All bootcamps Services Career solutions Contact Enrol now
Next batch — enrolling now 10 modules · 6 weeks

Cyber Security Engineer

Defenders and ethical hackers, on call for the real attack surface.

Level Beginner+ to Intermediate
Duration 6 weeks
Schedule Live cohort · 3 evenings a week · US-Eastern

A blue-team-first security curriculum — network and web security, identity, cryptography, OS hardening, incident response, cloud security and offensive tooling — taught by engineers who have run real production SOCs.

A live cohort, taught in real timeLive cohort · 3 evenings a week · US-Eastern. You ask your question in the room and get the answer while it still matters.
The full curriculum, module by moduleTen modules built and taught by engineers who do this work — the syllabus below is all of it, with nothing held back for an upsell.
InfraBuild Labs platform accessYour seat includes of access to the InfraBuild Labs platform. Its interactive lab content is DevOps-first today; this track is delivered as a live cohort plus the full curriculum.
Cohort fee

One payment for the seat, with of InfraBuild Labs platform access included.

Enrol now  → Questions first? Talk to us  →

Checkout runs on the InfraBuild Labs platform. Every application is reviewed by hand, and your seat is confirmed once it is approved.

The whole syllabus, up front

Six weeks, ten modules, built the way a security team is built — foundations first, then the network, then the application, then the response.

10 modules · 6 weeks · taught live
01 Security Foundations

CIA triad, threat models, the attack lifecycle (Cyber Kill Chain, MITRE ATT&CK), risk vs vulnerability.

02 Network Security

TCP/IP, firewalls, IDS/IPS with Snort and Suricata, VPNs, segmentation, packet capture in Wireshark.

03 Cryptography & PKI

Symmetric vs asymmetric, hashing, the TLS handshake, certificates, key management, OpenSSL hands-on.

04 Identity & Access

AuthN vs AuthZ, MFA, OAuth/OIDC, SAML, IAM in AWS and Azure, least privilege, RBAC vs ABAC.

05 OS & Endpoint Hardening

Linux hardening to CIS, Windows GPOs, EDR basics, patching, secure baselines, audit logging.

06 Web Application Security

OWASP Top 10 in depth — injection, auth flaws, XSS, CSRF, SSRF, broken access control. Burp labs.

07 Offensive Tooling

Recon with Nmap, enumeration, exploitation with Metasploit, privilege escalation, lateral movement.

08 Incident Response

The NIST IR lifecycle — triage, containment, eradication, recovery, postmortems, SIEM hunting in Splunk.

09 Cloud Security

AWS shared responsibility, IAM, KMS, VPC, GuardDuty, Security Hub, CloudTrail, posture management.

10 GRC & Compliance

SOC 2, ISO 27001, NIST CSF, PCI-DSS, risk frameworks, audit evidence, policies, vendor risk.

What you will actually touch

The tools named in the job descriptions you are aiming at — learned in the order they turn up in real work.

Linux Wireshark Nmap Burp Suite Metasploit OWASP ZAP Splunk Kali Linux AWS Security OpenSSL

Four kinds of people end up in this room

If one of these sounds like you, you will be in the right cohort. If none of them do, tell us and we will point you at the track that fits.

Freshers

Enter security from scratch on a hands-on blue-team and ethical-hacking path.

IT professionals

Add security depth — network, web, cloud — to the IT skills you already have.

Developers

Ship secure code: OWASP, threat modelling, secrets management, DevSecOps.

Career switchers

Move from sysadmin, support or audit into SOC, GRC or pentesting.

What you will be able to do

Not topics covered — things you can do on your own once the six weeks are behind you.

Roles this leads to

The job titles this curriculum is built against. We teach to the work these roles do, not to a certificate.

Security Analyst (SOC) Security Engineer Penetration Tester Cloud Security Engineer GRC Analyst

Before you enrol

The things people ask us on the call, answered here so you do not have to book one first.

Do I need experience before I start?
Beginner+ to Intermediate. Module 01 starts with threat models, the kill chain and MITRE ATT&CK rather than assuming you already carry them around. What helps most is comfort with networking basics and a Linux command line — both come back in nearly every module after that.
When does the next cohort run?
Next batch — enrolling now. It runs for 6 weeks — Live cohort · 3 evenings a week · US-Eastern. We confirm your exact start date when your application is approved.
Are the classes live, or recorded video?
Live. The schedule above is real class time with an instructor in the room — you interrupt, you ask, you get an answer. That is the whole reason this is sold as a cohort and not as a video library.
How much of this is hands-on?
Every module is worked through with the instructor, tool by tool, and the outcomes above are what you should be able to do unaided by the end. To be exact about what a seat buys: a live cohort, the full curriculum, and access to the InfraBuild Labs platform. The platform's interactive lab content is DevOps-first today — we would rather say so here than let you find out later.
What is InfraBuild Labs, and how long do I keep it?
It is our own lab platform: browser terminals wired to real machines, guided exercises and per-task verification. Its interactive content is DevOps-first today, so on this track treat it as the environment you practise and build in rather than a second copy of this syllabus. Your seat includes of access.
How does enrolment actually work?
Four steps. You apply on the labs platform and pick this track. You pay for the seat — a partner referral code comes off the price at that point. We review the application by hand. Once you are approved you get your labs account and the cohort schedule, and you start.
A partner gave me a referral code — where does it go?
If you arrived on a link carrying the code, it is already applied: you can see it on the price above, and it stays with you for thirty days even if you close the tab. If you have a code but no link, enter it at checkout. Either way the platform is the authority on what it is worth — the figure you see here comes from it, not from this page.
Is this a red-team course or a blue-team course?
Blue-team first, and we would rather be plain about that. Detection, hardening, identity, incident response, cloud posture and GRC are the spine of the track. Module 07 is offensive — recon, enumeration, exploitation, privilege escalation, lateral movement — because you cannot defend an attack path you have never walked, and Module 06 puts you in Burp Suite against the OWASP Top 10.
Do you help with interviews and the job search?
That is a separate service, deliberately. The bootcamp buys you the skill and the work to show for it; our Career Solutions line covers resume and LinkedIn work, mock interviews and application support. Ask us and we will tell you honestly whether you need it yet.

Take the seat

The next batch is enrolling now. Three evenings a week, six weeks, and every application read by a human before a seat is confirmed.