Service

Developer security training

Practical security training that helps development teams reduce recurring findings over the long term.

When this service fits

Many security problems arise not from a lack of will, but from a lack of context in everyday development. When teams understand how attacks work in practice, they make better architecture, implementation, and review decisions.

Three specific formats

The formats combine attacker perspectives with many years of development experience. Instead of general awareness content, participants work on technical decisions, code and API patterns, and realistic findings from their work context.

Attacker thinking for development teams

  • Target group: Development, QA and architecture teams who want to identify security risks earlier and better prioritize them.
  • Previous knowledge: Experience with software development or software testing; Special security knowledge is not required.
  • Duration: two to four hours.
  • Agenda: Understand real attack chains, identify attack surfaces in your own product, evaluate findings from the attacker’s perspective and derive effective countermeasures.
  • Result: a common understanding of risk and concrete test questions for refinement, implementation and review.

Secure coding for Java and web development

  • Target group: Java, backend and web developers who want to avoid recurring vulnerabilities in their code.
  • Previous knowledge: Solid basics in the programming language used and experience with web applications; I tailor examples and exercises to the technology stack.
  • Duration: one training day, divided into two half days if desired.
  • Agenda: Authentication and authorization, input and output handling, server-side access, secure use of framework functions and review of typical vulnerability patterns.
  • Result: applicable coding and review rules, practiced protective measures and a prioritized checklist for everyday development.

API Security Workshop

  • Target group: Teams that develop, test or have architectural responsibility for REST or comparable web APIs.
  • Previous knowledge: Basic knowledge of HTTP, API design and your own authentication and authorization concepts.
  • Duration: half a day to a full day.
  • Agenda: API attack surfaces, object and function-based authorization, tokens and sessions, input validation, rate limits, sensitive data flows and meaningful security tests.
  • Result: a prioritized API risk picture as well as concrete test cases and protective measures for development, review and quality assurance.

All formats are live trainings with technical demonstrations and shared application. I include customer-specific examples or anonymized findings when they are approved and improve the learning transfer.

What you get

I provide understandable attack scenarios, concrete protective measures and comprehensible decision-making criteria. The formats chosen are based on your technologies, typical weak points and specific product risks.

  • a coordinated learning goal and an agenda tailored to the target group
  • practical exercises and technical demonstrations
  • Documents or checklists for further internal use
  • Space for questions about your own architectural and development decisions
  • a short recommendation for meaningful deepening and transfer into everyday life

Typical process

  1. We clarify target group, previous knowledge, technologies and recurring risks.
  2. I suggest learning objectives, format and exercises.
  3. The training takes place remotely or on site with agreed practical components.
  4. Finally, we secure transfer measures for reviews and development.

Prerequisites

The participants need a common technical starting point. For hands-on formats, work equipment, required tools and, if necessary, an isolated practice environment must be available. I only use customer-specific findings that have been approved and sufficiently anonymized.

Typical timeframe

Compact workshops last two to four hours, in-depth training takes one to two days. Multi-part formats make sense if exercises, transfer tasks and a later exchange of experiences are to be combined.

Not included

It does not include standardized compulsory instructions, phishing simulations, examination certificates or a permanent learning platform. The training does not replace a technical test of the product.

โ† All services