Certified Security Champion Training

Comprehensive competency development in the field of secure software development

The requirements for secure software applications in companies are steadily increasing. Protecting data and safeguarding systems against external attacks is becoming ever more important—and complex. With our Security Champion Training, we show software developers how to consistently integrate security into their daily work. Only through targeted skill development among developers can the security of software applications be ensured for the future.

By completing the training, you qualify as a Security Champion and become an expert in secure software development. Step by step, we provide you with the necessary knowledge and skills, enabling you to advise your teams on security issues and point out potential gaps. You will also practice essential hard and soft skills, learning to successfully apply modern security methods and tools. The training content covers the entire software development process and is enriched with extensive practical sessions.

Your Benefits

  • You can comprehensively consider security in the development of your software products and involve your colleagues and product owners.
  • You gain an in-depth understanding of the principles of secure software engineering.
  • You can define security requirements for your company and independently conduct threat and risk analyses.
  • You learn to adopt the attacker’s perspective to identify potential security and safety weaknesses.
  • You know how to evaluate information from vulnerability databases and derive the necessary steps for your organization.
  • You can apply the principles of defensive coding and security by design.
  • You master the fundamentals of applied cryptography—independent of specific tools—and learn how to use them securely.
  • You know how to conduct manual and automated code reviews with a security focus.
  • You are able to check the security of your applications using a build pipeline.
  • You learn to effectively communicate your security expertise and resolve conflicts related to secure software development.

Content

Module 1: Introduction

  • Raising awareness for security through real-world examples
  • Definitions, boundaries, and trends
  • Relevant security laws and standards
  • Role and responsibilities of a Security Champion

Module 2: Defining requirements & analyzing risks

  • Definition of security requirements
  • Security in the agile software development lifecycle
  • Risk analysis: classification of risks and risk treatment

Module 3: Learning and applying methods

  • Secure design and defensive coding: principles, patterns, and guidelines
  • Applied cryptography: fundamentals, encryption, key management
  • Automated and manual code reviews
  • DevSecOps: explanations, challenges, and objectives

Module 4: Security champion in practice

  • Soft skills: communication theories, role play for training, knowledge transfer, conflict management
  • "Coffee to Know" – practical training for conveying security knowledge
  • Team-based homework to reflect and apply knowledge in real-world examples

Process

© Fraunhofer IEM

The training lasts for 13 weeks. Every 4 weeks, you'll go through the classroom module, homework, and online feedback phases three times. This allows you to combine theoretical content with practical elements and continuously deepen your knowledge. After completing this training, you can take an oral exam (30 min) and receive a certificate from the Fraunhofer Personnel Certification Body with your exam results. The certificate documents your knowledge and increases your chances of professional success.

Target Group

The training program is aimed at software developers.

Prerequisite: A degree or vocational qualification in computer science, business informatics, or a comparable field.

The training is designed not only for large corporations but also explicitly for small and medium-sized enterprises.

Certification & Examination

The Security Champion Training is certified according to ISO 17024.

After successfully completing the training, you can obtain the certificate »Security Champion (Software Security) – Basic Level« from the Fraunhofer Personnel Certification Authority.

The oral exam (approx. 30 min) covers the training content. By passing the exam and earning the certificate, you document your skills and sustainably enhance your career opportunities. More information.

Your Trainers

Academy Trainerin Samira Taaibi
© Fraunhofer IEM

Samira Taaibi

Samira Taaibi is an employee in the "Secure Services and Apps" department at Fraunhofer IEM. She is a Certified Scientific Trainer (Foundational Level) and an expert on the topics of maturity models and Security Champion. 

LinkedIn profile

Dr. Thorsten Koch

Dr. Thorsten Koch is a senior researcher in the “Secure IoT Systems” department at Fraunhofer IEM. As a Certified Scientific Trainer (Foundational Level), he has designed, adapted, and conducted numerous training courses for companies in recent years. He is also an ISA/IEC 62443 cybersecurity expert.

LinkedIn profile

Academy Trainer Thorsten Koch
© Fraunhofer IEM

Tailor-made training – on-site or online

Would you like to train a group of employees in your organisation? Together, we will tailor the training to your needs in order to significantly increase the learning effect. We offer you the opportunity to customise the content to your company's individual requirements. The training will take place at the location and on the date of your choice.

Contact us