Tom Seaborne · Security Engineering

In progress — Security Engineering Fundamentals

Tom Seaborne

Information Security Engineer

I'm documenting a deliberate path from networking fundamentals to a job-ready Security Engineer skillset — grounded in real job-market data, hands-on labs, and evidence I can show, not just describe.

Development roadmap

    Courses & platforms I'm using for this phase

      Complete In progress Upcoming · click a phase above to see its topics

      01 Security Engineering Fundamentals

      Sub-categories
      • Networking
      • Core Security
      • Windows
      • Linux
      Specific topics
      • TCP/IP
      • OSI
      • IPv4/IPv6
      • Subnetting
      • DNS
      • DHCP
      • ARP
      • TCP/UDP
      • Ports
      • Routing
      • Switching
      • HTTP/HTTPS
      • TLS
      • SSH
      • VPN
      • Firewalls
      • Proxies
      • Segmentation
      • IDS/IPS
      • Wireshark
      • Packet analysis
      • CIA
      • Defence in depth
      • Least privilege
      • Authentication
      • Authorisation
      • Security controls
      • Hardening
      • Risk
      • Threats
      • Vulnerabilities
      • Attack surface
      • Security architecture
      • Logging
      • Monitoring

      02 IAM / Identity

      Sub-categories
      • Active Directory
      • Entra ID
      • Authentication
      • Authorisation
      • Privileged Access
      Specific topics
      • MFA
      • SSO
      • RBAC
      • PAM
      • Kerberos
      • LDAP
      • NTLM
      • SAML
      • OAuth
      • OpenID Connect
      • Conditional Access
      • Service accounts
      • Privileged accounts
      • Identity attacks
      • Zero Trust

      03 Security Operations / Detection

      Sub-categories
      • SIEM
      • EDR
      • Detection Engineering
      • Threat Hunting
      • Incident Response
      Specific topics
      • Windows Event Logs
      • Linux logs
      • Authentication logs
      • Network telemetry
      • Alert triage
      • Incident investigation
      • MITRE ATT&CK
      • Sigma
      • YARA
      • KQL
      • SPL
      • SOAR concepts

      04 Cloud Security

      Sub-categories
      • AWS
      • Azure
      • Cloud IAM
      • Cloud Networking
      • Cloud Monitoring
      Specific topics
      • Logging
      • Encryption
      • Secrets
      • Least privilege
      • Security architecture
      • Cloud incident response
      • Cloud misconfiguration
      • Shared responsibility
      • AWS IAM
      • VPC
      • Security Groups
      • S3
      • CloudTrail
      • CloudWatch
      • GuardDuty
      • KMS
      • Secrets Manager
      • Lambda
      • Azure Entra ID
      • Azure IAM
      • Azure Networking
      • Azure Logging
      • Defender for Cloud

      05 Automation / Scripting

      Sub-categories
      • Python
      • PowerShell
      • APIs
      • KQL / SPL
      • Security Automation
      Specific topics
      • Security automation
      • APIs
      • Data processing
      • Log processing
      • Automation
      • Tool integration
      • Security investigations
      • Reporting

      06 Vulnerability Management

      Sub-categories
      • Discovery
      • CVE / CVSS / EPSS
      • Risk & Prioritisation
      • Remediation
      Specific topics
      • CVE
      • CVSS
      • EPSS
      • CWE
      • Vulnerability scanners
      • Asset criticality
      • Patch management
      • Remediation SLAs
      • Risk acceptance
      • Exceptions
      • Compensating controls
      • Reporting
      • Asset→Discovery→Vulnerability→Validation→Risk→Prioritisation→Remediation→Verification

      07 Application / API Security

      Sub-categories
      • Web Security
      • APIs
      • OWASP
      • Secure Development
      Specific topics
      • HTTP
      • Sessions
      • Cookies
      • Authentication
      • Authorisation
      • REST
      • JSON
      • OWASP Top 10
      • OWASP API Security
      • SQL injection
      • XSS
      • CSRF
      • SSRF
      • IDOR / BOLA
      • Security misconfiguration
      • Burp Suite
      • Security testing

      08 Threat Modelling / Security Design

      Sub-categories
      • Threat Modelling
      • Attack Surface
      • Security Architecture
      • Risk / Security Controls
      Specific topics
      • Assets
      • Threats
      • Trust boundaries
      • Data flows
      • STRIDE
      • Attack trees
      • Mitigations
      • Defence in depth

      09 Containers / Kubernetes / IaC

      Sub-categories
      • Docker
      • Kubernetes
      • Terraform
      Specific topics
      • Images
      • Containers
      • Registries
      • Dockerfiles
      • Container security
      • K8s Architecture
      • Pods
      • Services
      • Deployments
      • Namespaces
      • K8s RBAC
      • Network policies
      • K8s Secrets
      • Infrastructure as Code
      • State
      • Modules
      • Terraform IAM
      • IaC security
      • Misconfiguration

      10 DevSecOps

      Sub-categories
      • CI/CD
      • SAST / DAST / SCA
      • Supply Chain
      Specific topics
      • Git
      • GitHub
      • Secret scanning
      • Dependency security
      • Container scanning
      • IaC scanning
      • Software supply chain
      • SBOM concepts

      11 AI / LLM Security

      Sub-categories
      • LLM Security
      • RAG
      • Agents
      • AI Threat Modelling
      Specific topics
      • LLM architecture
      • Prompt injection
      • Jailbreaking
      • Data leakage
      • Insecure output handling
      • Excessive agency
      • RAG security
      • Agent security
      • Model supply chain
      • OWASP LLM Top 10
      • MITRE ATLAS
      • NIST AI RMF

      12 SOAR

      Sub-categories
      • Security Orchestration
      Specific topics
      • Playbooks
      • Orchestration
      • Automated enrichment
      • Automated investigation
      • Automated response
      • API integrations
      • Incident workflows

      13 Post-Quantum Cryptography

      Sub-categories
      • Awareness
      Specific topics
      • Why quantum computing threatens current cryptography
      • RSA / ECC at a high level
      • Post-quantum cryptography
      • NIST PQC
      • Migration challenges
      • Crypto-agility

      Recent projects

      DETECTION ENGINEERING

      Home Lab SIEM: Detecting Brute-Force Auth Attempts

      Built a small Splunk instance ingesting auth logs, wrote and validated a correlation rule, then documented false-positive tuning.

      Splunk · Sysmon · MITRE ATT&CK
      NETWORKING

      Packet-Level Walkthrough of a TLS Handshake

      Captured and annotated a full TLS 1.3 handshake in Wireshark to build a concrete mental model of the protocol.

      Wireshark · OpenSSL
      MARKET ANALYSIS

      What 12 UK Security Engineer Job Specs Actually Ask For

      First pass at extracting recurring vs. emerging requirements from real listings, and how it reshaped near-term priorities.

      Job-market research · Write-up

      How I'm learning

      Every topic goes through the same cycle before I consider it "known" — concept, then hands-on lab, then breaking and fixing it myself, then writing it down. Memorisation isn't the goal; being able to do the work is.

      Concept Lab Investigate Build Break Fix Document