Security Engineering Roadmap

Nine levels from asset thinking and trust boundaries to application security, infrastructure, detection, architecture review and production agent security.

0 / 38 roadmap lessons mastered0%
  1. 1

    Level 1 · Think in assets and boundaries

    Security fundamentals, trust boundaries and practical threat modeling.

    What Security Engineering Actually Is
    Trust Boundaries
    Threat Modeling: The Process
  2. 2

    Level 2 · Establish and constrain identity

    Authentication, password storage, sessions and authorization.

    Authentication vs Authorization
    Password Storage
    Sessions
    Authorization Models
    Broken Access Control (IDOR / BOLA)
  3. 3

    Level 3 · Defend application boundaries

    Web, API and input interpretation failures.

    Web Security: Browser to Database
    Cross-Site Scripting (XSS)
    Cross-Site Request Forgery (CSRF)
    SQL Injection and Parameterization
    API Security as a Boundary
    Parse, Validate, Authorize, Process
  4. 4

    Level 4 · Protect secrets and transport

    Cryptographic primitives, TLS and secret lifecycle.

    Cryptography Fundamentals
    TLS as a Security Boundary
    Secrets Management
    The Secret Lifecycle
  5. 5

    Level 5 · Limit infrastructure blast radius

    Database, network, OS and container controls.

    Database Security Properties
    Network Segmentation
    Privilege Separation
    Container Security and Its Limits
  6. 6

    Level 6 · Secure cloud and delivery

    IAM, workload identities, dependencies and CI/CD.

    Identity and Access Management (IAM)
    Short-Lived Credentials
    Software Supply Chain Security
    CI/CD Security
  7. 7

    Level 7 · Detect and recover

    Testing, detection, vulnerability management and incident response.

    Security Testing Portfolio
    Detection Engineering
    Vulnerability Management by Exposure
    Incident Response Lifecycle
  8. 8

    Level 8 · Review architectures

    Apply threat modeling and attack simulation to complete systems.

    Security Review Mode: Any Architecture, Ten Questions
    Defense in Depth
    Secure Software Design Principles
  9. 9

    Level 9 · Secure agentic production systems

    Treat models and external context as untrusted while constraining tools.

    AI and Agent Security
    Direct and Indirect Prompt Injection
    The Model Is Not the Authorization Layer
    Agent Sandboxing