Security Engineering Roadmap
Nine levels from asset thinking and trust boundaries to application security, infrastructure, detection, architecture review and production agent security.
0 / 38 roadmap lessons mastered0%
- 1
Level 1 · Think in assets and boundaries
Security fundamentals, trust boundaries and practical threat modeling.
- 2
Level 2 · Establish and constrain identity
Authentication, password storage, sessions and authorization.
- 3
Level 3 · Defend application boundaries
Web, API and input interpretation failures.
- 4
Level 4 · Protect secrets and transport
Cryptographic primitives, TLS and secret lifecycle.
- 5
Level 5 · Limit infrastructure blast radius
Database, network, OS and container controls.
- 6
Level 6 · Secure cloud and delivery
IAM, workload identities, dependencies and CI/CD.
- 7
Level 7 · Detect and recover
Testing, detection, vulnerability management and incident response.
- 8
Level 8 · Review architectures
Apply threat modeling and attack simulation to complete systems.
- 9
Level 9 · Secure agentic production systems
Treat models and external context as untrusted while constraining tools.