DevSecOps stands for development, security, and operations. It describes a way of building software where security is part of every stage of the delivery pipeline, instead of a review that happens just before release.
The term grew out of DevOps, which brought development and operations teams together to ship software faster through automation and shared ownership. As release cycles shortened from months to days, end-of-cycle security reviews became a bottleneck and a source of late surprises. Adding “Sec” in the middle reflects the idea that security belongs inside the process alongside the other two disciplines.
You will often hear DevSecOps described as “shifting left,” meaning security testing moves earlier in the timeline, closer to when code is written. Fixing a flaw in a pull request is far cheaper than fixing it in production, and developers have the most context about the code at that moment.
