DevSecOps EngineerAvailable

Threat Modelling for Engineers

About this course

Threat modelling is not a security team exercise. This course teaches engineers to identify threats in their own systems using STRIDE and PASTA, build data flow diagrams for microservices, and automate threat model updates in CI.

What you will learn

  • Why engineers should own threat modelling
  • STRIDE methodology with worked API examples
  • Data flow diagrams for microservices architectures
  • PASTA: a risk-centric alternative to STRIDE
  • Threat modelling a real API endpoint end to end
  • Common threat patterns in cloud-native systems
  • Automating threat model updates in pull requests
  • Communicating risk to non-technical stakeholders

Your instructor

Ayodele Ajayi

Principal Engineer

Principal Engineer based in Kent, UK, with extensive experience across cloud-native security, platform engineering, and distributed systems. Ayodele has led engineering teams at scale and writes about what he learns — with a bias towards things that actually work in production.

Continue building your skills in this area.

Zero Trust Architecture from Scratch

8 lessons

CI/CD Security Hardening

8 lessons