top of page
Image by Annie Spratt

Cybersecurity Engineering - Professional Program

Cybersecurity Engineering — Pro Bundle

Payment options available

 

A complete path to cybersecurity engineering practice and proof. Includes full course access and the CPL capstone portfolio review. Your evaluation is based on your engineering artifacts, evidence, and outcomes.

Includes:

  • Course access

  • Course eBooks

  • CPL capstone review (1 attempt)

  • Plus, a lifetime ISAU membership

Build and integrate defensible capabilities across components, integrated platforms, and complex connected environments. Learn core cyber defense, engineering-grade architecture practices, and repeatable verification and validation using a structured security engineering lifecycle and the Cybersecurity Engineering Concepts (CEC).

What will I Learn?

Cybersecurity Engineering Program

Description

ISAUnited’s Cybersecurity Engineering Program is the professional training path for practitioners who want to move beyond tool operation and become accountable builders of secure, reliable systems. This program develops the Defensible Builder - the cybersecurity engineer who can translate security intent into real-world implementation across components, platforms, and connected environments.

Participants learn a disciplined, repeatable approach to translating security responsibilities into technical specifications, integrating identity, network, data, and monitoring protections across interfaces, and validating that safeguards work in real-world conditions. You will strengthen your approach to reviewing components, engineering boundaries, handling failures, and documenting decisions with clear rationale, measurable acceptance criteria, and evidence that withstands scrutiny. The result is consistent security, enhanced resilience, and fewer surprises during incidents.

The program is delivered in two progressive parts, so you can start applying engineering practice immediately and then deepen your capabilities in integration discipline, verification and validation, operational measurement, and defensible documentation. If you are a practitioner who builds, configures, or integrates systems and wants a structured engineering method that produces proof, not promises, this program provides the mindset and practical approach to engineer security as a measurable outcome.

Field of study: Cybersecurity Engineering

 

Program level: Certified Professional

 

Pathway: Certified Professional Cybersecurity Engineer (CPCE) License

 

Delivery format: 100% online (self-paced) with technical instructor support

 

Pace: 10 days (2 weeks)

 

Prerequisites: Cybersecurity Essentials are required for this program; see below. 

​​

Credits: 20 CPEs

 

Exam: Capstone Portfolio

ISAU-eBK-Expert-ENG_cover.png

Mastering Cybersecurity Engineering (ebook included)

The official course text and Source of Truth for cybersecurity engineering. It maps directly to the Define, Design, Deploy, Detect, Defend, and Demonstrate lifecycle and the ten security domains, and is used in knowledge checks and the capstone portfolio.

Edition:      First Edition 2026

  • Practical models: design modeling, engineering concepts, component integrity, risk management, adversarial analysis

  • Helps you turn goals into measurable acceptance criteria

  • Guides release ready by default with simple continuous integration and delivery gate policies

What will I take?

BASIC Courses

B100 

Course: Defensible 10 Standards Foundations

Field: Cybersecurity Essentials

This course introduces students to the Defensible 10 Standards and explains how the ten domains organize security responsibilities across enterprise and cloud environments. Students learn the purpose of each domain, the relationships among controls, requirements, and measurable acceptance criteria, and how to interpret a system diagram through the D10S lens. 

B102

Course: Cybersecurity Core Principles
 

Field: Cybersecurity Essentials

A practical introduction to the ideas that anchor secure design, from confidentiality and integrity to least privilege, layered defenses, and verifiable operations. Learn how these principles shape choices in architecture, configuration, and daily practice across data centers and cloud services. Through real examples and guided critiques, connect each principle to measurable outcomes that reduce risk and produce resilient, trustworthy systems.

B104

Course: Cybersecurity Controls Management Framework

Field: Cybersecurity Essentials

This course teaches students how to build a clear, organized system for selecting, mapping, measuring, and maintaining security controls across enterprise and cloud environments. Students learn to translate policy goals into concrete requirements, plan evidence from the outset, and conduct ongoing checks that demonstrate that protections work in real-world operations.

B107

Course: Security by Design Foundations

Field: Cybersecurity Essentials

Security by Design Foundations teaches you to plan and review security like an engineer: set measurable goals, use simple design models to place controls, make sound trade-offs, add lightweight delivery guardrails, and produce evidence that your choices work. Built for both managers and technical teams.

 

B108

Course: Security Project Management
 

Field: Cybersecurity Essentials

This course introduces students to security project management as a disciplined practice for planning and delivering secure technology work. Students learn to define scope, roles, and milestones; manage risks and dependencies; coordinate technical and business stakeholders; and track security outcomes from requirements through validation.

CORE Courses

ENG600

Course: Introduction to Defensible Engineering

Field: Cybersecurity Engineering

An introduction to defensible cybersecurity engineering, organized around ten core security domains used to assign responsibility in enterprise and cloud environments. Covers what each domain includes, how controls connect to requirements and measurable acceptance criteria, and how to read a system diagram to identify boundaries, interfaces, and what must be protected.

ENG601

Course:  Cybersecurity Engineering Concepts (CEC) Practicum

Field: Cybersecurity Engineering

This course introduces practical methods for engineering secure systems by using structured, real-world design and implementation techniques. Learners will explore the full lifecycle of system protection through modeling, validation, and technical execution, with emphasis on engineering traceability, repeatability, and accountability in modern system environments.

ENG650

Course: Defensible Engineering Framework

Field: Cybersecurity Engineering

A practical framework for building and integrating secure systems using defensible engineering methods. Learn to translate domain expectations into technical specifications, place protections at boundaries and interfaces, document engineering trade-offs, and verify results with repeatable tests and operational signals. Emphasis is on implementation discipline, traceable decisions, and measurable outcomes.

ENG651

Course:  Defensible Engineering Mechanisms

Field: Cybersecurity Engineering

Explore how defensive mechanisms are identified, designed, and verified within secure enterprise and cloud systems. It explains how mechanisms such as gateways, firewalls, identity services, scanners, WAF, and monitoring components enforce protection across architectures. Learners study how these mechanisms are placed, tested, and sustained to ensure defensible, measurable security outcomes.

ENG654

Course:  Proof Engineering, Verification & Validation, Evidence Packs

Field: Cybersecurity Engineering

Proves security design and control intent with repeatable testing, clear acceptance criteria, and documented results. Covers verification and validation planning, test case design, negative testing, evidence collection, and traceability from requirements to outcomes. Builds audit-ready evidence packs that remain current through change, with peer-reviewed scoring.

 

CORE Courses

ARC551

Course: Technical Adversarial & Defensible Analysis Advanced
 

Field: Cybersecurity Architecture

This advanced course teaches how to review a solution architecture diagram from an attacker’s perspective and translate findings into a defensible security design. Students learn to map attack stages and entry points, model threats against components and data flows, align attacker behaviors to real techniques, and produce clear remediation recommendations. 

 

What is the Exam?

 Cyber Capstone Portfolio

Description

A focused, real-world scenario that lets you prove mastery through a concise, defensible submission. The Capstone Portfolio is a solo, written, remote, and time-boxed to two weeks (10 business days) from assignment. Earlier submission is acceptable. There are no multiple-choice tests and no interviews.

 

What you will complete

  • Artifact 1: Project Brief and Scope
    Define the problem, project scope, requirements, technical specifications, assumptions, constraints, and risk context.

  • Artifact 2: High-Level Architecture and System Context
    Present the system context, trust boundaries, major components, entry surfaces, and initial control direction.

  • Artifact 3: Detailed Deployment and Threat Analysis
    Show the deployment design and placement of defensible engineering mechanisms, supported by Technical Adversarial and Defensible Analysis.

  • Artifact 4: Detection and Response Strategy
    Provide the monitoring approach, detection logic, incident-response considerations, and operational-readiness plan.

  • Artifact 5: Defensible Design and Residual Risk Briefing
    Summarize the final defensible decisions, tradeoffs, residual risk, and supporting rationale in a concise presentation deck with speaker notes.

How it is evaluated

Your submission is evaluated using the ISAUnited Defensible Capability Score, a two-section scoring model based on written deliverables only.

Part 1 - Technical Artifact Evaluation (Pass or Fail), scores the submitted capstone artifacts across the Define, Design, Deploy, Detect, and Defend phases for technical completeness, correctness, traceability, and defensibility.

Part 2 - Skills, Knowledge, and Abilities (SKA) Capability Profile (Professional Capability) evaluates how you performed through the capstone by assessing disciplined practice, reasoning quality, judgment, and communication across seven capability dimensions, with evidence references tied to the submitted artifacts.

 

Outcome
Successful completion satisfies the Capstone requirement for the ISAUnited Certified Professional License in your selected track.

What Do I Get?

CPL_Eng_Sample_2025.PNG

Your Professional License - Certified Professional Cybersecurity Engineer (CPCE)

This is the license you earn when you pass the CPL evaluation (included in the Pro Bundle). The evaluation is capstone-based—no multiple-choice exams. A successful review adds your name to the ISAUnited public registry.

  • Designation: Certified Professional Cybersecurity Engineer  (CPCE)

  • Credentialing: Digital certificate + verifiable License ID/issue date

  • The Certified Professional License is valid for a three-year term.

  • Renewal requires 60 Continuing Professional Education credits

Are you Ready?

Do you have questions about which program to choose or how the CPL works? Book a quick consult and we’ll help you or send us a message below.

Scrabble Letters

Acronym Library

Decode Our Alphabet Soup!

bottom of page