Certified in Proficiency of Security Engineering (CPSE)
Engineering Practice: The Six-Stage Pipeline, Built on an Honest Reckoning With Why Shift-Left Failed

Shift left is the right idea. It’s also been implemented badly across the industry for a decade — and this course says so, directly, before teaching you how to do it properly. Requirements through runtime defense, anchored to SolarWinds, Log4Shell, Capital One, and more.
Inside the program:
- Lifetime Training Access
- 1-Year Exam License Validity
- Official Online Training
- Official Exam-Prep Quizzes
- Official Course Study Guide
How to Keep Designation Active?
- No CPE Maintenance Needed
- Attend Free Refresher Training
- Contribute 5 Articles Per Year
- Keep Annual Membership Active
Every Team Knows They Should "Shift Left." Almost None of Them Do It Well.
Shift left — pushing security earlier in the lifecycle — has been the industry’s stated doctrine for a decade. Its actual implementation has, just as consistently, produced security theater: developers handed more responsibility with no reduction in feature load and no organizational support to back it up. CPSE names that failure directly, in its first lesson, and builds six stages of real practice that don’t repeat it.
- You'll write security requirements as testable acceptance criteria, not documents nobody reads.
- You'll build a real threat model using STRIDE, DREAD, and PASTA, anchored to a build-pipeline compromise most 2020-era teams weren't trained to see coming.
- You'll know exactly what static analysis can and can't find — and where a genuinely new category of AI-reasoning tools fits, honestly hedged against the evidence that actually exists.
- You'll gate every release the way infrastructure should be gated: automated, reproducible, and never bypassed under pressure.
Every AI security tool this course discusses — Anthropic’s Claude Security and OpenAI’s Daybreak — is named together, every time. A course that credits only one vendor’s capability in a genuinely industry-wide shift would be exactly the kind of favoritism this certification is built to avoid.
What Sets This Program Apart
An Honest Reckoning With Shift-Left
Most training assumes shift-left works if you just do more of it. This course opens by explaining why it’s failed industry-wide for a decade — and builds six stages that don’t repeat the mistake.
Real Incidents at Every Stage
SolarWinds for threat modeling. Log4Shell for static analysis. Capital One for dynamic testing. Codecov for release gating. A 2026 zero-day for runtime defense. Every stage, one real, dated, sourced anchor.
Cattle, Not Pets
A genuine engineering discipline for release infrastructure — automated, reproducible, disposable by design — not a slide about “DevSecOps” with no practical follow-through.
Vendor-Neutral on AI Security Tooling
Where this course discusses AI-assisted security tools, it names direct competitors together, every time, and states plainly what current evidence does and doesn’t support.
Is This Program Right for You?
CPSE is built for practitioners who want the actual engineering practice behind “secure development lifecycle,” not another slide deck restating the acronym. It assumes you’ve completed CGSL and are ready to turn diagnosis into building practice.
You are responsible for how security actually gets built into a pipeline, not just documented as a policy.
You want a structured, six-stage model to evaluate and improve your organization’s existing pipeline against.
You are now ready for the required second half of the security foundation path.
Your organization needs a vendor-neutral, evidence-based framing before you commit to one.
CPSE is the second of two Foundation courses your Level 2 or 3 credential requires — you can start your specialization first and complete CPSE alongside it, or apply for a Foundations Exam Waiver if you’ve got the hands-on experience to skip its exam.
PROGRAM OUTCOME
What You'll Learn
Six lessons, one per pipeline stage, each producing a specific, testable outcome the next stage depends on.
Write real security requirements
Turn compliance obligations, risk context, and abuse cases into testable acceptance criteria a developer can actually build against.
Build and score a threat model
Apply STRIDE, DREAD, and PASTA to find what a team’s own imagination might otherwise miss — anchored to a real, category-defining incident.
Know what each testing category actually finds
Static analysis, dynamic testing, and the genuinely new AI-reasoning category — what each catches, what each misses, and how to combine them.
Gate releases and defend runtime
Cattle-not-pets release engineering, plus the WAF/RASP/CSPM/SIEM stack — and why runtime defense is never optional, no matter how good everything upstream is.
WHO IS THIS FOR
Built for practitioners who are ready to move from diagnosis to building practice
CPSE assumes the structural literacy CGSL builds. If you’re comfortable with that foundation and ready for hands-on engineering practice across all six pipeline stages, this course is calibrated for you.
This course is perfect for
- Engineers and architects who own how security gets built into a real pipeline
- AppSec leads evaluating or redesigning their organization's existing security engineering practice
- Anyone who has completed CGSL and is continuing toward Level 2 or Level 3 certification
- Practitioners who want a vendor-neutral, evidence-based view of emerging AI security tooling
This course may not be for you if
- You haven't yet completed CGSL, which is a required prerequisite
- You're looking for governance and diagnostic content rather than hands-on engineering practice — that's CGSL
- You want deep, single-tool vendor training rather than a vendor-neutral pipeline model
- You're not currently working in or near a software engineering or AppSec function
- 6 pipeline stages.
- 5 real, dated incidents anchoring the practice.
- One honest chapter on why shift-left keeps failing — and what actually fixes it.
- The required second half of Gloria Institute’s Security Foundation Level.
6 lessons, one per stage of the pipeline, from the first requirement to the last runtime alert.
What You Will Study
Six core lessons with interactive scenarios and a graded knowledge check each, followed by certification exam eligibility once the course is complete.
Certification Exam
Once you’ve completed all 6 lessons, you’re eligible to sit the certification exam. Use the course companion guide, the ready reckoner handout and the comprehensive study guide, which is available for you to prepare.
Where requirements come from, OWASP ASVS and NIST SSDF, and a direct confrontation with why shift-left has failed industry-wide for a decade — before this course asks you to do it better.
STRIDE, DREAD, and PASTA, anchored to the 2020 SolarWinds compromise — a threat vector most pre-2020 threat models weren't built to name as a category.
SAST, SCA, secrets scanning, and IaC scanning — plus an honest look at the emerging AI-reasoning category, anchored to Log4Shell and the case for a current SBOM.
DAST, IAST, fuzzing, and penetration testing — what each finds that static analysis structurally cannot, anchored to the 2019 Capital One breach.
Container scanning, SBOM attestation, signing and provenance, and policy as code — all built on a cattle-not-pets discipline, anchored to the 2021 Codecov compromise.
WAF, RASP, CSPM, and SIEM, and the feedback loop back to Lesson 1 — anchored to a 2026 case demonstrating just how far the exploitation window has compressed.
Once you've completed all six lessons, you're eligible to sit the certification exam. Use the course companion guide and the comprehensive study guide, which is available for you to prepare.
OBJECTIVES
The Path To Becoming A Practitioner
Every lesson in CPSE builds toward practical, applicable engineering skill — not a slide-deck understanding of “secure SDLC,” but a working model you can apply to a real pipeline. By the end of this course, you’ll be able to build the pipeline, not just describe it.
Specify and gate real requirements
Write testable security acceptance criteria and know exactly which controls are non-negotiable before a system touches sensitive data.
Model threats a team might otherwise miss
Apply structured, systematic threat modeling to trust boundaries most teams don’t think to name — until an incident forces the issue.
Build a pipeline that resists both convenience and pressure
Gate every release with reproducible, automated controls, and defend runtime with a stack that never treats detection as optional.
OVERVIEW
About This Course
CPSE is the second of two mandatory foundation certifications in the GI Security certification path, and it picks up exactly where CGSL leaves off. Where CGSL built the diagnostic capacity to recognize structural security failure, CPSE teaches the engineering practice for building systems that resist it from the start — a six-stage pipeline running from security requirements through threat modeling, static and dynamic analysis, release gating, and runtime defense.
This course opens with something most security training won’t say out loud: shift left, the industry’s stated doctrine for a decade, has been implemented badly almost everywhere it’s been tried — developers handed more security responsibility with no reduction in feature load and no organizational support to make the added responsibility functional. CPSE names that failure directly before asking you to do six stages of practice better.
Every stage is anchored to a real, dated, independently verified incident, chosen deliberately across different organizations and different eras so no single company’s reputation carries the argument. Where this course discusses emerging AI-assisted security tooling, it names direct competitors together, every time, and states plainly what current evidence supports and what it doesn’t.
CGSL should be completed first. Together, both Foundation courses’ training is required for every Gloria Institute Level 2 field specialization and Level 3 role specialization credential to issue — though you’re free to start your specialization course before finishing either.
Everything you need to learn the pipeline, apply it, and prepare for certification.
What's Included
When you enroll, you’ll gain access to the complete interactive course along with the accompanying reference guide. Once you’re prepared, the certification package — which includes the exam voucher and course study guide — will be provided to you as well.
- Six interactive online lessons covering all six pipeline stages
- Branching scenarios and graded knowledge checks in every lesson
- A free companion guide covering all six lessons, included with enrollment
- Five real, dated, sourced incident case studies anchoring the pipeline
- Official course study guide for certification exam prepration
- Certification exam eligibility and voucher
- Access to the Gloria Institute learner community and future certification path updates
Eligibility & Requirements
CPSE is the second of Gloria Institute’s two mandatory security foundation courses, and it assumes the diagnostic vocabulary CGSL builds. Hands-on engineering context strongly recommended.
This course builds directly on CGSL's structural literacy foundation and should be taken second, not first.
Not required, but the course moves at a pace calibrated for someone already working in or near a software engineering pipeline.
Approximately 6–7 hours of core lesson content, plus additional time for exam preparation.
CGSL and CPSE training together is required for every Gloria Institute Level 2 and Level 3 credential to issue. You can enroll in a Level 2 or 3 course anytime — its credential won't issue until Foundations training is complete and the Foundations exam is passed or waived. Practitioners with 5+ years of hands-on secure coding, DevSecOps, or penetration testing experience can apply for a Foundations Exam Waiver to skip the exam specifically. [See Waiver Eligibility →]
The Credential That Opens Doors
When you complete a Gloria Institute program, you earn more than just a certificate—you gain recognition for practical, industry-relevant expertise that employers value.
Our certificates are thoughtfully designed to reflect the credibility and quality of our programs. Each credential specifies the specific competencies you’ve mastered, providing clear evidence of your professional development to current and prospective employers. Each Gloria Institute certificate includes:
- Program-specific competencies achieved
- Digital badge for certifications
- Completion date
- Unique verification number
- Support for certificate verification
Sample Certificate
Here’s an example of the certificate you’ll get when you finish a program at the Gloria Institute successfully:

Enrollment, Examination, and Policy FAQs
Yes. CGSL is a required prerequisite, since CPSE builds directly on the diagnostic vocabulary it establishes.
If you've got 5+ years of hands-on secure coding, DevSecOps, or penetration testing experience, you can apply to waive the CPSE certification exam specifically — not the training. CPSE's content (the six-stage pipeline, threat modeling, release gating, runtime defense) is the Foundation course most waiver applicants have already been doing in some form on the job, which is exactly what the waiver is for. You'll still complete the CPSE lessons in full, since that's the shared vocabulary every Gloria Institute specialization assumes. [Apply for a Waiver →]
Yes. Course enrollment includes the 6 interactive lessons and the free companion guide. A certification exam voucher and a comprehensive student study guide are also part of this course.
Because teaching the same failed implementation with better vocabulary wouldn't actually help you. This course names the industry's decade-long failure pattern directly so the six stages that follow don't repeat it.
No. Where AI-assisted security tooling is discussed, this course names direct competitors together, every time, and states plainly what current evidence supports — deliberately avoiding favoring any single vendor.
The companion guide, included with enrollment, covers the same material as the course for quick review. The student course study guide is a thorough product built specifically for exam preparation — compressed review, practice questions, and a full mock exam.
The exam voucher comes with a free retake. A mandatory waiting period applies between attempts. Specific retake policy and pricing for additional retakes are detailed at the point of exam voucher purchase.
CPSE was built by Gloria Institute practitioners with decades of combined hands-on security engineering, implementation, and consulting experience — not a certification board working from secondhand case studies. Every concept, practice, and framework in this course was developed and refined through real security work: what worked, what didn't, and what changed after watching the same structural failures recur across other practitioners and organizations.
Turn what you diagnosed into what you build.
Enroll in CPSE and complete the diagnostic-to-practice pipeline Gloria Institute’s entire security certification path is built on — or apply for a Foundations Exam Waiver if your hands-on experience already covers this ground.
Haven’t taken CGSL yet? Start there first.
