Deep Dive: Secure Agentic Coding

This training course provides hands-on instruction on how to use modern AI coding tools, agent-based workflows, and automation to develop software efficiently and, above all, securely, in a controlled manner, and in compliance with regulations.
This training provides answers to the following questions
- How can I use AI coding tools professionally and guide them through effective prompting, context management, and clear instructions?
- How do I translate an idea into a structured, AI-supported development process—from requirements through architecture and implementation to review?
- How can I effectively integrate MCP servers, automation tools, and spec-driven development frameworks into my development workflow?
- How can I ensure consistently high code quality, security, data protection, and compliance?
Headline 3
Text 3
Description
This course provides exactly the foundation you’re missing: practical, technically sound, and directly applicable to your own project. Participants will learn how to translate business requirements into precise AI instructions, set up a complete development workflow (idea → PRD → architecture → code → review), and effectively integrate their own servers and tools using the Model Context Protocol (MCP). In addition, workflow automation with n8n and Prefect, as well as spec-driven development frameworks such as BMAD, GSD, and Spec Kit, are explained and tested using concrete examples. The course concludes with an in-depth look at security and compliance in the day-to-day work of AI-powered developers, including hands-on sessions on security scans, testing, and code review.
Participants will leave the course with a blueprint they have developed themselves for a modern, agent-based development process that combines speed, structure, and security from the very beginning.
Course content
During the course, participants will work together to develop a small sample project in which they will directly apply the methods and tools covered. The project will run throughout the entire course—from the initial idea through business requirements, the PRD, and architecture, all the way to implementation, testing, security checks, and code review.
Ideally, participants will bring a specific idea from their day-to-day work in advance—such as a small internal process, a recurring task, or a manageable problem that could be improved with a software solution. Together, the group will tailor the idea to a realistic scope that fits within the course duration. Alternatively, a generic sample project can be used, which will be adapted to the group’s prior knowledge, interests, and technical constraints.
As a result, the course not only produces a practical project outcome but also provides a transferable blueprint for a structured, secure, and AI-supported development process.
Basics & Getting Started
- LLM Fundamentals & the New Role of Developers (Tokens, Context Windows, Strengths/Limitations, Paradigm Shift)
Understanding the Risk Chain: Hallucinations, Prompt Injection - Setting Up and Getting Familiar with AI Coding Tools (Setup, Agent Mode, Instruction Files)
Basic Privacy Settings, Code Telemetry, Training Data Opt-Out - Context Management & Prompting + First Hands-On Exercises Using a Sample Project
- Hands-On — Translating Business Requirements into AI Instructions
Structured AI Development
- Custom Instructions & Workspace Configuration (Instruction Files, Hierarchies, Extensions)
Secure Coding in Instructions, Built-in Guidelines
- The Complete AI Development Workflow (Idea → PRD → Architecture → Code → Review)
Threat Modeling + Security Gates
- Hands-On — Spec-First Feature Development
- Hands-On — Second Feature & Iteration
Agentic Ecosystems
- MCP Deep Dive (Protocol Architecture, Primitives, Server Setup)
- Hands-On — Connecting the MCP Server to the Project
- Workflow Automation (n8n & Prefect) + Spec-Driven Development Frameworks (BMAD, GSD, Spec Kit)
Access Control + Secrets Management
- Hands-On — Integrating Frameworks and Workflows into the Project
Enterprise Integration & Capstone
- AI in Everyday Development + Security & Compliance Deep Dive
- Mechanics for working in a (more) token-efficient way
- Marketplaces for Sharing Skills
- Hands-On — Quality Assurance & Testing (Security Scan, Tests, Code Review)
- Capstone — Finalize Sample Project
- Create Presentations, a Retrospective, and a Team Playbook
This training is aimed at companies and organizations. It is individually tailored to your requirements and the team's prior knowledge and can be carried out in-house or online. This training can be economical from as few as three participants.
Target Group
- Software developers
- Architects
- Project managers
Duration & Format
- 2 to 5 days, individually tailored
- In-person or online training
Our trainers
Our promise: from practice, for practice & always up to date. That's why all our trainers are active experts with many years of experience in the subject area they teach.
Your Benefit
Our training courses not only impart knowledge, they also change mindsets. Your developers will learn to identify security vulnerabilities early on and avoid them in a targeted manner. The result: more robust applications, more confidence - and a clear advantage in everyday project work.
All trainers are actively working Security Consultants. They contribute their experience with everyday problems, which often conflict with security requirements, and thus contribute to a pragmatic, realistic approach to security.
- Practical methods instead of theory to avoid typical security gaps in web applications and mobile apps.
- Content according to the latest standards by actively working, experienced Security Consultants.
- Secure coding for long-term maintainability and quality of the source code.
- Increased security awareness in the team prevents pitfalls at an early stage.
- Protection against liability risks & damage to reputation.





