All roadmaps
Roadmap

DevSecOps Engineer

From Linux fundamentals to shipping secure software at scale, the complete DevSecOps engineer path.

19stages143topics~122hours

Curated from the best, MDN · Kubernetes · AWS · OWASP · Google SRE & more

Senior DevSecOps Engineers command £90K–£150K+ at companies like Cloudflare, HashiCorp, Snyk, and Datadog. Post-SolarWinds and Log4Shell, supply chain and runtime security engineers are among the most sought-after profiles in cloud infrastructure. The FAANG bar now expects threat modeling, IaC security scanning, and CSPM, not just "knows how to run Trivy."

The complete path, 26 of 143 topics have lessons here; the other 117 are marked learn anywhere. We won't pretend we cover everything.

01
Stage 1 / 19 · 7 topics · 0 lessons

Computing & OS Foundations

The bedrock every DevSecOps engineer stands on: how computers, operating systems, and processes actually work.

02
Stage 2 / 19 · 9 topics · 0 lessons

Linux Command Line & Shell

Live in the terminal: navigate, automate, and operate Linux systems with confidence.

03
Stage 3 / 19 · 9 topics · 1 lessons

Networking Fundamentals

How packets move and how services talk, the substrate of all distributed and secure systems.

04
Stage 4 / 19 · 8 topics · 0 lessons

Programming & Automation Languages

Write the code that automates infrastructure, glues pipelines, and builds security tooling.

05
Stage 5 / 19 · 9 topics · 2 lessons

Security Fundamentals

The core security mental models that make DevSecOps 'Sec' rather than just DevOps.

06
Stage 6 / 19 · 8 topics · 0 lessons

Cloud Platforms

Modern infrastructure lives in the cloud, master one provider deeply and the shared-responsibility model.

07
Stage 7 / 19 · 8 topics · 0 lessons

Containers & Container Security

Containers are the unit of deployment, and a major attack surface you must lock down.

08
Stage 8 / 19 · 10 topics · 4 lessons

Kubernetes & Orchestration

Operate and secure containerized workloads at scale with Kubernetes.

09
Stage 9 / 19 · 8 topics · 4 lessons

Infrastructure as Code

Define infrastructure declaratively, version it, and secure it before it ever deploys.

10
Stage 10 / 19 · 8 topics · 3 lessons

CI/CD Pipelines

Automate build, test, and deploy, the assembly line where security gates get embedded.

11
Stage 11 / 19 · 9 topics · 3 lessons

Application & Code Security (Shift-Left)

Find and fix vulnerabilities in code and dependencies before they ship.

12
Stage 12 / 19 · 6 topics · 0 lessons

Secrets & Identity Management

Protect the keys to the kingdom, credentials, tokens, and machine identity.

13
Stage 13 / 19 · 7 topics · 1 lessons

Cloud Security & Posture Management

Continuously secure cloud environments against misconfiguration and drift.

14
Stage 14 / 19 · 7 topics · 0 lessons

Observability & Security Monitoring

You can't secure what you can't see, logs, metrics, traces, and detection.

15
Stage 15 / 19 · 6 topics · 2 lessons

Compliance, Governance & GRC

Translate regulatory and contractual requirements into enforceable technical controls.

16
Stage 16 / 19 · 7 topics · 2 lessons

Incident Response & Resilience

When prevention fails, detect fast, respond decisively, and recover gracefully.

17
Stage 17 / 19 · 5 topics · 1 lessons

Offensive Security & Testing

Validate defenses the way attackers do, pentesting, red teaming, and bug bounties.

18
Stage 18 / 19 · 7 topics · 3 lessons

DevSecOps Culture & Practices

The methodology that ties it together, shifting security left and owning it as a team.

19
Stage 19 / 19 · 5 topics · 0 lessons

Career, Certifications & Job Readiness

Package your skills, prove them, and land the role.

You're job-ready.

Clear every stage, earn the certificate, and walk into interviews prepared. The complete path, nothing hidden, no gaps.

Destination reached