Course overview
Start hereAI for Security Engineers
START HERE

Priya's Wednesday, Two Ways

8 lessons · 24 prompts

A day in the life of a Security Engineer: what changes with these prompts.

Track progress as a member

Priya, a security engineer at a regional hospital network

Priya starts Wednesday with a vulnerability scan from Tuesday night: 412 findings across 60 servers. She pastes the top section into ChatGPT with the triage prompt from the course, asking for priorities grouped by internet-facing systems and known exploits. By the time standup starts, she has a short list she can send to the server team with fix instructions attached.

Mid-morning, a threat intel note lands about a credential-stealing tool. She uses the detection rule lesson in Claude to draft a Sigma rule and a matching SIEM query for failed VPN logins followed by a successful one from a new country. She tests it against last month's staging index and tweaks one field name before saving it.

After lunch, a billing clerk clicks a link in a fake invoice email. Priya opens Gemini and runs the incident response prompt with her notes, the alert timestamps, and the endpoint logs. It returns a timeline and a containment checklist she can follow, plus a short update she sends to the finance director in plain language.

By four o'clock she has finished what used to take until Thursday. She spends the extra hour walking a new analyst through the access review process, then leaves on time for her daughter's school concert.

Before

  • Alerts pile up faster than you can read them
  • Audit evidence scattered across three shared drives
  • Explaining risk to leadership takes a whole afternoon
  • Detection rules written late, tested in a hurry

After this course

  • First drafts ready before your morning coffee
  • Findings sorted and handed off by standup
  • Plain-language updates written in minutes
  • Time for mentoring, testing, and going home on time

What you'll learn

  • Triage Findings: Turn raw scan output and CVE feeds into clear priorities and fix instructions for system owners.
  • Detection Rules: Convert threat intelligence and hunches into working SIEM queries, Sigma rules, and YARA signatures.
  • Tool Configuration: Understand what tool settings do and produce baseline configurations, firewall rules, and hardening checklists.
  • Incident Response: Turn scattered logs and alerts into a timeline, a containment plan, and clear updates.
  • Pen Test Reporting: Scope engagements, document findings, and explain attack paths so clients and engineers can act.
  • Access and Identity: Design and review permissions so people and systems get only the access they need.
  • Policies and Audits: Draft policies, map controls to frameworks, and organize evidence so audits take less time.
  • Explain Security Clearly: Communicate risk and teach staff about threats without jargon or alarm.

How this course works

  1. 8 lessonsOne task of your job each, from triage vulnerability findings to explain security to non-technical people.
  2. Ready-to-paste promptsCopy, fill in the parts in {{brackets}}, paste into ChatGPT, Claude or Gemini.
  3. Tick and completeTick the prompts you tried and mark each lesson complete.
  4. Get certifiedFinish and keep the prompts as your own library.