Application Security Deep Dive

From awareness to security maturity

Application Security Fundamentals introduces the principles of secure software development and vulnerability identification. This Deep Dive builds on that foundation by helping you integrate security into your development process. You'll learn how to analyze code from a security perspective, apply security testing techniques, and understand the security implications of AI-assisted development.

Application Security Deep Dive Yielddd

Security should be embedded throughout the software development lifecycle. In this training, you'll learn how to apply security by design, incorporate security into your daily development practices, and reduce the likelihood of introducing vulnerabilities into your applications.

Through realistic applications, practical assignments, and security-focused exercises, you'll gain insight into how vulnerabilities arise, how to identify them, and how to integrate security into every stage of the software development lifecycle. The knowledge and skills you develop can be applied directly within your own development environment.

Duration: 1 day (8 hours, including hands-on sessions)
Audience: Developers and Software Architects with experience in C#, JavaScript, or TypeScript, and a basic understanding of development tooling and application security.

What you'll learn

Following a short introduction, you'll work through demonstrations, practical exercises, and hands-on assignments.

This dynamic training focuses on identifying and analyzing vulnerabilities in realistic software applications. You'll work with two different codebases:

  • A C# backend with a Vue.js frontend
  •  A JavaScript Express.js application 

By working directly with these applications, you'll gain insight into how vulnerabilities are introduced, how to identify them, and how to prevent them. You'll also learn how to integrate security into your development process through:

  • Security Code Analysis
    • Analyze multiple codebases, including C#, TypeScript, and Infrastructure as Code.
    • Identify security vulnerabilities and common implementation flaws.
    • Understand how vulnerabilities arise, how to prevent them, and how to strengthen your code against them. 
  • Secure Software Development Lifecycle (SSDLC)
    • Learn how to integrate security into every phase of the software development lifecycle.
    • Introduce practical security activities into your daily development process.
    • Understand how the SSDLC supports the development of secure software. 
  • Security Testing
    • Explore the different types of application security testing, including SAST, IAST, and DAST.
    • Learn when to apply each testing method and which tools support them. 
  • Security & AI
    • Explore the risks associated with AI tools such as ChatGPT and GitHub Copilot.
    • Understand the impact on privacy, data integrity, and automation bias. 
  • Threat Modeling & STRIDE
    • Learn how the STRIDE model supports systematic threat analysis.
    • Identify potential threats and determine appropriate mitigation strategies.
    • Connect threat modeling to practical software design and development decisions. 

Security throughout the software development lifecycle

By the end of this training, you'll have the knowledge and practical experience to integrate security into your daily development activities. You'll identify risks earlier, apply appropriate testing techniques, and strengthen your code using proven security practices. The result is software that is more secure, more resilient, and better prepared for today's threat landscape.

Our other security trainings:

Interested? We will contact you shortly.

Clients

  • Aareon
  • Mentha Capital
  • Brightpensioen
  • Main Capital
  • DELA
  • Auxilium
  • Shoe Investments
  • Brink Software
  • Argos Wityu
  • Investnl
  • Delta Equity Partners
  • BDO
  • Crowe
  • Antea
  • DSW
  • Axivate
  • BCE
  • Buckaroo Logo
  • Capital A
  • Green Choice
  • Cbusinez
  • Aebi Schmidt
  • Dirkzwager
  • KPN Ventures
  • Edge Next
  • Louwman
  • Europool
  • Cloudbilling
  • ANP
  • Ecclesia
  • Centraal Boekhuis
  • Meijers
  • Aiden
  • Fortino
  • Meesman
  • Bright Cape
  • Blanco
  • Festos
  • Finindus
  • Groenraedt
  • Eyeon
  • Nordian Capital Partners
  • Clocktimizer
  • Hertek
  • Blauwtrust
  • OX Greenfield
  • Hunter Douglas
  • Cyclovriend
  • Bugs Business
  • Hypoport
  • Plain Vanilla
  • Coosto
  • ICT Group
  • Impact Buying
  • Blackfin
  • Intersolve
  • Yellax
  • Karmijn
  • KNGF
  • Lexar Partners
  • Virtual Vaults
  • Farfield
  • Nedvest
  • Qwoater
  • VANAD
  • Heerema
  • Netaspect
  • Agidens
  • NL Investeert
  • Blue10
  • NPM Capital
  • Sabanci
  • First Dutch
  • Newport Capital
  • Nza
  • Jeugdzorg NL
  • Pondres
  • Syntess
  • Primera
  • Quadrum
  • Shift Invest
  • Trigentis
  • Verne
  • Ufenau
  • Vortex

Secure your digital assets

Iris van Voorden

Sales Director IT
Iris Van Voorden Contactblok

Cybersecurity

Our Security Training Courses are part of a broader security practice. We offer security assessments and enablement:

YieldDD’s security services deliver deep, actionable visibility into the security posture of your digital assets. 

Cybersecurity services YieldDD

Insights

Previous
Next