Career Roadmaps
Structured paths into security
Pick a role and follow an ordered path through the academy — each step links to the content that builds the skill.
GRC Analyst
Governance, risk, and compliance — translate frameworks into auditable controls.
- 1Learn the core frameworks
ISO 27001, SOC 2, and NIST CSF.
- 2Understand control mapping
How one control satisfies many frameworks.
- 3Practice risk & privacy
GDPR Article 32 and risk treatment.
- 4Prepare for interviews
Policies vs. standards, SOC 2 types, residual risk.
Cloud Security Engineer
Secure cloud workloads and map provider controls to compliance.
- 1Master IAM & least privilege
Do the hands-on IAM lab.
- 2Learn the control mappings
Encryption, logging, network security in the cloud.
- 3Study cloud security patterns
AWS, Azure, GCP, Kubernetes.
- 4Interview practice
Shared responsibility, security groups vs. NACLs.
Application Security Engineer
Build security into software — from threat modeling to secure SDLC.
- 1Threat modeling
STRIDE and data-flow diagrams.
- 2Secure SDLC
Security across the development lifecycle.
- 3Practice the fundamentals
Auth vs. authz, injection defenses.
- 4Test your knowledge
Take the quizzes.
AI Security Engineer
Secure AI systems against emerging, fast-moving threats.
- 1Learn the AI threat landscape
OWASP LLM Top 10, MITRE ATLAS.
- 2Defend against prompt injection
Do the hands-on lab.
- 3Understand AI governance
NIST AI RMF, ISO 42001, EU AI Act.
- 4Interview practice
AI-specific risks and defenses.