← Every path

H2-CSSE · Core certification path

Secure Software Engineering

H2 Certified Secure Software Engineer

Write code that is secure by construction, not patched after a pentest. Secure design, language-level pitfalls in Go, Python and TypeScript, using cryptography correctly, authorization in the code, and shipping AI-assisted without shipping the model's vulnerabilities.

7 courses · 28 lessons · ~49 h of guided work

Assumes Foundation

What you leave with

A service you designed threat-first, free of the language-level and OWASP pitfalls, with correct crypto, in-code authorization, and an AI-assisted workflow that does not ship what the model got wrong.

Languages
Go, Python, TypeScript
Design
Threat modelling
Crypto
libsodium / age / KMS
Authz
Cedar / OPA in-code
Review
SAST + human

Syllabus

7 courses · every lesson graded · minutes are guided work

  1. Course 01

    Production services in Go and Python

    Write the service the rest of this path hardens: a Python client and a Go HTTP service that time out, retry safely, log usefully and come with tests that mean something.

    5 lessons · ~10 h

    Tools Go, Python, pytest, go test, ruff, golangci-lint

    1. 01Python for servicesA typed Python client with a virtual environment, pinned dependencies, and pytest coverage on the failure paths.120 min
    2. 02Go for servicesAn HTTP service in Go with context, timeouts, structured logs and a graceful shutdown.150 min
    3. 03Errors, retries, idempotencyA client that retries with backoff and jitter, and a server that makes the retry safe.90 min
    4. 04Tests that mean somethingUnit, integration and a contract test between your client and server; a CI job that runs them.120 min
    5. 05Assessment: ship a serviceGiven a spec, ship a service with tests and no secrets in source. Graded by the test runner and a secrets scan.120 min

    Course checkTo finish, you ship a service from a spec with tests and no secrets in source, and the test runner and a secrets scan grade it.

    You leave withBy the end you have a small HTTP service in Go with a Python client, both under tests you trust, with retries that cannot double-charge and a shutdown that loses nothing.

  2. Course 02

    Secure design and threat modelling

    Decide security at design time. Trust boundaries, abuse cases, and the design choices that make whole bug classes impossible instead of merely caught.

    4 lessons · ~7 h

    1. 01Trust boundariesWhere data crosses trust; the boundary as the place bugs live.90 min
    2. 02Abuse casesEvery feature's misuse case, written alongside its use case.90 min
    3. 03Designing bug classes outChoices that make injection or IDOR impossible, not just detectable.120 min
    4. 04Secure defaultsThe safe path as the easy path; the API that is hard to misuse.90 min

    Course checkThreat-model a proposed feature, identify the design changes that eliminate bug classes, and justify each.

    You leave withA threat model and a design for a real feature where the risky bug classes were designed out, not deferred to a scanner.

  3. Course 03

    Language-level secure coding

    The pitfalls that are specific to Go, Python and TypeScript, exploited and then fixed, so you recognize them while typing rather than in a report.

    4 lessons · ~8 h

    1. 01GoNil, concurrency data races, unchecked errors, and the standard-library sharp edges.120 min
    2. 02PythonDeserialization, injection through string building, and dependency risk.120 min
    3. 03TypeScript and the browserPrototype pollution, XSS, and trusting the client; the type system's limits.120 min
    4. 04Input handlingValidation, canonicalization and encoding; the order that matters.90 min

    Course checkGiven vulnerable snippets in all three languages, exploit each and ship the idiomatic fix.

    You leave withA tour of the real pitfalls in Go, Python and TypeScript, each exploited and fixed in idiomatic code.

  4. Course 04

    Using cryptography correctly

    Most crypto bugs are misuse, not broken algorithms. The right library for each job, the mistakes that void it, and post-quantum where it belongs.

    4 lessons · ~7 h

    1. 01Don't roll your ownThe library for each job; why AEAD, why not ECB, why a KDF for passwords.120 min
    2. 02The misuse bugsNonce reuse, missing authentication, timing side channels; reproduced and fixed.120 min
    3. 03Key management in codeKeys from a KMS or vault, never in source; rotation the code supports.90 min
    4. 04Post-quantum in the appWhere ML-DSA and ML-KEM belong in application code today.90 min

    Course checkImplement encryption, signing and password storage for a service using the correct primitives; a review checks for misuse.

    You leave withA service using authenticated encryption, correct password hashing and signatures, with a post-quantum signature where it fits.

  5. Course 05

    Secure APIs and authorization in code

    Build the API that the offensive path cannot walk through: authentication, object-level authorization, and rate limiting decided in code and tested.

    4 lessons · ~7 h

    1. 01API authenticationTokens validated correctly; the boundary between authn and authz.90 min
    2. 02Object-level authorizationEvery object access checked against the caller; tests that fail on IDOR.120 min
    3. 03Authorization as codeCedar or OPA in the service; policy tested like code.120 min
    4. 04Abuse resistanceRate limits, pagination limits and the mass-assignment guard, all tested.90 min

    Course checkBuild an API with object-level authorization covered by tests; an attacker script fails to read another tenant's data.

    You leave withAn API with authentication, tested object-level authorization, and rate limiting, that resists the attacks from the offensive path.

  6. Course 06

    Secrets, configuration and dependencies

    The un-glamorous bugs that cause most breaches: a secret in source, a bad default in config, a dependency you never vetted.

    3 lessons · ~5 h

    1. 01Secrets out of sourceConfig from environment and vault; a pre-commit and CI scan that catch a leak.90 min
    2. 02Safe configurationDefaults that fail closed; config validated at start-up.90 min
    3. 03Dependency hygieneVetting, pinning and updating; the transitive dependency you did not know you had.90 min

    Course checkTake a service with a leaked secret, an unsafe default and an unvetted dependency, and fix all three with checks that prevent recurrence.

    You leave withA service with no secret in source, safe-by-default configuration, and a dependency policy with a check that enforces it.

  7. Course 07

    AI-assisted coding without the vulnerabilities

    Coding assistants ship the same bug classes they were trained on. Review AI-written code, prompt for the secure version, and keep the model out of your secrets.

    4 lessons · ~6 h

    1. 01What assistants get wrongThe bug classes they reproduce; why fluent code is not safe code.90 min
    2. 02Reviewing AI codeA checklist for machine-written code; the findings that recur.90 min
    3. 03Prompting for the secure versionGetting the safe implementation the first time; constraints that hold.90 min
    4. 04Keeping the model out of secretsWhat an assistant may see; data handling and the exfiltration risk.90 min

    Course checkReview a body of AI-generated code, find the planted vulnerabilities, and rewrite the prompts to prevent them.

    You leave withA workflow that uses an AI assistant and still ships secure code: a review checklist, secure prompting patterns, and a policy on what the model may see.

Certification course

H2 Certified Secure Software Engineer

$499 · one price · courses + 90-day labs + exam

Ship a feature end to end under review: threat model, secure implementation across two languages, correct crypto and authorization, and a pass through SAST plus an adversarial review, with every finding closed.

Opens when Foundation is complete and the 7 course checks are passed. One proctored attempt, plus a free retake if you fail by a margin. The credential is an Open Badges 3.0 credential, signed and verifiable.

Counts toward H2-CTSE. Certified T-Shaped Security Expert is the credential of the whole T: hold all seven core credentials and it is awarded automatically, free, with no extra exam.

Create an account to enrol