Program

/

CODE BLUE 2026

Trainings

Tentative DevSecOps Masterclass: AppSec Automation Edition

DevOps has revolutionized the speed and scale at which organizations deliver software, but application security often struggles to keep pace with this rapid development lifecycle. As modern systems rely heavily on cloud infrastructure, containerization, and complex software supply chains, traditional security approaches become bottlenecks rather than enablers.
This hands-on two-day masterclass teaches security engineers, developers, and DevOps professionals how to implement practical DevSecOps and Application Security Automation across the software delivery pipeline. Participants will learn to integrate automated security testing, supply-chain integrity controls, secrets management, and policy enforcement directly into CI/CD workflows.
Through extensive hands-on labs, attendees will implement automated SAST, SCA, SBOM generation, supply-chain signing, DAST automation, and Policy-as-Code enforcement using modern tools such as Semgrep, OWASP ZAP, Nuclei, Open Policy Agent, Cosign, and HashiCorp Vault. The training also explores emerging AI-assisted DevSecOps workflows, including automated triage and intelligent vulnerability analysis. By the end of the course, participants will have built complete DevSecOps pipelines that integrate security from code to deployment—enabling organizations to scale security without slowing down innovation.

Training Outline

  • Title

    DevSecOps Masterclass: AppSec Automation Edition

  • Trainer

    Vishnu Prasad(we45)

  • Language

    English

  • Date

    2026-11-14 9:00 - 18:30
    2026-11-15 9:00 - 18:30

  • Venue

    Bellesalle Shinjuku Grand Conference Center (5F)

  • Capacity

    30(*Minimum students count is 10)

  • Remarks

    Include 2day Conference ticket(November 17th to 18th, 2026) for training attendees

Training Application

Buying Ticket
Price 300,000 JPY (Inc.TAX)
Sales period 〜November 11th
Sales Status

Training Detail

Who should take this course
  • Professionals involved in DevSecOps, application security, and cloud-native software development
Student requirements
  • Basic understanding of application security concepts (e.g., OWASP Top 10)

What skills will participants learn at your training?

  • Hands-On DevSecOps Security Automation: Participants will gain practical experience integrating automated security testing tools directly into CI/CD pipelines, enabling organizations to detect vulnerabilities early and continuously throughout the software delivery lifecycle.
  • Securing the Software Supply Chain: Attendees will learn how to implement supply-chain integrity controls such as SBOM generation, artifact signing, and provenance verification using technologies like Cosign and SLSA.
  • Automated Security Testing at Scale: Participants will build automated testing workflows using SAST, DAST, and Infrastructure-as-Code security tools to ensure applications, APIs, and infrastructure are continuously validated for security vulnerabilities.
  • Policy-Driven Security Enforcement: Through hands-on exercises with Open Policy Agent, attendees will learn how to implement Policy-as-Code frameworks that enforce security controls across APIs, infrastructure, and deployment pipelines.

What students should bring

  • Laptop with latest version of browser installed. Laptop should not have any sort of network and firewall restrictions.

What students will be provided with

  • All participants will receive access to a cloud-based lab environment with all required tools, including various LLMs and agent frameworks. Just bring a laptop with a web browser – no special hardware or local setup needed.

アブハイ・バルガフ の写真

Abhay Bhargav

アブハイ・バルガフ

Abhay Bhargav is the Founder and Chief Research Officer at AppSecEngineer, an elite, hands-on online training platform and we45 a specialized AppSec Company. Abhay started his career as a breaker of apps, in pentesting and red-teaming, but today is more involved in scaling AppSec with Cloud-Native Security and DevSecOps He has created some pioneering works in the area of DevSecOps and AppSec Automation, including the world's first hands-on training program on DevSecOps, focused on Application Security Automation. In addition to this, Abhay is active in his research of new technologies and their impact on Application Security, specifically Cloud-Native Security. In addition, Abhay has contributed to pioneering work in the Vulnerability Management space, being the architect of a leading Vulnerability Management and Correlation Product, Orchestron. Abhay is also committed to Open-Source and has developed the first-ever Threat Modeling solution at the crossroads of Agile and DevSecOps, called ThreatPlaybook. Abhay is a speaker and trainer at major industry events including DEF CON, BlackHat, OWASP AppSecUSA, EU and AppSecCali. His training programs have been sold-out events at conferences like AppSecUSA, EU, AppSecDay Melbourne, CodeBlue (Japan), BlackHat USA, SHACK and so on. He's authored two international publications on Java Security and PCI Compliance as well.