Course Overview

The evolution of software architecture has made microservices a fundamental approach for building scalable and flexible applications. However, securing microservices brings unique challenges due to their distributed nature and multiple communication points. Learning how to protect microservices effectively is crucial for maintaining data integrity, ensuring seamless authentication, and defending against modern threats. This course, Building Microservice Security, is designed to give you the knowledge and practical strategies necessary to strengthen microservices across their entire lifecycle.

This course begins with an introduction to microservices, covering core concepts, types, and real-world applications, along with the benefits and challenges they pose. It then moves into the four critical aspects of microservice security, addressing common vulnerabilities and solutions, including securing REST communications, using API Gateways, and leveraging Service Mesh architectures. You'll also dive deep into authentication and authorization mechanisms like JWT, OAuth 2.0, and OpenID Connect. Further, the course explores securing the development process with practices like dependency analysis, Docker image scanning, and infrastructure as code security. Finally, it highlights the importance of monitoring, log consolidation, and distributed tracing for maintaining strong security post-deployment.

By the end of this course, you will confidently secure microservices at every stage—from design to runtime—while ensuring scalable, reliable, and secure system operations.

What You Will Learn

  • What is a microservice in practice, the main types of services and technologies involved in creating and running microservices?
  • Strategies to provide authentication and authorization to microservices
  • What tools and practices should be used in CI/CD pipelines to check for vulnerabilities in your code base, docker images, and libraries?
  • Types of tools that can be used to help detect, resist, react to, and recover from attacks. These types of tools include service mesh, API gateway, application monitoring, and log consolidation.
  • Good practices to configure security for microservices in a Kubernetes cluster.

Program Curriculum

  • Course Introduction and Basic Service-related Concepts
  • Defining Microservice, Microservices in Practice
  • Benefits and Challenges of Microservices
  • Main Types of Microservices
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 1 Quiz

  • Microservice Security Challenges and How to Address Them
  • Security of Data Communication for REST Services
  • Additional Mechanisms to Protect Data Communication
  • API Gateway
  • Service Mesh
  • Chapter 2 Quiz

  • Core Concepts Related to Authentication
  • Core Concepts Related to Authorization
  • The JWT Standard
  • OAuth 2.0
  • Open ID Connect
  • Authentication and Authorization for REST Services with JWT
  • Authentication and Authorization for Asynchronous Services
  • Chapter 3 Quiz

  • Security in the Software Lifecycle
  • Awareness of Application Security
  • Analyzing the Application Code
  • Dependency Analysis
  • Docker Image Scanning
  • Infrastructure as Code Security
  • Secrets Management
  • Chapter 4 Quiz

  • Security Tools in a Microservice Runtime Infrastructure
  • Monitoring
  • Log Consolidation
  • Error Tracking and Distributed Tracing
  • Chapter 5 Quiz

  • Course Takeaways
  • Thank You and Contact Information
Load more modules

Instructor

Paulo Merson

Paulo Merson has been programming in the small and programming in the large for over 30 years. He's a dev at the Brazilian Federal Court of Accounts, adjunct faculty in the Masters of Software Engineering program at Carnegie Mellon University, and faculty in the University of Brasilia master's program in Applied Computing. He often delivers professional training to fellow devs in the US and Europe. His speaking experience also includes talks at DDD Europe, OOP, XP Agile, JavaOne, SPLASH/OOPSLA, SATURN, and lectures to grad students in different universities. Paulo holds a BSc in CS from the University of Brasilia and a Master of Software Engineering from Carnegie Mellon University.

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Choose the Pro Plan That Fits Your Learning Journey

Invest in your future with flexible Pro subscription plans. Whether you're starting your cybersecurity journey or expanding your expertise, choose the membership duration that works for you and gain access to our complete learning platform.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Ideal for continuous learning, offering extensive resources with 900+ courses and diverse Learning Paths to enhance your skills.

$ 599.00
Billed annually or $69.00 billed monthly

What is included

  • Access to 900+ Premium Short Courses
  • 70+ Structured Learning Paths
  • Validation of Completion with All Courses and Learning Paths
  • New Courses Added Every Month
Early Access Offer

Pro +

Experience immersive learning with Practice Labs and CTF Challenges for comprehensive skill-building.

$ 699.00
Billed annually or $79.00 billed monthly

Everything in Pro and

  • 500+ Practice Labs with Guided Instructions
  • 400+ CTF Challenges with Detailed Walkthroughs
  • New Practice Labs and Challenges Added Every Month

Related Courses

1 of 50