Rooman
Professional Programmes · Security · 240 hours

Cyber Security Expert. Defend, detect and respond to real attacks.

Rooman's Cyber Security Expert programme is a 240-hour programme across the security lifecycle: foundations, network and system defence, ethical hacking, security operations and cloud security. You work with Nmap, Nessus, Metasploit, Wireshark, Splunk and the ELK Stack, and earn the Rooman Certificate with NSDC recognition.

240 hours12 modulesPlacement driveCapstone project

What you'll be able to do

Defend a network, then test it.

Security teams protect systems, find weaknesses before attackers do, and respond when something goes wrong. This programme covers each of those jobs, from first principles to the SOC and the cloud.

01

Defend

Harden networks and systems.

Design firewall rules, configure IDS/IPS and VPNs, and harden Linux and Windows.

02

Attack

Test like an ethical hacker.

Scan with Nmap and Nessus, exploit with Metasploit and test web apps against the OWASP Top 10.

03

Respond

Run security operations.

Triage alerts in Splunk and ELK, hunt threats and handle an incident end to end.

Skills covered

  • Security principles, policies and frameworks
  • Firewalls, IDS/IPS and VPNs
  • Linux and Windows hardening
  • Vulnerability scanning with Nmap and Nessus
  • Ethical hacking and penetration testing
  • SIEM operations with Splunk and ELK
  • Incident response and forensics basics
  • AWS and Azure cloud security

Who it's for

Built for your first security role.

The programme is for engineering graduates and final-year students. It starts from the basics, so IT or networking knowledge helps but is not required.

Roles where these skills are used

  • SOC Analyst
  • Cybersecurity Analyst
  • Network Security Engineer
  • Cloud Security Engineer
  • Ethical Hacker
  • Security Operations Specialist

Entry requirements.

  • B.E or B.Tech in CS, IT, ECE, EEE or Instrumentation, final year or recent graduate
  • Good English communication skills; a minimum of 70% marks through your academics is preferred
  • Basic IT or networking knowledge helpful, not required

Not sure which course fits? Take the 10-minute career assessment, or talk to a counsellor.

240 hours · 12 modules

A curriculum across the security lifecycle.

Twelve modules in six stages: security foundations, network security, system security, ethical hacking, security operations and cloud security.

01Security principles and threats16 hrs

What you are protecting, and what it is protected from.

Topics covered

  • The CIA triad: confidentiality, integrity and availability
  • Threat landscape: phishing, ransomware, insider threats and APTs
  • Malware types: viruses, worms, trojans, spyware and ransomware

You produce: a threat summary for an organisation.

02Policies, frameworks and risk16 hrs

How organisations govern security.

Topics covered

  • Security policies: acceptable use, passwords and incident response
  • Security frameworks: NIST and ISO 27001
  • Risk assessment and risk management basics

You produce: a basic risk assessment.

03Network defence20 hrs

Controlling what enters and leaves a network.

Topics covered

  • Firewalls: hardware and software, rule design and packet filtering
  • Intrusion detection and prevention (IDS/IPS)
  • VPNs, secure tunnels and remote access

You produce: a firewall rule set with IDS/IPS and VPN access.

04Scanning and segmentation20 hrs

Finding weaknesses and limiting their reach.

Topics covered

  • Port scanning: discovery, and assessment versus exploitation
  • Vulnerability scanning with Nmap and Nessus
  • Network segmentation and zero-trust principles

You produce: a vulnerability scan report.

05Operating system hardening20 hrs

Locking down Linux and Windows machines.

Topics covered

  • Hardening Linux and Windows: best practice and security controls
  • Patching, security updates and exploit prevention
  • Permissions: user and group access control, file and directory hardening

You produce: a hardened Linux and Windows host.

06Secure configuration and endpoint monitoring20 hrs

Keeping systems secure and knowing what happens on them.

Topics covered

  • Secure configurations: baselines, firewall rules and registry settings
  • Endpoint detection and response (EDR) basics
  • System logging and audit trails

You produce: a secure baseline with audit logging.

07Ethical hacking methodology20 hrs

How attacks unfold, and how to test for them legally.

Topics covered

  • Phases of hacking: reconnaissance, scanning, gaining and maintaining access, covering tracks
  • Reconnaissance: information gathering, footprinting and target identification
  • Exploitation and ethical penetration testing

You produce: a reconnaissance report on a lab target.

08Penetration testing tools and techniques24 hrs

Testing networks, web applications and wireless.

Topics covered

  • Tools: Metasploit, Wireshark, Burp Suite and offensive Python
  • Web application security testing (OWASP Top 10)
  • Wireless network security testing

You produce: a vulnerability assessment and penetration test (VAPT).

09Incident response and the SOC20 hrs

Detecting, triaging and escalating security events.

Topics covered

  • Incident response: detection, investigation, containment and recovery
  • SOC operations: monitoring, threat triage and escalation
  • SIEM with Splunk and the ELK Stack: log analysis, threat detection and alerts

You produce: a triaged set of SIEM alerts.

10Threat hunting and forensics20 hrs

Looking for attackers and handling evidence.

Topics covered

  • Threat hunting fundamentals
  • Forensics basics: evidence handling and basic forensic tools
  • Case study: end-to-end incident response simulation

You produce: an end-to-end incident response simulation.

11Cloud identity and threats20 hrs

Who can do what in the cloud, and what goes wrong.

Topics covered

  • Identity and access management: RBAC, MFA and fine-grained permissions
  • Cloud-specific threats: misconfigurations, insecure APIs and data exposure
  • The shared responsibility model

You produce: an IAM policy review.

12Secure cloud design and compliance24 hrs

Building and auditing secure cloud environments.

Topics covered

  • Secure cloud design on AWS and Azure: encryption, VPCs and logging
  • Container and Kubernetes security
  • Cloud compliance: SOC 2, ISO and HIPAA

You produce: a cloud security audit.

Tools covered

The tools you'll work with.

You work with the tools security teams use to scan, test, monitor and respond.

Tools covered in Cyber Security Expert
Tool groupToolsWhat you use them for
ScanningNmap, NessusDiscover hosts and find vulnerabilities
Penetration testingMetasploit, Burp Suite, Wireshark, offensive PythonExploit, intercept and analyse traffic
Security operationsSplunk, ELK StackAnalyse logs, detect threats and raise alerts
Cloud securityAWS and Azure security servicesSecure identities, networks and data in the cloud

Capstone

Attack it ethically. Then defend it.

Your capstone projects are a vulnerability assessment and penetration test, SOC alert triage, a cloud security audit and an incident response simulation, each run in a lab environment and written up as a report.

Every stage includes hands-on labs with real security tools.

What you finish with.

  • A vulnerability assessment and penetration test report
  • A SOC alert triage log
  • A cloud security audit
  • An incident response report
  • A hardened Linux and Windows baseline

Your credential

Rooman Certificate.

The Rooman Certificate, with NSDC recognition. You earn the Rooman Certificate, recognised by NSDC, when you complete the programme and its capstone projects.

Placement support runs alongside the final modules: resume workshops, mock interviews, job referrals and Rooman's placement drive. Your capstone projects become the portfolio you take to interviews.

What's included

Everything you need to finish.

  • Instructor-led sessions with hands-on labs
  • Projects in every module and a capstone
  • Generative AI built into the curriculum
  • Resume workshops, mock interviews and job referrals
  • The Rooman Certificate, with NSDC recognition
  • A counsellor to guide you from enrolment to placement

Before you enrol

Questions future security analysts ask.

Can't find your answer? Call 080 6945 1000 or WhatsApp us.

Who is this programme for?

Engineering graduates and final-year students who want to start a career in cyber security.

Do I need prior IT knowledge?

No. The programme starts from the basics, though IT or networking knowledge helps.

Which tools will I use?

Nmap, Nessus, Metasploit, Burp Suite, Wireshark, Splunk, the ELK Stack, and AWS and Azure security services.

What kind of projects will I do?

Vulnerability assessments, SOC alert triage, a cloud security audit and an incident response simulation.

Will this help me earn CEH?

The ethical hacking modules cover much of the same ground as EC-Council's CEH. Rooman also runs a dedicated CEH course.

How much time does it take?

240 hours, including labs and projects. Rooman runs evening and weekend batches.

How is it delivered?

Residential, online or hybrid. Rooman runs evening and weekend batches, and a counsellor will tell you which formats your batch offers.

Is placement support included?

Yes. You get resume workshops, mock interviews and job referrals, and you take part in Rooman's placement drive.

Which certificate will I receive?

The Rooman Certificate, with NSDC recognition, and a portfolio of your security reports.

How do I find out fees and batch dates?

Talk to a Rooman counsellor on 080 6945 1000 or WhatsApp +91 97390 86029. They will share current fees, payment options and upcoming batch dates.

Next step

Start with a conversation.

Tell us your degree or current role, and a counsellor will call you with batch dates, fees and payment options.

I'm enquiring

We’ll only use your details to contact you about this course.

Course details reviewed on 25 September 2026.