Cybersecurity
Engineering.
Learn how to identify security weaknesses, understand common attack paths, strengthen systems, analyse network activity and respond to incidents through authorised labs and controlled training environments.
Duration
7 weeks
Learning format
Physical or remote
Practical environment
Authorised security labs
Course outcome
Security assessment and remediation report
Understand attacks to build
stronger defences.
The programme combines defensive engineering, vulnerability assessment and controlled security testing. Learners practise only against systems they are expressly authorised to assess.
Find and explain security risk
Learn how to identify exposed services, weak configurations, application vulnerabilities and control gaps, then communicate the technical and business impact clearly.
Move from findings to remediation
A useful assessment does more than list vulnerabilities. You will learn to prioritise findings, recommend practical fixes and verify whether corrective actions reduce the identified risk.
Core cybersecurity
disciplines.
The course connects technical testing with secure configuration, monitoring, incident response and professional reporting.
Network security
Services, ports, segmentation, traffic analysis, firewalls and network exposure.
Web security
Authentication, sessions, access control, input handling and common web-application weaknesses.
Cloud security
Identity, storage exposure, secrets, logging, permissions and infrastructure configuration.
Vulnerability assessment
Discovery, validation, evidence collection, severity and remediation prioritisation.
Controlled testing
Authorised testing methodology, scope, rules of engagement and safe laboratory practice.
Incident analysis
Logs, timelines, evidence preservation, containment and recovery decisions.
Security reporting
Reproducible evidence, clear findings, severity, impact and remediation guidance.
Security governance
Policies, risk ownership, controls, standards and assurance concepts.
What you will
produce.
The capstone is an authorised assessment of a deliberately vulnerable training application or lab environment—not an unapproved public system.
Assessment plan
Define scope, objectives, permitted techniques, exclusions, evidence handling and testing boundaries.
Attack-surface review
Identify exposed services, application functions, trust boundaries and likely areas of security risk.
Validated findings
Document reproducible security weaknesses with evidence gathered safely inside the authorised environment.
Risk prioritisation
Consider exploitability, impact, exposure and business context when assigning finding severity.
Remediation plan
Recommend specific configuration, code, access and monitoring improvements.
Professional report
Present an executive summary, technical findings, evidence, priorities and remediation roadmap.
Security testing requires
clear authorisation.
Every practical exercise is limited to Pintop-provided labs, intentionally vulnerable applications or another environment for which written permission has been confirmed.
Permitted practice
Learners may scan, inspect and test only the systems, accounts, addresses and techniques included in the authorised exercise. The scope and limits provided by the instructor must be followed.
Not permitted
Course knowledge must not be used to access, scan, disrupt, exploit or collect information from another person’s system without clear legal authority and permission.
Seven-week
curriculum.
The curriculum progresses from foundational risk concepts to authorised technical assessment, incident analysis and professional reporting.
01
Security foundations and threat modelling
Confidentiality, integrity, availability, assets, threats, vulnerabilities, attack surfaces, trust boundaries, controls and introductory security frameworks.
02
Network security and traffic analysis
IP addressing, ports, protocols, segmentation, firewalls, packet inspection, service discovery and authorised network scanning.
03
Web-application security
Input handling, injection, authentication, sessions, access control, browser security, request inspection and safe lab testing.
04
Authorised security-testing methodology
Scope, rules of engagement, reconnaissance, validation, evidence, risk control, note-taking and responsible reporting.
05
Cloud and infrastructure security
Identity and access management, public exposure, secrets, storage, logging, containers, configuration review and infrastructure scanning.
06
Incident response and evidence
Preparation, detection, triage, containment, log review, evidence preservation, timeline development, recovery and lessons learned.
07
Assessment capstone and reporting
Conduct an authorised lab assessment, prioritise findings, prepare an executive summary and deliver a practical remediation roadmap.
Who this course is
for.
The programme is designed for learners who want a responsible, practical introduction to security assessment and defensive engineering.
Aspiring cybersecurity professionals
Learners developing foundational experience in security operations, assessment, incident response or assurance.
Software developers
Developers who want to recognise common security weaknesses and make better design, authentication and input-handling decisions.
IT and infrastructure professionals
Administrators and technical support professionals moving toward vulnerability management, cloud security or security operations.
What you should know
before starting.
Previous cybersecurity experience is not required, but basic networking and command-line familiarity will help you progress through the practical exercises.
Recommended foundation
- Basic understanding of IP addresses and ports.
- Awareness of websites, servers and databases.
- Basic command-line familiarity.
- Comfort installing development or lab tools.
- Willingness to document findings carefully.
- Commitment to legal and authorised security practice.
What you will need
- A computer capable of running approved lab tools.
- Reliable internet access for remote participation.
- Administrator access to your learning computer.
- Enough storage for virtual machines or lab files.
- A modern browser and code or text editor.
- Time for exercises and the final assessment report.
Learn to identify security risk and communicate the fix.
Complete the application to select your preferred learning format. Current fees, cohort dates, availability, equipment requirements and payment instructions are confirmed during registration.
