Practical DevSecOps is the training partner behind 10 hands-on certifications - CDP, CDE, CCSE, CCNSE, CAISP, CMCPSE, CTMP, CASP, CSSE and CSC - used by 12,500+ security professionals and teams at IBM, Accenture, PwC, Booz Allen Hamilton, Standard Chartered and PayPal. Our courses are browser-based labs, not slideware, and our exams are 6 hour hands-on challenges with written reports.
We are hiring a Course Creator to design and build that content. This is a builder's role: you will own courses end to end - curriculum, labs, lab infrastructure, video lessons, exam challenges and grading rubrics - for topics at the front edge of DevSecOps, AI security and cloud-native security.
If you have ever finished a security course and thought "I could have taught this better, and with real labs," this is that job.
Build courses
-
Own new and existing courses end to end: learning outcomes, module structure, lesson scripting, hands-on labs and assessments.
-
Design lab exercises that force learners to do the work - build the pipeline, break the model, harden the cluster - not watch someone else do it.
-
Record and script video lessons, write technical guides, checklists and reference material.
-
Design exam challenges and the grading rubrics that go with them, and support exam evaluation.
Research and stay ahead
-
Research emerging technologies and turn them into teachable lab scenarios - AI/LLM security, MCP servers and agentic AI, supply chain security, Kubernetes, zero trust.
-
Attack and defend AI models, inference endpoints and MCP servers; translate those findings into lessons.
-
Keep the existing catalogue current as tools, CVEs and frameworks move (OWASP LLM Top 10, MITRE ATLAS, SLSA, CIS benchmarks, ASVS).
Build the platform around the content
-
Build and maintain the lab infrastructure so learners can focus on the skill, not the setup.
-
Build internal tooling that shortens the time from idea to shipped lesson.
-
Look for ways to scale and streamline how content gets produced and reviewed.
Support learners
-
Be a visible, responsive presence in support forums and the Mattermost community.
-
Turn recurring learner questions into better content.
Must have
-
5+ years in application security, product security or DevSecOps roles.
-
Strong hands-on depth in at least two of: CI/CD security (SCA, SAST, DAST, secrets), container and Kubernetes security, IaC/CaC (Terraform, Ansible, Inspec), AI/LLM security, API security, threat modeling, software supply chain security.
-
Working fluency with Docker, Git, and at least one CI system (GitLab CI, Jenkins, GitHub Actions, CircleCI).
-
Scripting and automation in Python, Bash or Go - enough to build labs, not just run tools.
-
Genuinely good technical writing. You can explain a hard concept to a mid-level engineer in plain English and make them want to try it.
Ability to work independently in a distributed team with minimal supervision.
-
Nice to have
-
Prior experience creating training content, courseware, workshops or conference trainings.
-
A public body of work: blog, CTF challenges, open-source tooling, conference talks (Black Hat, OWASP AppSec, BSides, DevSecCon), CVEs.
-
Experience with LLM tooling and frameworks (LangChain/LangGraph, vector stores, agent frameworks) from a security perspective.
-
Video production or screencast experience.
What we are not looking for
-
Someone who has only run scanners and triaged tickets.
-
Someone who needs a full spec before starting.
-
Apple/Mac stack (MBP, Keynote).
-
Highly competitive compensation.
-
Flexible work schedule; hybrid from our Hyderabad office, or fully remote for the right person.
-
Free access to every Practical DevSecOps certification, plus a budget for conferences and training.
-
Time explicitly allocated for research - staying current is the job, not something you do after hours.
-
Your work is seen and used by thousands of security professionals worldwide.