
Security is not added at the end. It is written into every line of code.
A free advanced course for developers and tech leads who want to turn OWASP recommendations into concrete design, implementation, review and delivery decisions: fewer vulnerabilities in production, fewer emergency patches and software your users can trust.
- Language
- Taught in Spanish
- Format
- Online, on our virtual campus
- Access
- Free
- Duration
- 4 h 3 min
- Content
- 10 modules and 42 lessons
- Level
- Advanced
- Taught by
- CUANTICO's AI team
What it covers
Security arrives late: software is designed to work, not to withstand attacks. The pentest comes at the end, patches are made under pressure and the same vulnerabilities come back. The later a flaw is found, the more it costs to fix.
The answer is to build securely from the design and verify it continuously within the development process.
Who it is for
Advanced level: requires experience in development, web architectures and APIs, version control and CI/CD.
- Senior and full-stack developers.
- Tech leads and architects.
- DevOps and platform teams.
- DevSecOps and AppSec teams.
- Code reviewers and quality teams.
- Engineering managers and CTOs.
What you will learn
By the end you will be able to:
- Apply OWASP principles across the whole development cycle.
- Implement authentication, authorization, validation, session and data controls.
- Analyze code, dependencies, configuration and pipelines.
- Align your controls with ASVS.
- Make security verifiable in architecture, reviews and delivery.
- Prioritize remediation by risk.
Why OWASP?
OWASP is the open application security community whose projects are the common language of developers, auditors, security teams and regulators: the Top 10, the API Security Top 10, ASVS, the testing guides, the Cheat Sheets and the maturity models.
Knowing the Top 10 is not enough. The course closes the gap between knowing it and applying it.
Signs it is for you
- Every pentest brings the same findings.
- Pull requests are approved without security criteria.
- Authorization in your APIs is unclear.
- Your dependencies have known vulnerabilities.
- Your CI/CD ships without verifying security.
- You have to demonstrate compliance (ISO/IEC 27001, data protection).
- You want a security culture without slowing delivery down.
Syllabus
10 modules and 42 lessons.
| Module | Lessons |
|---|---|
| 1. OWASP framework and risk | 1 |
| 2. Secure design | 3 |
| 3. Identity and access | 5 |
| 4. Secure input and logic | 7 |
| 5. Data protection | 7 |
| 6. Web applications and APIs | 4 |
| 7. Components and supply chain | 4 |
| 8. Configuration and observability | 3 |
| 9. Verification and secure delivery | 7 |
| 10. Resilience and leadership | 1 |
What you take away
- A risk-based decision framework.
- Secure design patterns.
- Code review criteria for pull requests.
- A guide to using ASVS.
- A DevSecOps pipeline model.
- Arguments to defend the investment in security.
- A common language across development, security and business.
Skills
- OWASP
- Secure coding
- Code review
- Threat modeling
- API security
- DevSecOps
- Vulnerability management
- Supply chain security
- OWASP ASVS
What this course is not
- It is not an introductory course.
- It is not an offensive hacking course.
- It is not a rote review of the Top 10.
- It is not tied to one programming language.
What makes it different
- From knowledge to decision: what to do in each case.
- The whole cycle: design, code, review, testing and delivery.
- Verifiable standards: the ASVS controls.
- Designed for teams that ship software.
- Built from the team’s practice.
Free
You get free access to the 10 modules and 42 lessons, at your own pace. It is a CUANTICO initiative to strengthen the secure development culture of technology teams in Colombia and Latin America.
Taught by
CUANTICO's AI team, with researchers in Colombia, the United States and Spain and the support of CuantaIA. The team designs, builds and operates platforms that handle sensitive information, with practices aligned with ISO/IEC 27001 (certification in progress).
This course gathers the practices the team applies in its own projects.
Frequently asked questions
What level is it?
Advanced.
Which programming language?
It is language-independent: it works for Java, C#, Python, JavaScript and TypeScript, Go, PHP and others.
How long does it take?
4 h 3 min. With 40 minutes a day, you finish it in a week.
Does it prepare for a certification?
It is not aimed at any specific certification.
Does it help with compliance?
It supports the secure development requirements of frameworks such as ISO/IEC 27001. It does not replace professional advice.
Is there a certificate?
No.
How much does it cost?
It is free.
Start today, for free
The course is free, online and at your own pace.
