Training developers in writing secure code is not easy. What do you think of the Security Knowledge Framework ?
https://www.securityknowledgeframework.org
SKF is a fully open-source Python-Flask web-application that uses the OWASP Application Security Verification Standard to train you and your team in writing secure code, by design.