Engineering Practice: The Six-Stage Pipeline, Built on an Honest Reckoning With Why Shift-Left Failed
Shift left is the right idea. It’s also been implemented badly across the industry for a decade — and this course says so, directly, before teaching you how to do it properly. Requirements through runtime defense, anchored to SolarWinds, Log4Shell, Capital One, and more.
CSEP
$499
What's Included:
- Lifetime Training Access
- 1-Year Exam License Validity
- Official Online Training
- Official Exam-Prep Quizzes
- Official Course Study Guide
Salent Points:
- CPE Maintenance Not Required
Every Team Knows They Should "Shift Left." Almost None of Them Do It Well.
Shift left — pushing security earlier in the lifecycle — has been the industry’s stated doctrine for a decade. Its actual implementation has, just as consistently, produced security theater: developers handed more responsibility with no reduction in feature load and no organizational support to back it up. CSEP names that failure directly, in its first lesson, and builds six stages of real practice that don’t repeat it.
- You'll write security requirements as testable acceptance criteria, not documents nobody reads.
- You'll build a real threat model using STRIDE, DREAD, and PASTA, anchored to a build-pipeline compromise most 2020-era teams weren't trained to see coming.
- You'll know exactly what static analysis can and can't find — and where a genuinely new category of AI-reasoning tools fits, honestly hedged against the evidence that actually exists.
- You'll gate every release the way infrastructure should be gated: automated, reproducible, and never bypassed under pressure.
Every AI security tool this course discusses — Anthropic’s Claude Security and OpenAI’s Daybreak — is named together, every time. A course that credits only one vendor’s capability in a genuinely industry-wide shift would be exactly the kind of favoritism this certification is built to avoid.
What Sets This Program Apart
An Honest Reckoning With Shift-Left
Most training assumes shift-left works if you just do more of it. This course opens by explaining why it’s failed industry-wide for a decade — and builds six stages that don’t repeat the mistake.
Real Incidents at Every Stage
SolarWinds for threat modeling. Log4Shell for static analysis. Capital One for dynamic testing. Codecov for release gating. A 2026 zero-day for runtime defense. Every stage, one real, dated, sourced anchor.
Cattle, Not Pets
A genuine engineering discipline for release infrastructure — automated, reproducible, disposable by design — not a slide about “DevSecOps” with no practical follow-through.
Vendor-Neutral on AI Security Tooling
Where this course discusses AI-assisted security tools, it names direct competitors together, every time, and states plainly what current evidence does and doesn’t support.
Is This Program Right for You?
CSEP is built for practitioners who want the actual engineering practice behind “secure development lifecycle,” not another slide deck restating the acronym. It assumes you’ve completed CGSL and are ready to turn diagnosis into building practice.
You are responsible for how security actually gets built into a pipeline, not just documented as a policy.
You want a structured, six-stage model to evaluate and improve your organization’s existing pipeline against.
You are now ready for the required second half of the security foundation path.
Your organization needs a vendor-neutral, evidence-based framing before you commit to one.
GI-CSEP is the second of two required foundation courses standing between you and that specialization.
PROGRAM OUTCOME
What You'll Learn
Six lessons, one per pipeline stage, each producing a specific, testable outcome the next stage depends on.
Write real security requirements
Turn compliance obligations, risk context, and abuse cases into testable acceptance criteria a developer can actually build against.
Build and score a threat model
Apply STRIDE, DREAD, and PASTA to find what a team’s own imagination might otherwise miss — anchored to a real, category-defining incident.
Know what each testing category actually finds
Static analysis, dynamic testing, and the genuinely new AI-reasoning category — what each catches, what each misses, and how to combine them.
Gate releases and defend runtime
Cattle-not-pets release engineering, plus the WAF/RASP/CSPM/SIEM stack — and why runtime defense is never optional, no matter how good everything upstream is.
Who Is This For
Built for practitioners who are ready to move from diagnosis to building practice
CSEP assumes the structural literacy CGSL builds. If you’re comfortable with that foundation and ready for hands-on engineering practice across all six pipeline stages, this course is calibrated for you.
This course is perfect for
- Engineers and architects who own how security gets built into a real pipeline
- AppSec leads evaluating or redesigning their organization's existing security engineering practice
- Anyone who has completed CGSL and is continuing toward Level 2 or Level 3 certification
- Practitioners who want a vendor-neutral, evidence-based view of emerging AI security tooling
This course may not be for you if
- You haven't yet completed CGSL, which is a required prerequisite
- You're looking for governance and diagnostic content rather than hands-on engineering practice — that's CGSL
- You want deep, single-tool vendor training rather than a vendor-neutral pipeline model
- You're not currently working in or near a software engineering or AppSec function
- 6 pipeline stages.
- 5 real, dated incidents anchoring the practice.
- One honest chapter on why shift-left keeps failing — and what actually fixes it.
- The required second half of Gloria Institute’s Security Foundation Level.
6 lessons, one per stage of the pipeline, from the first requirement to the last runtime alert.
What You Will Study
Six core lessons with interactive scenarios and a graded knowledge check each, followed by certification exam eligibility once the course is complete.
Where requirements come from, OWASP ASVS and NIST SSDF, and a direct confrontation with why shift-left has failed industry-wide for a decade — before this course asks you to do it better.
STRIDE, DREAD, and PASTA, anchored to the 2020 SolarWinds compromise — a threat vector most pre-2020 threat models weren't built to name as a category.
SAST, SCA, secrets scanning, and IaC scanning — plus an honest look at the emerging AI-reasoning category, anchored to Log4Shell and the case for a current SBOM.
DAST, IAST, fuzzing, and penetration testing — what each finds that static analysis structurally cannot, anchored to the 2019 Capital One breach.
Container scanning, SBOM attestation, signing and provenance, and policy as code — all built on a cattle-not-pets discipline, anchored to the 2021 Codecov compromise.
WAF, RASP, CSPM, and SIEM, and the feedback loop back to Lesson 1 — anchored to a 2026 case demonstrating just how far the exploitation window has compressed.
Once you've completed all six lessons, you're eligible to sit the certification exam. Use the course companion guide and the comprehensive study guide, which is available for you to prepare.
OBJECTIVES
The Path To Becoming A Practitioner
Every lesson in CSEP builds toward practical, applicable engineering skill — not a slide-deck understanding of “secure SDLC,” but a working model you can apply to a real pipeline. By the end of this course, you’ll be able to build the pipeline, not just describe it.
Specify and gate real requirements
Write testable security acceptance criteria and know exactly which controls are non-negotiable before a system touches sensitive data.
Model threats a team might otherwise miss
Apply structured, systematic threat modeling to trust boundaries most teams don’t think to name — until an incident forces the issue.
Build a pipeline that resists both convenience and pressure
Gate every release with reproducible, automated controls, and defend runtime with a stack that never treats detection as optional.
OVERVIEW
About This Course
CSEP is the second of two mandatory foundation certifications in the GI Security certification path, and it picks up exactly where CGSL leaves off. Where CGSL built the diagnostic capacity to recognize structural security failure, CSEP teaches the engineering practice for building systems that resist it from the start — a six-stage pipeline running from security requirements through threat modeling, static and dynamic analysis, release gating, and runtime defense.
This course opens with something most security training won’t say out loud: shift left, the industry’s stated doctrine for a decade, has been implemented badly almost everywhere it’s been tried — developers handed more security responsibility with no reduction in feature load and no organizational support to make the added responsibility functional. CSEP names that failure directly before asking you to do six stages of practice better.
Every stage is anchored to a real, dated, independently verified incident, chosen deliberately across different organizations and different eras so no single company’s reputation carries the argument. Where this course discusses emerging AI-assisted security tooling, it names direct competitors together, every time, and states plainly what current evidence supports and what it doesn’t.
CGSL must be completed first. Together, both foundation courses are mandatory prerequisites for every Gloria Institute’s security Level 2 field specialization and Level 3 role specialization certification.
Everything you need to learn the pipeline, apply it, and prepare for certification.
What's Included
Enrollment includes the full interactive course and its companion reference guide. Certification itself — the exam voucher and optional study guide — is available separately once you’re ready.
- Six interactive online lessons covering all six pipeline stages
- Branching scenarios and graded knowledge checks in every lesson
- A free companion guide covering all six lessons, included with enrollment
- Five real, dated, sourced incident case studies anchoring the pipeline
- Official course study guide for certification exam prepration
- Certification exam eligibility
- Access to the Gloria Institute learner community and future certification path updates
Eligibility & Requirements
CSEP is the second of Gloria Institute’s two mandatory security foundation courses, and it assumes the diagnostic vocabulary CGSL builds. Hands-on engineering context strongly recommended.
CGSL is a required prerequisite
This course builds directly on CGSL’s structural literacy foundation and should be taken second, not first.
Engineering or AppSec experience recommended
Not required, but the course moves at a pace calibrated for someone already working in or near a software engineering pipeline.
Time commitment
Approximately 6–7 hours of core lesson content, plus additional time for exam preparation.
Required for further certification
CGSL and CSEP together are mandatory prerequisites for every Gloria Institute’s Level 2 and Level 3 security field specialization and role specialization credential.
The Credential That Opens Doors
When you complete a Gloria Institute program, you earn more than just a certificate—you gain recognition for practical, industry-relevant expertise that employers value.
Our certificates are thoughtfully designed to reflect the credibility and quality of our programs. Each credential specifies the specific competencies you’ve mastered, providing clear evidence of your professional development to current and prospective employers. Each Gloria Institute certificate includes:
- Program-specific competencies achieved
- Digital badge for certifications
- Completion date
- Unique verification number
- Support for certificate verification
Sample Certificate
Here’s an example of the certificate you’ll get when you finish a program at the Gloria Institute successfully:
Enrollment, Examination, and Policy FAQs
Yes. CGSL is a required prerequisite, since CSEP builds directly on the diagnostic vocabulary it establishes.
Yes. Course enrollment includes the 6 interactive lessons and the free companion guide. A certification exam voucher and a comprehensive student study guide are also part of this course.
Because teaching the same failed implementation with better vocabulary wouldn't actually help you. This course names the industry's decade-long failure pattern directly so the six stages that follow don't repeat it.
No. Where AI-assisted security tooling is discussed, this course names direct competitors together, every time, and states plainly what current evidence supports — deliberately avoiding favoring any single vendor.
The companion guide, included with enrollment, covers the same material as the course for quick review. The student course study guide is a thorough product built specifically for exam preparation — compressed review, practice questions, and a full mock exam.
The exam voucher comes with a free retake. A mandatory waiting period applies between attempts. Specific retake policy and pricing for additional retakes are detailed at the point of exam voucher purchase.
CSEP was developed by a team of security experts from the industry. The operation is headed by Haroon Mansoori, who brings more than 30 years of expertise in security engineering. Gloria Institute's certifying board is expanding over time; current governance details are maintained on our About page.
Turn what you diagnosed into what you build.
Enroll in CSEP, the required second foundation course, and complete the diagnostic-to-practice pipeline Gloria Institute’s entire security certification path is built on.
Haven’t taken CGSL yet? Start there first.
