After 13 years of experience, including 6 in SOC, 4 in Penetration Testing, and 3 in cyber Industrial Control System (OT), I'm seeking another area of information security, this time in DevSecOps. Advice and resources are always welcome.
I suggest starting with the OWASP DevSecOps Guideline. It lays out and explains many things, from an introduction to DevSecOps to a maturity model to what is known as 'Shift Left' security. The same project also has a document repository on GitHub.
Beyond that, I suggest looking at resources from vendors that you trust or work with. For example, I'm a fan of Cloudflare. AWS and Google each offer guidance and skills training for DevSecOps in their environment
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.