A focused course, tailored for you
The Senior Security Analyst Merchant-Risk Detection Playbook
How a senior security analyst inside a global commerce platform turns merchant fraud, account-takeover bursts, and partner-app abuse into ranked, owned, closed alerts.
The alert fires. A high-GMV merchant just accepted a thousand orders from one ASN in ten minutes. By the time triage decides whether this belongs to fraud, trust, platform-abuse, or security, the chargebacks have already started landing.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
A senior security analyst inside a commerce-platform business sits at an awkward boundary. The signals look like classic security telemetry (failed auths, anomalous tokens, traffic shape changes) but the impact lands as merchant fraud, payout loss, support escalation, and reputational damage. The triage rules were written for a SaaS company with a single product surface, not a marketplace with hundreds of thousands of seller accounts, a partner-app ecosystem, and a payments stack on top. So a meaningful share of high-severity events sit in queue while ownership is debated. That is the gap the course closes: the detection logic, the routing logic, and the handoff contracts that turn an ambiguous merchant-side event into a ranked, owned, closed incident. The implementation playbook lands the work in a real commerce-platform topology, not a generic reference architecture.
What you walk away with
- Write merchant-side detection queries that name the owner (fraud, trust, platform-abuse, or security) before the alert fires.
- Build the handoff contract that resolves the four-team triage ambiguity for high-GMV merchant events inside ten minutes of detection.
- Stand up the partner-app token-scope abuse detection layer that the OAuth audit log alone does not produce.
- Translate post-incident chargeback signals back into pre-incident detection rules feeding the SIEM.
- Present merchant-risk detection coverage to a CISO or VP of Trust in a format that maps to GMV impact rather than alert volume.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- 12 written modules, each with detection logic, runbook, and team-handoff contract.
- Downloadable rule templates for SIEM (Splunk SPL, Sumo, and a vendor-neutral pseudocode variant).
- The four-team triage decision matrix as an editable artefact.
- The hand-built implementation playbook, mapped to a commerce-platform stack rather than a generic SOC reference architecture.
- Worked examples for every module, drawn from public commerce-platform incident reports.
What you will have in hand by Day 1, Week 1, Month 1
Within 24 hours, learning environment account provisioned and the hand-built implementation playbook delivered alongside.
Week 1: modules 1 to 4 (telemetry map, four-team triage, ATO across three populations, partner-app abuse).
Week 2: modules 5 to 8 (checkout bots, payout-fraud staging, BIN-chargeback feedback, cross-merchant correlation).
Week 3: modules 9 to 12 (insider risk, detection-as-code, merchant-incident response, executive reporting).
Implementation playbook used in parallel: pick three detection rules from your real stack and walk them through the merchant-risk framework end to end.
Before and after
Merchant-side alerts sit in queue while four teams debate ownership, post-mortems focus on response time when the upstream defect was routing logic, and the detection layer cannot articulate its coverage in terms anyone outside the SOC understands.
Merchant-side alerts arrive pre-routed, the four-team handoff contract is named in the rule itself, the chargeback feedback loop closes back into detection, and the quarterly merchant-risk review reads in GMV-impact units that the executive risk committee actually uses.
What happens if you do not address this
The next high-GMV merchant ATO sits in triage long enough for payout fraud to land, the chargebacks arrive in 60 days, and the post-mortem concludes that detection was working but ownership was unclear. The same conclusion was written the previous quarter and will be written the next quarter unless the routing logic moves upstream into the detection layer itself.
Who it is for
A senior security analyst inside a commerce, marketplace, or platform business where merchant accounts, partner apps, and payments sit on top of the core security telemetry layer. Two to seven years of SOC, detection-engineering, or trust-and-safety adjacent work. Already comfortable with SIEM query languages, MITRE ATT&CK mapping, and Python or Go for tooling. Frustrated by detections that fire correctly but route incorrectly, and by post-mortems that focus on response time when the real defect was upstream in the ownership model.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. Around 14 to 18 hours of reading and exercises over three weeks. The implementation playbook adds another 6 to 10 hours of guided work on a real detection from your own queue.
Why $199 is the right number
SANS detection-engineering courses cover the rule-writing craft but assume a corporate-IT surface, not a marketplace plus payments stack. Vendor-led SIEM certifications optimise for tool fluency, not for merchant-side context. Internal threat-intel reading and conference talks cover individual attack classes but rarely the four-team routing logic that decides whether a finding becomes an owned incident. This course is the merchant-risk detection layer specifically, written for the senior security analyst who already has the SIEM skills and needs the platform-specific framework.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.