  • Lab 01

    Threat-model a payment feature and derive security requirements

  • Lab 02

    Exploit and then fix injection and access-control flaws

  • Lab 03

    Write failing tests for a vulnerability, then make them pass

  • Lab 04

    Review a pull request for security defects

  • Lab 05

    Add static analysis and dependency scanning to a pipeline

Reserve a place or book a private cohort.

A senior engineer reviews every enquiry and replies within one business day.