Sofia has run red team engagements against banks, hospitals and one national rail operator. She teaches security to people who build software rather than to specialists, on the grounds that this is where the leverage is. Her threat modelling exercises are the most-completed practical assessments on the platform.
Application Security for Builders
Security for the people writing the code, not for a specialist team.
- Completion rate
- 76%
- Free previews
- 1
- Total time
- 7h
30-day refund, no questions asked
- 7h, lifetime access
- Learn on desktop, tablet and phone
- Verifiable certificate on completion
- AI tutor with full course context
Training a team?
Volume pricing from five seats, with assignment, reminders and completion reporting included.
See team plans →What you will be able to do
- Run a threat model on a feature in under an hour
- Recognise the vulnerability classes that keep recurring
- Choose secure defaults so the easy path is the safe one
- Review a colleague's code for security without being tiresome
Skills this course develops
Each maps to the same taxonomy your organization’s roles are defined in, so progress here moves your skill profile.
About this course
Sofia Novak has broken into banks, hospitals and a rail operator. This course teaches what she looks for, so you can find it first. Threat modelling, the vulnerability classes that keep recurring, secure defaults, and how to make security review a normal part of shipping.
Requirements
- Experience building web applications
Curriculum
3 modules · 13 lessons · 7h
The mental shift, and a repeatable process.
- What an attacker actually does firstVideoPreview21m
- Threat modelling in under an hourVideo24m
- Trust boundaries in a modern stackVideo20m
- Lab: model a real featureAssignment55m
Your instructor
What learners say
2,617 reviews
- Rafael OrtizProduct ManagerRated 4.0 out of 511 months ago
Genuinely good, with one caveat: the first module moves slowly if you already know the basics. Skip to module two if you do — the rest is excellent and the case studies are specific rather than generic.
- Camille DuboisDesignerRated 3.0 out of 59 months ago
Solid content, but I came in from a non-technical background and the assumed knowledge in module four caught me out. The prerequisites could be clearer about that. Everything before it was excellent.
- Yuki NakamuraData ScientistRated 5.0 out of 52 months ago
The instructor is honest about what does not work, which is rarer than it should be. There is a whole lesson on a failed approach and why it failed. I learned more from that than from most successful case studies.
Learners who took this also took
TypeScript at Scale
Types that catch real bugs without making the codebase unreadable.
Daniel Roth
62.8K
Web Performance Engineering
Measure, then fix — in that order, every time.
Daniel Roth · Ben Kowalski
47.1K
Cloud Architecture & Reliability
Designed around real postmortems, because that is where the lessons are.
Arjun Mehta
51.3K