Security Engineering · 300-level
Security Engineering
A staff-level tour of how systems get broken and how they get defended — threat modeling, the OWASP vulnerability classes, identity, applied cryptography, cloud and supply-chain security, detection and response, and a secure SDLC that turns controls into tests.
SEC-3013 creditselectiveno prerequisites
What's inside
Sections & lessons
01
Threat modeling
- Mapping trust boundaries with data-flow diagramsconcept35 min
- Enumerating threats with STRIDE, element by elementconcept35 min
- Attack trees and ranking risk by expected lossconcept40 min
- Threat-modeling a payment webhook end to enddemo45 min
02
Application security & OWASP
- Injection: why parameterized queries end the classconcept40 min
- XSS, contextual output encoding, and CSP as defense in depthconcept35 min
- SSRF: from a URL field to cloud credentialsconcept40 min
- Insecure deserialization and reading the OWASP Top 10 as a backlogconcept35 min
03
Authentication, authorization & identity
- Sessions vs. tokens: storage, revocation, and blast radiusconcept40 min
- OAuth2 and OIDC flows you will actually deployconcept40 min
- Authorization: RBAC, ABAC, and killing IDORconcept40 min
- Phishing-resistant MFA and the bypasses that beat OTPconcept35 min
04
Cryptography in practice
- Password storage: Argon2id, bcrypt, and cracking economicsconcept40 min
- Symmetric, asymmetric, and why you want AEADconcept35 min
- TLS 1.3, certificate validation, and the trust chainconcept40 min
- Key management, envelope encryption, and what NOT to roll yourselfconcept35 min
05
Cloud & infrastructure security
- IAM least privilege and shrinking blast radiusconcept40 min
- Network segmentation, security groups, and default-denyconcept35 min
- The instance metadata service: identity, IMDSv2, and container pitfallsdemo40 min
- Lab: auditing an over-permissioned roledemo40 min
06
Secrets & supply-chain security
- Secret management, rotation, and what leaks in gitconcept40 min
- Dependency risk, typosquatting, and the SBOMconcept40 min
- Securing CI/CD: the pipeline is productionconcept35 min
- Signing, provenance, and SLSAconcept35 min
07
Detection & response
- Logging for security and detection engineeringconcept40 min
- SIEM, detections-as-code, and beating alert fatigueconcept40 min
- The incident-response lifecycle and forensic basicsdemo35 min
08
Secure SDLC & compliance
- Shift-left: SAST, DAST, IAST, and where each liesconcept40 min
- Threat-driven testing and security in code reviewconcept35 min
- SOC 2, ISO 27001, and turning controls into testsreflection35 min
This module ends in a gate you can fail.
That's what makes passing it mean something. Take the DSAT, get placed, and start earning.