Home › Course & curriculum

The curriculum: nine months, week by week

The programme is called “AI-Driven Security Operations Specialist”. That is exactly how the title appears on the licence, with nothing added. It runs for nine months full-time, and four weeks of holiday are included.

Teaching is completely live: Monday to Friday, with a teacher, in a virtual classroom. This page shows you how a teaching day runs, what happens in each of the six phases, where the holiday weeks are and what equipment you get.

The video

The nine months in 68 seconds

What happens in which phase — from your first typed commands to the security team.

The curriculum at a glance68 seconds · with subtitles

The sound is off until you turn it on.

Try it out

This email is an attack. Can you find it?

Three details give the scam away. Tap them. After that you will know whether this job suits you.

Inbox 1 suspicious message
From DHL Paketdienst <>
Subject
Date

Ihre Sendung konnte nicht zugestellt werden. Bitte begleichen Sie den Restbetrag von 2,99 €, damit wir die Zustellung erneut versuchen können.

Zustellung bestätigen:

0 of 3 Where would you look first? Look at the addresses, not at the text.
All three found.

That was not luck — you checked exactly the signs that a security team looks for too. If this suits you, the rest can be learned.

Check in 2 minutes whether your office will pay

Nine months, six stages, three ranks

Your route from the first day to the certificate

You start from zero and work your way forward, stage by stage. Along the way you earn three ranks at TryHackMe — the same exams that security people take all over the world. You can fail — if you do not pass the first time, you get a second attempt, free of charge. We prepare you for them; even so, we cannot promise that you will pass.

StartWeek 1 SEC0Week 14 SEC1Week 23 SAL1Week 30 CertificateWeek 39
TryHackMe certification SEC0 Pre-Security
SEC0Pre-SecurityWeek 14
TryHackMe certification SEC1 Cyber Security 101
SEC1Cyber Security 101Week 23
TryHackMe certification SAL1 Security Analyst Level 1
SAL1Security Analyst L1Week 30

The exams are run by TryHackMe, not by us. If you fail the first time, a second attempt is free. Exams you have passed can be checked by anyone through Credly.

Keep scrolling — the route moves with you.

Weeks 1–7 · Stage 1

You learn how a computer really works

Operating systems, networks, the language security people use. We start from zero — phase 1 asks for no prior knowledge. You work on the computer from the first day, not on paper.

simpleclub for the basics, a live teacher for everything else

Weeks 8–14 · Stage 2

You see for the first time what an attack looks like

How data travels through the internet, where it is intercepted, what an attacker leaves behind. At the end of this stage comes your first exam.

Rank 1
SEC0 — Pre-Security Run by TryHackMe, verifiable through Credly

Weeks 15–23 · Stage 3

You learn the tools used for defence

Reading log files, assessing alerts, recognising malware. From here on you work on the same tasks that come up every day in the job.

Rank 2
SEC1 — Cyber Security 101 You show that you can spot weak points and read logs

Weeks 24–30 · Stage 4

You work a shift in the security team

In the SOC‑Simulator you are given a real incident and work on it the way you would on a working day: shift handover, prioritisation, escalation, report.

Rank 3
SAL1 — Security Analyst Level 1 The most demanding of the three exams

Weeks 31–36 · Stage 5

You build tools that take work off your hands

Small programs, AI tools in the security team, data protection in everyday work. What you build here goes into your portfolio on GitHub — and later it is a work sample that people can look at.

Weeks 37–39 · Stage 6

The last three weeks belong to your job application

CV, LinkedIn profile, two practice job interviews. We are a training provider, not a job placement service — we cannot promise you a job. What we do: get you to the point where your application is ready.

Week 39 · Goal reached

Certificate from the CYBERSQUAD Akademie

The final qualification for the further training, issued by us, with the licence number of the programme. Separate from that: the three ranks along the way come from TryHackMe. It is not a qualification in a recognised training occupation, of the kind the IHK awards — that would be something different.

On 2 August 2027

What you take away

01 Your certificateFrom the CYBERSQUAD Akademie, for the further training you have completed
02 Up to three ranksSEC0, SEC1, SAL1 — through Credly anyone can check that you passed
03 A portfolio on GitHubThe programs from stage 5. Anyone interested can take a look
04 Your case reportsFrom the SOC‑Simulator: how you handle and document an incident

Monday to Friday, always live

What a day on the route looks like

9:00Start of the day in the group
9:15The teacher explains the new topica real person, live, and you can ask questions
11:00You practise yourself, the teacher helpsyou are never alone with a task
13:00Practice on the training platformTryHackMe
15:00Case work and review
16:40End of the working day

What “online” often means

  • Recorded videos that count as teaching
  • One contact person, by ticket
  • Every teacher brings their own materials

What it means here

  • Every lesson with a teacher. The licence states: asynchronous share 0.
  • From 9:00 to 16:40 there is a real person you can ask.
  • Content from simpleclub and TryHackMe — the same quality in every lesson, no matter who teaches.

From the licence

The key facts

Programme

AI-Driven Security Operations SpecialistThis is exactly how the title appears on the approval, with nothing added. The job behind it is called Junior SOC Analyst.

Start

Monday, 2 November 2026 plannedFor that we need a minimum number of registrations. If too few people sign up, we move the start by two to four weeks and tell you straight away.

Duration

9 months full time 39 weeks until 2 August 2027, including four weeks of holiday.

Location

Online, from home We provide the laptop and the headset. Virtual classroom, one fixed group.

Costs

0 € with an approved BildungsgutscheinYour Jobcenter or Agentur für Arbeit decides whether you get one.

Before the first day

Equipment: what we provide, what you need

You do not have to buy anything. The devices and all the accounts come from us. What you bring yourself is an internet connection, a quiet place and the time.

LaptopWe provideBefore the start you get a laptop with a camera from us, on loan for the duration of the further training. All the programs you work with run on it or in the browser. You do not need a computer of your own.
HeadsetWe provideHeadphones with a microphone. You get this from us too. That way the group understands you, and you understand the group.
Access to the learning platformsWe provideThe virtual classroom runs on Microsoft Teams. There is also the practice platform TryHackMe with the SOC‑Simulator. The explainer videos from simpleclub are in German. On top of that, there is an AI tutor to help you learn. We set up all the accounts for you.
AI tools for Phase 5We provideWe also provide access to the AI tools that are used in the lessons. You do not have to take out any subscription and you pay nothing.
Internet at homeYou needA stable internet connection of at least 10 Mbit/s. The lessons run all day with video and sound. A normal home connection is enough for that.
A quiet place to workYou needA table, a chair and a place where you can speak and listen without being disturbed.
TimeYou needMonday to Friday from 9:00 to 16:40, for nine months. That is full time. Check honestly beforehand whether it fits into your daily life. We talk about it in the preliminary conversation.

In brief

Dictionary: the technical terms from the curriculum

These words appear in the curriculum. Almost all of them are English. Nobody has to know them beforehand. They are explained in the lessons, and you can always ask questions.

Open the dictionary
  • SOC — Security Operations Center. The department in a company that looks at the alerts from the security systems and decides which of them is serious. security centre
  • SIEM — Security Information and Event Management. A program that collects the log files from the whole company in one place. It raises an alarm when something does not match. collects all the logs
  • Log / log file — A file in which a system writes down what has happened: who logged in and when, which program was started, which connection was made. the trail
  • Alarm and false alarm — An alarm is a message from the system. A false alarm looks dangerous but is harmless. Telling the two apart is the daily work in a SOC. the technical terms: alert, false positive
  • MITRE ATT&CK — A public collection in which experts around the world have gathered the steps that attackers use. You sort an incident into it, so that everyone in the team means the same thing. spoken: Mitre Attack
  • Phishing — Fake messages that look like real post from a bank, a parcel service or your own employer. The goal is a password, a payment or a click on a dangerous link. fake messages
  • Malware / malicious software — A program that is meant to cause damage or steal data. This also includes ransomware, which encrypts all the files in a company. harmful program
  • Firewall — A protective system in the network. Like a guard at the door, it checks which data may come in and go out. network protection
  • Linux — An operating system like Windows, just used differently. In companies it runs on almost all servers. That is why you learn it from Phase 1 onwards. operating system
  • Virtual machine — A second computer that runs as a program on your laptop. You can try out anything in it. If something breaks, you delete it and start again. short: VM
  • Lab — A ready-made practice environment in the browser, in which you solve a task hands-on. On TryHackMe you work in labs almost every day. practice on the computer
  • OWASP Top 10 — A list of the ten most common weak points in web applications. It is maintained by a non-profit organisation and is widely used across the industry. list of weak points
  • Vibe Coding — You describe in German what a program should do. The AI writes the code. You check it, test it and improve it. Phase 5
  • Teaching unit (UE) — The unit of measurement for lessons: 45 minutes. Our further training has 1,400 of them, 8 on every teaching day. 45 minutes

Honest answers

Common questions about the curriculum

If your question is not here, call us: 0211 81994488, Monday to Friday. Marsí, our AI adviser, answers first. If you want to speak to a person, a member of our team will call you back. You can check for yourself beforehand whether the Jobcenter or Agentur für Arbeit will pay for your further training — in two minutes, without signing up.

I have never programmed before. Is that a problem?
No. Phase 1 starts at zero: first computers and operating systems, then networks, then attacks. Programming comes only later on, and in small steps. In Phase 5 you describe to the AI in German what you need. While you do that, you learn to read the code and check it.
What if I am ill for a day?
You report your absence and send in the sick note, just as you would in a company. There are no recordings of the lessons. Your teacher helps you catch up, and your group helps too. That is why it is important that missed days stay the exception.
Do I have to study in the evenings and at weekends?
The lessons are Monday to Friday from 9:00 to 16:40. After that you are free. Anyone who wants to practise on top of that can do so. It is not compulsory. All 1,400 teaching units are live lessons. There is no self-study time that you have to work through at home.
Is everything in German?
The lessons and the explainer videos are in German. The practice platform is partly in English, because the whole industry uses English technical terms. Your teacher explains them. You have to understand and speak German well enough to follow the lessons — we do not ask for a particular level. We check beforehand in a short conversation whether it is enough.
What happens if I do not pass a TryHackMe exam?
Then you will be missing that one extra certificate. Your qualification with us is not affected by it: the provider’s own certificate from the CYBERSQUAD Akademie does not depend on the TryHackMe exams. The lessons carry on as normal for you.
Can I join later, once the course has already started?
No. The group starts together on the same day, because each phase builds on the one before. If your Bildungsgutschein comes too late, we will talk about the next start date.
Can I work on the side?
The lessons are full time and take place on five working days between 9:00 and 16:40. During that time you cannot work. If you receive benefits, talk to your contact person at the Jobcenter or Agentur für Arbeit about any work on the side beforehand.
I have children. How is that supposed to work?
Caring responsibilities are not a reason to be turned down. Costs for the care of children can also be funded under § 87 SGB III, including for further training in a virtual classroom. Ask us about it before you say no.
Who pays for this further training?
As a rule, the funding covers it. Since 2025 the Bildungsgutschein (training voucher) has always been issued by the Agentur für Arbeit — even if it is the Jobcenter that looks after you. It is a discretionary benefit: the Agentur für Arbeit decides in your individual case. If you are unemployed, § 81 SGB III applies. If your job is ending soon, § 17 SGB III applies. If you are in permanent employment, the funding goes through your employer under § 82 SGB III. In that case there is often no Bildungsgutschein at all; instead an Anmeldebescheinigung (confirmation of enrolment) from us is enough (§ 81 Absatz 4 Satz 4 SGB III). If you are 45 or older, your employer’s share can be waived completely. This only applies to companies with fewer than 500 employees. If your company belongs to a group, all employees of the group count as well (§ 82 Absatz 2 Satz 4 und Absatz 6 SGB III).

Two minutes. Then you know which rule applies to you.

Three questions, no sign-up and no obligation.

Marsí · WhatsApp Appointment · 1 click