DevSecOps EngineerAvailable
Threat Modelling for Engineers
About this course
Threat modelling is not a security team exercise. This course teaches engineers to identify threats in their own systems using STRIDE and PASTA, build data flow diagrams for microservices, and automate threat model updates in CI.
What you will learn
- Why engineers should own threat modelling
- STRIDE methodology with worked API examples
- Data flow diagrams for microservices architectures
- PASTA: a risk-centric alternative to STRIDE
- Threat modelling a real API endpoint end to end
- Common threat patterns in cloud-native systems
- Automating threat model updates in pull requests
- Communicating risk to non-technical stakeholders
Your instructor
Ayodele Ajayi
Principal Engineer
Principal Engineer based in Kent, UK, with extensive experience across cloud-native security, platform engineering, and distributed systems. Ayodele has led engineering teams at scale and writes about what he learns — with a bias towards things that actually work in production.