
Network Security Engineer — career path
StationX Intermediate
Networks first, then the security of them: Network+ and CCNA for the plumbing, Security+ for the controls, then firewalls, IDS and packet analysis on real machines.
The path
Step 1 — Networking foundation
Subnets, routing, switching — the fluency the job is built on.
follows a certification path
Learn
- PathFollow the CompTIA Network+ (N10-009) path — the networking certification adverts ask for first
Step 2 — Enterprise networking
Configure real Cisco kit the way enterprises run it.
follows a certification path
Learn
- PathFollow the Cisco CCNA (200-301) path — the hands-on networking certification
Step 3 — Security foundation
The controls you will be putting on the network.
follows a certification path
Learn
- PathFollow the CompTIA Security+ (SY0-701) path — the security baseline for the role
Step 4 — Firewalls, IDS and traffic analysis
Build and tune the controls, then read the traffic they see.
3 courses · 35 labs
Learn
- CoursepfSense Fundamentals - Secure Your Network With pfSense 🔒 StationX Unlimited
11 sections · 60 lectures
- Section 1: Introduction 1
- Section 2: Firewalls Refresher 2
- Section 3: pfSense Installation 2
- Section 4: Creating A Virtual Lab 4
- Section 5: pfSense Initial Setup 8
- Section 6: pfSense Firewall 11
- Section 7: pfBlockerNG 3
- Section 8: Snort IDS/IPS 7
- Section 9: Suricata IDS/IPS 7
- Section 10: Configuring a DMZ 12
- Section 11: Maintenance 3
- CourseSnort Intrusion Detection, Rule Writing, and PCAP Analysis 🔒 StationX Unlimited
3 sections · 16 lectures
- Training Overview 2
- Lectures 1
- Hands-on Labs 13
- CourseMaster Wireshark 3 in 5 Days 🔒 StationX Unlimited
6 sections · 34 lectures
- Training Overview 2
- Day One 3
- Day Two 8
- Day Three 7
- Day Four 7
- Day Five 7
Practise
- LabsNetwork Security — 12 labs 🔒 StationX Unlimited
- Assess A High-Risk System
- Auditing Service Accounts
- Block Incoming Traffic on Known Port
- Holistic Network Identification and Protection
- Implement Single System Changes in Firewall
- Network Topology Generation
- Protect Against Beaconing
- Rogue Device Identification and Blocking
- Setting Up SYSLOG Forwarding From a Windows System
- Sinkholing C2 Traffic
- Threat Designation
- Windows System Hardening with PowerShell
- LabsNetwork Intrusion Detection — 8 labs 🔒 StationX Unlimited
- LabsNetwork Forensics — 15 labs 🔒 StationX Unlimited
- Analyze Browser-based Heap Spray Attack
- Automated in-Depth Packet Decoding
- Clonezilla_Network
- Identifying Intrusion and Mitigating Attacks with RHEL Server
- Identifying Malicious Callbacks
- Identifying Malicious Network Connections
- Incident Detection and Identification
- Nexpose: Analysis & Reporting (Executive, High Risk and Recommendation Reporting)
- Parse Files Out of Network Traffic
- Searching for Indicators of Compromise
- Setting up Filters and Queries in Kibana
- Use pfTop to Analyze Network Traffic
- Verify Attributes of Identified SilentBanker Intrusion
- Verify Attributes of Intrusion Through Additional Analysis
- Windows Event Log Manipulation via Windows Event Viewer
Step 5 — Run the network
The operations skills that keep a secure network up.
1 course · 49 labs
Learn
- CourseLinux Network Administration 🔒 StationX Unlimited
5 sections · 24 lectures
- Training Overview 2
- Introduction 2
- Lab Setup 4
- Linux Network Administration 15
- Audio Version of the Training 1
Practise
- LabsNetwork Operations Specialist Training Series — 49 labs 🔒 StationX Unlimited
- Analyze Malicious Network Traffic
- Applying Filters to TCPDump and Wireshark
- Auditing Service Accounts
- Auditing Service Accounts and Creation of Service Accounts To Run Specific Services
- Auditing Service Accounts and Setting Up Automated Log Collection
- Baseline Systems in Accordance with Policy Documentation
- Block Incoming Traffic on Known Port
- Clonezilla_Network
- Comparing Controls
- Conduct Root Cause Analysis for System Crashes
- Conduct Supplemental Monitoring
- Control Assessment and Evaluation
- Creating a List of Installed Programs, Services and User Accounts from a WIN2K12 Server
- Denial of Service PCAP Analysis
- Firewall Setup and Configuration
- Host Identification Scanning via Windows
- Host Identification Scanning with Linux
- Identify Access to a LINUX Firewall Through SYSLOG Service
- Intro to Linux - Routing and SSH Tunnels
- LNX101 - OpenSSH Installation, Configuration, and Hardening
- LNX101 - Setting Up a Firewall With UFW and Firewalld
- LNX101 - Telnet vs. SSH
- Manual Vulnerability Assessment
- Manually Analyze Malicious PDF Documents
- Manually Analyze Malicious PDF Documents 2
- Monitoring and Verifying Management Systems
- Network Segmentation (FW/DMZ/WAN/LAN)
- Network Topology Generation
- PAM Lab
- Parse Files Out of Network Traffic
- Participate in Attack Analysis Using Trusted Tool Set
- Patching With WSUS
- Preliminary Scanning
- Protect Against Beaconing
- Recover from Incident
- Rogue Device Identification and Blocking
- Scanning From Windows
- Scanning with Nmap
- Securing Linux - Firewalls
- Securing Linux for System Administrators
- Setting Up SYSLOG Forwarding From a Windows System
- Setting Up Zones in a Firewall
- Snort Signatures, IDS Tuning, and Blocking
- Tweaking Firewall Rules for Detection
- Use pfTop to Analyze Network Traffic
- Using Snort and Wireshark to Analyze Traffic
- Vulnerability Analysis/Protection
- Windows Event Log Manipulation via Windows Event Viewer
- Windows System Hardening with PowerShell
Where this leads
- Cisco CyberOps Associate (200-201) — Intermediate
- Security Engineer — career path — Advanced
- CISSP — Certified Information Systems Security Professional — Advanced
Advanced · after the job
The AI-Driven Network Security Engineer
Senior roles are going to the people who can direct AI to build security solutions. When you're working in the role and ready for that step, the AI Master's Program is where it's taught — an advanced, application-only programme.
See the AI Master's Program →Application-only. A separate programme for when you're ready.