Get started in cybersecurity with a new security engineer learning curve at TryHackMe

BBHC
3 min readSep 12, 2023

--

Introduction

Cybersecurity is a rapidly growing field, and the demand for skilled security engineers will only increase in the coming years. If you’re interested in a career in cybersecurity, the new Security Engineer Learning Path at TryHackMe is a great place to start.

This comprehensive approach includes all the skills necessary to be a successful safety engineer, e.g.

Introduction to Security Engineering

Security Engineer Intro
What does a day in the life of a security engineer look like?

Security Principles
Learn about the security triad and common security models and principles.

Introduction to Cryptography
Learn about encryption algorithms such as AES, Diffie-Hellman key exchange, hashing, PKI, and TLS.

Identity and Access Management
Learn about identification, authentication, authorisation, accounting, and identity management.

Threats and Risks

Governance & Regulation
Explore policies and frameworks vital for regulating cyber security in an organisation.

Threat Modelling
Building cyber resiliency and emulation capabilities through threat modelling.

Risk Management
Learn about framing, assessing, responding, and monitoring risk.

Vulnerability Management
Learn how to identify, detect, mitigate and report a vulnerability effectively.

Network and System Security

Secure Network Architecture
Learn about and implement security best practices for network environments.

Linux System Hardening
Learn how to improve the security posture of your Linux systems.

Microsoft Windows Hardening
To learn key attack vectors used by hackers and how to protect yourself using different hardening techniques.

Active Directory Hardening
To learn basic concepts regarding Active Directory attacks and mitigation measures.

Network Device Hardening
Learn techniques for securing and protecting network devices from potential threats and attacks.

Network Security Protocols
Learn about secure network protocols at the different layers of the OSI model.

Virtualization and Containers
Introduction to common virtualization technologies and applications.

Intro to Cloud Security
Learn fundamental concepts regarding securing a cloud environment.

Auditing and Monitoring
Learn about auditing, monitoring, logging, and SIEM.

Software Security

OWASP Top 10–2021
Learn about and exploit each of the OWASP Top 10 vulnerabilities; the 10 most critical web security risks.

OWASP API Security Top 10–1
Learn the basic concepts for secure API development (Part 1).

OWASP API Security Top 10–2
Learn the basic concepts for secure API development (Part 2).

SSDLC
This room focuses on the Secure Software Development Lifecycle (S-SDLC), its processes, and methodologies.

SAST
Learn about Static Application Security Testing.

DAST
Learn about Dynamic Application Security Testing.

Weaponizing Vulnerabilities
Learn how a vulnerability evolves and methods to weaponize multiple vulnerabilities leading to RCE.

Introduction to DevSecOps
Learn about the story of DevSecOps, Software Development Models & Shifting Left.

Mother’s Secret
Exploit flaws found in Mother’s code to reveal its secrets.

Managing Incidents

Intro to IR and IM
An introduction to Incident Response and Incident Management.

Logging for Accountability
Learn about the role accountability plays in logging and incident response.

Becoming a First Responder
Explaining how first responders work and what to do if you are a first responder to a cyber incident.

Cyber Crisis Management
An introduction into cyber crisis management and how a CMT works.

This comprehensive path covers all the essential skills you need to become a successful security engineer, including:

  • Penetration testing
  • Incident response
  • Threat modeling
  • Security Engineer

Who is this option for?

This option is designed for anyone who wants to learn about cybersecurity and security technology. Whether you are a beginner or an experienced security professional, you will discover something valuable this way.

How to get started

To get started, just create an account on TryHackMe and go through the Security Engineer learning path. You can then start working through the modules at your own pace.

The benefits of completing this method

There are many benefits to completing the security engineer learning path with TryHackMe. Here are a few:

You will gain the skills and knowledge you need to secure a career in cybersecurity.
You can showcase your skills to potential employers.
You keep seeing the latest security threats.

Conclusion

The Security Engineer learning path on TryHackMe is a great way to get started in cyber security. If you’re interested in a career in this field, I encourage you to check it out.

Link

I hope this blog post has been helpful. If you have any questions, please feel free to leave a comment below.

--

--