Security Notes

Security engineering, explained to be said out loud

Consolidated notes for security engineering interviews — cloud, detection, incident response, networking, malware and system design. Every topic starts in plain language, carries memory hooks, and ends with model answers you can rehearse.

How to use this
  1. Skim the breadth notes end to end — every topic in one page.
  2. Open a deep dive when a topic feels thin.
  3. Drill the practice questions until the answers come out in 60 seconds.

Start here 5

The breadth layer, the classic end-to-end question, the mindset and the self-assessment.

Networking 5

TCP/IP, DNS, HTTP, TLS and packet capture.

Cryptography & Identity 2

Primitives, PKI, OAuth/OIDC, SAML, JWT and password storage.

Web & AI Security 2

Application security and the OWASP LLM Top 10.

Cloud 6

AWS and GCP fundamentals, IAM, cost guardrails and cloud IR.

Hands-on Labs 7

Terraform-backed AWS scenarios: IR, EKS and CloudTrail detection.

Kubernetes 3

Cluster fundamentals, hardening and Kubernetes incident response.

Linux 4

Internals, privilege escalation and production deployments.

Windows 2

Active Directory and the registry.

Hardening 2

Linux and macOS baselines.

Detection Engineering 6

Pipelines, endpoint and identity detection, threat hunting.

Incident Response & Forensics 5

Triage, phishing, OpSec, reporting and digital forensics.

Malware & Exploitation 5

Reverse engineering, evasion, anti-debugging and memory corruption.

CI/CD & Supply Chain 3

Pipeline security, GitHub hardening and dependencies.

Compliance 1

Frameworks and what auditors actually ask for.

System Design 31

Foundations plus 25 classic designs with the security angle.

Coding 2

Python patterns for the coding round.

Behavioral & Closing 2

STAR stories and the questions to ask at the end.