When does class start/end?
Class hours may vary, please reach out to contact@ascendientlearning.com if you have any questions.
Harden DevSecOps for AI coding agents across every lifecycle phase. AI coding agents are framed as an insider-threat surface, with the CIA triad applied to AI-generated code and the OWASP Top 10 for...
Read MoreHarden DevSecOps for AI coding agents across every lifecycle phase. AI coding agents are framed as an insider-threat surface, with the CIA triad applied to AI-generated code and the OWASP Top 10 for Agentic Applications grounding the rest of the course. Plan, Code, and Build cover threat modeling with STRIDE and LINDDUN, AGENTS.md and CLAUDE.md as context contracts, licensing contamination, spec-driven design as an invariant-enforcement strategy, linting and type systems as agent guardrails, slopsquatting, and AIBOM hygiene. Test, Release, and Deploy cover mutation testing of weak agent assertions, rules-file-backdoor attacks, sandboxed agent execution, dual-LLM and capability-based runtime defenses, and EU-AI-Act-compliant audit trails. Operate, Monitor, and the human layer cover runtime prompt-injection defense, automation bias, agentic misalignment, risk-tiered review rubrics, and quality metrics that resist velocity theater. Hands-on labs produce CIA diagnostics, AGENTS.md hardening, mutation tests, rules-file-backdoor catches, sandbox-escape defenses, and a CI attribution check that yields an EU-AI-Act-compliant audit trail. The course is designed for software developers, technical leads, and security professionals deploying AI coding agents in production codebases.
By the end of this course, participants will be able to:
This course is designed for:
Participants should enter this course with:
This course assists organizations to:
All attendees must have a modern web browser and an Internet connection.
By the end of this module, you will be able to characterize AI coding agents as an insider-threat surface, apply the CIA triad to AI-generated code, and locate where each DevSecOps phase needs existing practices versus emerging ones to handle agent-driven work.
By the end of this module, you will be able to apply STRIDE and LINDDUN to AI-augmented systems, capture security and licensing requirements in architectural decision records, codify trust assumptions in AGENTS.md and CLAUDE.md context contracts, and use spec-driven development to enforce invariants.
By the end of this module, you will be able to use linting, pre-commit hooks, type systems, and schema validation as deterministic guardrails on AI-generated code, organize the codebase to limit agent blast radius, and treat the IDE itself as a security surface.
By the end of this module, you will be able to maintain SBOMs and AIBOMs, configure dependency review and allowlists, detect hallucinated package suggestions (“slopsquatting”), and keep lockfiles deterministic when agents edit dependencies.
By the end of this module, you will be able to wire SAST, DAST, and TDD into AI-assisted workflows; expose weak agent assertions through mutation and property-based testing; and protect existing tests from silent agent modification across refactors.
By the end of this module, you will be able to enforce mandatory review and signed commits on AI-authored changes, configure AI reviewers with project-specific rules, use agent hooks as deterministic review gates, and recognize rules-file backdoor attacks against context files.
By the end of this module, you will be able to integrate AI coding agents into change-management gates, validate IaC and policy-as-code, sandbox agent execution at process, container, and MicroVM levels, and use short-lived non-human identities for agent activity.
By the end of this module, you will be able to recognize prompt injection as an injection class, apply dual-LLM and capability-based defenses, harden MCP servers and isolate agent context, and monitor agent tool use at runtime to detect exfiltration.
By the end of this module, you will be able to instrument SIEM-grade audit logs for agent activity, satisfy EU AI Act Articles 19 and 26 log-retention requirements, attribute commits to human versus agent authors, and recover from incidents where the agent misrepresents what it did.
By the end of this module, you will be able to recognize rubber-stamping, automation bias, and velocity theater inside an AI-heavy team; design risk-tiered review rubrics; and choose quality metrics that don’t reward speed at the expense of correctness.
Class hours may vary, please reach out to contact@ascendientlearning.com if you have any questions.
Classes typically include a 1-hour lunch break around midday. However, the exact break times and duration can vary depending on the specific class. Your instructor will provide detailed information at the start of the course.
Most courses are conducted in English, unless otherwise specified. Some courses will have the word "FRENCH" marked in red beside the scheduled date(s) indicating the language of instruction.
GTR stands for Guaranteed to Run; if you see a course with this status, it means this event is confirmed to run. View our GTR page to see our full list of Guaranteed to Run courses.
We have training locations across the United States and Canada - View a complete list of classroom training locations.
At Ascendient Learning, we offer training that is Instructor-Led, Online, Virtual, and Self-Paced.
Yes, we provide training for groups, individuals and private on sites. View our group training page for more information.
As a vendor-authorized training partner, we offer a curriculum that our partners have vetted. We use the same course materials and facilitate the same labs as our vendor-delivered training. These courses are considered the gold standard and, as such, are priced accordingly.
It depends on your requirements, your role in your company, and your depth of knowledge. The good news about many of our learning paths, you can start from the fundamentals to highly specialized training.
We continuously work with our vendors to evaluate and refresh course material to reflect the latest training courses and best practices.
Ascendient Learning instructors have an average of 27 years of practical IT experience and have also served as consultants for an average of 15 years. To stay current, instructors spend at least 25 percent of their time learning new, emerging technologies and courses.
Lab access is dependent on the vendor and the type of training you sign up for. However, many of our top vendors will provide lab access to students to test and practice. The course description will specify lab access.
We will work with you to identify training needs and areas of growth. We offer a variety of training methods, such as private group training, on-site of your choice, and virtually. We provide courses and certifications that are aligned with your business goals.
Getting started on a certification pathway depends on your goals and the vendor you choose to get certified in. Many vendors offer entry-level IT certification to advanced IT certification that can boost your career. To get access to certification vouchers and discounts, please contact info@ascendientlearning.com.
You will get access to the PDF of course books and guides, but access to the recording and slides will depend on the vendor and type of training you receive.
View our filing status and how to request a W9.
It was very informative and covered all the required materials along with handson labs for practice.
Good training material and good instruction. More time needs to be provided for the lab work.
Sean is the very good instructor. I would like to take his class again in the future.
Great training it covered the most importan topics if GitHub copilot with good explanation and good labs.
great class and packed with material, would have lived to spread it more into many days but overall very informative.
Ascendient Learning is the coming together of three highly respected brands; Accelebrate, ExitCertified, and Web Age Solutions - renowned for their training expertise - to form one company committed to providing excellence in outcomes-based technical training.
With our winning team, we provide a full suite of customizable training to help organizations and teams upskill, reskill, and meet the growing demand for technical development because we believe that when talent meets drive, individuals rise, and businesses thrive.