A focused course, tailored for you
The Senior Security Specialist Detection Portfolio Playbook
Own a detection-engineering portfolio that holds up to red-team replay and external audit in the same week.
The next red-team report and the next SOC 2 evidence request will both ask about the same detection rules. Right now those two answers do not match.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
Senior security specialists at hyperscale environments carry detection rules across multiple platforms, threat models that age out fast, and audit evidence requests that arrive on a different cycle from the red-team test cycle. The work that gets credit is the rule that catches a real incident. The work that gets criticism is the rule that fired late, the rule that never fired, the rule that fired ten thousand times in a quiet week, and the rule that has no documented test behind it when the assessor asks. This course closes that gap. It treats the detection set as a portfolio, with a threat-model justification per rule, a unit test per rule, a replay test against red-team artefacts, a documented false-positive budget, a tuning history, and an audit evidence pack ready for SOC 2, ISO 27001, and external regulator inquiries without a scramble.
What you walk away with
- Map every detection rule you own to a specific threat-model entry with documented coverage rationale.
- Convert ad hoc detection logic into unit-tested, version-controlled detection-as-code with a replay harness.
- Produce an audit evidence pack covering SOC 2, ISO 27001, and regulator inquiries that an external assessor accepts without follow-up.
- Run a documented false-positive budget per rule, with tuning history and on-call impact tracked over time.
- Hand over a detection-portfolio review document at quarterly reviews that satisfies engineering managers and internal audit at the same meeting.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- Twelve text-based modules in the Art of Service learning environment.
- Downloadable templates for the portfolio brief, threat-model mapping table, unit test fixtures, replay coverage report, tuning log, audit evidence pack, runbook, post-incident detection retro, and quarterly review slide-pair.
- Worked examples for both SIEM correlation detections and EDR behavioural detections.
- Hand-built implementation playbook tuned to your environment, delivered alongside course access.
What you will have in hand by Day 1, Week 1, Month 1
Within 24 hours your learning environment account is provisioned and the implementation playbook is delivered alongside it.
Twelve modules, paced at roughly one per week for a part-time pace, or two per week for a focused build.
Templates and worked examples downloadable from module one onward.
Before and after
You own a detection set that catches real attacks, but the evidence behind each rule lives in your head, in a Slack thread, or in a one-off doc. Audit requests and red-team retros surface gaps in different places and you reconcile them by hand.
Your detection set is a documented portfolio with mapping, tests, replay coverage, FP budgets, runbooks, and an audit evidence pack. Audit, red team, on-call, and engineering leadership all read from the same artefacts.
What happens if you do not address this
The next red-team report and the next external audit will continue to land on different weeks asking overlapping questions. Each one will consume engineering capacity that could have been spent closing the next coverage gap. Over a year that capacity loss compounds, and the portfolio drifts further from the threat model.
Who it is for
A senior information security specialist with three or more years of detection engineering or security operations experience inside a large-scale platform environment. Owns or co-owns a meaningful slice of the detection ruleset. Reports up to a security engineering manager or detection lead. Carries on-call for the rules they author. Sees internal red-team test results, external audit requests, and regulator queries cross their desk in the same month.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. Three to five hours per module at a part-time pace. Roughly forty to sixty hours total for the full portfolio build, depending on how much existing detection content is in scope.
Why $199 is the right number
Vendor-led detection engineering training tends to focus on one product, one rule language, and one threat-emulation library. This course is platform-agnostic on the rule language and focuses on the portfolio discipline that survives a platform migration. Free conference talks on detection-as-code give you the principles. This course gives you the templates and the implementation playbook so the principles ship into your environment without a parallel engineering effort.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.