Skip to content
Abstract code protected by a shield and a padlock, with a pipeline running through checkpoints
Course · CUANTICO Academy

Security is not added at the end. It is written into every line of code.

A free advanced course for developers and tech leads who want to turn OWASP recommendations into concrete design, implementation, review and delivery decisions: fewer vulnerabilities in production, fewer emergency patches and software your users can trust.

Language
Taught in Spanish
Format
Online, on our virtual campus
Access
Free
Duration
4 h 3 min
Content
10 modules and 42 lessons
Level
Advanced
Taught by
CUANTICO's AI team

What it covers

Security arrives late: software is designed to work, not to withstand attacks. The pentest comes at the end, patches are made under pressure and the same vulnerabilities come back. The later a flaw is found, the more it costs to fix.

The answer is to build securely from the design and verify it continuously within the development process.

Who it is for

Advanced level: requires experience in development, web architectures and APIs, version control and CI/CD.

  • Senior and full-stack developers.
  • Tech leads and architects.
  • DevOps and platform teams.
  • DevSecOps and AppSec teams.
  • Code reviewers and quality teams.
  • Engineering managers and CTOs.

What you will learn

By the end you will be able to:

  • Apply OWASP principles across the whole development cycle.
  • Implement authentication, authorization, validation, session and data controls.
  • Analyze code, dependencies, configuration and pipelines.
  • Align your controls with ASVS.
  • Make security verifiable in architecture, reviews and delivery.
  • Prioritize remediation by risk.

Why OWASP?

OWASP is the open application security community whose projects are the common language of developers, auditors, security teams and regulators: the Top 10, the API Security Top 10, ASVS, the testing guides, the Cheat Sheets and the maturity models.

Knowing the Top 10 is not enough. The course closes the gap between knowing it and applying it.

Signs it is for you

  • Every pentest brings the same findings.
  • Pull requests are approved without security criteria.
  • Authorization in your APIs is unclear.
  • Your dependencies have known vulnerabilities.
  • Your CI/CD ships without verifying security.
  • You have to demonstrate compliance (ISO/IEC 27001, data protection).
  • You want a security culture without slowing delivery down.

Syllabus

10 modules and 42 lessons.

ModuleLessons
1. OWASP framework and risk1
2. Secure design3
3. Identity and access5
4. Secure input and logic7
5. Data protection7
6. Web applications and APIs4
7. Components and supply chain4
8. Configuration and observability3
9. Verification and secure delivery7
10. Resilience and leadership1

What you take away

  • A risk-based decision framework.
  • Secure design patterns.
  • Code review criteria for pull requests.
  • A guide to using ASVS.
  • A DevSecOps pipeline model.
  • Arguments to defend the investment in security.
  • A common language across development, security and business.

Skills

  • OWASP
  • Secure coding
  • Code review
  • Threat modeling
  • API security
  • DevSecOps
  • Vulnerability management
  • Supply chain security
  • OWASP ASVS

What this course is not

  • It is not an introductory course.
  • It is not an offensive hacking course.
  • It is not a rote review of the Top 10.
  • It is not tied to one programming language.

What makes it different

  • From knowledge to decision: what to do in each case.
  • The whole cycle: design, code, review, testing and delivery.
  • Verifiable standards: the ASVS controls.
  • Designed for teams that ship software.
  • Built from the team’s practice.

Free

You get free access to the 10 modules and 42 lessons, at your own pace. It is a CUANTICO initiative to strengthen the secure development culture of technology teams in Colombia and Latin America.

Taught by

CUANTICO's AI team, with researchers in Colombia, the United States and Spain and the support of CuantaIA. The team designs, builds and operates platforms that handle sensitive information, with practices aligned with ISO/IEC 27001 (certification in progress).

This course gathers the practices the team applies in its own projects.

Frequently asked questions

  • What level is it?

    Advanced.

  • Which programming language?

    It is language-independent: it works for Java, C#, Python, JavaScript and TypeScript, Go, PHP and others.

  • How long does it take?

    4 h 3 min. With 40 minutes a day, you finish it in a week.

  • Does it prepare for a certification?

    It is not aimed at any specific certification.

  • Does it help with compliance?

    It supports the secure development requirements of frameworks such as ISO/IEC 27001. It does not replace professional advice.

  • Is there a certificate?

    No.

  • How much does it cost?

    It is free.

Start today, for free

The course is free, online and at your own pace.

Let's talk on WhatsApp

Leave your details and we'll open the chat. You will see the message in WhatsApp before sending it.

The site does not store these details: we email you a confirmation and notify our sales team.

We received your request

Fields marked with * are required.

With country code, for example +1 305 123 4567.
Do not share patient data, health information or passwords.