Skip to main content
Image coming soon

The Senior Security Specialist Detection Portfolio Playbook

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The Senior Security Specialist Detection Portfolio Playbook

Own a detection-engineering portfolio that holds up to red-team replay and external audit in the same week.

The next red-team report and the next SOC 2 evidence request will both ask about the same detection rules. Right now those two answers do not match.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

Senior security specialists at hyperscale environments carry detection rules across multiple platforms, threat models that age out fast, and audit evidence requests that arrive on a different cycle from the red-team test cycle. The work that gets credit is the rule that catches a real incident. The work that gets criticism is the rule that fired late, the rule that never fired, the rule that fired ten thousand times in a quiet week, and the rule that has no documented test behind it when the assessor asks. This course closes that gap. It treats the detection set as a portfolio, with a threat-model justification per rule, a unit test per rule, a replay test against red-team artefacts, a documented false-positive budget, a tuning history, and an audit evidence pack ready for SOC 2, ISO 27001, and external regulator inquiries without a scramble.

What you walk away with

  • Map every detection rule you own to a specific threat-model entry with documented coverage rationale.
  • Convert ad hoc detection logic into unit-tested, version-controlled detection-as-code with a replay harness.
  • Produce an audit evidence pack covering SOC 2, ISO 27001, and regulator inquiries that an external assessor accepts without follow-up.
  • Run a documented false-positive budget per rule, with tuning history and on-call impact tracked over time.
  • Hand over a detection-portfolio review document at quarterly reviews that satisfies engineering managers and internal audit at the same meeting.

The 12 modules

Module 1. From Detection Set to Detection Portfolio
Reframe the rules you own as a portfolio with a stated coverage objective, ownership map, and lifecycle states. Inventory current rules, classify by data source, classify by threat-model entry, and identify rules with no clear owner. Produce a single-page portfolio brief you can show an engineering manager that answers what you cover, what you do not cover, and what is in flight. This is the artefact every later module ties back to.
Module 2. Threat Model to Detection Mapping
Build a mapping table from threat-model entries to specific detection rules, with explicit coverage rationale for each link. Use a lightweight STRIDE or MITRE ATT&CK mapping for the systems you actually work on. Identify threat-model entries with no detection, detections with no threat-model justification, and stale entries where the system changed but the mapping did not. Output is a living mapping document the team can reference in design reviews.
Module 3. Detection-as-Code Repository Hygiene
Move detection content into a version-controlled repository with a defined module structure, code review process, test gating, and deployment pipeline to the SIEM or rules engine. Cover branch strategy, commit message standards, change-review evidence, and reproducibility from a clean checkout. The repository becomes the source of truth that audit and on-call both reference. Includes a sample directory layout suitable for a multi-author team.
Module 4. Unit Testing Detections
Write tests that prove each rule fires on the events it should and stays silent on the events it should not. Use synthetic event fixtures plus parameterised test cases. Cover positive, negative, and edge-case events. Wire tests into the repository pipeline so a change cannot ship without a green test. Includes a worked example for SIEM correlation rules and another for EDR behavioural detections.
Module 5. Replay Harness Against Red-Team Artefacts
Build a replay harness that takes red-team test artefacts, beaconing samples, or threat-emulation outputs and feeds them through the deployed detection set. Produce a coverage report showing which artefacts triggered which rules, time to first alert, and any artefacts that produced no alert at all. This is the document you bring to the next red-team retro instead of arguing rule-by-rule.
Module 6. False-Positive Budgets and Tuning Logs
Set a documented false-positive budget per rule expressed in alerts per week per analyst, track actual rates over time, and record every tuning change with rationale. This stops silent tuning that masks coverage gaps and gives on-call leads a defensible answer when a rule starts firing too often. The tuning log doubles as audit evidence that detection content is actively maintained.
Module 7. Audit Evidence Pack Construction
Build a reusable evidence pack that satisfies SOC 2 CC7, ISO 27001 Annex A controls covering logging and monitoring, and external regulator queries. Pack contents include the portfolio brief, the mapping table, sample test outputs, sample replay outputs, tuning logs, and the on-call hand-off document. The objective is an assessor reads the pack and closes the control without an interview. Includes templates for each component.
Module 8. Cross-Platform Coverage and Telemetry Gaps
Identify systems that produce no useful telemetry, systems that produce telemetry the detection pipeline does not ingest, and systems where ingestion is broken but no alert fires. Build a coverage gap report that ranks gaps by threat-model severity, not by ease of fix. The report becomes the basis of engineering team capacity asks at planning cycles. Walks through both cloud-native and on-host telemetry classes.
Module 9. On-Call Hand-Off and Runbook Discipline
Every detection in the portfolio needs a runbook that an on-call analyst who is not the rule author can act on. Build the runbook template, link runbooks to detections at the repository level, and put runbook completeness on the same review gate as the unit test. Includes a worked runbook for a credential-misuse detection and a worked runbook for a data-exfiltration detection.
Module 10. Detection Performance Against Real Incidents
After every real incident, run a structured post-mortem that asks which detections fired, which fired late, which would have fired with different tuning, and which were missing entirely. Roll these findings back into the threat-model mapping, the unit tests, and the replay harness. This module gives you a closed loop between live incidents and the portfolio rather than a one-off retro doc.
Module 11. Briefing Engineering Leadership
Quarterly review materials that compress the portfolio state into one slide for engineering leadership and one slide for security leadership. Coverage versus threat model, mean time to detect by detection class, tuning rate, audit readiness, and the one ask that needs leadership air cover. The slide-pair format keeps the review out of the rule-by-rule weeds and on the coverage question that decides next-quarter capacity.
Module 12. The Senior Specialist Portfolio Review
Assemble everything into a portfolio review packet you can use at a calibration cycle, a promotion review, or an internal transfer interview. The packet is the artefact that proves senior-level ownership beyond rule count. Includes a sample review packet, a self-assessment rubric calibrated to senior-IC expectations at platform-scale environments, and a one-page narrative template that summarises a year of detection-portfolio work in language non-security stakeholders read.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

Module 1 produces the portfolio brief you cite in every later conversation.
Modules 2 to 5 cover the engineering substrate: mapping, repo, tests, replay.
Modules 6 to 9 cover the operational discipline: budgets, evidence, gaps, runbooks.
Modules 10 to 12 cover incident learning, leadership briefing, and the review packet.

What you get with this course

  • Twelve text-based modules in the Art of Service learning environment.
  • Downloadable templates for the portfolio brief, threat-model mapping table, unit test fixtures, replay coverage report, tuning log, audit evidence pack, runbook, post-incident detection retro, and quarterly review slide-pair.
  • Worked examples for both SIEM correlation detections and EDR behavioural detections.
  • Hand-built implementation playbook tuned to your environment, delivered alongside course access.

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours your learning environment account is provisioned and the implementation playbook is delivered alongside it.

Twelve modules, paced at roughly one per week for a part-time pace, or two per week for a focused build.

Templates and worked examples downloadable from module one onward.

Before and after

Before

You own a detection set that catches real attacks, but the evidence behind each rule lives in your head, in a Slack thread, or in a one-off doc. Audit requests and red-team retros surface gaps in different places and you reconcile them by hand.

After

Your detection set is a documented portfolio with mapping, tests, replay coverage, FP budgets, runbooks, and an audit evidence pack. Audit, red team, on-call, and engineering leadership all read from the same artefacts.

What happens if you do not address this

The next red-team report and the next external audit will continue to land on different weeks asking overlapping questions. Each one will consume engineering capacity that could have been spent closing the next coverage gap. Over a year that capacity loss compounds, and the portfolio drifts further from the threat model.

Who it is for

A senior information security specialist with three or more years of detection engineering or security operations experience inside a large-scale platform environment. Owns or co-owns a meaningful slice of the detection ruleset. Reports up to a security engineering manager or detection lead. Carries on-call for the rules they author. Sees internal red-team test results, external audit requests, and regulator queries cross their desk in the same month.

Who this is NOT for. Not for analysts who only triage alerts and do not author detections. Not for security generalists who do not work inside a SIEM, EDR rule pipeline, or detection-as-code repository. Not for compliance staff who do not own the underlying detection content.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Three to five hours per module at a part-time pace. Roughly forty to sixty hours total for the full portfolio build, depending on how much existing detection content is in scope.

Why $199 is the right number

Vendor-led detection engineering training tends to focus on one product, one rule language, and one threat-emulation library. This course is platform-agnostic on the rule language and focuses on the portfolio discipline that survives a platform migration. Free conference talks on detection-as-code give you the principles. This course gives you the templates and the implementation playbook so the principles ship into your environment without a parallel engineering effort.

FAQ

Do I need a specific SIEM or EDR to follow along?
No. The templates use a vendor-neutral rule format and the worked examples are provided for both SIEM correlation logic and EDR behavioural detection logic. Translation notes cover the common rule languages.
What if my team is already on detection-as-code?
Most of the value then sits in modules 2, 5, 6, 7, and 10, where the gap is usually evidence and replay rather than repository hygiene. The course is structured so a team already past module 3 can skip ahead and use the templates without rework.
Can I use this for an internal transfer or promotion case?
Module 12 builds the portfolio review packet specifically for that. The rubric is calibrated to senior individual-contributor expectations at platform-scale security organisations.
Is the implementation playbook generic or built for my situation?
Hand-built for your environment from the intake form you complete after purchase. It cites the systems, telemetry sources, and audit obligations specific to your scope.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.