Online training - Call us on 1300 009 924
Online training - access your course anytime, anywhere! Call us on 1300 009 924
Technology

Cyber Security Online Bootcamp

T-CSIB
10 Months Access
Online and Self-Paced
12 Modules
4 TechDX certifications
Start Immediately
Pay upfront & save
Mentor Support Available
Powered by TechDX
Internship Opportunities Available
In partnership with

Course Overview

The Cyber Security Online Bootcamp is one enrolment that takes you through four stacked TechDX certifications, in order, from your first day in security to specialist threat intelligence work. You start as a Certified Cybersecurity Associate, then move through the Certified Cybersecurity Analyst, Certified SOC Analyst, and Certified CTI Analyst roles. Together, that is 400 hours of learning and 12 units, weighted 60% towards hands-on labs. No prior cyber security or IT experience is required, so this cyber security bootcamp suits people starting from scratch as well as IT workers moving across. Study is fully online and self-paced on the browser-based TDX Arena platform, so you fit it around work rather than the other way around.

Why a stacked pathway rather than one course

A single standalone course leaves you with one credential and no evidence of range. Here each stage gates the next, so you build in the right order without skipping fundamentals. Credentials also accrue as you go: finishing Stage 1 already gives you three units and a TechDX certification, so you have proof to show employers long before the final stage. The order mirrors how security teams are structured, from generalist to analyst to SOC and intelligence specialist.

Who is this course for?

  • Complete beginners with no cyber security or IT background, starting from basic computer literacy.
  • Career changers who want a structured route into security rather than scattered self-teaching.
  • IT and helpdesk workers moving sideways into security who need defensive skills fast.
  • People who want demonstrable, tested skills on real workflows instead of theory-only study.
  • Anyone studying around a job or family who needs self-paced access, not fixed classes.
  • People aiming specifically at SOC analyst or cyber threat intelligence roles in Australia.



The Cyber Defence pathway

Four certifications, one enrolment

The bootcamp stacks four TechDX certifications in sequence. Each one gates the next, so you are never dropped into material you have no grounding for, and you finish each stage with a credential you can show an employer before the whole bootcamp is done. Complete in order and each stage unlocks the next.

Recommended pacing is 10 hours per week for 10 weeks per certification. Platform access is granted per certification, 75 days each.

400
hours of learning
4
TechDX certifications
12
units
60 / 40
hands-on labs to lessons
Stage 1
Certified Cybersecurity Associate


Get prepped for your cyber career: Computing fundamentals, networking and system administration, through to cloud security and threat defence.

Stage 2
Certified Cybersecurity Analyst


Start your cyber journey: Threat detection, incident escalation and the SOC workflows used in live security environments.

Stage 3
Certified SOC Analyst


Core security operations skills: Tier 2 blue team work: log analysis, alert triage, incident response and vulnerability management.

Stage 4
Certified CTI Analyst


An intelligence-driven approach: Track threat actors, analyse malware infrastructure and produce intelligence that drives security decisions.

Tools and frameworks you will work with

The labs put you in front of real industry tooling, not screenshots of it. Instead of naming products, the list below sets out the kind of work you do and the frameworks that shape it.

  • Command line administration across desktop and server systems
  • Packet capture and network traffic analysis
  • SIEM platforms for log aggregation and alert triage
  • Endpoint hardening, identity and access control work
  • Vulnerability scanning and CVSS scoring to prioritise patching
  • Email and phishing analysis: headers, links and attachments
  • Malware sandboxes and host, log and memory forensics
  • Threat intelligence platforms and OSINT adversary research

Frameworks the bootcamp maps to

  • MITRE ATT&CK: Names adversary tactics and techniques so you can map detections and threats
  • NIST Cybersecurity Framework: Organises security work across identify, protect, detect, respond and recover
  • NIST SP 800-61 incident handling: The incident response lifecycle that shapes the SOC analyst stage of the bootcamp
  • OWASP Top 10: The common classes of web application weakness you review in labs
  • ASD Essential Eight: Australia's eight mitigation strategies, used to measure the hardening work you do
  • STIX and TAXII: The shared format and transport you use to produce and exchange intelligence

Course Modules

Twelve units across four certifications, taken in order. Each stage ends in a hands-on applied exam before the next one opens.

Stage 1 builds the technical foundation that every security role assumes you already have: how networks work, how systems are hardened, and how a security team runs. Roughly 60 per cent is lab time. Built for career changers, self-taught IT staff and early-career security workers; needs only basic computer literacy and reliable internet.

Foundations: Command line work across file systems, permissions, processes and logs, then the OSI and TCP/IP models, subnetting, routing and protocols like DNS and HTTPS. Packet captures trace a session layer by layer; hashing and encryption protect data.

Systems: You administer operating systems: users, groups, least-privilege access, services, logging and auditing. You then harden a build to a baseline, patch, test backup and restore, and snapshot virtual machines, all mapped to the ASD Essential Eight and NIST Cybersecurity Framework.

Operations: You triage alerts in a SIEM-style console, pull suspicious emails apart header by header, read sandbox detonation and scanner findings ranked by CVSS, review cloud identity and storage exposure, then label behaviour using MITRE ATT&CK and the cyber kill chain.


By the end of Stage 1 you can:

  • Explain how traffic moves across a network and where controls sit at each layer.
  • Administer and harden a host to a documented baseline, then record what changed and why.
  • Triage a security alert end to end and hand over a clear written summary.
  • Describe attacker activity using MITRE ATT&CK and the cyber kill chain.
  • Hold three units and the Certified Cybersecurity Associate certification from TechDX.

Stage 2 puts you on the analyst side of a security operations centre: working a live queue, deciding what is real, escalating with evidence. It suits help desk, network and IT staff aiming at detection or incident response roles, and assumes you already read logs and traffic confidently, as Stage 1 teaches.

Fundamentals: The baseline before you touch a live queue: pulling authentication, endpoint, DNS and proxy logs, mapping a host and its services, normalising timestamps across time zones, querying a log analysis interface, and what a Tier 1 analyst owns versus escalates.

Essentials: Monitoring and escalation day to day: working a SIEM alert queue, tuning out false positives, turning a detection into a written finding, triaging phishing attachments in a sandbox, ranking findings by CVSS, and escalating through NIST SP 800-61 stages.

Analysis: Investigation, not just alerts. You correlate endpoint, network and identity events into one timeline, reconstruct the intrusion against the cyber kill chain, use packet capture, trace lateral movement and persistence, validate indicators with OSINT, then report scope, impact and containment.

By the end of Stage 2 you can:

  • Work a live alert queue and decide what a genuine security incident is.
  • Escalate incidents with a clear timeline, affected assets and evidence a responder can act on.
  • Investigate endpoint and network activity end to end, then report scope, impact and containment steps.
  • Describe adversary behaviour using MITRE ATT&CK and the cyber kill chain in handover notes.
  • Pass a scenario-based applied exam that assesses detection and escalation under realistic conditions.

Stage 3 moves you from watching alerts to owning investigations. Where Tier 1 confirms, Tier 2 decides: you pivot across log sources, rebuild attack timelines and drive containment. Built for IT professionals moving into security operations and anyone who has finished Stage 2, it assumes hands-on log analysis and incident response.

SOC Operations and Threat Monitoring: Labs put you in a monitoring queue built from endpoint, network, identity and cloud telemetry. You tune noisy detection rules and justify them, run structured shift handover, write case notes, and map coverage against MITRE ATT&CK to name visibility gaps.

Threat Detection and Log Analysis: Detection engine room. You query and correlate authentication, operating system, DNS, proxy and endpoint logs in a SIEM, baseline normal, then find the deviation: credential abuse, lateral movement, persistence, command and control beaconing, staged data. Confirmed techniques become detection rules.

Incident Response and Vulnerability Management: You run an incident through the NIST SP 800-61 lifecycle: scope it, decide whether to isolate or keep watching, preserve volatile evidence, contain, verify eradication, then report. Vulnerabilities are prioritised by CVSS, exploitability and asset criticality, with Essential Eight controls.

By the end of Stage 3 you can:

  • Own a Tier 2 investigation end to end, from alert validation to documented closure.
  • Reconstruct an attack timeline by correlating log sources and mapping activity to MITRE ATT&CK.
  • Tune detections so real threats surface and false positives stop consuming analyst time.
  • Lead containment, eradication and recovery steps against the NIST SP 800-61 lifecycle.
  • Prioritise and track vulnerability remediation using CVSS, asset criticality and Essential Eight controls.

Stage 4 moves you from reacting to alerts to tracking the groups behind them, mapping their infrastructure and writing intelligence a SOC lead or a board can act on. It suits learners who finished Stage 3 and detection or response staff who like research and writing, with triage, escalation and log analysis experience.

Threat Intelligence Foundations: You run the intelligence cycle, from a stakeholder requirement through collection to dissemination. You grade source reliability, map adversary behaviour to MITRE ATT&CK, apply analysis of competing hypotheses, write with estimative language, and package findings in STIX for TAXII exchange.

Infrastructure Threat Hunting: You expand one observable, a domain, hash or certificate, into an infrastructure cluster using passive DNS, registration records and certificate reuse, confirm sandbox-derived command and control destinations and beaconing intervals, then convert it into a hunting hypothesis and detection logic.

Strategic Threat Hunting and AI Automation: You produce a sector threat assessment, turn executive questions into priority intelligence requirements, prioritise recommendations against the NIST Cybersecurity Framework and Essential Eight, automate feed ingestion, indicator scoring and ageing, verify AI-drafted analysis, then write executive, operational and tactical products.


By the end of Stage 4 you can:

  • Track threat actors across changing infrastructure and defend the clustering with evidence.
  • Turn one investigation into executive, operational and tactical intelligence products.
  • Map adversary behaviour to MITRE ATT&CK and state confidence in estimative terms.
  • Automate feed ingestion, enrichment and indicator ageing, then verify AI-assisted output.
  • Complete the pathway with four TechDX certifications and twelve units achieved.
How you will learn - TDX Arena
The TDX Arena

How you will learn

Everything runs on TDX Arena, the platform built for these certifications. It is browser based, so there is nothing to install and no special equipment to buy. Lessons, labs, exams, support and progress tracking sit in one place across all four certifications, and you set the pace: the recommended rhythm is 10 hours a week for 10 weeks per certification.

Browser based, nothing to install

TDX Arena runs in your browser. There is no software to set up, no virtual machine to configure and no special equipment to buy, so you need only basic computer literacy and reliable internet.

Adaptive, AI powered labs

Labs use real tools and real-world workflows, and they adapt as you work. The AI adjusts what comes next based on how you are performing, so time goes into the skills you have not yet secured.

Lab first: 60% hands-on, 40% lessons

Each of the four certifications is 100 hours, split 60% hands-on labs and 40% lessons. Most of your time is spent doing the work, not watching someone else describe it.

Exams that ask you to perform

Each certification ends in an applied, scenario-based exam. You are placed in a situation and assessed on what you do in it, rather than on recall from a bank of multiple choice questions.

Ember, your AI teaching assistant

Ember is available 24 hours a day through an avatar, by voice or by text. In-platform AI hints sit alongside it, so a lab you are stuck in at 11pm does not stall until morning.

One support channel, one progress view

Learner support is unified: one form, one email address and one phone number, whatever your question is about. Progress across all four certifications tracks in the same place, so you always know where you sit in the pathway.

Why lab-first matters in cyber security

Cyber security is judged on what you can do under pressure. Reading about triage does not build the reflexes an alert queue demands. Spending 60% of your hours in labs means the first time you investigate an incident is not on your first day at work.

What jobs will this course lead to?

Graduates of the Cyber Security Online Bootcamp will be well-prepared for entry-level positions in the cybersecurity field. The comprehensive training and hands-on experience gained through this program equip participants with the necessary skills to excel in various cyber security roles. Career opportunities for bootcamp graduates include:

  • Cyber Security Analyst: Responds to cyber incidents and monitors systems for security breaches.
  • Information Security Analyst: Protects an organisation's computer systems and networks by implementing and monitoring security measures.
  • IT Security Consultant: Advises organisations on best practices for protecting information and systems.
  • Vulnerability Analyst: Identifies and assesses an organisation's systems and network vulnerabilities.
  • Risk Analyst: Evaluates and manages the risks associated with cybersecurity threats and vulnerabilities.
  • Compliance Analyst: Ensures an organisation's security policies and procedures comply with relevant laws and regulations.
  • Junior Penetration Tester: Assists in conducting security assessments and penetration tests to identify potential security weaknesses.
  • Network Operations Specialist: Manages and supports cybersecurity infrastructure and network operations.
  • Cyber Defence Infrastructure Support Specialist: Provides technical support and ensures the security of cyber defence infrastructure.

With the knowledge and skills acquired in this bootcamp, graduates can confidently enter the cyber security job market and contribute to safeguarding organisations against cyber threats.

Career support that goes the distance

Your cyber security bootcamp is just the start. Our internship program can help you turn study into real work, real contacts and real outcomes.

Upskilled Internships

Turn your qualification into real Australian work experience. Complete 80% of your course and apply for a 12-week internship with a top host company, delivered with Career Success Australia. Past placements include NAB, BHP, PwC, Telstra and IBM.

Get in touch to know more.*

*Terms and conditions apply.

Industry Insights

Students who successfully complete this qualification may be able to pursue a rewarding career in Cyber security.

Employed

29,100 Professionals

Currently working in cyber security roles, reflecting the growing importance and demand for cyber security expertise in Australia.
Weekly Earnings

$1,920 per week

Cyber security professionals average weekly incomes, providing financial stability and highlighting the value of cyber security skills in the job market.
Full-Time Share

91% Work Full-time

Indicating the industry's commitment to sustained and robust contributions from its workforce.
Female Share

21% of the Workforce

The cyber security sector has a lower representation of women; this underscores the need for greater gender diversity within the field.
Average Age

40 years

Showcasing a diverse age range and the maturity of the workforce in handling complex cyber security challenges.

Payment Options

Pay Upfront & Save 15%
You pay $3550
RRP $4180
Spread the Cost - Payment Plans
You pay $97 per week*
*Paid fortnightly or monthly

What is included

  • Four certifications, twelve units: 
    Certified Cybersecurity Associate, Certified Cybersecurity Analyst, Certified SOC Analyst and Certified CTI Analyst, each carrying three named units, all under one enrolment.
  • 400 hours of lab-first content:
    Every certification is 100 hours split 60% hands-on labs and 40% interactive lessons, so most of your time is spent working, not reading.
  • Ember and learner support:
    Ember, your AI teaching assistant, answers questions 24 hours a day, backed by one support team for content, platform and enrolment queries.
  • Applied exams and an evidence pack:
    Each certification ends in a scenario-based practical exam and gives you a Skills List, Case Studies and an Achievement Report to show employers.
  • Browser-based platform access: 
    TDX Arena runs in your browser with no installs and no special equipment, so you can study from any reasonably current computer.

FAQs

No. This bootcamp is non-accredited training. It delivers four TechDX certifications and twelve units. It is not an AQF qualification, not a Statement of Attainment and not nationally recognised training, and it does not licence you to perform a regulated role. If you need a nationally recognised credential instead, Upskilled also delivers nationally recognised IT qualifications, including certificate and diploma level programs with a cyber security focus.

No. There is no prior cyber security or IT experience requirement. You need basic computer literacy and a reliable internet connection. Stage 1, the Certified Cybersecurity Associate, starts at foundations and builds from there, so complete beginners and people making a cyber security career change begin in the same place. Everything runs in your browser, with no installs, no lab hardware and no special equipment to buy.

The full stacked pathway is 400 hours, made up of four certifications of 100 hours each. At the recommended pace of 10 hours a week, each certification takes about 10 weeks and the whole bootcamp about 40 weeks. Every certification includes 75 days of platform access. Learning is online and self-paced, so most students fit it around full-time work by choosing their own hours and study nights or weekends.

The four TechDX certifications are Certified Cybersecurity Associate, Certified Cybersecurity Analyst, Certified SOC Analyst and Certified CTI Analyst. Yes, they are completed in order. The pathway is gated, so each stage unlocks once you finish the one before it. Each certification carries three units and ends in a hands-on applied exam, so your skills build in sequence from security foundations, into security operations, then into threat intelligence.

A SOC analyst works inside a security operations centre, monitoring alerts, triaging and investigating incidents and containing or escalating threats as they happen, guided by frameworks such as MITRE ATT&CK and NIST SP 800-61. Tier 1 handles first-line monitoring, alert triage and basic checks against known playbooks. Tier 2 investigates deeper, correlating log and network evidence, confirming scope and impact, then driving containment and remediation. A CTI analyst works ahead of the incident, researching adversaries, analysing intelligence and sharing it in formats such as STIX and TAXII. In short, SOC work is reactive and operational, CTI work is proactive and analytical.

Graduates will be well-prepared for entry-level positions in the cyber security field, including roles such as Cyber Defense Analyst, Forensic Cyber Investigator, Network Operations Specialist, Cyber Defense Infrastructure Support Specialist, Cyber Defence Incident Responder, Information Security Analyst, and more. It targets entry-level defensive security work: security operations centre analyst, cyber security analyst and threat intelligence analyst roles. There is no job guarantee, and hiring depends on the employer, your background and how you interview. For context, Jobs and Skills Australia reports 13,300 ICT Security Specialists employed in Australia, drawing on the ABS Labour Force Survey Detailed, February 2026, and 92% work full-time hours against 64% across all occupations (ABS 2021 Census).

The bootcamp provides comprehensive support services, including access to a pre-configured Virtual Machine in the cloud, quizzes, teacher guides, solutions for each lab, and a dedicated support team to assist with any questions or issues that may arise during your learning journey.

Support is unified: one form, one email address and one phone number, so you never have to work out who to ask. In the platform, Ember the AI teaching assistant answers questions 24 hours a day by avatar, voice or text, and AI-powered hints help when a lab stalls. Progress tracking shows where you sit against the pathway, and the Upskilled team handles enrolment, payment and access questions.

You get a Cyber Security Bootcamp completion Certificate from TechDX & Upskilled. Which is highly valuable in the industry. Finish all four stages and you hold four TechDX certifications and twelve units, three per certification. Each certification also comes with a completion package: a Skills List setting out what you can do, Case Studies from the work you completed, and an Achievement Report. These are TechDX industry certifications and units, not nationally recognised qualifications, and they exist to give employers evidence of hands-on capability.

Yes, you can apply for one. Upskilled offers a 12-week internship delivered with Career Success Australia, open to students who have completed 80% of their course. Places are applied for rather than guaranteed, and the host company makes the final choice. Past host companies include NAB, BHP, PwC, Telstra and IBM. An internship gives you Australian workplace experience to sit alongside your TechDX certifications when you start applying for roles.