Skip to content

FieldsCybersecuritySecurity Engineer

Security Engineer

Build the defenses that keep systems and data safe.

Career

Structure
8 modules, each ending in a milestone
Proof
Verified against real tasks from module 2
Ends in
A defended capstone and a high-assurance credential

Get early access

The journey

  1. Practised under observation

    1. Security foundations and the adversary lensThe shared ground of the whole field: systems, networks and cryptography understood well enough to defend, and the attacker's perspective learned deliberately.Practised under observation
      MilestoneThinks like both sides

      An attack path through a real environment is drawn step by step, the control that breaks each step is named, and the line between authorised work and a crime is stated before any technique is used.

  2. From here, milestones are verified rather than practised.

    Verified against a real task

    1. Threat modeling and risk-driven defenseDeciding what to defend before deciding how, with threat modeling as an engineering practice and risk as the allocator of finite effort.Verified against a real task
      MilestoneModels the threat, allocates the effort

      Effort goes where the organisation's real losses are rather than where the work is easy, and a control you chose not to build is named alongside the risk somebody accepted.

    2. Identity, access and authentication engineeringThe modern perimeter: identity systems built and operated, access decided by policy, and privilege kept minimal in practice rather than in principle.Verified against a real task
      MilestoneIdentity engineered, privilege minimized

      Every grant of access is justified by a task and bounded in time, and your own design is read for the escalation route before anyone else reads it for one.

    3. Application and data security engineeringSecuring what the organisation actually builds, with code read adversarially, application defences implemented, and data protected across its lifecycle.Verified against a real task
      MilestoneBuilt to resist, data protected

      Data never becomes instruction, every defence is proven by trying to defeat it rather than by asserting it holds, and a key or a certificate changes hands without an outage.

    4. Infrastructure, network and cloud security engineeringHardening what everything runs on, with hosts, networks and cloud estates defended and the neighbouring fields' territory honoured rather than duplicated.Verified against a real task
      MilestoneHardened, segmented, contained

      A design says what an attacker already inside can reach and how they would be seen, and the component that cannot be patched is carried with controls that compensate for it.

    5. Detection engineering and incident readinessBuilding the capability to see and respond: detections engineered against real techniques, logging that answers questions, and the response capability the analyst seat will operate.Verified against a real task
      MilestoneDetection that fires on the real thing

      The people who receive an alert can act on it, the detections behind it are written against named techniques rather than counted, and what this environment cannot see at all is written down.

    6. Verifying the defenses and the security programProving the controls hold, with validation by adversarial testing and the program structures that make security a practice rather than a series of projects.Verified against a real task
      MilestoneVerified, and running as a program

      Whether a control is deployed and whether it works are two different findings, and a framework control that reduces no real threat is named as such.

    7. The Security Engineer in the organizationThe seat's real difficulty: being the person who says a system is not safe enough, without becoming the reason nothing ships.Verified against a real task
      MilestoneTrusted, effective, still shipping

      The deployment that must not ship is stopped on evidence, and the ones that are merely imperfect are allowed to go.

    1. Capstone

      Defenses that hold, proven

      A complete security engineering engagement for a realistic organisation, proposed by you and approved by an instructor, worked under observation on authorised targets throughout, from a threat model and a risk register through identity, application, infrastructure and detection engineering to the validation and organisational layers of the seat.

      Defence

      You walk an instructor through your own defences: what this organisation cannot afford to lose and where it sits, which of your controls you have tested by attacking them, what you deliberately did not fix and who accepted that risk, and which control is present but not working. The credential is not awarded if you cannot account for your own work.

    2. Credential

      High-assurance credential

      Evidence that you can build controls that hold when attacked and prove they hold with evidence. It does not claim seniority, and it does not oblige any employer to accept it.

      See how proof works

What is not live yet

The desktop app, consent-based observation, scoring, and credentials are in development. Nothing here implies they are live yet.

Get early access