This book is ideal for students, professionals and security, DevOps, and technical operations teams who want to implement DevSecOps in corporate, cloud, multi-cloud, and hybrid environments. The content covers security integration and automation in CI/CD pipelines, environment configuration, credential management, policy enforcement, continuous monitoring, and incident response. Learn how to structure workflows with leading tools, run SAST, DAST, SCA, IaC, and container scans, customize rules, automate remediation workflows, generate evidence for audits, and ensure compliance with international frameworks such as NIST, ISO, PCI DSS, LGPD, and GDPR.
Includes:
• Professional structuring of multi-cloud DevSecOps pipelines
• Integration of Jenkins, GitLab CI, Azure DevOps, GitHub Actions
• Scanning with SonarQube, Trivy, Snyk, Bandit, Kics, ZAP, Burp Suite
• Secrets management with Vault, AWS Secrets Manager, Key Vault
• Audit automation, remediation, and technical reporting
• Access policies, RBAC, hardening, environment segmentation
• Integration with SIEM, SOAR, ITSM, and GRC platforms
• Report and evidence export for compliance
Master DevSecOps to protect operations, accelerate delivery, mitigate risks, and achieve corporate digital security certifications.
devsecops, ci/cd, security automation, pipelines, compliance, continuous integration, containers, kubernetes, cloud security, auditing
Diego Rodrigues
Technical Author and Independent Researcher
ORCID: https://orcid.org/0009-0006-
StudioD21 Smart Tech Content & Intell Systems
Email:studiod21portoalegre@
LinkedIn: linkedin.com/in/diegoexpertai
International technical author (tech writer) focused on the structured production of applied knowledge. He is the founder of StudioD21 Smart Tech Content & Intell Systems, where he leads the creation of intelligent frameworks and the publication of didactic technical books supported by artificial intelligence, such as the Kali Linux Extreme series, SMARTBOOKS D21, among others.
Holder of 42 international certifications issued by institutions such as IBM, Google, Microsoft, AWS, Cisco, META, Ec-Council, Palo Alto, and Boston University, he works in the fields of Artificial Intelligence, Machine Learning, Data Science, Big Data, Blockchain, Connectivity Technologies, Ethical Hacking, and Threat Intelligence.
Since 2003, he has developed more than 200 technical projects for brands in Brazil, the USA, and Mexico. In 2024, he established himself as one of the leading technical book authors of the new generation, with over 180 titles published in six languages. His work is based on his proprietary TECHWRITE 2.3 applied technical writing protocol, focused on scalability, conceptual precision, and practical applicability in professional environments.