IT Administrator to Security Practitioner
You already run the systems attackers target. This path converts daily administration experience into deliberate security skill — identity, endpoints, logs, and the evidence habits that define the role.
Most security practitioners were something else first — and IT administration is the strongest starting point there is. You already understand how identity, endpoints, networks, and SaaS platforms behave in production. What this path adds is the security frame: how those systems fail, how attackers use them, and how to produce the documentation and evidence that separates “I secured it” from “I can show you.”
The path alternates between analysis and hands-on work. The articles build the operating concepts; the labs make you do the job — reviewing real-shaped access data and reconstructing an incident from the kind of fragmentary evidence real responders get.
Modules marked available are open now in Release 0.1 as articles and labs. Modules marked coming in the next release will ship as full guided lessons; their subjects are listed so you can see the whole arc before committing.
Module sequence
Modules marked “Open now” link to working material. The rest arrive as guided lessons in the next release.
- 01
The security mindset for administrators
Coming in the next releaseAssets, threats, and controls as a way of seeing systems you already know — and why administrators make strong security hires.
- 02
Identity is the perimeter
Coming in the next releaseAccounts, sessions, tokens, and MFA mechanics across Google Workspace and Microsoft 365 — where account takeover actually happens.
- 03
Access reviews in practice
Open nowScope, extract, decide, remediate, evidence: the quarterly cycle that doubles as your first audit artifact.
- 04
A hands-on review of admin roles in a realistic SaaS estate — finding the stale, the shared, and the excessive.
- 05
Logs as evidence
Open nowBuilding an incident timeline from mixed, messy sources — the core analyst skill of sequencing what happened.
- 06
Endpoint baselines you can verify
Coming in the next releaseUpdates, encryption, screen lock, and endpoint protection enforced through management tooling — and reported on.
- 07
Vendor accounts, integrations, and MSP access — inventorying and constraining the risk you inherit.
- 08
Positioning for the security role
Coming in the next releaseTranslating administration experience into security language for resumes and interviews — without exaggeration.
What you will produce
- A completed access-review worksheet with documented decisions
- An incident timeline built from mixed evidence sources
- A personal endpoint-hardening baseline checklist
- A vendor-access inventory for a realistic environment