Security Engineering: Threat Detection and Monitoring
This security engineering course in Toronto is about the system behind the alerts. Over eight weeks you design continuous monitoring for an environment you do not fully control, then build adversary informed detection use cases from log, endpoint and network telemetry.
The starting position is that architecture and detection are the same problem. A defensible design decides what you can see, and what you can see decides what you can catch.
- Duration
- 8 weeks
- Format
- Live online, instructor-led
- Prerequisites
- Security Essentials: Network, Endpoint and Cloud
- Class size
- Capped at 12 learners

What you will be able to do
- Design a telemetry collection plan that fits a real budget
- Write detection use cases derived from specific attacker techniques
- Instrument Windows, Linux and cloud workloads for meaningful visibility
- Assess an existing architecture and name its monitoring blind spots
- Build detections that keep working after the environment changes
- Measure detection coverage and report it honestly to leadership
- Set data retention and cost boundaries you can defend in a budget meeting
Course outline
6 modules
- Designing for visibility rather than adding it later
- Trust zones, chokepoints and enforcement points
- Identity as the primary control plane
- Where legacy systems force compromises
- Documenting an architecture others can operate
What you need before you start
- Security Essentials or comparable operational security experience
- Practical familiarity with at least one operating system in production
- Basic scripting or query writing ability in any language
- Willingness to design under real constraints rather than ideal ones
Who this course is for
- Security engineers building or rebuilding a monitoring capability
- SOC analysts moving into engineering work
- Infrastructure and platform engineers taking on detection duties
- Team leads deciding what telemetry to fund
- Consultants assessing client monitoring maturity
Where this leads
Prepares you for
CySA+
Awarded by CompTIA
The monitoring and detection content maps well to CompTIA CySA+. CompTIA, not the academy, examines candidates and issues the credential. The included study notes are supplementary; the course is built around engineering practice first.
Questions about this course
More in cyber defence
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



