Skills map
68 skills. Learn the ones that open the most doors first.
Skills shared by several roles come first, so early learning keeps your options open.
Python scripting
2 rolesAutomating test cases and calling model APIs is daily work.
Agent loops and orchestration
Multi-step work needs clear control flow and stopping conditions.
Choosing models and products
Picking the right model for the task controls cost and latency.
Clear written communication
Managers and customers act on your summary, not your screenshots.
Cloud security architecture
Senior roles are judged on design decisions, not tickets closed.
Common attack types
Phishing, malware and credential abuse make up most of an analyst's queue.
Container networking and storage
Real applications need data persistence and service-to-service communication.
Container security
Reproducible, non-root, scanned images reduce supply-chain and runtime risk.
Containment and eradication
Acting in the right order preserves evidence and stops spread.
Data exfiltration and system prompt leakage
Leaked context is often the finding with the biggest business impact.
Detection engineering
Turning attacker behaviour into alerts is a core deliverable.
Direct and indirect prompt injection
The most common and most damaging LLM vulnerability class.
Docker images and Dockerfiles
Images are the deployable unit used by modern delivery platforms.
Evaluating output
Checking model output is the skill that separates production use from demos.
Evaluation and regression testing
A fix without a test comes back in the next release.
HTTP, APIs and authentication
Every LLM feature is reached through an API; most real breaches start with auth mistakes.
Human-in-the-loop controls
Consequential actions need approval gates that attackers cannot talk their way past.
Identity and access management
Identity is the primary cloud perimeter; most incidents involve over-broad access.
Incident response playbooks
The first hour of a credential leak decides the damage.
Infrastructure as code security
Catching a misconfiguration in review is far cheaper than in production.
Kubernetes reliability and security
Probes, resources, RBAC and network policy keep failures contained.
Kubernetes workloads and networking
Deployments and Services are the daily primitives of container platforms.
Least-privilege tool design
Limiting what a tool can do caps the damage of any injection that succeeds.
Linux administration
Most cloud compute is Linux; investigation happens at the shell.
MCP and tool design
Well-designed tools make agents both more capable and safer.
Organisation-wide policies
Preventive controls stop mistakes no individual review would catch.
OWASP Top 10 for LLM applications
The reference list clients and auditors ask you to test against.
OWASP Top 10 for web
The shared vocabulary for application risk that security reviews are written in.
Prompt structure
Clear instructions, context and examples drive most quality gains.
Prompting and system prompts
Injection is an attack on instructions; you need to know how instructions are layered.
Python or Bash automation
Security at cloud scale is automated or it does not happen.
Retrieval-augmented generation
Retrieved documents are an indirect injection path most teams overlook.
Security fundamentals
Confidentiality, integrity and availability frame how you judge severity.
Storage and encryption
Public buckets and unencrypted data remain common breach causes.
TCP/IP, DNS and TLS
Network controls and most detections are reasoned about at this layer.
Tool use and agents
Tools turn a text bug into a real action like sending email or reading files.
Virtual networks and security groups
Segmentation limits how far an attacker moves.