Skip to main content
Course

Professional Certificate in Vulnerability Engineering

Build the machine, not just the scans: scanning platforms, vulnerability data engineering, automation, and safe assessment of cloud, containers and operational technology.

Advanced

Level

6

Modules

30

Lessons

6

Graded quizzes

1

Assignments

15 hours

Estimated time

What you will be able to do

  • Design a scanning and assessment architecture that scales across sites
  • Normalize, deduplicate and enrich findings into one trustworthy data model
  • Automate routing, verification and closure with safe guardrails
  • Assess cloud, containers and operational technology without causing outages
  • Measure and report genuine exposure reduction rather than activity

What is inside

6 modules, 30 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    From Vulnerability Management to Exposure Management

    Why counting findings stopped telling anyone whether they were safer, and what replaced it. This module teaches exposure as the unit of work, continuous threat exposure management as an operating loop, attack paths and toxic combinations, the difference between what a vulnerability engineer builds and what an analyst operates, and how to make tooling, architecture, and build versus buy decisions you can defend. Taught through Cobalt Grid Energy, a fictional utility running both corporate information technology and operational technology environments.

    5 lessons · 15 quiz questions

  2. 02

    Building the Scanning Platform

    How a real detection platform gets built and scaled: distributed scan engines and where to place them, credentialed scanning, safe assessment of operational technology, agent fleets that stay healthy, cloud-native assessment services and their blind spots, container image and infrastructure as code scanning in pipelines, and application programming interface first tooling that lets you get findings out reliably. Taught through Cobalt Grid Energy, a regional utility with corporate information technology and operational technology environments.

    5 lessons · 15 quiz questions

  3. 03

    Vulnerability Data Engineering

    How raw output from many scanners becomes one dataset an organization will actually act on. Normalizing findings across network, cloud, container, code and operational technology tools, deduplicating and correlating the same weakness seen by different scanners, reconciling assets across competing sources of truth, designing the vulnerability data model, enriching findings with exploitation and business context, building the aggregation layer, and running the data quality controls that decide whether anyone believes your numbers. Taught through Cobalt Grid Energy, a utility with both corporate information technology and operational technology environments.

    5 lessons · 15 quiz questions

  4. 04

    Automation and Orchestration

    How to turn a manual remediation process into an engineered pipeline: removing toil without removing judgment, resolving asset ownership automatically, creating and routing tickets people will actually act on, running service level agreement clocks and escalation ladders, verifying and closing findings on evidence, wiring the pipeline into patch and configuration tooling, building playbook-style orchestration with guardrails that protect availability, and measuring honestly whether any of it reduced the work. Taught through Cobalt Grid Energy, an electric utility with a corporate information technology estate and an operational technology estate that cannot be treated the same way.

    5 lessons · 15 quiz questions

  5. 05

    Specialized Environments

    Everything you learned about scanning, prioritizing, and remediating changes shape when the target is a turbine controller, a container that lives for nine minutes, a public application programming interface, or a library buried four levels deep in someone else's software. This module takes Cobalt Grid Energy into its plants, its cloud accounts, its Kubernetes clusters, its customer portal, and its vendor contracts, and teaches how a vulnerability engineer works safely and credibly in each one.

    5 lessons · 15 quiz questions

  6. 06

    Program Leadership and Engineering Maturity

    How a vulnerability engineering function grows from a scanning team into an exposure management program. You will learn to run the program as an internal product with named users and a published service catalog, to earn engineering trust by shrinking developer friction and moving findings earlier in the build, to govern exceptions at scale so risk acceptance is a decision rather than a drift, to fold penetration test, red team, bug bounty and audit findings into one normalized pipeline, and to measure exposure reduction instead of scanning activity. Taught through Cobalt Grid Energy, a fictional regional utility with a large corporate information technology estate and a heavily regulated operational technology environment.

    5 lessons · 15 quiz questions · assignment