DRI Your Career
All coursesCourse N° 04 / Breaking Into the Security Mindset

Application security, no hoodie required.

Breaking Into the Security Mindset.

For the experienced engineer. Secure software is engineering, not just something for specialists, so you can learn how it works. This course is eight weeks, async, and guided by a security researcher.

Starts October 12, 20268 weeks · async~60 min / weekFrom $599
Illustration of a raccoon in round glasses, pondering a small padlockN° 04 / SEC

You know the stakes; you just don't know where to start.

A raccoon perched on a planet, surrounded by rockets, comets and galaxies

The landscape is vast, but you don't have to map all of it. Illustrations by Joe Groove.

Mythos and other offensive research models, the supply chain, CI breaches, CVEs, the collapse of the exploitation window from months into hours: the agentic era of software development is also the agentic era of vulnerability exploitation. You have product experience and technical skills, and you know the stakes, but understanding this fast-moving, jargon-rich field can feel like jumping onto a moving train.

It isn't magic, and it isn't just for lifelong hackers.

This course is for engineers and engineering managers who want to meet the security moment with new competencies. We'll get the train schedule, look at the map, and pack what we need for the trip, demystifying the landscape as we go. Then we'll dispense with the worry about who gets to do this, by doing it.

Most people who'd benefit from coaching never get it, because the price puts it out of reach, especially right now. This course is built to bridge that gap: structure, safe space, and personalised feedback, at a price that doesn't require a development budget.

You want to meet the security moment.

  • You're an engineer interested in bringing a security mindset into your engineering and product work.
  • You're an engineer who may even have considered shifting into security.
  • You know security is a gap for you, but it feels too intimidating to begin.
  • You feel stereotype threat about whether you're allowed to do it at all, because you didn't start hacking at the age of thirteen. (You are.)
  • You've found yourself the de facto security person on your team, and you want a clearer on-ramp.
  • Your team is shipping AI-assisted code and you're not sure what new risk that introduces, or how to set guardrails.
  • You want the support and accountability of coaching, without the price tag.

A security lens you can actually use.

  • A map of the fieldAn understanding of what the security sector consists of, and where it overlaps with your own interests and values.
  • What's actually possible nowInsight into what's technologically possible right now, in offense and defense, that doesn't depend on PR or pundits.
  • Local LLM workflowsHands-on with offline LLM workflows for vendor independence and privacy.
  • A way to keep upHow to stay on top of emerging trends without spinning out.
  • A plan for what's nextWhether that's bringing security into your own products, or even considering a new role.

Four modules in eight weeks.

A little reframing, the concepts you need, a hands-on project on a safe synthetic target, and support, with personal feedback on everything you turn in.

01
Weeks 1–2

Finding Yourself in Security.

The fictional hacker archetype casts a long shadow: self-doubt about who's allowed to do security, and fatalism about whether it's even possible. We bring it back to reality through three personae: you as the defender, the adversary, and who you protect and why. That leads into threat modeling, a high-level look at the state of the art on both sides, how practitioners use frameworks to manage the cognitive load, and our ethics and safety practices.

02
Weeks 3–4

Your Project, Part 1.

We dispel some magic by designing and building a small tool. We'll make a fun-sized offensive research script or agent, in a safe and synthetic context, consider the guardrails, and direct it to a surface you're interested in viewing from the other side. We pair this with local LLM workflows for data privacy and sovereignty from the start, and write up a vulnerability report on what we found.

03
Weeks 5–6

Your Project, Part 2.

Based on your takeaways from the previous two modules, you'll locate your first sources of research information on your vulnerability, and learn how to remediate it. Then we develop a theory of how to prevent it being written in the first place, in a team context, and get more concrete about guardrails in agentic and human coding.

04
Weeks 7–8

Bringing It Together.

We pull the camera back from a single flaw to your multi-system environment: CI/CD and supply chain, secure coding as policy, which “shift-left” tooling applies to your products, how to keep noise low, the intersection of least effort and most improvement, and staying realistic and current, so you can sleep at night.

Structured enough to keep you on track.

Self-paced and asynchronous, but you're never alone. You have a cohort, a project, and personal feedback on everything you turn in.

/ 01

8 weeks, 4 modules.

Self-paced, asynchronous content delivered over 8 weeks.

/ 02

~60 min a week.

Audio on a walk, reading between meetings, project work at your own pace. The project is the biggest variable, so you might use more time if it pulls you in.

/ 03

Audio conversations.

A conversation between Halle and Cate each module. An experienced security engineer and an experienced software engineer, exploring these topics alongside you.

/ 04

Written material.

Module content, frameworks, and the concepts you need, so the jargon is demystified.

/ 05

A hands-on project.

Build a small tool and use it to find, then remediate, a real vulnerability, on a safe, synthetic target you can’t hurt anyone with.

/ 06

Personal feedback.

Submit your exercises and project work and get personal written feedback on what you turn in.

The instructors.

Cate and Halle met at an iOS conference and have known each other for years. After discussing how difficult it's become as an engineer to get to grips with application security right now, they built the course they thought engineers actually needed, to make the current situation approachable, not mystifying.

Halle Winkler

Halle Winkler

Offensive Security Researcher · AppSec Engineer · Certified Ethical Hacker

A veteran indie software engineer and end-user privacy advocate who became an offensive security researcher and application security engineer. A Certified Ethical Hacker with 12 Apple Security credits spanning all Apple devices, with her CVE proofs of concept including a macOS remote-control camera and a Lock Screen keylogger, both packaged as sandboxed App Store apps. She lives in Berlin.

Cate Huston

Cate Huston

Author · Fractional CTO · Coach

Author of The Engineering Leader, fractional CTO at Twill, and engineering leadership coach. Previously in leadership roles at DuckDuckGo and Automattic.

More about Cate at cate.blog →

Common questions.

How much time will this take each week?
Plan for around 60 minutes a week. Audio you can listen to on a walk, reading you can do between meetings, and project work you drive at your own pace. The project is the biggest variable. If you get excited about it, you might blow past these limits (and your bedtime).
What do I need?
The course works with either offline or online LLMs, and introduces offline LLM workflows in Module 2. You don’t need an AI plan unless you want to use one to build tooling. A computer with a recent, reasonably powerful CPU and 32GB of RAM is ideal, with a 16GB fallback in the materials. Apple Silicon (a recent MacBook Pro or Mac Mini M4) is the best option among typical engineering machines; a MacBook Air might feel slow. Windows and Linux with similar hardware are supported.
Do I need to be actively coding to take this course?
Yes, to the extent that designing, building, and definitely debugging a small software tool is possible for you. If you’re just out of practice, this is a reasonable way to get back into it.
Is this course just for engineers?
It’s designed for engineers and engineering managers with at least some technical background. The project work is hands-on and technical in nature.
Do you offer scholarships?
We offer scholarships on a per-cohort basis. Get on the notify list below and we’ll let you know when they’re available.
Cohort opens · October 12, 2026

Meet the security moment.

Bring security into your engineering, with help from real humans. One-time payment, eight weeks, and personal feedback on your work.

One-time payment
$599$699
Early bird pricing active.

Need to expense this? See how → ·

Be first to know about the next cohort.

We'll email you when new dates and scholarship rounds open up.