Secure Software Development with AI (AI-SDLC)

This training course provides an introduction to the software development lifecycle using AI tools. It examines the use of AI tools from two different perspectives. First, it focuses on the safe use of AI tools that are becoming established in the development cycle. Additionally, it discusses AI tools specifically designed to improve software quality.
This training provides answers to the following questions
- What problems arise from the introduction of AI into the software development process?
- In the age of agentic coding, which vulnerabilities and error categories require special attention, and which ones can we increasingly ignore?
- What risks (security, data protection, copyright) do I introduce into my company if I use AI tools without proper oversight?
- Which AI tools can help me write better and more secure software?
- Where can I find help for self-help?
Headline 3
Text 3
Description
AI tools like GitHub Copilot, Cursor, and Claude have already fundamentally changed our day-to-day work as developers. Anyone who has simply gone with the flow may have already introduced new, uncontrolled risks into their own processes. To work productively and securely with these tools today as a software developer, DevOps engineer, or architect, you need more than just a basic understanding of LLMs: You must know the typical vulnerabilities associated with AI-generated code and the business risks that arise from uncontrolled use of these tools. At the same time, AI can be used strategically to actively improve code quality and security.
That’s exactly what this course offers: hands-on, technically sound, and immediately applicable—from Agentic coding to secure MCP integration to spec-driven development.
Participants will leave the course with a clear understanding of what a modern, AI-powered development process looks like—one that doesn't pit speed against security.
Course content
Course contents at a glance
The Transformation of Time: From SDLC to SSDLC, From SDLC to AI-SDLC
- LLM Fundamentals: Strengths, Limitations, Paradigm Shifts
- (Deteriorations?) Improvements to the Development Process: Understanding the Developer’s New Role
- From Autocomplete to Agent Mode: A Crash Course in Agentic Coding (Claude, Cursor, Copilot, Windsurf)
New Vulnerabilities in AI-Generated Code
- Which error classes are becoming more relevant in the age of agentic coding?
- Which classic vulnerabilities are becoming less of a concern?
- Real-World Examples: Avoiding and Identifying Common Security Vulnerabilities
Business Risks & Safe Use of Tools
- What about data protection, copyright, and compliance?
- Yolo-Security: Speed Becomes a Threat: Agentic Workflows and MCP Server
- Guidelines and Policies for Secure Tool Integration in the Enterprise
AI for Quality Assurance & Guidance
- The Real Potential of AI: Tools for Security Scans, Code Review, and Testing
- Spec-driven development: from idea to tested code
- Resources & Frameworks That Help in Everyday Work (OWASP, BMAD, GSD, Spec-First)
This training is aimed at companies and organizations. It is individually tailored to your requirements and the team's prior knowledge and can be carried out in-house or online. This training can be economical from as few as three participants.
Target Group
- Decision-makers
- Project managers
- Architects
- Software developers
- Security officers
Duration and format
- ½ day to one day, tailored to individual needs
- In-person or online training
Prerequisites
None
Our trainers
Our promise: from practice, for practice & always up to date. That's why all our trainers are active experts with many years of experience in the subject area they teach.
Your Benefit
Our training courses not only impart knowledge, they also change mindsets. Your developers will learn to identify security vulnerabilities early on and avoid them in a targeted manner. The result: more robust applications, more confidence - and a clear advantage in everyday project work.
All trainers are actively working Security Consultants. They contribute their experience with everyday problems, which often conflict with security requirements, and thus contribute to a pragmatic, realistic approach to security.
- Practical methods instead of theory to avoid typical security gaps in web applications and mobile apps.
- Content according to the latest standards by actively working, experienced Security Consultants.
- Secure coding for long-term maintainability and quality of the source code.
- Increased security awareness in the team prevents pitfalls at an early stage.
- Protection against liability risks & damage to reputation.





