gloria-institute-badge-csep
Certified in Security Engineering Practice (CSEP)

Engineering Practice: The Six-Stage Pipeline, Built on an Honest Reckoning With Why Shift-Left Failed

Shift left is the right idea. It’s also been implemented badly across the industry for a decade — and this course says so, directly, before teaching you how to do it properly. Requirements through runtime defense, anchored to SolarWinds, Log4Shell, Capital One, and more.

Self-paced Online Training
Board-issued Credential
Lifetime Course Access
1-Year Exam Validity
FOUNDATION LEVEL

CSEP

Scholarship Pricing Shown
$289

$499

Save $210

What's Included:

Salent Points:

Every Team Knows They Should "Shift Left." Almost None of Them Do It Well.

Shift left — pushing security earlier in the lifecycle — has been the industry’s stated doctrine for a decade. Its actual implementation has, just as consistently, produced security theater: developers handed more responsibility with no reduction in feature load and no organizational support to back it up. CSEP names that failure directly, in its first lesson, and builds six stages of real practice that don’t repeat it.

Every AI security tool this course discusses — Anthropic’s Claude Security and OpenAI’s Daybreak — is named together, every time. A course that credits only one vendor’s capability in a genuinely industry-wide shift would be exactly the kind of favoritism this certification is built to avoid.

What Sets This Program Apart

An Honest Reckoning With Shift-Left

Most training assumes shift-left works if you just do more of it. This course opens by explaining why it’s failed industry-wide for a decade — and builds six stages that don’t repeat the mistake.

Real Incidents at Every Stage

SolarWinds for threat modeling. Log4Shell for static analysis. Capital One for dynamic testing. Codecov for release gating. A 2026 zero-day for runtime defense. Every stage, one real, dated, sourced anchor.

Cattle, Not Pets

A genuine engineering discipline for release infrastructure — automated, reproducible, disposable by design — not a slide about “DevSecOps” with no practical follow-through.

Vendor-Neutral on AI Security Tooling

Where this course discusses AI-assisted security tools, it names direct competitors together, every time, and states plainly what current evidence does and doesn’t support.

Is This Program Right for You?

CSEP is built for practitioners who want the actual engineering practice behind “secure development lifecycle,” not another slide deck restating the acronym. It assumes you’ve completed CGSL and are ready to turn diagnosis into building practice.

You're an engineer or architect

You are responsible for how security actually gets built into a pipeline, not just documented as a policy.

You're a security engineer or AppSec lead

You want a structured, six-stage model to evaluate and improve your organization’s existing pipeline against.

You've completed CGSL

You are now ready for the required second half of the security foundation path.

You're evaluating AI-assisted security tooling

Your organization needs a vendor-neutral, evidence-based framing before you commit to one.

You're preparing for GI's Level 2 or Level 3 credential

GI-CSEP is the second of two required foundation courses standing between you and that specialization.

PROGRAM OUTCOME

What You'll Learn

Six lessons, one per pipeline stage, each producing a specific, testable outcome the next stage depends on.

Write real security requirements

Turn compliance obligations, risk context, and abuse cases into testable acceptance criteria a developer can actually build against.

Build and score a threat model

Apply STRIDE, DREAD, and PASTA to find what a team’s own imagination might otherwise miss — anchored to a real, category-defining incident.

Know what each testing category actually finds

Static analysis, dynamic testing, and the genuinely new AI-reasoning category — what each catches, what each misses, and how to combine them.

Gate releases and defend runtime

Cattle-not-pets release engineering, plus the WAF/RASP/CSPM/SIEM stack — and why runtime defense is never optional, no matter how good everything upstream is.

Who Is This For

Built for practitioners who are ready to move from diagnosis to building practice

CSEP assumes the structural literacy CGSL builds. If you’re comfortable with that foundation and ready for hands-on engineering practice across all six pipeline stages, this course is calibrated for you.

This course is perfect for
This course may not be for you if
  • 6 pipeline stages.
  • 5 real, dated incidents anchoring the practice.
  • One honest chapter on why shift-left keeps failing — and what actually fixes it.
  • The required second half of Gloria Institute’s Security Foundation Level.

6 lessons, one per stage of the pipeline, from the first requirement to the last runtime alert.

What You Will Study

Six core lessons with interactive scenarios and a graded knowledge check each, followed by certification exam eligibility once the course is complete.

Where requirements come from, OWASP ASVS and NIST SSDF, and a direct confrontation with why shift-left has failed industry-wide for a decade — before this course asks you to do it better.

STRIDE, DREAD, and PASTA, anchored to the 2020 SolarWinds compromise — a threat vector most pre-2020 threat models weren't built to name as a category.

SAST, SCA, secrets scanning, and IaC scanning — plus an honest look at the emerging AI-reasoning category, anchored to Log4Shell and the case for a current SBOM.

DAST, IAST, fuzzing, and penetration testing — what each finds that static analysis structurally cannot, anchored to the 2019 Capital One breach.

Container scanning, SBOM attestation, signing and provenance, and policy as code — all built on a cattle-not-pets discipline, anchored to the 2021 Codecov compromise.

WAF, RASP, CSPM, and SIEM, and the feedback loop back to Lesson 1 — anchored to a 2026 case demonstrating just how far the exploitation window has compressed.

Once you've completed all six lessons, you're eligible to sit the certification exam. Use the course companion guide and the comprehensive study guide, which is available for you to prepare.

OBJECTIVES

The Path To Becoming A Practitioner

Every lesson in CSEP builds toward practical, applicable engineering skill — not a slide-deck understanding of “secure SDLC,” but a working model you can apply to a real pipeline. By the end of this course, you’ll be able to build the pipeline, not just describe it.

Specify and gate real requirements

Write testable security acceptance criteria and know exactly which controls are non-negotiable before a system touches sensitive data.

Model threats a team might otherwise miss

Apply structured, systematic threat modeling to trust boundaries most teams don’t think to name — until an incident forces the issue.

Build a pipeline that resists both convenience and pressure

Gate every release with reproducible, automated controls, and defend runtime with a stack that never treats detection as optional.

OVERVIEW

About This Course

CSEP is the second of two mandatory foundation certifications in the GI Security certification path, and it picks up exactly where CGSL leaves off. Where CGSL built the diagnostic capacity to recognize structural security failure, CSEP teaches the engineering practice for building systems that resist it from the start — a six-stage pipeline running from security requirements through threat modeling, static and dynamic analysis, release gating, and runtime defense.

This course opens with something most security training won’t say out loud: shift left, the industry’s stated doctrine for a decade, has been implemented badly almost everywhere it’s been tried — developers handed more security responsibility with no reduction in feature load and no organizational support to make the added responsibility functional. CSEP names that failure directly before asking you to do six stages of practice better.

Every stage is anchored to a real, dated, independently verified incident, chosen deliberately across different organizations and different eras so no single company’s reputation carries the argument. Where this course discusses emerging AI-assisted security tooling, it names direct competitors together, every time, and states plainly what current evidence supports and what it doesn’t.

CGSL must be completed first. Together, both foundation courses are mandatory prerequisites for every Gloria Institute’s security Level 2 field specialization and Level 3 role  specialization certification.

Everything you need to learn the pipeline, apply it, and prepare for certification.

What's Included

Enrollment includes the full interactive course and its companion reference guide. Certification itself — the exam voucher and optional study guide — is available separately once you’re ready.

Eligibility & Requirements

CSEP is the second of Gloria Institute’s two mandatory security foundation courses, and it assumes the diagnostic vocabulary CGSL builds. Hands-on engineering context strongly recommended.

CGSL is a required prerequisite

This course builds directly on CGSL’s structural literacy foundation and should be taken second, not first.

Engineering or AppSec experience recommended

Not required, but the course moves at a pace calibrated for someone already working in or near a software engineering pipeline.

Time commitment

Approximately 6–7 hours of core lesson content, plus additional time for exam preparation.

Required for further certification

CGSL and CSEP together are mandatory prerequisites for every Gloria Institute’s Level 2 and Level 3 security field specialization and role specialization credential.

The Credential That Opens Doors

When you complete a Gloria Institute program, you earn more than just a certificate—you gain recognition for practical, industry-relevant expertise that employers value.

Our certificates are thoughtfully designed to reflect the credibility and quality of our programs. Each credential specifies the specific competencies you’ve mastered, providing clear evidence of your professional development to current and prospective employers. Each Gloria Institute certificate includes:

Sample Certificate

Here’s an example of the certificate you’ll get when you finish a program at the Gloria Institute successfully:

Enrollment, Examination, and Policy FAQs

Yes. CGSL is a required prerequisite, since CSEP builds directly on the diagnostic vocabulary it establishes.

Yes. Course enrollment includes the 6 interactive lessons and the free companion guide. A certification exam voucher and a comprehensive student study guide are also part of this course.

Because teaching the same failed implementation with better vocabulary wouldn't actually help you. This course names the industry's decade-long failure pattern directly so the six stages that follow don't repeat it.

No. Where AI-assisted security tooling is discussed, this course names direct competitors together, every time, and states plainly what current evidence supports — deliberately avoiding favoring any single vendor.

The companion guide, included with enrollment, covers the same material as the course for quick review. The student course study guide is a thorough product built specifically for exam preparation — compressed review, practice questions, and a full mock exam.

The exam voucher comes with a free retake. A mandatory waiting period applies between attempts. Specific retake policy and pricing for additional retakes are detailed at the point of exam voucher purchase.

CSEP was developed by a team of security experts from the industry. The operation is headed by Haroon Mansoori, who brings more than 30 years of expertise in security engineering. Gloria Institute's certifying board is expanding over time; current governance details are maintained on our About page.

Turn what you diagnosed into what you build.

Enroll in CSEP, the required second foundation course, and complete the diagnostic-to-practice pipeline Gloria Institute’s entire security certification path is built on.

Haven’t taken CGSL yet? Start there first.

Scroll to Top