Postgraduate Diploma · UK Academic Format

PG Diploma in DevSecOps
and Cyber Security

12 months full-time · 24 months part-time · 120 credits
Six 20-credit modules taught 60% hands-on, ending in a specialisation capstone.

Security built into the pipeline, not bolted on after it.

120Credits
6Modules
60%Practical
4Specialisation tracks
04 — Modules

Six modules, 120 credits

Each module runs 10 weeks at 20 credits, split into two five-week blocks — 40% teaching, 60% practical.

Module 01 · 20 credits

Information Security Management & DevOps Foundations

Coursework (60%) + Practical Portfolio (40%)
Teaching (40%)
Security frameworks: ISO 27001, NIST, CIS Controls
Risk assessment methodologies and business impact analysis
Compliance requirements: GDPR, SOX, PCI-DSS
Security governance and organisational structures
Practical (60%)
Deploy Prisma Cloud for multi-cloud security posture management
Implement Open Policy Agent (OPA) for policy as code
Build risk assessment dashboards with Grafana and Prometheus
Create compliance automation with Chef InSpec and Terraform
08 — Certifications

Aligned to the certifications employers screen on

Core security
CISSPCertified Information Systems Security Professional
CISMCertified Information Security Manager
CEHCertified Ethical Hacker
GSECGIAC Security Essentials
Technical specialisations
CKSCertified Kubernetes Security Specialist
GCIHGIAC Certified Incident Handler
GPENGIAC Penetration Tester
GCFAGIAC Certified Forensic Analyst
Platform certifications (optional)
AWS Certified Security – Specialty
Azure Security Engineer Associate
Google Cloud Professional Cloud Security Engineer

The programme prepares candidates for these certifications; examination, fees and any experience requirements are set by the awarding bodies and sit outside the diploma. CISSP in particular requires five years of documented professional experience for full certification.

11 — Questions

Frequently asked

Security that arrives after the build has already lost.

This programme trains engineers to put controls where they belong — inside the pipeline, inside the architecture, inside the way software gets made — and assesses them on whether the controls actually work.