Currently at around 60%.
Terminologies could have better defined.
At the very least, DevSecOps itself seems undefined. Terms like appsec engineers, development engineers, application engineers, etc sprinkled here and there without in author's opinion how they function differently from each other.
Sections/chapters could be made shorter/removed.
The whole chapter of education is about different ways to learn cybersecurity, online, offline, in person, in a class, etc. Some sections are summaries of previous works, e.g. STRIDE for threat modelling, clean code from, well, the Clean Code.
Some unsubstantiated claims. For one, in chapter 5, it says, paraphrased, having a CI/CD pipeline makes separation of duties more challenging. Why is separation of duties needed in this context in the first place remains unanswered. The whole DevOps movement is meant to break organization silo, to "shift left", to be agile. It isn't immediately obviously to me why all of a sudden we want separation of duties here.
Might update my review later.