Advanced · Hybrid cohort · 5 weeks
Secure pipelines without freezing delivery
Thread supply chain checks into pipelines that still ship weekly improvements.
Security and reliability share a language about change risk. You will map SBOM ingestion, signing hooks, and policy checks into stages that developers recognise. Stories stay grounded in SME realities — no theatrical hacker demos, just disciplined reviews.
What is inside
- Threat modeling lite for build systems
- SBOM ingestion patterns with storage cautions
- Policy-as-code snippets readable by non-specialists
- Pairing with security champions during office hours
- Release note additions that mention control changes
- Checklist for rotating build credentials
- Mentor review of one pipeline hardening PR
Outcomes
- Open a pipeline hardening PR with mentor-approved scope
- Publish a threat note your security partner can acknowledge
- Draft a joint retro format for reliability and security squads
Facilitator
Portrait placeholder for Hannah Owusu
Hannah Owusu
Security-aware SRE who helped regional banks tighten build attestations without halting cadence.
Tuition reference: SGD 1,880 · schedule Tue deep dives · Sat morning clinics · track Secure delivery
Questions cohorts ask
Notes from participants
“SBOM lab made our security partner nod faster than any slide deck we tried last year.”Victor · SME SaaS