Security Engineering · 300-level

Security Engineering

A staff-level tour of how systems get broken and how they get defended — threat modeling, the OWASP vulnerability classes, identity, applied cryptography, cloud and supply-chain security, detection and response, and a secure SDLC that turns controls into tests.

SEC-3013 creditselectiveno prerequisites
What's inside

Sections & lessons

01

Threat modeling

  • Mapping trust boundaries with data-flow diagramsconcept35 min
  • Enumerating threats with STRIDE, element by elementconcept35 min
  • Attack trees and ranking risk by expected lossconcept40 min
  • Threat-modeling a payment webhook end to enddemo45 min
02

Application security & OWASP

  • Injection: why parameterized queries end the classconcept40 min
  • XSS, contextual output encoding, and CSP as defense in depthconcept35 min
  • SSRF: from a URL field to cloud credentialsconcept40 min
  • Insecure deserialization and reading the OWASP Top 10 as a backlogconcept35 min
03

Authentication, authorization & identity

  • Sessions vs. tokens: storage, revocation, and blast radiusconcept40 min
  • OAuth2 and OIDC flows you will actually deployconcept40 min
  • Authorization: RBAC, ABAC, and killing IDORconcept40 min
  • Phishing-resistant MFA and the bypasses that beat OTPconcept35 min
04

Cryptography in practice

  • Password storage: Argon2id, bcrypt, and cracking economicsconcept40 min
  • Symmetric, asymmetric, and why you want AEADconcept35 min
  • TLS 1.3, certificate validation, and the trust chainconcept40 min
  • Key management, envelope encryption, and what NOT to roll yourselfconcept35 min
05

Cloud & infrastructure security

  • IAM least privilege and shrinking blast radiusconcept40 min
  • Network segmentation, security groups, and default-denyconcept35 min
  • The instance metadata service: identity, IMDSv2, and container pitfallsdemo40 min
  • Lab: auditing an over-permissioned roledemo40 min
06

Secrets & supply-chain security

  • Secret management, rotation, and what leaks in gitconcept40 min
  • Dependency risk, typosquatting, and the SBOMconcept40 min
  • Securing CI/CD: the pipeline is productionconcept35 min
  • Signing, provenance, and SLSAconcept35 min
07

Detection & response

  • Logging for security and detection engineeringconcept40 min
  • SIEM, detections-as-code, and beating alert fatigueconcept40 min
  • The incident-response lifecycle and forensic basicsdemo35 min
08

Secure SDLC & compliance

  • Shift-left: SAST, DAST, IAST, and where each liesconcept40 min
  • Threat-driven testing and security in code reviewconcept35 min
  • SOC 2, ISO 27001, and turning controls into testsreflection35 min

This module ends in a gate you can fail.

That's what makes passing it mean something. Take the DSAT, get placed, and start earning.