← Every path

H2-CFSE · Specialist path

Fintech

H2 Certified Fintech Security Engineer

Build a bank-grade payment stack and keep it running through an audit, an attack, a fraud campaign and an outage. A tokenized checkout, a ledger that can prove it was never rewritten, fraud and KYC, an open-banking API, the keys that sign it all, and the day it breaks.

6 courses · 39 lessons · ~69 h of guided work

Assumes Foundation + T-Shaped core; CPSE recommended

What you leave with

A running payment stack in test mode: tokenized checkout, a Merkle-anchored ledger, fraud and KYC, an open-banking API, post-quantum-signed keys, and a tested incident playbook.

Gateway
Envoy Gateway
Identity
Zitadel
Keys
OpenBao
Database
PostgreSQL / CNPG
Signatures
ML-DSA + classical
Payments
Stripe / Adyen test

Syllabus

6 courses · every lesson graded · minutes are guided work

  1. Course 01

    Payment Security

    Take a card payment without ever holding the card. Scope reduction by design, webhooks that cannot be replayed, money movement that cannot double, and the evidence a QSA asks for.

    8 lessons · ~14 h

    Tools Stripe/Adyen test mode, the H2 scanner privacy engine, Envoy Gateway

    1. 01How money movesA scope map of one card payment across issuer, network, acquirer and PSP, marking where the PAN, the token and the money each exist.120 min
    2. 02Scope reductionHosted-fields checkout; prove no PAN reaches your server; SAQ A posture, not SAQ D.120 min
    3. 03Webhooks done rightSignature verification, a replay window, ordering, and a dead-letter queue.90 min
    4. 04Idempotency and exactly-once moneyIdempotent charge and refund endpoints that survive a retry storm with no double charge.90 min
    5. 05Segmenting the cardholder environmentNetwork policy isolating the payment service, secrets from a vault, an egress allow-list.120 min
    6. 06Logging without leakingA PAN-discovery scan across logs and database, redaction in the pipeline, a test that fails if a PAN appears.90 min
    7. 073DS and SCA within a friction budgetA step-up challenge wired into checkout; conversion cost per challenge measured.90 min
    8. 08The evidence packThe artefacts an assessor asks for, mapped control by control to PCI DSS 4.0.120 min

    Course checkYour checkout is attacked for six hours: PAN exfiltration, replayed webhooks, double-charge storms, a log-leak probe. Pass if nothing lands and the evidence pack accounts for every control.

    You leave withA live tokenized checkout in test mode, a segmented cardholder environment, a PAN-free log pipeline, and a PCI DSS 4.0-aligned evidence pack.

  2. Course 02

    Ledger and Money Integrity

    A ledger that can prove it was never rewritten. Double-entry, append-only, hash-chained, Merkle-anchored to a witness you do not control. Back-dating becomes a proof failure, not a forensics job.

    6 lessons · ~11 h

    Tools PostgreSQL, Merkle tree implementation, a transparency log, ML-DSA

    1. 01Double-entry for engineersA ledger service with accounts, postings and an invariant that every transaction sums to zero.90 min
    2. 02Append-only storage and the hash chainAn immutable event table; each event carries the hash of the last. Edit the past, watch every hash break.90 min
    3. 03Merkle trees and proofsA tree over the log, inclusion proofs, consistency proofs, and tree heads signed with ML-DSA and a classical signature.150 min
    4. 04External anchoringPublish tree heads to a transparency log or timestamp authority; verify from outside your own infrastructure.90 min
    5. 05ReconciliationIngest PSP settlement files, match against the ledger, route breaks to suspense accounts.120 min
    6. 06Corrections without rewritingReversals and adjustments as new entries; effective date versus posted date, the trap behind every back-dating fraud.90 min

    Course checkYour ledger is seeded, after the fact, with back-dated and altered entries and a reconciliation break. Find every one from proofs alone, name the anchor that caught it, and produce the evidence bundle. A real engagement, reproduced as an exam.

    You leave withA ledger service with inclusion and consistency proofs, post-quantum-signed tree heads published to an external witness, and reconciliation against real settlement files.

  3. Course 03

    Identity, KYC and Fraud Engineering

    Onboard a customer, keep the wrong ones out, and do not lose the right ones. Identity, device and velocity signals, account-takeover defense and the ops loop that keeps rules honest.

    7 lessons · ~13 h

    Tools KYC vendor sandbox, Zitadel, a rules engine, crypto-shredding

    1. 01Onboarding with a KYC vendorA sandbox flow with document, sanctions and PEP checks; retain the minimum and prove it.120 min
    2. 02Customer identityPasskeys, step-up authentication and session risk.90 min
    3. 03Device and velocity signalsA rules engine over velocity, device and geo signals, with explainable decisions.120 min
    4. 04Account-takeover defenseCredential-stuffing defense, hardened recovery, SIM-swap pattern detection.120 min
    5. 05Chargebacks and SCA exemptionsThe chargeback lifecycle end to end; exemption logic that spends friction where it pays.90 min
    6. 06The fraud-ops loopA case queue, labels, feedback into rules, and a drift dashboard.120 min
    7. 07PII and crypto-shreddingPer-record keys so erasure is a key deletion; the ledger hash chain stays intact.90 min

    Course checkA scripted campaign runs against onboarding and checkout: synthetic identities, stuffed credentials, velocity abuse, friendly fraud. Graded on fraud caught and good customers not blocked. Both numbers count.

    You leave withA KYC onboarding flow, passkey identity with step-up, a rules engine on live signals, a chargeback lifecycle, and erasure that keeps the ledger chain intact.

  4. Course 04

    Financial API Security

    Open your ledger to third parties without opening it to everyone. FAPI-grade OAuth, consent as a first-class object, a gateway that validates and rate-limits, and telemetry that notices abuse before the auditor does.

    6 lessons · ~11 h

    Tools Envoy Gateway, Zitadel (FAPI), mTLS / DPoP

    1. 01FAPI-grade OAuthPushed authorization requests, PKCE, and DPoP or mTLS sender-constrained tokens.150 min
    2. 02Consent as an objectConsent records with scope, expiry and revocation, enforced at the gateway.90 min
    3. 03The gatewaySchema validation, rate limits and abuse rules in front of the ledger API.120 min
    4. 04Object-level authorizationDefenses for the IDOR family, with tests that fail when a client reads another's account.90 min
    5. 05Third-party onboardingPartner registration, certificate issuance and rotation, revocation that revokes.90 min
    6. 06API telemetryPer-client baselines and anomaly alerts from gateway logs.90 min

    Course checkOur team penetration-tests your gateway for five hours against the API top ten and the open-banking specifics. Pass on zero criticals; every high has a fix committed before the retest.

    You leave withAn open-banking-grade API in front of your ledger, third-party onboarding with certificate lifecycle, and per-client anomaly detection.

  5. Course 05

    Keys, Secrets and Custody

    The keys that sign the ledger, encrypt the fields and authenticate the webhooks. Where they live, who can touch them, how they rotate under traffic, and what a ceremony looks like when two people must agree.

    6 lessons · ~10 h

    Tools OpenBao, HSM/KMS concepts, ML-DSA

    1. 01KMS and HSM conceptsA threat model of every path a key could leave by.60 min
    2. 02Envelope encryption and transitTransit-backed field encryption for the ledger; the data key never leaves the vault.120 min
    3. 03Ceremonies, dual control, quorumAn unseal procedure on Shamir shares, in a runbook two people execute together.90 min
    4. 04Rotation under trafficRotate encryption and signing keys with zero downtime and a proof of no plaintext exposure.120 min
    5. 05A signing serviceML-DSA plus classical signatures for the ledger's tree heads and the checkout's webhooks.120 min
    6. 06Tokenization vaultFormat-preserving tokens with detokenization under policy and audit.90 min

    Course checkRotate every key in the stack while it takes traffic. Graded on zero downtime, zero plaintext exposure, and a ledger whose proofs still verify with the new signing key.

    You leave withA transit encryption service, a quorum-controlled unseal, zero-downtime rotation, a post-quantum signing service and a tokenization vault.

  6. Course 06

    Resilience and Incident Response for Finance

    The day it breaks. Operational-resilience mapping, backups you have actually restored, a PSP that disappears mid-checkout, a card breach with a clock on it, and rebuilding the ledger from the anchored log.

    6 lessons · ~11 h

    Tools CNPG backup/restore, chaos tooling, the anchored ledger

    1. 01Operational-resilience mappingCritical functions, impact tolerances and a dependency map in the shape regulators expect.90 min
    2. 02Backups you can restoreObject-store backups of the ledger database and a timed restore; RTO and RPO measured for real.120 min
    3. 03Chaos day: the PSP disappearsQueue-and-retry, failover, and the customer message that goes out while it is down.120 min
    4. 04Card-breach playbookContainment, evidence preservation, and the notification clocks that start the moment you know.120 min
    5. 05Regulators and auditorsReport templates and a timeline reconstruction from the anchored log.90 min
    6. 06Rebuild the ledger from the anchored logReconstruct ledger state from Merkle-anchored events and prove it matches the last witnessed head.120 min

    Course checkAn eight-hour simulated incident: a breach and an outage in the same window. Graded on containment, evidence preserved, communications on time, and a ledger you can prove is intact.

    You leave withMeasured RTO and RPO, a tested failover, a breach playbook with notification timelines, and a ledger you can reconstruct and prove.

Certification course

H2 Certified Fintech Security Engineer

$799 · one price · courses + 90-day labs + exam

48-hour practical: an audit, an attack, a fraud campaign and an outage, in that order, against the stack you built. Graded on evidence handed over, attacks repelled, fraud caught without blocking good customers, and a ledger you can prove is intact.

Opens when Foundation is complete and the 6 course checks are passed. One proctored attempt, plus a free retake if you fail by a margin. The credential is an Open Badges 3.0 credential, signed and verifiable.

Create an account to enrol