Security Foundations
Build a threat-and-control mental model.
- Assets and trust boundaries
- Threats and attack surface
- Identity and least privilege
- Defense in depth
- Logging and evidence
Build security understanding across Linux, networks, applications, DevSecOps, containers, Kubernetes and AI systems with practical engineering controls.
The exact sequence is adjusted to the audience. Foundation topics can be compressed for experienced teams; architecture and troubleshooting can be expanded for advanced programs.
Build a threat-and-control mental model.
Protect foundational infrastructure.
Move security into the delivery lifecycle.
Secure workloads and orchestration layers.
Understand common software-layer risks.
Address new risks introduced by AI applications.
Exercises emphasize observation, implementation, failure and diagnosis rather than command copying.
Review a Linux host attack surface
Harden SSH and service exposure
Add security gates to a CI pipeline
Review Kubernetes RBAC / pod security
Threat-model a RAG / agent application
Security programs can be focused on infrastructure, DevSecOps, Kubernetes, applications, AI systems or cross-domain architecture reviews.