
Application security might seem like a strange thing to build a coaching course about.
But the thing that makes coaching work is that the person comes out feeling bigger than the problem. That’s useful in many things. It’s especially useful in a field that seems to have been designed to be opaque. We’ve partnered with Halle Winkler to bring you a blend of her security expertise and our coaching mindset, in the DRI async+audio format.
This is our first partner course, and it gives us an opportunity to bring in another collaborator, with different skills. I’ve learned so much working on this, and I’m so excited to share it with you.
Halle and I met at an iOS conference years ago. She’s now an offensive security researcher and application security engineer, a Certified Ethical Hacker with twelve Apple security credits. Her CVE proofs of concept include a macOS remote-control camera and a Lock Screen keylogger.
There’s more talk about application security than there has ever been, which can make it seem more intimidating than ever – but we think it’s an opportunity to get to grips with it. If you’re a product engineer, you probably know more about this than you think you do. You understand systems. You’ve spent years thinking about managing a full range of inputs and all the unexpected states. What’s missing is the vocabulary, a map of the field, and the sense that you’re allowed to do this at all if you didn’t start hacking at thirteen. You are.
What is Breaking Into the Security Mindset?
Breaking Into the Security Mindset is an 8-week course for engineers and engineering managers who want to bring security into their engineering and product work. It isn’t magic and it isn’t only for lifelong hackers.
The course has 4 modules:
- Finding Yourself in Security — three personae: you as the defender, adversaries, and who you protect and why. Then threat modelling, the state of the art on both sides, and our ethics and safety practices.
- Your Project, Part 1 — build a small offensive research script or agent against a safe synthetic target, using local LLM workflows, and write up a vulnerability report on what you find.
- Your Project, Part 2 — research your vulnerability, remediate it, and then how you can adjust your development practices to prevent it being built in the first place.
- Bringing It Together — CI/CD and supply chain, secure coding as policy, which shift-left tooling applies to your products, and staying current so you can sleep at night.
Each module includes:
- Written content and frameworks, so the jargon is demystified
- Audio conversations between Halle and me
- Exercises to apply what you’ve learned to your situation
- Personal feedback from us on everything you turn in
- Project work you drive at your own pace
Plan for around 60 minutes a week. The project is the biggest variable. If it pulls you in, you might blow past that – and your bedtime!
Why now?
The agentic era of software development is also the agentic era of vulnerability exploitation. Teams are shipping AI-assisted code at volume, and a lot of people aren’t sure what risk that introduces or how to set guardrails around it. A lot of other people have quietly become the de facto security person on their team without ever deciding to.
This course is for you if you know security is a gap and it has felt too intimidating to begin. You’ll want to be actively coding, to the extent that building and debugging a small tool is possible for you. It’s not for you if you already work in security and want advanced technique.
Enrollment is open now.
Early bird pricing: $599 USD
Regular pricing: $699 USD
The course starts October 12th, 2026.

go deeper
Security
Security is everyone’s job now. Build the instincts to spot risk in your own work — without becoming the team’s blocker.
Leave a Reply