Course outline
Build your course
Choose the topics that fit your team’s stack, risks, and CRA work.
Details
Trainers

Nariman Aga-Tagiyev
Software Security Architect
Nariman Aga-Tagiyev is an Application Security Architect with more than 20 years of experience in software development. He has worked as a full-stack web application developer, backend developer, DevOps engineer, and cloud developer. Since 2016, he has been fully focused on application security-related activities.

Eden Yardeni
Application Security Architect
Eden Yardeni has built application security programs across several large enterprises. A software engineer by background, she joined the OWASP ASVS working group in 2024 and specializes in Security Champions programs, threat modeling, and secure software development lifecycles (SSDLCs).
Details
FAQ
Your Title Goes Here
Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.
What does .NET Secure Coding training cover?
We built our curriculum around ASVS, OWASP’s secure coding standard.
The core course covers the secure coding foundation we expect every .NET developer to know. It follows the parts of application security developers touch in daily work, from how data enters the application and how access is checked to how sensitive data is handled, how authentication is configured, and how the .NET platform can reduce common security mistakes.
The standard course is built around modern .NET, currently .NET 10, with ASP.NET Core examples. You can add modules for your stack and priorities, including MVC, Blazor, Entity Framework, legacy .NET Framework applications, cloud-native services, CI/CD security checks, and secure coding for AI-enabled features.
Who is this training for?
The course is designed for .NET developers, backend engineers, full-stack developers, tech leads, security champions, QA engineers, and architects. Participants do not need to be security specialists, but they should be comfortable reading and discussing C# and .NET application code.
Is this training hands-on?
Yes. Participants work through .NET exercises where they identify insecure patterns, explain the risk, and implement safer alternatives. The exercises connect OWASP ASVS requirements to the kind of code developers write, review, and maintain in their normal work.
Can the training be customized for our team?
Yes. You can tailor the training to your architecture, frameworks, product domain, and recurring security issues. Where useful, we can work with sanitized examples from your own codebase so the exercises reflect code patterns your developers recognize.
Next Steps
