Cybersecurity Skills Study Guide
Cybersecurity Skills Study Guide
Master cybersecurity skills across 25 specialized domains including Cloud Security, Application
Security, DevSecOps, Penetration Testing, and more with structured learning paths and curated
resources.
Author
Sanjeev Jaiswal
Edition: December 2025
Table of Contents
Whichever domain you choose in the Cybersecurity umbrella like Application Security, Cloud
Security, or DevSecOPs; there are common skills that one must learn to excel in this domain. I
have explained what you need to learn in those common skills here
So, I will explain where to study and how much time you should devote to learning those concepts
in these common skills so that you are job-ready and interview-ready too!
ToC
1. Linux Basics - 1-2 weeks
2. Networking Fundamentals - 2-4 weeks
3. Programming Fundamentals - 4-8 weeks
4. Cloud Computing Fundamentals - 3-4 weeks
5. Essential git commands - 1 week
6. Networking matters
It should not take more than a week to be comfortable with basic Linux commands to do
day-to-day activities. Once you are comfortable with basic commands, go for networking and
other security-related command in little depth.
Some common (50) commands, I can think of are in alphabetical order: 1. awk, cat, cd,
chmod, chown, cp, curl, dig, du, df 2. echo, export, find, grep, head, history, host, ifconfig, kill, less
3. locate, ls, man, mkdir, more, mount, mv, nslookup, ping, ps 4. pwd, rm and rmdir, scp, sed,
service/systemctl, sort, ssh, sudo, tail, tar 5. top, touch, uname, uniq, wget, whois, whatis, w, wc,
zip
Week 2: Security Focused Commands
Beyond basics commands for security professionals (mainly AppSec and Pentesters) are:
1. netcat, nslookup, host, dig, netstat, traceroute 2. nmap, nikto, fierce, dirb 3.
install/uninstall/update/upgrade 4. find, grep, ifconfig 5. learn the basics of regular expression as
well. 6. start and stop services 7. basic understanding of /opt /tmp and log server locations 8.
comfortable running scripts written in various languages like Python, ruby, go, etc.
Resources
Books 1. Linux Basics for Hackers: Recommended 2. The Linux Command Line 3. How Linux
works
Courses 1. Introduction to Linux Commands and Scripting 2. Linux Fundamentals for Security
Practitioners: Recommended
Videos 1. Linux for Ethical Hackers: Recommended 2. Hacking for beginners: Linux and
Common Commands 3. 50 most popular Linux and Terminal Commands
Networking Fundamentals
Duration: 2-4 weeks
Except for the Audit and Compliance role, I assume almost every security professional needs to
have a basic to intermediate understanding of Computer Networks to excel in its domain.
Resources
Books 1. See if you know basics as mentioned in this presentation 2. Computer Networking: A
Top-Down Approach by Kurose and Ross: Recommended 3. Networking All-in-One For Dummies
Courses 1. Computer Networking by georgia Tech on Udacity: Recommended 2. Bits and Bytes
of Computer Networking by Google on Coursera
Programming Skills
Duration: 4-8 weeks
Recently, it has become a mandatory skill for any tech security job role to have a decent
knowledge of at least one programming language. Common Programming languages that attract
security folks are: Python (recommended), Go (gaining popularity), Ruby.
Resources
Books 1. Learn Python 3 the Hard Way - Recommended 2. Violent Python 3. Black Hat Python -
Must Read 4. Full Stack Python Security - Must for AppSec Professionals 5. Masterting Python for
Networking and Security
Videos 1. Python Security Best Practices 2. Security Checks for Python Code 3. Intro to Python
for Security Professionals
Cloud Computing
Duration: 3-4 weeks
Cloud Computing is everywhere these days be it Industrial, Pharma, Finance, IT etc. Sooner or
later, it will be a mandatory skills to have for any cybersecurity job roles.
For a deeper focus on identity and access, see the Identity and Access Management (IAM)
Security Study Plan.
There are separate plans for Cloud Security Study Plan as listed below: 1. AWS Security Study
Plan 2. Azure Security Study Plan 3. GCP Security Study Plan
Resources
Books 1. Cloud Computing for Dummies 2. AWS in Action
Videos 1. Cloud Computing Playlist by Fkexmind 2. What is Cloud Computing by AWS 3. Inside a
Cloud Data Center
git commands
Duration: 1 week
You must understand any of the Version Control Software and git is one of the famous one at
present. Don't go for gui version like sourcetree rather try to learn and understand common git
commands at terminal level.
There are many job roles/titles which make it as a mandatory skill, such as: Application Security,
Penetration tester, DevSecOps, API Security, Security Engineering.
Resources
Books 1. Pro Git by Appress - Highly recommended 2. Beginning git and github by Apress 3.
github cheatsheet
Videos 1. git and github for beginners - crash course by freecodecamp 2. git fundamentals for
beginners - full course for free by Flexmind
Courses 1. Git Fundamentals for everyone on Udemy 2. Version Control with Git by Atlassian on
Coursera 3. Learn git and github by codecademy
Networking matters
Once you are on track and now understands the heat, it's time to: 1. Make some good LinkedIn
contacts from the application security domain. 2. Find a mentor or follow someone who shares
blogs, tutorials, talks on these topics. 3. Make connections through various security conference
online/offline 4. Publish some good appsec articles, may be basic concepts, but you must publish.
Choose [Link] or something of your choice. 5. Join webinars, conferences, newsletters. 6.
Help someone who is still a beginner or struggling to understand appsec concepts. You will even
learn better while guiding/helping others.
By the time you cover all these checklists, you will be already on a way to have a good start in a
web security job role. All the best!
Chapter 2
AWS Security
I am making the study plan irrespective of job role under AWS Security category. It can be AWS
Security Analyst, AWS Security Researcher or AWS Security Engineer or Cloud Security
Operations Expert or Cloud Security Manager.
So, check how much you can cover and close the checkbox. The more you close, the better
candidate you are for the job role. Also, I assume you have already checked and comfortable with
Common Security Skills study plan.
ToC
1. AWS Fundamentals - 2-3 weeks
2. AWS Native Security core skills - 4-6 weeks
3. AWS Security Whitepapers - 2 weeks
4. Check your AWS Pentesting Skills - 2-3 weeks
5. Check your Knowledge against common security benchmark and frameworks
6. AWS Security Videos and Courses
7. AWS Security Interview Questions
8. People to follow on twitter
AWS Fundamentals
Duration: 2-3 weeks
I am listing only the topic name. How much you learn and comfortable with the concept or topic is
upon you. And I will share the minimal link to make you up to the mark and you are free to learn
anything more than this for better candidacy and experience.
Key Services to Cover: 1. Amazon S3 2. KMS 3. VPC 4. Lambda 5. AWS EKS and ECS 6.
AMAZON RDS
What I mean to say here is: 1. AWS core services related security skills 2. AWS Security services
hands-on knowledge
AWS has awesome lists of whitepapers related to AWS Security. We are adding few important
one here. You can anytime check more for updated or new security whitepapers here
GCP Security
I am making the study plan irrespective of job role under GCP Security category. It can be Cloud
Security Analyst, Cloud Security Researcher or Cloud Security Engineer or Cloud Security
Operations Expert or Cloud Security Manager or Cloud Governance.
So, check how much you can cover and learn practically. The more you are good at these
concepts, the better candidate you are for the job role. Also, I assume you have already checked
and comfortable with Common Security Skills study plan.
Key Services to Cover: 1. GCS (Google Cloud Storage) 2. GKE 3. VPC (Virtual Private Cloud) 4.
Firewall Rules and policies 5. Load Balancer 6. Cloud DNS 7. Cloud CDN 8. Google Cloud Armor
9. Google Cloud Logging 10. BigQuery 11. API Gateway 12. Certificate Manager 13. Secrets
Manager 14. Cloud Run 15. Cloud Function
What I mean to say here is: 1. GCP core services related to security 2. GCP Security services
hands-on knowledge
GCP has awesome lists of whitepapers related to GCP Security. We are adding few important
one here. You can anytime check more for updated or new security whitepapers here
This study plan is based on milestones. So, check how much you can cover and close the
checkboxes. The more you close, the better candidate you are for the job role. Also, I assume you
have already checked and are comfortable with Common Security Skills study plan.
Just to make sure that everyone understands what you need to learn to be a pentester. It is
altogether different from bug bounty, Red Team etc. but to excel in any of those roles you should
be good at pentesting. It's not necessary that you can be a Red Teamer or Bug bounty hunter if
you know pentesting. But a red teamer is surely very good at pentesting. Also, Vulnerability
assessment is not pentesting, however, VAPT is a common skills required for pentesters job.
In short:
1. Pentesters are offensive security folks who try to find as many security vulnerabilities as
possible, access the risk and exploit as much as possible. They can play as internal or
external attackers for the organization.
2. Red Teamers are least bothered of finding all security gaps, and their ultimate goal is to
find one way in, exploit it and then escalate laterally through your system to access the
juiciest data they can.
3. It's totally upon your preference and timings that you should join bug bounty platform or not.
Read more here about Pentesters vs Red Team
Usually it will take you 6 months to be good at fundamentals to get a job at entry level.
If you are also interested in testing Android or iOS apps, read the Mobile Application Security
Study Plan alongside this one.
ToC:
1. Pentesting Concepts - 6 weeks
2. Tools of Trade - 2 weeks
3. Lab Practices - 8 weeks
4. Books (Read 1-2 books) - 2-3 months
5. Videos
6. Courses - Try to complete at least one course (1-2 months)
7. Certifications - on your bandwidth and wish
Pentesting Concepts
Duration: 6 weeks
Go with your pace, but make sure you understand the basic security concepts very well like HTTP
Security Response headers, Bruteforce, DoS, XSS, CSRF, Injection, IDoR, JWT etc.
Understand the fundamental concepts on what it is, how it can be vulnerable and how you can
either exploit it or mitigate it. 1. Understanding how proper implementation of AuthN and AuthZ
contribute to robust security. What can an attacker do to exploit it. 2. How session and cookies
can be vulnerable, bypassed or even exploited 3. In-depth understanding of XSS 4. Some REST
concepts like CRUD. 5. Different types of injections specially SQLi, RFI,LFI 6. Mass Assignment
7. CSP concepts 8. SSRF 9. Automated Bruteforce 10. Credential Stuffing 11. JWT Tokens 12.
Basic of encoding, decoding, hashing 13. Session Fixation, Session Hijacking 14. 3rd Party
Vulnerability checks and exploitations 15. Understand the work defined for black box and white
box testing 16. SAST vs DAST 17. CORS
Tools of Trade
Duration: 2 weeks
They say tools are not everything but tools play an important role to make you a better and
efficient penetration tester. But, don't just be tool junkie. Try to understand in-depth of each tool,
its functionalities and when to use with how concept! I am not writing names of many tools for
DAST, SAST etc like acunetix, appscan, checkmarx etc. Kali OS will have almost all the tools that
you would need for pentest, but I would explicitly mention few of them here as well.
Lab Practices
Duration: 8 weeks
Books
1. The Web Application Hacker's Handbook (read this book as the first thing or learn from web
security academy)
2. OWASP Top 10 2021 Testing Guide (read this as the 2nd book)
3. The Hacker Playbook 3: Practical Guide To Penetration Testing
4. Real World Bug Hunting
5. Web Hacking 101 by Peter Yaworski - pdf
Videos
1. Penetration Testing for Beginners - Youtube
2. Web Security Course - Playlist
Courses
It's upto you to choose some paid or free courses to speed up what you have learned so far to test
how much you understand under web pentesting category. You should choose lab based courses
though. 1. Cybrary 2. Pentester academy - I liked few of its courses on 1. Python for Pentesters 2.
JavaScript for Pentesters 3. Pentesting with Metasploit 4. WAP Challenges 5. Web Application
Pentesting 3. Introduction to Web Security form Stanford 4. Pentesting for beginners 5. Pentesting
from EdX 6. Web Security Academy (You can ignore reading Web Application Hackers
Handbook, if you are learning from here!) 7. Computer Systems Security form MIT 8. [Link]
Certifications
Certification gives you an entry for HR calls, but remember real hands-on experience can beat
anything. 1. CEH: not highly recommended, but good to start with if you don't know anything
about security. 2. eJPT 3. eWPTXv2 4. OSCP 5. OSWE 6. GPEN 7. GWAPT
Networking matters
Once you are on track and now understands the heat, it's time to: 1. Make some good LinkedIn
contacts from security domain 2. Find a mentor 3. Make connections through various security
conference online/offline 4. Publish some good hacking articles, may be basic concepts but you
must publish. Choose medium 5. Join webinars, conferences 6. help someone who is still a
beginner
By the time you cover all these checklists, you will be already on a way to have a good start in
web security job role. All the best!
Interview Questions
Possible Web Security interview questions is shared at different github repo to keep it aligned with
career roadmap guide.
Chapter 5
Application Security
This study plan is based on milestones. So, check how much you can cover within the timeline.
The more you cover the topics, the better candidate you are for the job role. Also, I assume you
have already checked and are comfortable with Common Security Skills study plan.
Just to make sure that everyone understands what you need to learn to be an Application Security
Engineer. Application Security is different from Web Security or commonly people think it as
offensive security or pentesting. Though it needs some concepts aligned with pentester, it's
altogether a totally different skill set.
It is more towards shift left security including Threat Modeling, Secure Code Review, Secure
Code Design, Training Developers, taking care of overall SDL process, and of course OWASP
Top 10 web and API security. I have another page specifically for "API Security Study Plan"
because that skill also needs good time to learn.
In short:
1. AppSec is not Pentesting (Penetration Testing) or Web Security (people use it generically).
2. Think more of a combination of developer and attacker
3. Talking to developers, giving training to them or going through the code should not scare
you.
4. Tougher than Pentesting (Topic of debate for another day)
5. Can write code for PoC, Exploit or demo with comfort
6. API security should be your area of interest.
7. Good understanding of Identity and Access Management (IAM) will help for auth-related
design and reviews.
Usually it will take you 6-12 months to be good at the Application Security fundamentals to get a
job at entry level.
ToC:
1. Web Application Concepts - 6 weeks
2. Threat Modeling - 2-3 weeks
3. Secure Code Review - 6-8 weeks
4. Cryptography - 3 weeks
5. Security Development Lifecycle (SDL) - 4 weeks
6. Books
7. Videos
8. Courses - Try to complete at least 1-2 courses (1-2 months)
9. Certifications - on your bandwidth and wish
10. Interview Questions
11. Application Security Tools
12. Whom to follow on Twitter
This topic will have an overlap with the concepts required for Pentesting, but you have to now
think more of a defender than offender. Go with your pace, but make sure you understand the
basic web security concepts very well like HTTP Security Response headers, Bruteforce, CSRF,
Injection, JWT, Cryptography, Hashing, Encoding etc.
Understand the fundamental concepts on what it is, how it can be vulnerable and how you can
either exploit it or mitigate it. 1. Understanding how proper implementation of AuthN and AuthZ
contribute to robust security. What can an attacker do to exploit it and how to mitigate/defend it 2.
How session and cookies work and how it can be vulnerable, bypassed or even exploited 3.
Understand how session management can be more secured 4. In-depth understanding of XSS
from both perspective exploit and mitigation 5. REST concepts like CRUD. 6. Different types of
injections specially SQLi, RFI,LFI, RCE 7. Mass Assignment 8. Concepts like rate limit,
bruteforce, replay attack, MITM, session fixation, session hijack, credential stuffing 9. CORS
concepts 10. How can you prevent SSRF attacks 11. JWT Tokens in depth 12. Basic of encoding,
decoding, hashing 13. Good understand of Cryptography and its implementation in application 14.
SAST vs SCA
Threat Modeling
Read Threat Modeling Study Plan
Cryptography
Read Cryptography
Security Development Lifecycle (SDL)
Read Security Development Lifecycle
Books
1. Agile Application Security
2. Application Security Program Handbook
3. Writing Secure Code
4. The Tangled Web: A Guide to Securing Modern Web Applications
5. Alice and Bob Learn Application Security
6. OWASP Code Review Guide
Videos
1. Introduction to Application Security
2. Scaling your AppSec Program with semgrep
3. Building an AppSec Program from the ground up by Snyk
4. Application Security - Understanding, Exploiting and Defending against Top Web
Vulnerabilities by Cerner
5. Securing Web Application
6. Web Application Security: 10 things developers need to know
7. Application Security from SANS Institute
Courses
1. Software Security on Coursera
2. Cloud Application Security
3. Application Security Guide - Udemy
4. Sec522: Application Security: Securing Web Apps, APIs, and Microservices from SANS
Really nice one but costly.
5. Free OWASP Top 10 practice from Kontra Security
Certifications
1. CSSLP: Certified Secure Software Lifecycle Professional Recommended
2. CASE: Certified Application Security Engineer for Java and .NET professionals
3. GWEB: GIAC Certified Web Application Defender
Interview Questions
Possible Application Security interview questions is shared at different github repo to keep it
aligned with career roadmap guide.
AppSec Tools
1. Checkmarx for SAST or HCL AppSCan (Previously it was IBM AppScan)
2. Snyk Code for SAST and Snyk Open Source for SCA
3. git-secrets or gitleaks or trufflehog to find out secrets
4. Chef Inspec
5. OWASP Dependency Check is for SCA
6. Bandit for python code
7. Sonarqube for SAST with few plugins like findsecbugs
8. RetireJS for JS libraries
9. Contrast for IAST solution
10. Coverity from Snyopsys
11. You must not ignore Burp Suite Pro
12. Veracode
13. InSight from Rapid7
API Security
This study plan is based on milestones. So, check how much you can cover within the timeline.
The more you cover the topics, the better candidate you are for the varied job roles which require
good knowledge of API security. Also, I assume you have already checked and comfortable with
Common Security Skills study plan.
It will cover what you need to learn to excel in API security (part of AppSec domain). And, please
keep in mind that it would require knowledge of: 1. How website works 2. How API endpoints are
defined and its request and response 3. You know basics of coding to write your own APIs for
testing 4. OWASP Top 10 for web 5. OWASP Top 10 for API 2023 (Latest version)
I will explain very basic or just the overview so that you can start learning those concepts from
there.
Note: Usually it will take you 3-6 months to be good at the API Security fundamentals to get a job
at entry level.
API Fundamentals
Duration: 2 weeks
API endpoints are like specific doors or entrances at the restaurant that allow the app and the
restaurant's system to exchange information. Each endpoint serves a particular purpose or action.
For example, there might be an endpoint for submitting an order, another one for retrieving the
menu, and yet another one for tracking the status of your order.
When you click "Place Order" in the app, it sends a request to a specific API endpoint designated
for order submission. This request contains all the necessary information, such as the items you
ordered, your delivery address, and any special instructions. The endpoint receives this request
and processes it. It may check if the items are available, calculate the total cost, and initiate the
delivery process.
Similarly, if you want to check the status of your order later, the app sends a request to a different
API endpoint dedicated to order tracking. This endpoint retrieves the relevant information about
your order, such as whether it's being prepared, out for delivery, or already delivered. The
endpoint then sends this information back to the app, which displays it to you.
In summary, API endpoints act as communication channels between different systems, allowing
them to exchange information and perform specific actions. They serve as designated entry points
that receive requests from one system and provide the necessary responses based on the
requested action.
2. Types of microservices
Try to understand what types of microservices exist from application architectural view. Then it will
be easy for you to understand microservices patter. Once you know these concepts, it will actually
help you to the API security assessment accurately.
When it comes to API security in the context of microservices, there are a few important types of
microservices that developers and security professionals should be aware of. Let's explore them:
You can't deny the fact that Cloud is everywhere and understanding how API is being used in
cloud would be an aded advantage for you. A cloud-native API refers to an API that is designed,
developed, and deployed with a cloud-native approach, taking full advantage of cloud computing
capabilities and principles. Cloud-native APIs are specifically tailored for cloud environments,
enabling scalability, resilience, and flexibility. Here are a few examples of cloud-native APIs:
1. RESTful API: Representational State Transfer (REST) is a widely used architectural style
for building APIs. RESTful APIs are designed to be stateless and use standard HTTP
methods such as GET, POST, PUT, and DELETE to interact with resources. They are
well-suited for cloud-native environments as they leverage the HTTP protocol and can be
easily consumed by different clients, including web browsers, mobile apps, and other
services.
2. Event-Driven APIs: Event-driven APIs enable asynchronous communication and are often
used in cloud-native architectures. They allow services to exchange information and trigger
actions based on events. For example, when a new user registers on a platform, an
event-driven API can publish an event that triggers other services to send welcome emails,
update user profiles, or perform other related actions. Cloud-native event-driven APIs often
utilize message queues, event brokers, or streaming platforms to facilitate event processing.
3. GraphQL API: GraphQL is a query language and runtime for APIs that allows clients to
request specific data in a flexible and efficient manner. It enables clients to retrieve only the
data they need, reducing the amount of network traffic and improving performance. GraphQL
APIs are popular in cloud-native environments where microservices often need to interact
with multiple data sources. They provide a single entry point for clients to fetch data from
various services and aggregate responses.
4. Serverless APIs: Serverless computing allows developers to build and deploy applications
without managing the underlying infrastructure. Serverless APIs, often implemented using
serverless computing platforms like AWS Lambda or Azure Functions, enable developers to
focus solely on writing the API logic while leaving the infrastructure management to the cloud
provider. Serverless APIs scale automatically based on demand, and developers only pay for
the actual execution time of the API functions.
5. OpenAPI (formerly Swagger): OpenAPI is a specification that defines and documents
RESTful APIs. It provides a machine-readable format for describing the API's endpoints,
request/response payloads, and authentication mechanisms. OpenAPI allows developers to
generate code stubs, automatically generate API documentation, and even test and mock
APIs. It promotes collaboration and interoperability between different teams and tools in a
cloud-native development ecosystem.
These examples illustrate different types of cloud-native APIs that leverage cloud infrastructure
and principles to deliver scalable, resilient, and flexible solutions. Cloud-native APIs enable
organizations to take full advantage of cloud computing benefits, such as elasticity, cost
efficiency, and rapid deployment, while building robust and modern applications.
Now, as you understand basic blocks of API, types of API, microservices, cloud-native APIs etc.
Let's understand few basic concepts while dealing with API Security like AuthN, AuthZ, OAuth,
API Gateway, why API security is different from web security and so on.
Here are some of the key differences between API security and web application security: 1.
Focus: Web application security focuses on securing the user interface, server, and database
parts of a web application. API security, however, concentrates on securing the API and the data
it transmits. 2. Attack Vectors: Web applications are often targeted by attacks such as SQL
injection, cross-site scripting (XSS), cross-site request forgery (CSRF), and file inclusion. API
security, on the other hand, is typically targeted by attacks such as API spoofing, parameter
manipulation, and man-in-the-middle (MitM) attacks. 3. Authentication and Authorization: Web
application security often relies on username and password authentication, session management,
and access control to protect web applications. API security, on the other hand, typically uses
OAuth, API keys, or JSON Web Tokens (JWTs) for authentication and authorization. 4. Usage:
Web applications typically provide a user interface to interact with, whereas APIs are back-end
components that allow different systems to communicate. As a result, API security focuses on
securing APIs that expose application functionality to other systems.
Overall, API security and web application security are equally important and require different
measures to ensure they remain safe and secure. While web application security focuses on the
user interface, server, and database, API security focuses on the API itself, the data it transmits,
and the ways in which different systems interact with it.
API security refers to the measures taken to protect an Application Programming Interface (API)
from unauthorized access, modification, and exploitation. APIs are a set of rules and protocols
that allow various software applications to interact with each other. Therefore, they need to be
secure to ensure that only authorized parties have access to them.
1. Encryption: This involves the use of encryption techniques to protect the data being
transmitted between API endpoints. For example, HTTPS (HyperText Transfer Protocol
Secure) is commonly used for secure data transmission.
2. Authentication: This involves verifying the identity of the user or application accessing the
API. Authentication can be achieved through the use of usernames and passwords or the use
of tokens that expire after a certain period.
3. Authorization: This involves determining what actions a user or application can perform
after they have been authenticated. For example, some users may have access to read data,
while others may have access to modify data.
4. Rate Limiting: This involves limiting the number of requests that a user or application can
make to the API. This helps to prevent Denial of Service attacks by limiting the amount of
resources that can be consumed by a user.
Practical Examples:
• Google Maps API: Google Maps API requires an API key for authentication. This key is
specific to the developer's account and is used to restrict access to the API to authorized
users. It also uses HTTPS to encrypt the data being transmitted between the API endpoints.
• Stripe API: The Stripe API uses authentication and API keys to restrict access to authorized
users. It also uses rate limiting to prevent excessive API usage and offers real-time fraud
detection to prevent fraudulent transactions.
• Twilio API: The Twilio API uses authentication and authorization to restrict access to
authorized users. It also uses HTTPS to encrypt data and provides rate throttling to prevent
excessive API usage. Additionally, it offers access control features to restrict API access to
specific IP addresses or domains.
3. Why API Security
1. Data Protection: APIs often handle sensitive data, such as user credentials, personal
information, financial data, or business secrets. Securing APIs ensures that this data remains
confidential and is not compromised or accessed by unauthorized entities.
2. Authorization and Access Control: APIs provide access to various resources and
functionalities. Implementing proper security measures ensures that only authenticated and
authorized users or systems can access and perform actions on those resources. It helps
prevent unauthorized access, data breaches, and misuse of the API.
3. Trust and Reputation: Security breaches or vulnerabilities in APIs can damage the trust and
reputation of an organization. Users and clients expect their data to be handled securely.
Demonstrating a commitment to API security enhances trust, improves customer satisfaction,
and helps maintain a positive reputation.
4. Compliance with Regulations: Many industries are subject to regulatory requirements
regarding data protection and privacy, such as GDPR (General Data Protection Regulation)
or HIPAA (Health Insurance Portability and Accountability Act). Ensuring API security helps
organizations comply with these regulations and avoid legal consequences or penalties.
5. Prevention of Attacks: APIs can be targeted by various types of attacks, including injection
attacks, cross-site scripting (XSS), cross-site request forgery (CSRF), or denial-of-service
(DoS) attacks. Implementing security measures mitigates the risk of these attacks and
protects the API and underlying systems from being compromised.
6. Secure Integration: APIs are often used to integrate different systems, services, or
third-party applications. Proper security measures ensure that these integrations are
performed securely, protecting both the API provider and the entities consuming the API from
potential vulnerabilities or data leaks.
7. Monitoring and Auditing: API security enables organizations to monitor and audit API
activities, such as tracking API usage, detecting abnormal behavior, or identifying potential
security incidents. This visibility allows for timely response and remediation, reducing the
impact of security breaches.
In summary, API security is essential to protect sensitive data, ensure authorized access,
maintain trust and reputation, comply with regulations, prevent attacks, secure integrations, and
enable monitoring and auditing. It is a fundamental aspect of building robust and secure
applications and systems in today's interconnected digital landscape.
Authentication (AuthN) and authorization (AuthZ) are two essential concepts in API security. Let's
explore each of them with practical examples:
1. Role-Based Access Control (RBAC): In RBAC, permissions are assigned based on roles.
For example, in a content management system, an administrator role may have access to
create, edit, and delete content, while a regular user role may have read-only access. When a
user is authenticated, their role determines the actions they can perform.
2. Attribute-Based Access Control (ABAC): ABAC grants access based on various attributes
associated with the user or the resource. For instance, in a healthcare system, a doctor may
have access to medical records of their assigned patients based on their role as a doctor and
the specific patient's attribute.
3. Scope-Based Access Control: APIs often implement scope-based access control, where
each authenticated user is granted specific scopes or permissions. For example, in an email
API, a user with "read" scope can only retrieve emails, while a user with "read" and "send"
scopes can both read and send emails.
4. Fine-Grained Access Control: Fine-grained access control allows for precise control over
individual resources. For instance, in a file-sharing application, you can define permissions at
the file or folder level, specifying which users or groups can read, write, or delete specific files.
In summary, authentication (AuthN) is the process of verifying a user's identity, while authorization
(AuthZ) determines the permissions and access rights granted to an authenticated user. These
two concepts work together to ensure that only authenticated users with appropriate privileges
can access the desired resources or perform specific actions.
5. Rate limit
Rate limiting is a strategy for limiting network traffic. It puts a cap on how often someone can
repeat an action within a certain timeframe - for instance, trying to log in to an account. Rate
limiting can help stop certain kinds of malicious bot activity. It can also reduce strain on web
servers.
Why is it important? 1. Preventing DoS/DDoS: Stops attackers from flooding your API with
requests to crash it. 2. Brute Force Protection: Limits the speed at which an attacker can guess
passwords or tokens. 3. Resource Management: Ensures fair usage of your API resources
among all users.
Common Algorithms: - Token Bucket: Tokens are added to a bucket at a fixed rate. Each
request consumes a token. If empty, request is denied. - Leaky Bucket: Requests are processed
at a fixed rate, smoothing out bursts. - Fixed Window: Counts requests in a fixed time window
(e.g., 100 req/min). Can be bypassed at window edges. - Sliding Window: A more accurate
version of fixed window that smooths out the edges.
Implementation: - Rate limits are often implemented at the API Gateway or Load Balancer level.
- Use HTTP headers to communicate limits to clients: - X-RateLimit-Limit: The maximum number
of requests allowed in a window. - X-RateLimit-Remaining: The number of requests remaining in
the current window. - X-RateLimit-Reset: The time at which the current window resets. - Return
429 Too Many Requests status code when the limit is exceeded.
6. API Gateway
An API Gateway is an API management tool that sits between a client and a collection of backend
services. It acts as a reverse proxy to accept all application programming interface (API) calls,
aggregate the various services required to fulfill them, and return the appropriate result.
Popular API Gateways: - Kong: Open-source, highly extensible. - Apigee (Google Cloud):
Enterprise-grade full lifecycle API management. - AWS API Gateway: Fully managed service for
AWS environments. - Azure API Management: Managed service for Azure. - Tyk: Open-source
API gateway and management platform.
Books
1. API Security in Action
2. Hacking APIs: Breaking Web Application Programming Interfaces
3. Web Application Security
4. Advanced API Security
Videos
1. API Security: Everythign you need to know to protect your APIs
2. The 2022Guide to API Security
3. Analysing the OWASP API Security Top 10 for Pen Testers
Courses
1. API Security Fundamentals form APISec University (free)
2. API Penetration Testing Course from APISec University (free)
3. API Security on Google Cloud's Apigee API Platform
4. API Fundamentals from Qualys for (free)
5. Introduction to the OWASP API Security Top 10 - Cybrary (free)
Certifications
1. CSSLP
2. API Security Architect Certification
3. Certified API Security Professional
Interview Questions
Possible API Security interview questions is shared at different github repo to keep it aligned with
career roadmap guide.
Chapter 7
Threat Modeling
Threat Modelling
"[!IMPORTANT] If you are into Product security or application security or security engineering, you
would need this study plan more than any other security professionals. However, it is advised for
every security professional to have a fair understanding of Threat Modeling fundamentals."
"[!Note] It should take 1-2 months for good understanding of Threat Modeling with some hands-on
experiences."
"[!TIP] You must go through OWASP Threat Modeling Cheat Sheet for basic understanding."
In short, - Threat modeling is the process of identifying, analyzing, and mitigating potential
security threats to a system or organization. - It involves identifying the assets that need to be
protected, analyzing the potential threats to those assets, and developing strategies to mitigate or
eliminate those threats. - The early you perform Threat Modeling the better result you would get.
Methodologies
Duration: 2 weeks
Books :books:
1. Threat Modeling: Design for Security by Adam Shostack
2. Threat Modeling by Izar Tarandach
After learning Threat Modeling, you can connect it with monitoring and incident response by
exploring the Blue Team, Detection & Response Study Plan.
Chapter 8
Here’s a detailed study plan for GRC (Governance, Risk, and Compliance) professionals and
beginners:
GRC Overview
• Governance: The framework and processes that ensure an organization’s strategies,
objectives, and risks are managed and aligned with its goals. It includes policies, procedures,
and decision-making structures.
• Risk Management: Identifying, assessing, and mitigating risks that could impact the
organization’s ability to achieve its objectives. This involves risk assessment, risk control, and
risk monitoring.
• Compliance: Ensuring that the organization adheres to laws, regulations, standards, and
internal policies. It involves compliance audits, monitoring, and reporting.
Key Components:
• Governance Frameworks: COSO, COBIT
• Risk Management Frameworks: ISO 31000, NIST SP 800-30, NIST RMF
• Compliance Frameworks: GDPR, HIPAA, SOX, ISO27K1, SOC
Why GRC
• Governance & Oversight provides methods to guide, constrain and conscribe the
organization to achieve its purpose, mission, vision, and values.
• Strategy & Performance provides methods to guide, arrange and operate resources to
achieve objectives and monitor performance.
• Risk & Decision-Support provides methods to identify and address the e■ect of uncertainty
on objectives, including ways to support decisions under uncertainty.
• Compliance & Ethics provides methods to identify and address mandatory and voluntary
obligations and the underlying ethical principles and values.
• Security & Continuity provides methods to identify and address threats to critical physical
and digital assets and infrastructure.
• Audit & Assurance provides methods to enhance confidence that the organization is reliably
achieving objectives, addressing uncertainty, and acting with integrity.
But for the scope of this study plan we will focus on the following elements: - Governance &
Oversight - Risk & Decision-Support - Security & Continuity - Audit & Assurance
ToC
1. GRC Fundamentals - 2 weeks
2. Governance and Policy - 2 weeks
3. Risk Management Deep Dive - 2 weeks
4. Compliance and Auditing - 2 weeks
5. Tools, Metrics and Operations - 2 weeks
6. Resources
GRC Fundamentals
Duration: 2 weeks
Understand the core concepts of Governance, Risk, and Compliance and how they integrate.
Soft Skills
• Communication: Effectively communicating GRC issues and strategies to stakeholders.
• Problem-Solving: Addressing complex GRC challenges with creative solutions.
In the field of Governance, Risk, and Compliance (GRC), there are a variety of roles that span
different responsibilities and levels of expertise. These roles focus on ensuring that organizations
adhere to regulatory standards, effectively manage risks, and maintain strong governance
practices. Below is a breakdown of the different jobs and roles in GRC:
1. GRC Analyst
2. Responsibilities:
3. Conduct risk assessments and analyze data to identify risks and compliance gaps.
4. Monitor and report on governance, risk, and compliance activities.
5. Assist in implementing GRC tools and technologies.
6. Draft and update policies and procedures to ensure regulatory compliance.
7. Skills Required:
8. Strong analytical and communication skills.
9. Knowledge of risk management frameworks (ISO 31000, NIST).
10. Understanding of relevant regulations (GDPR, HIPAA, SOX).
11. Typical Employers: Banks, financial institutions, large enterprises, IT firms.
12. Risk Management Specialist
13. Responsibilities:
14. Identify, assess, and monitor risks across different areas of the organization.
15. Develop and implement risk mitigation strategies.
16. Conduct regular risk assessments and create risk reports for senior management.
17. Work with business units to integrate risk management into operations.
18. Skills Required:
19. Proficiency in risk management frameworks (COSO, ISO 31000).
20. Strong problem-solving and analytical abilities.
21. Risk modeling and analysis experience.
22. Typical Employers: Insurance companies, financial institutions, consulting firms.
23. Compliance Officer
24. Responsibilities:
25. Ensure the organization adheres to relevant laws, regulations, and internal policies.
26. Conduct compliance audits and report on compliance risks.
27. Stay updated on changes in regulatory requirements and ensure the organization adjusts
accordingly.
28. Train employees on compliance policies and procedures.
29. Skills Required:
30. Knowledge of industry-specific regulations (e.g., HIPAA, SOX, GDPR).
31. Strong attention to detail and analytical skills.
32. Audit and regulatory experience.
33. Typical Employers: Healthcare, banking, tech firms, regulated industries.
34. GRC Consultant
35. Responsibilities:
36. Provide advisory services to clients on GRC frameworks, policies, and procedures.
37. Conduct audits and assessments for governance, risk, and compliance.
38. Design and implement GRC programs and tools for clients.
39. Train and educate client teams on GRC best practices.
40. Skills Required:
41. In-depth knowledge of multiple GRC frameworks and standards.
42. Strong communication and client management skills.
43. Ability to tailor GRC solutions to specific industries.
44. Typical Employers: Consulting firms (Big Four: Deloitte, PwC, EY, KPMG).
45. Internal Auditor
46. Responsibilities:
47. Conduct internal audits to ensure compliance with policies, regulations, and internal
controls.
48. Evaluate the effectiveness of risk management and governance processes.
49. Report audit findings to management and suggest improvements.
50. Monitor remediation efforts and follow up on recommendations.
51. Skills Required:
52. Experience with auditing standards (IIA, ISO 19011).
53. Detail-oriented with strong analytical skills.
54. Knowledge of risk management and internal control frameworks.
55. Typical Employers: Large corporations, government organizations, public institutions.
56. GRC Program Manager
57. Responsibilities:
58. Oversee the design and implementation of the GRC program across the organization.
59. Ensure integration of GRC activities with overall business strategies.
60. Lead cross-functional teams in managing governance, risk, and compliance initiatives.
61. Track GRC program performance metrics and report to senior leadership.
62. Skills Required:
63. Project management experience (PMP, PRINCE2).
64. Deep understanding of GRC processes and tools.
65. Strong leadership and communication skills.
66. Typical Employers: Large enterprises, multinational corporations, consulting firms.
67. IT Risk and Compliance Manager
68. Responsibilities:
69. Manage IT-related risks and ensure compliance with information security standards.
70. Oversee IT audits and risk assessments.
71. Ensure compliance with IT-specific regulations like GDPR, PCI DSS, and SOX.
72. Implement and monitor IT governance frameworks such as COBIT and NIST.
73. Skills Required:
74. Strong knowledge of information security, IT governance, and regulatory requirements.
75. Certifications such as CISM, CRISC, or CISSP.
76. Experience with IT risk assessment and mitigation.
77. Typical Employers: Technology companies, financial institutions, healthcare providers.
78. Chief Risk Officer (CRO)
79. Responsibilities:
80. Develop and lead the organization’s risk management strategy and framework.
81. Oversee enterprise risk management, internal audits, and compliance activities.
82. Report to the board of directors on risk exposure and mitigation efforts.
83. Drive risk culture and awareness throughout the organization.
84. Skills Required:
85. Strong leadership and strategic planning abilities.
86. Advanced knowledge of risk management and governance frameworks.
87. Experience working at the executive level.
88. Typical Employers: Large enterprises, multinational corporations, regulated industries.
89. Chief Compliance Officer (CCO)
90. Responsibilities:
91. Develop and oversee the organization’s compliance program.
92. Ensure that the organization complies with all external regulations and internal policies.
93. Lead compliance audits and investigations.
94. Serve as the key point of contact for regulatory agencies.
95. Skills Required:
96. Deep understanding of regulatory requirements in the organization’s industry.
97. Strong communication and decision-making abilities.
98. Experience with legal and compliance frameworks.
99. Typical Employers: Banks, healthcare organizations, multinational companies.
100. Enterprise Risk Manager
101. Responsibilities:
102. Manage enterprise-wide risk, ensuring a unified approach to risk across all business
units.
103. Implement risk management strategies at the organizational level.
104. Ensure compliance with risk management standards like ISO 31000.
105. Present risk reports and mitigation strategies to senior leadership.
106. Skills Required:
107. Proficiency in enterprise risk management frameworks (ERM).
108. Ability to work with cross-functional teams and lead risk management initiatives.
109. Excellent analytical and problem-solving skills.
110. Typical Employers: Large corporations, public sector, consulting firms.
111. GRC Software Specialist/Administrator
112. Responsibilities:
113. Manage the organization’s GRC software platform (e.g., RSA Archer, MetricStream).
114. Configure and customize GRC tools to support governance, risk, and compliance
activities.
115. Train staff on the use of GRC technology.
116. Ensure data integrity and proper reporting from the GRC platform.
117. Skills Required:
118. Technical expertise in GRC software.
119. Familiarity with governance, risk, and compliance processes.
120. Strong project management and troubleshooting skills.
121. Typical Employers: Large corporations, IT service providers, financial institutions.
#### G = People - People are the ones who commit misconduct and make
mistakes and miscalculations. #### R = Wicked Problems; Complex Adaptive
Sytem of Systems - Wicked Problems - describe a complex, dynamic, and
multifaceted problem that is difficult or even impossible to solve
completely. - Complex adaptive system of systems - is a type of system that
is made up of many interacting subsystems, each with its own behavior,
rules, and feedback loops. #### C = Fractality - Fractality refers to the
property of self-similarity or the repetition of patterns at different
scales in a system or structure.
GRC Model
A GRC model refers to the structured approach an organization adopts to integrate governance,
risk management, and compliance into its operations. The goal of the model is to ensure all three
elements (Governance, Risk, and Compliance) work together efficiently and align with the
organization’s overall strategy and objectives. There are several well-established
models/frameworks used in GRC:
• First Line: Operational management owns and manages risks. They are responsible for
identifying, assessing, and controlling risks in day-to-day operations.
• Second Line: Risk management and compliance functions provide oversight. They develop
policies and monitor their application.
• Third Line: Internal audit provides independent assurance by reviewing the effectiveness of
the governance and risk management framework.
COSO (Committee of Sponsoring Organizations) Framework:
• Focuses on internal controls, risk management, and corporate governance.
• It outlines five key components:
• Control Environment,
• Risk Assessment,
• Control Activities,
• Information and Communication, and
• Monitoring.
COBIT (Control Objectives for Information and Related Technologies):
A framework for the governance and management of IT enterprise systems. Helps ensure
alignment between IT and business goals, manage risk, and ensure compliance. Unified GRC
Model:
This model integrates GRC activities across the organization into a cohesive framework, where
governance, risk management, and compliance are addressed in a unified manner. It avoids silos
by aligning risk management, compliance functions, and governance under a single operational
structure, often supported by technology platforms for GRC automation.
• Integration: GRC activities (governance, risk, and compliance) should be integrated across
departments and not handled in isolation.
• Accountability: Clear roles and responsibilities should be defined for those managing
governance, risk, and compliance.
• Process Alignment: Risk management and compliance activities should align with
organizational governance processes and strategic objectives.
• Technology Enablement: Use of GRC tools to manage policies, track risks, and ensure
compliance can significantly enhance efficiency.
Measuring GRC
Measuring the effectiveness of a GRC program involves establishing metrics that assess how well
the governance, risk, and compliance functions are performing. These measurements provide
insight into whether the GRC model is helping the organization achieve its goals while managing
risks and adhering to regulatory requirements.
Governance Metrics: * Policy Adherence Rate: Measures how well employees and processes
comply with internal policies. * Decision-Making Efficiency: Evaluates the effectiveness and
timeliness of decisions made based on governance frameworks. * Stakeholder Engagement:
Surveys and feedback from stakeholders to measure their involvement in governance.
Risk Management Metrics: * Risk Identification Rate: Measures how frequently new risks are
identified, indicating proactive risk management. * Risk Mitigation Success: Assesses how
effective the organization is in addressing identified risks (i.e., reduction in the number of
incidents). * Risk Appetite Adherence: Evaluates how well the organization operates within its
defined risk appetite or tolerance.
Compliance Metrics: * Compliance Breach Rate: The number of compliance violations or
regulatory breaches. * Audit Findings: The number and severity of issues identified during audits,
particularly regarding compliance with internal or external regulations. * Compliance Training
Completion Rate: The percentage of employees who have completed required compliance
training.
Incident Response and Recovery Metrics: * Mean Time to Detect (MTTD): Measures the
average time it takes to detect a security or compliance incident. * Mean Time to Respond
(MTTR): Tracks how quickly an organization can respond to and mitigate an incident. * Incident
Recurrence Rate: Measures whether the same or similar incidents are occurring repeatedly,
indicating the effectiveness of risk controls.
GRC Program Efficiency: * Cost of Compliance vs. Non-Compliance: Compares the cost of
implementing and maintaining compliance with the financial impact of non-compliance (penalties,
fines, etc.). * GRC Integration Efficiency: Evaluates how well governance, risk management, and
compliance processes are integrated into business operations. * Technology Utilization:
Measures the degree to which GRC technologies are used effectively to automate processes,
streamline reporting, and reduce manual effort.
Overall Performance Metrics: * ROI on GRC Investments: This metric evaluates the return on
investment (ROI) for GRC initiatives, comparing costs against measurable benefits, such as
reduced incidents, improved compliance, and more effective risk management. * Risk Exposure
Reduction: Measures the overall reduction in risk exposure across different categories
(operational, financial, legal) as a result of GRC activities. * Audit Results: Successful internal or
external audit outcomes indicate strong GRC processes.
Certification
For Beginners: - Certified in Risk and Information Systems Control (CRISC): Focuses on risk
management. - Certified Information Systems Auditor (CISA): Covers auditing, control, and
assurance.
For Expert Level: - Certified in Risk Management Assurance (CRMA): Focuses on risk
management and assurance. - Certified Information Security Manager (CISM): Focuses on
information security management, including governance and risk management.
Resources
Books
• “Governance, Risk, and Compliance Handbook for Financial Services” by J. J. Stone
• “Managing Risk in Information Systems” by D. G. Peltier
• “The Complete Guide to Cybersecurity Risks and Controls” by Anne Kohnke, et al.
Videos/Tutorials
• YouTube Channels: GRC-related content can be found on channels like “InfoSec Institute,”
“Cybrary,” and “SANS Institute.”
• Practical GRC Series: Part 1 by Prabh Nair
• Practical GRC Series: Part 2 by Prabh Nair
Online Platforms
• LinkedIn Learning: Offers courses on risk management, governance, and compliance.
• Pluralsight: Provides courses on GRC concepts and frameworks.
• Coursera/Udemy/Udacity/EdX: Look for courses on GRC fundamentals, risk management,
and compliance.
Communities
• ISACA: Offers resources, forums, and events for GRC professionals.
• GRC Summit: An annual event where professionals can network and learn about the latest
in GRC.
• ISC2 Community: An active group where professionals help each other through various
ways including meetup, training, guidance, job referrals etc.
Useful Links
• You will get what you need for ISO 27001 here
• NIST RMF
Chapter 9
Azure Security
This study plan is designed to help you master Azure Security, from foundational concepts to
advanced security engineering and operations. It aligns with Microsoft certifications like AZ-500
and SC series.
ToC
1. Azure Fundamentals - 2 weeks
2. Identity and Access Management - 2 weeks
3. Platform Protection - 2 weeks
4. Security Operations - 2 weeks
5. Resources
Azure Fundamentals
Duration: 2 weeks
Platform Protection
Duration: 2 weeks
Security Operations
Duration: 2 weeks
Resources
Certifications
• AZ-500: Azure Security Technologies (Core certification).
• SC-900: Security, Compliance, and Identity Fundamentals.
• SC-200: Security Operations Analyst (Sentinel/Defender focus).
• SC-300: Identity and Access Administrator (Entra ID focus).
Learning Paths
• Microsoft Learn: Azure Security Engineer
• Microsoft Learn: SC-200
DevSecOps
This study plan is based on milestones. So, check how much you can cover within the timeline.
The more you cover the topics, the better candidate you are for the job roles which require good
knowledge of DevSecOps. Also, I assume you have already checked and are comfortable with
Common Security Skills study plan.
Just to make sure that everyone understands what you need to learn to be a DevSecOps
Engineer / DevSecOps-focused security engineer. DevSecOps is not just "adding security tools to
CI/CD". It is about building security into how software is planned, built, tested, delivered, and
operated - with as much automation and feedback as possible.
It is more towards: - working closely with developers, SRE/DevOps, and AppSec, - integrating
security checks into pipelines and platforms, - defining secure defaults and guardrails, - enabling
teams to ship fast and safely.
Usually it will take you 6-12 months to be good at the DevSecOps fundamentals to get a job at
entry level or move laterally from AppSec/DevOps into a DevSecOps role.
In short
1. DevSecOps is not a separate silo - it is how development, security, and operations work
together.
2. Think more of a combination of developer, DevOps/SRE, and security engineer.
3. You should be comfortable with CI/CD systems, containers, and basic cloud concepts.
4. You should know enough Application Security to choose and tune the right checks.
5. Automation, feedback loops, and culture change are as important as tools.
ToC
1. DevSecOps Fundamentals - 3-4 weeks
2. CI/CD and Automation Basics - 3-4 weeks
3. Security Testing in the Pipeline - 4-6 weeks
4. Cloud, Containers and IaC Security - 4-6 weeks
5. Platform Guardrails and Governance - 3-4 weeks
6. Metrics, Feedback and Culture - 2-3 weeks
7. Books
8. Videos
9. Courses
10. Certifications
11. Interview Questions
DevSecOps Fundamentals
Duration: 3-4 weeks
Goal here is to understand what DevSecOps is and what problems it tries to solve.
Here you focus on what kinds of security checks you can automate and where.
Books
1. Any solid DevOps/Continuous Delivery book to understand the base culture and practices.
2. Books on building Application Security programs (see Application Security plan) - useful for
understanding what you are automating.
3. Books on cloud-native security and container security that include CI/CD viewpoints.
Videos
1. Conference talks on DevSecOps (OWASP, DevOpsDays, KubeCon, etc.).
2. Videos showing real-world CI/CD security implementations.
3. Talks on security automation, policy-as-code, and platform engineering.
Courses
1. DevSecOps-focused courses that cover CI/CD, automation, and security tooling.
2. Cloud-native security courses that include pipeline and platform topics.
3. Container and Kubernetes security courses that show how to integrate checks into
pipelines.
Certifications
1. Cloud security certifications related to your main cloud provider (AWS/Azure/GCP).
2. DevOps/Cloud-native certifications that cover CI/CD and containers.
3. Application Security or Secure SDLC certifications if you want to emphasize the security
side.
Interview Questions
You can reuse many questions from the Application Security interview questions and from any
cloud/security interviews, but focus on how you would automate and integrate security into
pipelines and platforms.
1. How would you add security checks into an existing CI/CD pipeline without slowing teams
down too much?
2. How do you decide which security tools to run on pull requests vs in nightly builds?
3. How would you integrate container and IaC scanning into the delivery process?
4. How would you measure the success of a DevSecOps initiative over 6-12 months?
Chapter 11
Docker Security
This study plan is based on milestones. So, check how much you can cover within the timeline.
The more you cover the topics, the better candidate you are for the job roles which require good
knowledge of Docker and container security. Also, I assume you have already checked and are
comfortable with Common Security Skills study plan.
Just to make sure that everyone understands what you need to learn to be good at
Docker/container security. Docker Security is a focused subset of cloud-native security and
DevSecOps. You need to understand how images and containers work, what can go wrong, and
how to build and run them securely across the SDLC.
It is more towards: - building minimal and secure container images, - understanding runtime
hardening and isolation, - integrating image scanning into CI/CD, - and working with DevSecOps /
Platform teams on secure base images.
Usually it will take you 4-8 weeks to be comfortable with Docker Security fundamentals, assuming
you already know basic Docker usage.
In short
1. Docker Security is not just running a scanner on images.
2. Think more of image hygiene + least privilege + secure defaults.
3. You should be comfortable writing and reviewing Dockerfiles.
4. You must understand how containers differ from VMs and what isolation they provide (and
don’t).
5. You should know where Docker Security fits into DevSecOps and cloud security.
ToC
1. Docker and Container Fundamentals - 1-2 weeks
2. Image Build and Supply Chain Security - 1-2 weeks
3. Runtime Hardening and Host Security - 1-2 weeks
4. Scanning, Policies and CI/CD Integration - 1-2 weeks
5. Books
6. Videos
7. Courses
8. Certifications
9. Interview Questions
Goal here is to be very comfortable with how Docker works before going deep into security.
Here you focus on building secure images and understanding supply chain risk.
Even with secure images, runtime and host configuration matter a lot.
Books
1. Any good Docker/Container fundamentals book - focus on sections about security and best
practices.
2. Books on container security or cloud-native security that include Docker as a base.
Videos
1. Docker security talks from major conferences (DockerCon, KubeCon, OWASP).
2. Short tutorials on writing secure Dockerfiles and hardening images.
3. Videos on container runtime hardening and host security.
Courses
1. Docker/Container security courses that cover image hardening and runtime security.
2. DevSecOps courses that include container image scanning and CI/CD integration.
Certifications
1. Container or cloud-native security certifications where Docker is a key part of the
curriculum.
2. General cloud security certifications (AWS/Azure/GCP) if you deploy Docker workloads to
cloud.
Interview Questions
You can reuse some questions from Application Security and DevSecOps, but focus on
containers:
Kubernetes Security
This study plan is based on milestones. So, check how much you can cover within the timeline.
The more you cover the topics, the better candidate you are for the job roles which require good
knowledge of Kubernetes and container orchestration security. Also, I assume you have already
checked and are comfortable with Common Security Skills study plan.
Just to make sure that everyone understands what you need to learn to be good at Kubernetes
Security. Kubernetes Security builds on Docker/container security and cloud security. You need to
understand how Kubernetes works, how workloads are deployed and exposed, and what controls
exist at cluster, namespace, and workload levels.
It is more towards: - securing clusters and control plane access, - defining secure defaults for
workloads (namespaces, RBAC, network policies), - integrating Kubernetes security checks into
DevSecOps pipelines, - and working with platform/SRE teams to keep clusters hardened.
Usually it will take you 6-10 weeks to be comfortable with Kubernetes Security fundamentals,
assuming you already know basic Docker and some Kubernetes usage.
In short
1. Kubernetes Security is not just enabling a few network policies.
2. Think more of multi-layer defense: cluster, namespace, workload, network, and supply
chain.
3. You should be comfortable with basic Kubernetes concepts (pods, deployments, services,
ingress, configmaps, secrets).
4. You should understand how containers and images are built and scanned (see Docker
Security Study Plan).
5. You should know how Kubernetes fits into DevSecOps and cloud-native security.
ToC
1. Kubernetes Fundamentals for Security - 1-2 weeks
2. Cluster and Control Plane Security - 1-2 weeks
3. Workload and Identity Security - 2-3 weeks
4. Network, Policies and Multi-tenancy - 1-2 weeks
5. Supply Chain and Runtime Security - 1-2 weeks
6. Books
7. Videos
8. Courses
9. Certifications
10. Interview Questions
Cluster Hardening
Duration: 1-2 weeks
Workload Security
Duration: 1-2 weeks
1. Supply chain:
2. Image registries and allowed registries.
3. Image scanning before deployment.
4. Admission controllers or policy engines (at a high level) to enforce constraints.
5. Runtime security:
6. Monitoring workloads for suspicious behavior.
7. Basic idea of using runtime security tools to detect attacks.
8. Cross-link to other plans:
9. Docker Security Study Plan.
10. DevSecOps Study Plan.
11. Relevant cloud security study plans if running managed Kubernetes.
Books
1. Kubernetes fundamentals books - focus on the chapters about security.
2. Dedicated Kubernetes security or cloud-native security books that cover RBAC, network
policies, and admission control.
Videos
1. Kubernetes security talks from KubeCon, CNCF events, and OWASP.
2. Tutorials on securing RBAC, network policies, and pod security.
3. Videos on managed Kubernetes security (EKS, AKS, GKE) from cloud providers.
Courses
1. Kubernetes security-focused courses (often part of cloud-native security tracks).
2. Hands-on labs for Kubernetes RBAC, network policies, and workload hardening.
3. DevSecOps courses which include Kubernetes integration.
Certifications
1. Kubernetes-related certifications that cover security (CKA/CKS and similar) if they align
with your goals.
2. Cloud security or cloud-native certifications where Kubernetes is a major component.
Interview Questions
You can reuse questions from Docker Security, DevSecOps, and cloud security but focus on
Kubernetes specifics:
1. How would you secure access to a Kubernetes cluster for multiple teams?
2. How would you restrict which services/pods can talk to each other?
3. What are the risks of running privileged containers and how do you prevent it?
4. How would you ensure only trusted images are deployed in a cluster?
Chapter 13
Network Security
In this plan, let's assume that you already have some computer science skills (linux basics,
common windows or mac os use, search on the internet, edit a file...).
But first, what is network security ? Network security includes all methods, both defensive and
offensive, to protect and maintain functional a network.
This plan has several objectives, in short : - Understand networks and how it works - Common
vulnerabilities and how to detect them - How to remedy these vulnerabilities and secure your
network
ToC
1. Network Fundamentals - 2 weeks
2. Network Defense - 2 weeks
3. Network Attacks and Analysis - 2 weeks
4. Wireless and Advanced Topics - 2 weeks
5. Resources
Network Fundamentals
Duration: 2 weeks
In this first part you will focus on learning the basics concepts of networks (architectures,
protocols, OSI model).
Network Defense
Duration: 2 weeks
To finish with this plan, as I said above, you should at least create free-accounts on platforms
such as tryhackme or rootme. This is useful to learn cybersecurity and developp skills and
knowledge.
You should create a github account too, to post code and projects about cybersecurity or
whatever you want (if you don't code yet, please consider this other tryhackme module. After
that, you will certainly find content on youtube to go further in programming, which is more
than useful for cybersecurity.
A X(twitter) account can be useful too to keep informed of cybersecurity news and to build a
reputation into the domain.
If you want to go deeper into monitoring, detection and incident response after Network Security,
read the Blue Team, Detection & Response Study Plan.
Chapter 14
Cryptography
In this plan, let's assume that you already have some computer science skills (linux basics,
common windows or mac os use, search on the internet, edit a file...).
But first, what is cryptography ? cryptography is the practice and study of techniques for
secure communication in the presence of adversarial behavior.
This plan has several objectives, in short : - learn about cryptography theoric concepts - become
familiar with useful cryptography tools - how to apply all this acknoledgment in the context of
cybersecurity
ToC
1. Theoretical Concepts - 2 weeks
2. Applied Cryptography - 2 weeks
3. Cryptography Tools - 2 weeks
4. Cryptanalysis & Challenges - 2 weeks
5. Resources
Theoretical Concepts
Duration: 2 weeks
In this first part you will focus on learning the basics concepts of cryptography (algorithms,
keys, PKI, hashing).
Applied Cryptography
Duration: 2 weeks
How to apply this knowledge in the context of cybersecurity and secure communications.
Cryptography Tools
Duration: 2 weeks
Become familiar with useful cryptography tools for analysis and implementation.
Resources
Platforms
• [Link]
• TryHackMe
• RootMe
Books
• Serious Cryptography by Jean-Philippe Aumasson
• Real-World Cryptography by David Wong
Chapter 15
This study plan is based on milestones. So, check how much you can cover within the timeline.
The more you cover the topics, the better candidate you are for the job roles which require good
knowledge of software supply chain security. Also, I assume you have already checked and are
comfortable with Common Security Skills study plan.
Just to make sure that everyone understands what you need to learn to be good at Software
Supply Chain Security. Software supply chain security is about securing all the components, tools,
and services that go into building, packaging, and delivering software: source code,
dependencies, build systems, CI/CD pipelines, artifacts, and runtime environments.
It is more towards: - understanding how code and dependencies flow from dev laptops to
production, - securing dependencies and third-party components, - hardening build and CI/CD
systems, - ensuring integrity of artifacts and deployments, - and responding to supply chain
incidents quickly.
Usually it will take you 8-16 weeks to be comfortable with software supply chain security
fundamentals, depending on your background in AppSec, DevSecOps, and cloud.
In short
1. Software supply chain security is not just dependency scanning.
2. Think more of end-to-end integrity: from source to production.
3. You should be comfortable with version control, CI/CD, and package managers.
4. You should know the basics of DevSecOps, Docker/Kubernetes, and cloud.
5. You must understand how real-world incidents happened to avoid repeating them.
ToC
1. Supply Chain Fundamentals - 2-3 weeks
2. Dependencies and Package Ecosystems - 2-3 weeks
3. Build Systems and CI/CD Security - 2-3 weeks
4. Artifact Integrity, Signing and SBOM - 2-3 weeks
5. Historical Supply Chain Incidents - 1-2 weeks
6. Detection, Response and Governance - 2-3 weeks
7. Books
8. Videos
9. Courses
10. Certifications
11. Interview Questions
This is about making sure what you build is exactly what gets deployed.
Finally, focus on how to detect and respond to supply chain issues and how to govern the
program.
Books
1. Any good book on software supply chain or modern software security that includes supply
chain chapters.
2. Books on DevSecOps and cloud-native security that cover CI/CD and dependencies.
Videos
1. Conference talks on software supply chain attacks and defenses.
2. Deep dives on major incidents (e.g., large vendor compromises, dependency attacks).
3. Talks on SBOMs, signing, and secure build pipelines.
Courses
1. Courses specifically focused on software supply chain security, if available.
2. DevSecOps courses with strong coverage of CI/CD and dependency scanning.
3. Cloud-native security courses that include supply chain topics.
Certifications
1. General cloud security and DevSecOps certifications that include supply chain security.
2. Any vendor-neutral or vendor-specific certifications that emphasize secure SDLC and
CI/CD.
Interview Questions
You can reuse questions from Application Security, DevSecOps, and cloud security, but add
supply chain focus:
1. How would you reduce the risk of malicious dependencies in a large organization?
2. What controls would you put around CI/CD systems to protect against supply chain
attacks?
3. How would you respond if a widely used third-party library in your product was suddenly
found to be compromised?
4. How would you explain the importance of SBOMs and artifact signing to engineering
leadership?
Chapter 16
This study plan is designed to help you master the art of Secure Code Review. It covers
methodologies, common vulnerabilities, tools, and best practices for identifying security flaws in
source code.
ToC
1. Code Review Fundamentals - 2 weeks
2. Common Vulnerabilities in Code - 2 weeks
3. Process and Checklists - 2 weeks
4. Tools and Automation - 2 weeks
5. Resources
Resources
Guides
• OWASP Secure Code Review Guide
• OWASP Top 10
• CWE Top 25
Tools
• Semgrep
• SonarQube
• CodeQL
Practice
• Secure Code Warrior (Free trial/community)
• SonarQube Rules Explorer (Learn by seeing bad vs good code)
Chapter 17
Secure SDLC
This study plan is based on milestones. So, check how much you can cover within the timeline.
The more you cover the topics, the better candidate you are for roles which require good
understanding of secure SDLC / SDL. Also, I assume you have already checked and are
comfortable with Common Security Skills study plan.
Just to make sure that everyone understands what you need to learn to be good at Security
Development Lifecycle. SDL is about building security into each phase of software delivery - from
requirements and design to coding, testing, release, and maintenance - instead of treating
security as a separate step at the end.
It is more towards: - defining security activities and checkpoints in the SDLC, - aligning
developers, product, and security teams on expectations, - integrating
AppSec/DevSecOps/Product Security work into a repeatable process, - and giving organizations
a structured way to measure and improve security maturity.
Usually it will take you 6-12 weeks to be comfortable with SDL fundamentals and how to apply
them in real projects.
In short
1. SDL is not just a document - it is how security is embedded into the way software is built.
2. Think more of a framework that connects Application Security, DevSecOps, Product
Security, and Architecture.
3. You should be comfortable talking about phases of SDLC and which security activities
belong where.
4. You should know how to keep SDL practical for agile and cloud-native teams.
5. You must understand how to start small and evolve the SDL over time.
ToC
1. SDL Fundamentals - 1-2 weeks
2. Security in Requirements and Design - 2-3 weeks
3. Security in Implementation and Code Review - 2-3 weeks
4. Security Testing and Verification - 2-3 weeks
5. Release, Operations and Feedback - 1-2 weeks
6. Frameworks and Maturity Models - 1-2 weeks
7. Books
8. Videos
9. Courses
10. Certifications
11. Interview Questions
SDL Fundamentals
Duration: 1-2 weeks
Books
1. Books on building Application Security or Product Security programs - for seeing how SDL
is implemented in practice.
2. Any secure software development or secure coding books that tie into SDLC.
Videos
1. Developing Secure Software (LFD121) by The Linux Foundation (free).
2. Conference talks on SDL / secure SDLC and how organizations implemented it in
agile/DevOps environments.
3. Talks on OWASP SAMM and real-world program maturity journeys.
Courses
1. Courses focused on secure software development or secure SDLC.
2. DevSecOps and Application Security courses that show how to integrate security into
pipelines and processes.
Certifications
1. CSSLP: Certified Secure Software Lifecycle Professional.
2. Other secure software development or AppSec/DevSecOps certifications depending on
your focus.
Interview Questions
You can reuse many questions from the Application Security and Product Security interview sets,
but think of them through the SDL lens:
1. How would you introduce security into an existing agile SDLC with minimal disruption?
2. Which security activities would you recommend at each phase of the SDLC and why?
3. How would you measure whether your SDL is working and improving over time?
Chapter 18
Security Architecture
This study plan is based on milestones. So, check how much you can cover within the timeline.
The more you cover the topics, the better candidate you are for the job roles which require good
knowledge of security architecture. Also, I assume you have already checked and are comfortable
with Common Security Skills study plan.
Just to make sure that everyone understands what you need to learn to be a Security Architect /
Security Architecture-focused engineer. Security Architecture is different from just "doing AppSec"
or "doing pentesting". You need to understand how to design secure systems end-to-end across
applications, infrastructure, cloud, data, and identities.
It is more towards: - defining guardrails and reference architectures, - driving secure design
decisions early, - aligning with frameworks and standards, - and working closely with AppSec,
Cloud, Infrastructure and GRC teams.
Usually it will take you 6-12 months to be good at the Security Architecture fundamentals to get a
job at entry level or move laterally into an architect-type role.
In short:
1. Security Architecture is not only pentesting or only AppSec.
2. Think more of a combination of engineer, designer, and risk manager.
3. Talking to engineering leaders, architects, product owners, and GRC teams should not
scare you.
4. You must be comfortable with diagrams, data flows, and threat modeling.
5. You should understand both on■prem and cloud architectures (at least one major CSP).
6. You should be able to review designs and propose secure patterns with confidence.
ToC:
1. Security Architecture Fundamentals - 4-6 weeks
2. Frameworks, Standards and Models - 3-4 weeks
3. Designing Secure Architectures - 4-6 weeks
4. Threat Modeling and Risk Management - 3-4 weeks
5. Secure SDLC and Architecture Governance - 3-4 weeks
6. Reference Architectures and Patterns - 3-4 weeks
7. Books
8. Videos
9. Courses
10. Certifications
11. Interview Questions
Goal here is to understand what security architecture means and where it fits in the overall
security program.
You don't need to memorize everything, but you should know what exists, when to use it, and
where to look.
Security architecture is effective only if it is built into the way software is delivered.
Books
1. Enterprise Security Architecture: A Business-Driven Approach
2. Agile Application Security - good for seeing how architecture and AppSec work together
3. Security Engineering by Ross Anderson - classic reference on designing secure systems
4. The Tangled Web: A Guide to Securing Modern Web Applications
Videos
1. Search for "Security Architecture" talks from OWASP, Black Hat, or RSA on YouTube.
2. Talks on threat modeling and secure design (many are linked from the Threat Modeling
Study Plan).
3. Cloud provider "Well■Architected" security deep■dives (AWS, Azure, GCP official
channels).
Courses
1. Any good "Enterprise Security Architecture" or "Security Architecture and Design" course
from trusted platforms.
2. Cloud security architecture courses from your preferred CSP (AWS, Azure, or GCP) - align
with your cloud security plan.
3. Threat modeling and secure design courses (see Threat Modeling study plan for specific
links).
Certifications
1. CSSLP: Certified Secure Software Lifecycle Professional
2. CCSP: Certified Cloud Security Professional
3. Vendor-specific cloud security or architecture certifications (AWS, Azure, GCP) depending
on your focus.
Interview Questions
You can use the Application Security interview questions and think how you would answer them
from an architecture perspective (design choices, trade■offs, and patterns), and extend with:
1. How would you design a secure architecture for a public web application with APIs and
mobile clients?
2. How would you design logging and monitoring for a critical payments system?
3. How would you approach threat modeling for a new microservices-based product?
Chapter 19
GenAI Security
This study plan covers all the topics, concepts, blogs, videos, books, videos, newsletters etc. by
keeping GenAI security in mind.
It should take 6-9 months to be good at GenAI security so that you can do one or more of the
below listed things: 1. LLM pentesting 2. GenAI security assessment 3. Design and implement
secure GenAI/LLM architectures for organizations. 4. Understanding of GenAI from GRC
perspective 5. Knowledge of different GenAI security frameworks 6. AI enabled Threat Modeling
or Threat Modeling of AI systems 7. Good grip on LLM safety, LLM Guardrails, Responsible AI, AI
ethic etc.
It would help you in your current work as well as finding a new work using GenAI security skills.
Note: I am not writing anything that would require core AI/ML skills. It's all are done after keeping
security focus in mind.
"[!IMPORTANT] This field is still evolving, so our repo would too! Stay tuned!"
Prompt Engineering
Duration: 1 week
Fine Tuning
Duration: 2 weeks
AI Agents
Duration: 1 week
Understanding AI Agents
■ AI Agent Fundamentals
• What are AI agents and how they differ from simple LLMs
• Agent architectures: ReAct, Plan-and-Execute, Multi-agent systems
• Tool use and function calling
• Memory and state management in agents
• [ ] Types of AI Agents
• Conversational agents
• Task-specific agents
• Autonomous agents
• Multi-agent systems and collaboration
AI Agent Security
■ Security Risks with AI Agents
• Excessive agency and unauthorized actions
• Tool misuse and privilege escalation
• Agent-to-agent communication security
• Persistent memory security risks
• [ ] Securing AI Agents
• Principle of least privilege for agents
• Action validation and approval workflows
• Monitoring agent behavior and decisions
• Secure tool integration patterns
Hands-on Practice: - [ ] Build a simple AI agent with security controls - [ ] Test agent behavior
under various scenarios - [ ] Implement monitoring for agent actions
Agentic AI
Duration: 1 week
Security in Agentic AI
■ Unique Security Challenges
• Emergent behaviors in agentic systems
• Goal misalignment and specification gaming
• Inter-agent security and trust
• Scalability of security controls
• [ ] Governance for Agentic AI
• Establishing boundaries and constraints
• Monitoring and auditing agentic behavior
• Human oversight and intervention mechanisms
• Ethical considerations in autonomous systems
Hands-on Practice: - [ ] Design security controls for agentic systems - [ ] Analyze case studies of
agentic AI failures - [ ] Develop monitoring strategies for autonomous agents
Understanding MCP
■ MCP Fundamentals
• What is Model Context Protocol
• MCP architecture and components
• Client-server communication patterns
• Resource management and sharing
• [ ] MCP Implementation
• Setting up MCP servers and clients
• Resource discovery and access
• Tool integration through MCP
• Context sharing between applications
MCP Security
■ Security Considerations
• Authentication and authorization in MCP
• Resource access control
• Data privacy in context sharing
• Network security for MCP communications
• [ ] Best Practices
• Secure MCP server deployment
• Client-side security measures
• Monitoring MCP interactions
• Incident response for MCP systems
Hands-on Practice: - [ ] Set up a secure MCP environment - [ ] Implement access controls for
MCP resources - [ ] Test MCP security configurations
Certifications
Duration: Based on your bandwidth and goals
Scenario-Based Questions
■ Risk Assessment Scenarios
• "A company wants to implement a customer service chatbot using GPT-4. What security
risks would you identify?"
• "How would you conduct a security assessment of an existing LLM application?"
• "Design a secure architecture for a RAG-based document Q&A system"
• [ ] Incident Response Scenarios
• "An LLM application is leaking sensitive customer data. How would you investigate?"
• "Users report that the chatbot is providing inappropriate responses. What's your approach?"
• "A competitor seems to have extracted your fine-tuned model. How do you respond?"
Implementation Checklist
■ Evaluate tools based on your specific use case
■ Set up monitoring and alerting for LLM applications
■ Implement input/output filtering and validation
■ Deploy model scanning in CI/CD pipelines
■ Establish incident response procedures
■ Regular security assessments and penetration testing
■ Stay updated with latest tools and techniques
Additional Resources
1. Courses & University Materials
2. Stanford CS324: Large Language Models
3. Princeton COS 597G: Understanding Large Language Models
4. Coursera: Generative AI with LLMs (AWS & [Link])
5. Coursera: Generative AI Engineering with LLMs Specialization
6. Coursera: Generative AI for Cybersecurity Professionals (IBM)
7. Coursera: AI for Cybersecurity Specialization (Johns Hopkins)
8. AttackIQ: Foundations of AI Security
9. Security Guides & Checklists
10. OWASP Top 10 for LLM Applications
11. OWASP LLM AI Security and Governance Checklist
12. NIST AI Risk Management Framework (AI RMF)
13. NIST AI RMF Playbook
14. NIST Adversarial Machine Learning
15. Microsoft: Threat Modeling AI/ML
16. [Link]: Quick AI Threat Model Check
17. Failure Modes in Machine Learning
18. Articles & Blogs
19. DataCamp: What are Foundation Models
20. Lasso Security: Riding the RAG Trail
21. IronCore Labs: Security Risks with RAG Architectures
22. Cloud Security Alliance: Mitigating Security Risks in RAG
23. Nightfall AI: RAG - The Essential Guide
24. Immuta: Why RAG is Revolutionising GenAI
25. Medium: Prompt Injection Jailbreaking
26. Medium: Safeguarding LLM with LLM Guard
27. Mercari: Security Incident Response using LLM
28. Tools & Platforms
29. LLM Security Portal
30. PortSwigger: Web LLM Attacks
31. [Link]: AI/ML Bug Bounty Platform
32. ProtectAI GitHub (LLM Guard, ModelScan, AI Exploits)
33. LLM Guard Playground
34. Challenges & CTFs
35. Gandalf: LLM Security Challenge
36. Prompt Airlines: AI Security CTF
37. SecOps Group: Certified AI/ML Pentester Exam
38. Videos
39. WhyLabs: Intro to LLM Security
Chapter 20
Product Security
This study plan is based on milestones. So, check how much you can cover within the timeline.
The more you cover the topics, the better candidate you are for the job roles which require good
knowledge of Product Security. Also, I assume you have already checked and are comfortable
with Common Security Skills study plan.
Just to make sure that everyone understands what you need to learn to be a Product Security
Engineer / Product Security Lead. Product Security is different from a pure "pentesting" role. It is
closer to Application Security, but more embedded with product teams, helping them ship secure
features quickly while balancing risk, user experience, and business goals.
It is more towards: - enabling and coaching product & engineering teams, - building and improving
security into the product lifecycle, - driving secure design, threat modeling, and remediation, -
partnering with AppSec, Cloud, and GRC to make security a feature of the product.
Usually it will take you 6-12 months to be good at the Product Security fundamentals to get a job
at entry level or move laterally from AppSec/engineering into a Product Security role.
In short:
1. Product Security is not only bug hunting or pentesting.
2. Think more of a combination of application security engineer, product engineer, and
security program owner.
3. You work very closely with PMs, tech leads, architects, and developers.
4. You should be comfortable talking about risk, trade■offs, and timelines.
5. You should know enough AppSec, Cloud, and SDLC to help teams make good decisions.
6. You must be able to translate technical issues into business impact and priorities.
ToC:
1. Product Security Fundamentals - 3-4 weeks
2. Working with Product and Engineering - 2-3 weeks
3. Secure SDLC in Product Teams - 4-6 weeks
4. Threat Modeling and Risk-Based Prioritization - 3-4 weeks
5. Metrics, Backlog and Communication - 2-3 weeks
6. Integrations with AppSec, Cloud and GRC - 2-3 weeks
7. Books
8. Videos
9. Courses
10. Certifications
11. Interview Questions
Goal here is to understand what Product Security is and where it sits between AppSec,
engineering, and the rest of the security org.
Here you focus on making the Secure SDLC practical for product teams.
You also need to help leadership understand where the product stands.
Books
There is no single canonical "Product Security" book, but these are very useful:
Videos
1. Talks on building or scaling Product Security / AppSec programs (search recent
OWASP/BSides/Black Hat talks).
2. Videos on secure SDLC and DevSecOps that emphasize working with product/engineering
teams.
3. Threat modeling and secure design talks (linked from the Threat Modeling and Application
Security study plans).
Courses
1. Courses on building Application Security or Product Security programs from well■known
training providers.
2. DevSecOps / Secure SDLC courses that include integration with CI/CD and product
workflows.
3. Threat modeling and architecture courses that show how to work with cross■functional
teams.
Certifications
1. CSSLP: Certified Secure Software Lifecycle Professional
2. Cloud security certifications (AWS/Azure/GCP) if your products are cloud■native.
3. Application Security or DevSecOps■oriented certifications, depending on your focus.
Interview Questions
You can reuse many questions from the Application Security interview questions but think about
them in terms of how you would embed security into product teams.
1. How would you integrate security into a team that ships features every 1-2 weeks?
2. How do you decide which security issues must be fixed before release and which can go
into backlog?
3. How would you introduce threat modeling into a product team that has never done it
before?
4. How would you communicate a critical security issue to product and engineering
leadership?
Chapter 21
IAM Security
This study plan is based on milestones. So, check how much you can cover within the timeline.
The more you cover the topics, the better candidate you are for job roles which require strong
Identity & Access Management skills (AppSec, Cloud Security, Product Security, GRC, Security
Architecture, etc.).
Also, I assume you have already checked and are comfortable with Common Security Skills study
plan.
It will cover what you need to learn to excel at IAM from both application and cloud perspectives.
How this connects: Use this plan alongside the AWS, Azure, and GCP security study plans for
cloud-specific IAM, and with the Application Security, Security Architecture, and Security
Development Lifecycle study plans when you are designing or reviewing secure systems.
In short
1. IAM is not just “creating users and groups” - it is access control for everything.
2. Think of IAM as the new perimeter across apps, APIs, cloud, and SaaS.
3. You must be comfortable with AuthN/AuthZ concepts and common protocols.
4. You should understand how IAM is implemented in AWS, Azure, and GCP at a high level.
5. You should recognize common IAM misconfigurations and how to avoid them.
ToC
1. IAM Fundamentals - 2 weeks
2. Authentication (AuthN) Deep Dive - 2 weeks
3. Authorization (AuthZ) & Access Control - 2 weeks
4. Cloud Provider IAM (AWS/Azure/GCP) - 3-4 weeks
5. Identity Lifecycle, Privileged Access & Federation - 2-3 weeks
6. Threats, Misconfigurations & Hardening - 2-3 weeks
7. Books
8. Videos
9. Courses
10. Certifications
11. Interview Questions
IAM Fundamentals
Duration: 2 weeks
Goal: build a solid mental model of IAM, identities, and access control.
Goal: understand how identities are managed over time and across systems.
Videos
1. Conference talks on IAM, SSO, OAuth/OIDC pitfalls, and cloud IAM misconfigurations.
2. Cloud provider official IAM deep-dive videos (AWS re:Invent, Azure, GCP).
3. Talks on Zero Trust and modern identity-centric security.
Courses
1. Cloud security fundamentals courses with strong IAM modules.
2. Vendor-specific identity courses (e.g., AWS, Azure, GCP IAM).
3. Courses focused on OAuth 2.0 / OIDC and modern auth patterns.
Certifications
1. Cloud security certifications (AWS/Azure/GCP) where IAM is a major part of the exam.
2. Identity-focused or access management certifications if they align with your goals.
3. General security certs (CISSP, CCSP, etc.) for broader context around IAM.
Interview Questions
You can reuse questions from Application Security, Cloud Security, and Security Architecture, but
focus on Identity & Access:
1. How would you design authentication and authorization for a new web/mobile app?
2. How would you migrate on-prem identities to a cloud IdP safely?
3. How do you enforce least privilege across many AWS accounts or Azure subscriptions?
4. How would you investigate and respond to a suspected IAM credential compromise?
Chapter 22
This study plan is based on milestones. So, check how much you can cover within the timeline.
The more you cover the topics, the better candidate you are for job roles focused on Blue Team,
SOC, Detection Engineering, and Incident Response.
Also, I assume you have already checked and are comfortable with Common Security Skills study
plan.
It will cover what you need to learn to monitor, detect, and respond to attacks across endpoints,
networks, applications, and cloud.
How this connects: Start with Common Skills and Network Security, then pair this plan with the
cloud study plans (AWS, Azure, GCP) and Web Pentest / Application Security so you can detect
attacks you or others already know how to perform. Combine it with Threat Modeling to turn
identified threats into concrete detections and playbooks.
In short
1. Blue Team is not just “watching a SIEM” - it’s about detecting and responding to real
attacks.
2. You must understand how logs, telemetry, and alerts are generated and correlated.
3. You should know the incident response lifecycle and how to build playbooks.
4. You should be comfortable mapping activity to frameworks like MITRE ATT&CK.
5. You should understand basics of cloud, endpoint, and network telemetry.
ToC
1. Blue Team & SOC Fundamentals - 2 weeks
2. Logging, Telemetry & SIEM - 2-3 weeks
3. Detection Engineering & Threat Hunting - 3-4 weeks
4. Incident Response (IR) Fundamentals - 3-4 weeks
5. Digital Forensics Basics - 2-3 weeks
6. Cloud & Modern Environments - 2-3 weeks
7. Books
8. Videos
9. Courses
10. Certifications
11. Interview Questions
Goal: understand what the Blue Team does and how SOCs operate.
Goal: understand detection & response in cloud, SaaS, and modern stacks.
Books
1. Any strong Blue Team / SOC operations book.
2. Books on incident response and digital forensics.
3. Books that walk through case studies of real intrusions.
Videos
1. Conference talks on detection engineering, Blue Teaming, and SOC operations.
2. IR and DFIR case study talks (how real incidents were handled).
3. Vendor-agnostic content on SIEM best practices and ATT&CK-based detections.
Courses
1. Blue Team / SOC analyst fundamentals courses.
2. IR/DFIR-focused training with hands-on labs.
3. Threat hunting and detection engineering courses using common SIEM/XDR tools.
Certifications
1. Entry-level SOC / Blue Team certs if available from reputable providers.
2. IR/DFIR-oriented certifications if you want to specialize.
3. General security certs (like Security+) to support foundational knowledge.
Interview Questions
You can reuse questions from Network Security, Cloud Security, and GRC but focus on detection
& response:
1. How would you design logging for a new web application or API?
2. How do you triage an alert that might be a false positive?
3. How would you investigate a suspected account compromise in a cloud environment?
4. How do you measure the effectiveness of your detections and IR process?
Chapter 23
This study plan is based on milestones. So, check how much you can cover within the timeline.
The more you cover the topics, the better candidate you are for job roles which require good
knowledge of mobile (Android/iOS) application security.
Also, I assume you have already checked and are comfortable with Common Security Skills study
plan and Web Pentest study plan.
It will cover what you need to learn to test and secure mobile apps, including client, API, and
backend aspects.
How this connects: Use this plan together with the Web Pentest, Application Security, and API
Security study plans, since mobile apps almost always talk to web backends and APIs.
In short
1. Mobile security is not just “web in a smaller screen” - there are platform-specific risks.
2. You must understand Android and iOS app models and storage.
3. You should be comfortable proxying traffic, analyzing APK/IPA, and using common tools.
4. You should align with OWASP MASVS/MSTG for methodology.
5. You must consider both the app and its backend APIs.
ToC
1. Mobile Fundamentals - 2 weeks
2. Android Security - 3-4 weeks
3. iOS Security - 3-4 weeks
4. Mobile Testing Methodology (OWASP MASVS/MSTG) - 3-4 weeks
5. Tools & Labs - 3-4 weeks
6. Books
7. Videos
8. Courses
9. Certifications
10. Interview Questions
Mobile Fundamentals
Duration: 2 weeks
Android Security
Duration: 3-4 weeks
iOS Security
Duration: 3-4 weeks
Books
1. Any good book focused on mobile application security or testing.
2. Web and API security books to complement backend testing knowledge.
Videos
1. Conference talks on Android and iOS application security.
2. Walkthroughs of mobile app security assessments.
3. Official platform security overviews from Google/Apple.
Courses
1. Mobile application security or mobile pentesting courses with hands-on labs.
2. Android/iOS development basics (optional but helpful to understand code).
3. General web/API security courses to strengthen backend testing.
Certifications
1. Mobile security-focused certifications if they align with your goals.
2. General offensive security certs (OSCP/eWPTX/etc.) if you want broader pentest
credentials.
Interview Questions
You can reuse questions from Web & API Security but add mobile specifics:
1. How would you test a mobile banking app for insecure storage?
2. What is OWASP MASVS and how would you use it in an assessment?
3. How would you approach bypassing certificate pinning (conceptually)?
4. What are common pitfalls in mobile auth and session management?
Chapter 24
This study plan is based on milestones. So, check how much you can cover within the timeline.
The more you cover the topics, the better candidate you are for roles which require reverse
engineering (RE), exploit analysis, or malware analysis skills.
Also, I assume you have already checked and are comfortable with Common Security Skills study
plan and Network Security study plan.
How this connects: This plan is a good next step if you already know Network Security and have
some exposure to Blue Team, Detection & Response or Web Pentest. It helps you explain how
malware and exploits work behind the alerts.
In short
1. Reverse engineering is about understanding how software works from the binary up.
2. Malware analysis combines RE with incident response and threat intel.
3. You should be comfortable with low-level concepts (processes, memory, file formats).
4. You must treat malware safely (isolated labs, no real systems).
5. This path takes time; progress slowly and practice a lot.
ToC
1. Foundations: OS & Architecture - 3-4 weeks
2. Static Analysis Basics - 3-4 weeks
3. Dynamic Analysis Basics - 3-4 weeks
4. Malware Analysis Workflow - 3-4 weeks
5. Advanced Topics - 4-6 weeks
6. Books
7. Videos
8. Courses
9. Interview Questions
Foundations: OS & Architecture
Duration: 3-4 weeks
Advanced Topics
Duration: 4-6 weeks
Books
1. Introductory RE or malware analysis books from reputable authors.
2. Books that walk through real-world malware case studies.
Videos
1. Conference talks on RE and malware analysis.
2. Walkthroughs of analyzing real malware samples (from trustworthy sources).
3. Short videos explaining assembly and OS internals.
Courses
1. Beginner RE/malware analysis courses with controlled labs.
2. More advanced RE courses if you decide to go deeper.
3. Complementary courses on Windows internals or exploit development.
Interview Questions
1. How would you safely analyze a suspicious binary you received from the SOC?
2. What is the difference between static and dynamic analysis and when would you use each?
3. How do you communicate your malware analysis findings back to defenders?
Chapter 25
This study plan is based on milestones. So, check how much you can cover within the timeline.
The more you cover the topics, the better candidate you are for roles that benefit from strong
OSINT and social engineering awareness (red team, blue team, GRC, security awareness).
Also, I assume you have already checked and are comfortable with Common Security Skills study
plan.
How this connects: OSINT and social engineering skills complement Web Pentest and red
teaming, help GRC and Blue Team, Detection & Response understand human-focused risks, and
enrich Threat Modeling by adding people and process attack vectors.
In short
1. OSINT is about collecting and correlating public information from many sources.
2. Social engineering is about manipulating human behavior - use it ethically and within rules
of engagement.
3. Both attackers and defenders use OSINT and SE (offense and awareness/training).
4. Legal and ethical boundaries are critical.
ToC
1. OSINT Fundamentals - 2 weeks
2. People & Infrastructure OSINT - 3-4 weeks
3. Social Engineering Fundamentals - 2-3 weeks
4. Offensive Use Cases (Ethical) - 2-3 weeks
5. Defensive Use Cases & Awareness - 2-3 weeks
6. Books
7. Videos
8. Courses
9. Interview Questions
OSINT Fundamentals
Duration: 2 weeks
Goal: understand how OSINT and SE are used in engagements with proper authorization.
Books
1. Books on social engineering and human-based attacks from reputable authors.
2. Books focused on OSINT techniques and case studies.
Videos
1. Talks on social engineering from security conferences.
2. OSINT practical walkthroughs (within ethical & legal boundaries).
3. Corporate awareness-style videos explaining phishing and SE.
Courses
1. Intro OSINT courses that emphasize legality and ethics.
2. Social engineering awareness and simulation courses.
3. Red team or phishing simulation courses if relevant to your job.
Interview Questions
1. How would you use OSINT during a security assessment while staying within legal and
ethical boundaries?
2. How would you design an internal phishing awareness campaign?
3. How can OSINT and SE knowledge help improve an organization■s security posture?
Resources & Links
Continue your cybersecurity learning journey with these additional resources curated by the
author:
Thank you for reading! If you found this study plan helpful, please consider starring the GitHub
repository and sharing it with others who are starting their cybersecurity journey.
© 2025 Sanjeev Jaiswal. All rights reserved.
SAST (Static Application Security Testing) analyzes source code or binaries for vulnerabilities without executing the program, allowing for early detection of code-level vulnerabilities like buffer overflows before deployment. DAST (Dynamic Application Security Testing), on the other hand, involves testing an application during its execution, which is beneficial for identifying runtime issues such as server misconfigurations and authentication problems. Each has unique benefits: SAST allows for faster remediation of coding errors during development, while DAST helps identify issues that manifest only during runtime .
Single Page Applications (SPAs) load a single HTML page and dynamically update it as the user interacts with the application, reducing the number of server requests. This architecture can enhance security by minimizing server interactions, thus reducing attack surfaces such as SQL Injection which occur during server-side processing. However, it also poses security implications because business logic executed in the client-side JavaScript could be susceptible to attacks like Cross-Site Scripting (XSS) if not properly secured .
Session Fixation is an attack where a user is tricked into authenticating a session identifier (session ID) chosen by the attacker, allowing the attacker to hijack the user session after authentication. Prevention strategies include regenerating session IDs on login to ensure an attacker cannot predict or use a fixed session ID. Implementing HTTPS ensures that session cookies are encrypted in transit. Setting appropriate cookie attributes like HttpOnly and Secure, and having a short session expiration time can further protect against such attacks .
JWT (JSON Web Token) is used in authentication as a compact, self-contained way to transmit information between parties securely. It contains JSON objects, including claims about identity, and is usually signed to ensure authenticity and integrity. However, misuse such as using weak signing algorithms (e.g., none or HS256 without secret management) can lead to security vulnerabilities, allowing attackers to manipulate tokens or impersonate users. Ensuring JWTs are properly signed, well-managed, and kept confidential is essential to secure web applications .
To integrate security checks effectively into a CI/CD pipeline, without significant disruption, it's crucial to automate the process. Strategies include using fast, incremental scans during the CI phase that focus on new code changes while deferring comprehensive checks to nightly builds. Incorporating security testing tools, like static analysis (SAST) tools, that can run concurrently with existing tests helps maintain pace. Ensuring feedback mechanisms are in place to quickly notify developers of vulnerabilities, along with clear remediation guidance, facilitates timely fixes without major delays in development .
Understanding API endpoints and the associated request-response lifecycle is crucial in API security because endpoints define the interaction ways with the API. Security risks such as unauthorized access and data leaks occur if endpoints are improperly secured. Knowledge of how endpoints manage authentication, data transmission, and error handling guides the identification and mitigation of vulnerabilities. This comprehension is essential for ensuring APIs execute requests safely and securely, maintain session integrity, and prevent data exposure .
Server-Side Request Forgery (SSRF) occurs when an attacker forces a server to make unauthorized requests to arbitrary domains, which can potentially lead to internal network breaches or data leaks. To minimize SSRF risks, limit outbound requests to necessary external services by implementing strict network access controls. Use whitelisting for trusted URLs and IP addresses, and validate user inputs to prevent arbitrary request payloads. Monitoring request logs and configuring network-level firewalls further enhance protection against SSRF attacks .
Content Security Policy (CSP) is a security measure that defines which resources a web application can load or execute. By specifying trusted sources, CSP helps mitigate Cross-Site Scripting (XSS) attacks by blocking the browser from loading or executing scripts from unauthorized sources. This restricts malicious scripts from manipulating the DOM or stealing sensitive information, even if XSS vulnerabilities exist in the application's code. CSP, combined with input sanitation, forms a robust defense against XSS attacks .
Using weak cipher suites in SSL/TLS protocols can leave web communications vulnerable to various attacks, such as Man-in-the-Middle (MITM) and downgrade attacks, which could allow attackers to decrypt sensitive information. Weak ciphers may offer inadequate encryption, be susceptible to brute force attacks, and could have known vulnerabilities that attackers can exploit. Evaluating and deploying strong cipher suites ensures robust encryption, forward secrecy, and protection against eavesdropping, securing data integrity and confidentiality in web communications .
Third-party vulnerability checks are crucial in modern web applications as many utilize external libraries and services, each potentially introducing vulnerabilities. Failure to conduct such checks can result in exposure to outdated or compromised components that attackers can exploit, leading to data breaches or service disruptions. Regular vulnerability assessments and updates from trustworthy sources or vulnerability databases reduce these risks, ensuring components meet security standards and maintain application integrity .