Curated by role · designed for cohorts

Don't pick courses.
Pick a role.

We build full learning paths for the four roles we see most. Each is a multi-month cohort with hands-on labs, mentor hours, and a final engagement-style assessment.

Path · AppSec engineer

For the engineer who owns the security of the code they ship.

Threat modelling, secure coding, and live red-team rotations. You finish having scoped, run, and reported a mini-engagement.

$3,600
per seat · 5+ unlocks team pricing
WK 1–3
Threat modeling
STRIDE, attack trees, real reviews of your repo.
Repo-specific threat model
WK 4–6
Web exploitation
OWASP Top 10 in depth, exploit chains.
Exploit portfolio
WK 7–9
Secure code review
Static + dynamic. Reviewing PRs you wrote.
Annotated PRs
WK 10–12
Build pipeline security
SLSA, signing, supply-chain attacks.
Hardened CI baseline
WK 13–14
Live red-team rotation
Shadow a Cyb5r engagement for 2 weeks.
Field report
WK 15–16
Capstone
You scope, run, and report a mini-engagement.
Cyb5r-AppSec certification

Upcoming cohorts

MAX 14 PER COHORT · SENIOR OPERATOR-LED
Jul 08 · 2026
OPEN · 8 SEATS
Oct 14 · 2026
OPEN · 14 SEATS
More dates added monthly
Taught by people who still ship

Every instructor is an active operator.

Marta K.
Marta K.
Red team lead
ex-CISA · 12 yrs
Daniel O.
Daniel O.
AI assurance
ex-Anthropic · 8 yrs
Aiya R.
Aiya R.
Cloud + IR
ex-AWS sec · 10 yrs
Tom V.
Tom V.
Training lead
ex-SANS · 11 yrs
Lior B.
Lior B.
vCISO · advisory
ex-CISO finance · 14 yrs