Security & Defense

Cybersecurity Engineer

From OWASP Top 10 and network security to threat modeling, cryptography, and DevSecOps.

Progression:0%
0 / 7 Milestones Mastered
L1

1. Beginner

Network fundamentals and security mindset.

Network Security & Wireshark

essential

Packet analysis, OSI model, ports, ARP spoofing, TCP handshake tampering.

Wireshark captureTCP flagsDNS spoofingFirewall rules
L2

2. Foundation

Applied cryptography and public key infrastructure.

Applied Cryptography

essential

Symmetric (AES-GCM), asymmetric (RSA, ECC), hashing (SHA-256), HMAC, TLS 1.3.

Diffie-Hellman key exchangeDigital signaturesCertificate authoritiesSalt & Pepper
L3

3. Core Skills

Application security and OWASP Top 10 vulnerabilities.

OWASP Top 10 & Web Exploits

essential

SQL Injection, SSRF, IDOR, Broken Authentication, Cross-Site Scripting (XSS).

SSRF bypassesIDOR testingDOM XSS vs Stored XSSBurp Suite proxy
L4

4. Framework

Cloud security and IAM least privilege.

Cloud Security & IAM Hardening

essential

AWS IAM policies, least privilege principle, metadata service (IMDSv2), container escape prevention.

IAM privilege escalationS3 bucket misconfigsKubernetes RBACIMDSv2
L5

5. Real Projects

Build an automated vulnerability scanner.

Automated API Security Scanner

essential

Fuzzing endpoints, detecting unauthenticated routes, checking CORS and CSP headers.

API fuzzingSecurity header verificationJSON Web Token tampering
L6

6. Advanced

DevSecOps and Threat Modeling.

Threat Modeling (STRIDE) & SAST/DAST

essential

STRIDE framework, supply chain security, SBOM, Semgrep rules in CI.

STRIDE analysisSBOM generationSemgrep custom rulesZero Trust architecture
L7

7. Interview Prep

Breach scenario mitigation and architectural security review.

Security Architecture Defense

essential

Defending against DDoS attacks, compromised credentials, and zero-day patch rollouts.

DDoS mitigationCredential stuffing defensesIncident containment

Hands-on Portfolio Projects for this Roadmap

Custom Automated Security Header & CORS Auditor
Enterprise Threat Model Document for Payment Gateway
Vulnerable-by-Design Banking App with Exploits and Fixes