---
title: "STACKIT Security Engineer"
description: "A learning path for security engineers: cloud security fundamentals, IAM, Zero Trust networking, secrets management, security operations, and secure software delivery on STACKIT."
hideBreadcrumbs: true
sidebar:
  hidden: true
scfTrail:
  maintainers:
    - user: "tobias.mueller"
  tags: ["STACKIT University", "Security", "IAM", "Zero Trust", "Compliance", "DevSecOps"]
  steps:
    - style: "compass"
      title: "STACKIT Introduction"
      trailContext: "Sovereign cloud vision and a service overview."
      assetId: "advisory/assetcontainer/stackit/stackit-introduction"
    - style: "hut"
      title: "STACKIT Portal"
      trailContext: "IAM and resource concepts, project setup, and the cost calculator."
      assetId: "advisory/assetcontainer/stackit/stackit-portal"
    - style: "stairs"
      title: "STACKIT Portfolio"
      trailContext: "The full service portfolio: IaaS, PaaS, data, AI, security, and supporting services."
      assetId: "advisory/assetcontainer/stackit/stackit-portfolio"
    - style: "shield"
      title: "Fundamentals of STACKIT Cloud Security"
      trailContext: "Shared responsibility, security architecture, and governance."
      assetId: "architecture/assetcontainer/stackit/fundamentals-of-stackit-cloud-security"
    - style: "t-bar"
      title: "IAM for Security Engineers"
      trailContext: "Identity, access management, and best practices."
      assetId: "architecture/assetcontainer/stackit/iam-fundamentals"
    - style: "chart"
      title: "Network Security & Zero Trust"
      trailContext: "Microsegmentation and Zero Trust."
      assetId: "architecture/assetcontainer/stackit/network-security-zero-trust"
    - style: "gondola"
      title: "Secrets Management & Encryption"
      trailContext: "Key management and encryption on STACKIT."
      assetId: "architecture/assetcontainer/stackit/secrets-management-encryption"
    - style: "crevasse"
      title: "Container & Kubernetes Security"
      trailContext: "Runtime protection and image scanning."
      assetId: "architecture/assetcontainer/stackit/container-kubernetes-security"
    - style: "chairlift"
      title: "Security Operations & Threat Detection"
      trailContext: "Logging, monitoring, threat detection, and incident response."
      assetId: "architecture/assetcontainer/stackit/security-operations-threat-detection"
    - style: "summit"
      title: "Secure Software Development & Application Security"
      trailContext: "SSDLC, application security, and software supply chain security."
      assetId: "architecture/assetcontainer/stackit/secure-software-development-application-security"
source_url: "https://framework.stackit.cloud/architecture/trails/stackit/security-engineer/"
source_file: "docs/architecture/trails/stackit/security-engineer.mdx"
---

## Steps

### 1. STACKIT Introduction

Stage: `compass`

Sovereign cloud vision and a service overview.

Asset: [/advisory/assetcontainer/stackit/stackit-introduction/](/advisory/assetcontainer/stackit/stackit-introduction/) — source: [/raw/advisory/assetcontainer/stackit/stackit-introduction.md](/raw/advisory/assetcontainer/stackit/stackit-introduction.md)

### 2. STACKIT Portal

Stage: `hut`

IAM and resource concepts, project setup, and the cost calculator.

Asset: [/advisory/assetcontainer/stackit/stackit-portal/](/advisory/assetcontainer/stackit/stackit-portal/) — source: [/raw/advisory/assetcontainer/stackit/stackit-portal.md](/raw/advisory/assetcontainer/stackit/stackit-portal.md)

### 3. STACKIT Portfolio

Stage: `stairs`

The full service portfolio: IaaS, PaaS, data, AI, security, and supporting services.

Asset: [/advisory/assetcontainer/stackit/stackit-portfolio/](/advisory/assetcontainer/stackit/stackit-portfolio/) — source: [/raw/advisory/assetcontainer/stackit/stackit-portfolio.md](/raw/advisory/assetcontainer/stackit/stackit-portfolio.md)

### 4. Fundamentals of STACKIT Cloud Security

Stage: `shield`

Shared responsibility, security architecture, and governance.

Asset: [/architecture/assetcontainer/stackit/fundamentals-of-stackit-cloud-security/](/architecture/assetcontainer/stackit/fundamentals-of-stackit-cloud-security/) — source: [/raw/architecture/assetcontainer/stackit/fundamentals-of-stackit-cloud-security.md](/raw/architecture/assetcontainer/stackit/fundamentals-of-stackit-cloud-security.md)

### 5. IAM for Security Engineers

Stage: `t-bar`

Identity, access management, and best practices.

Asset: [/architecture/assetcontainer/stackit/iam-fundamentals/](/architecture/assetcontainer/stackit/iam-fundamentals/) — source: [/raw/architecture/assetcontainer/stackit/iam-fundamentals.md](/raw/architecture/assetcontainer/stackit/iam-fundamentals.md)

### 6. Network Security & Zero Trust

Stage: `chart`

Microsegmentation and Zero Trust.

Asset: [/architecture/assetcontainer/stackit/network-security-zero-trust/](/architecture/assetcontainer/stackit/network-security-zero-trust/) — source: [/raw/architecture/assetcontainer/stackit/network-security-zero-trust.md](/raw/architecture/assetcontainer/stackit/network-security-zero-trust.md)

### 7. Secrets Management & Encryption

Stage: `gondola`

Key management and encryption on STACKIT.

Asset: [/architecture/assetcontainer/stackit/secrets-management-encryption/](/architecture/assetcontainer/stackit/secrets-management-encryption/) — source: [/raw/architecture/assetcontainer/stackit/secrets-management-encryption.md](/raw/architecture/assetcontainer/stackit/secrets-management-encryption.md)

### 8. Container & Kubernetes Security

Stage: `crevasse`

Runtime protection and image scanning.

Asset: [/architecture/assetcontainer/stackit/container-kubernetes-security/](/architecture/assetcontainer/stackit/container-kubernetes-security/) — source: [/raw/architecture/assetcontainer/stackit/container-kubernetes-security.md](/raw/architecture/assetcontainer/stackit/container-kubernetes-security.md)

### 9. Security Operations & Threat Detection

Stage: `chairlift`

Logging, monitoring, threat detection, and incident response.

Asset: [/architecture/assetcontainer/stackit/security-operations-threat-detection/](/architecture/assetcontainer/stackit/security-operations-threat-detection/) — source: [/raw/architecture/assetcontainer/stackit/security-operations-threat-detection.md](/raw/architecture/assetcontainer/stackit/security-operations-threat-detection.md)

### 10. Secure Software Development & Application Security

Stage: `summit`

SSDLC, application security, and software supply chain security.

Asset: [/architecture/assetcontainer/stackit/secure-software-development-application-security/](/architecture/assetcontainer/stackit/secure-software-development-application-security/) — source: [/raw/architecture/assetcontainer/stackit/secure-software-development-application-security.md](/raw/architecture/assetcontainer/stackit/secure-software-development-application-security.md)

