Cybersecurity Engineer
From OWASP Top 10 and network security to threat modeling, cryptography, and DevSecOps.
1. Beginner
Network fundamentals and security mindset.
Network Security & Wireshark
Packet analysis, OSI model, ports, ARP spoofing, TCP handshake tampering.
2. Foundation
Applied cryptography and public key infrastructure.
Applied Cryptography
Symmetric (AES-GCM), asymmetric (RSA, ECC), hashing (SHA-256), HMAC, TLS 1.3.
3. Core Skills
Application security and OWASP Top 10 vulnerabilities.
OWASP Top 10 & Web Exploits
SQL Injection, SSRF, IDOR, Broken Authentication, Cross-Site Scripting (XSS).
4. Framework
Cloud security and IAM least privilege.
Cloud Security & IAM Hardening
AWS IAM policies, least privilege principle, metadata service (IMDSv2), container escape prevention.
5. Real Projects
Build an automated vulnerability scanner.
Automated API Security Scanner
Fuzzing endpoints, detecting unauthenticated routes, checking CORS and CSP headers.
6. Advanced
DevSecOps and Threat Modeling.
Threat Modeling (STRIDE) & SAST/DAST
STRIDE framework, supply chain security, SBOM, Semgrep rules in CI.
7. Interview Prep
Breach scenario mitigation and architectural security review.
Security Architecture Defense
Defending against DDoS attacks, compromised credentials, and zero-day patch rollouts.