Skip to content
Flag of Europe
Made in the European Union · Independently built · Released under EUPL 1.2

Secure Coding in Java

A code-first training that turns the OWASP risk catalogue into concrete Java practice. Developers leave able to spot, fix and prevent the vulnerability classes that actually hit JVM applications.

Hands-on labs 1–2 days On-site · live-online EN / DE Solid Java required

What your team can do after

Concrete, transferable skills — not a slideware tour.

Agenda

Six modules, each ending in a hands-on lab on deliberately vulnerable code — find it, exploit it, fix it.

  1. Input & output Validation, encoding, the injection family (SQL, command, path, template).
    Lab: exploit & fix an injectable endpoint.
  2. Authn & authz Sessions, tokens, broken access control — and how jSentinel models it.
    Lab: break and repair an access-control check.
  3. Crypto & secrets Password hashing (Argon2id/PBKDF2), key & secret handling.
    Lab: fix a weak hashing + secret-in-code setup.
  4. Deserialization & parsing Unsafe deserialization, XXE, SSRF.
    Lab: trigger and close an XXE/SSRF hole.
  5. Dependencies & supply chain SBOMs, known-vuln scanning, reproducible builds.
    Lab: read an SBOM, triage a CVE.
  6. Designing for security Threat modeling, secure defaults, defense in depth.
    Lab: threat-model a sample feature.

Who it's for

Java developers, tech leads and reviewers building web, REST or backend systems — anyone who ships JVM code and owns what happens when it's attacked.

Prerequisite: solid everyday Java; no security background required.

Logistics

📋 Course details

Formats
On-site · live-online · on-demand (in preparation)
Duration
Typically 1–2 days — depth and agenda tailored to your team
Languages
English or German
Group size
Private team cohorts or individual seats on scheduled dates
Trainer
Sven Ruppert, author of jSentinel — long-time Java developer and speaker
How to book: request the course with team size, format and dates — we tailor the agenda and send a proposal, then deliver; your team keeps the lab materials and a Q&A window. Explore the companion AI-Security for Developers.