Live online classes

12 ECTS

Expert Programme in Offensive Security and Red Teaming

Get in touch

Why study the Expert Programme in Offensive Security and Red Teaming?

There is plenty of training that explains hacking concepts. What is much harder to find is training that reproduces a real engagement: receiving only a domain and a signed contract, mapping the attack surface, compromising systems, escalating privileges and delivering a report that a CISO can actually read.

The programme is built around challenges. Each module presents a specific scenario that you solve using the tools covered in that module, just as you would in a real-world engagement. The final project is a complete engagement against a simulated company with hybrid infrastructure: web, a Windows network with Active Directory, and an internal AI assistant.

This specialisation also prepares you to:

  • Take the INE Security eJPT v2 exam, with the exam voucher included in the programme fee.
  • Build a technical portfolio with write-ups on GitHub and professional reports that you can showcase in any recruitment process.
  • Add AI Red Teaming to your skill set, a specialism that very few Spanish-language programmes currently cover.

Prerequisites

This specialisation is not an entry point into cybersecurity. It is designed for professionals who already have a solid foundation and want to deepen their expertise on the offensive side. It is the natural next step after IMMUNE’s Online Master’s in Cybersecurity and is well suited to professionals coming from a SOC, systems administration or security-focused development.

Mandatory Requirements
  • Having successfully completed IMMUNE’s Master’s in Cybersecurity (or an equivalent qualification).
  • Demonstrable knowledge of:
    • Basic pentesting: reconnaissance (Nmap, theHarvester), exploitation with Metasploit, introductory OWASP Top 10, and basic Active Directory concepts.
    • Advanced TCP/IP networking, Windows/Linux internals, system hardening, and basic cloud security (AWS/Azure).
    • Audit methodologies (PTES, OWASP TG) and tools (Nessus/Qualys).
    • SOC architecture, SIEM, introductory Threat Hunting, and MITRE ATT&CK.
    • Introductory OWASP LLM Top 10, UEBA and machine learning for detection.
Recommended Requirements:
  • Prior professional experience in IT, systems or security.
  • Technical reading proficiency in English: much of the documentation and many of the platforms are in English.

What will you learn?

  • Plan and execute a complete pentesting engagement, from reconnaissance through to reporting, while respecting the defined scope and rules of engagement.
  • Exploit vulnerabilities in networks, Linux and Windows systems, and web applications following OWASP methodologies.
  • Compromise corporate Active Directory environments and move laterally without triggering defences.
  • Audit AI systems: prompt injection, jailbreaking, attacks on RAG systems, and evaluation of autonomous agents.
  • Write an executive report for senior management and a technical report with CVSS scoring for the teams.
  • Prepare for the eJPT v2 exam with a solid practical foundation.

Challenge-Based Learning Methodology

Tools

Learn how to use industry-leading tools

Bash
BloodHound
Burp Suite Pro
CrackMapExec
Gandalf (Lakera)
Git
GOAD
Hack The Box
Hashcat
Impacket
Kail Linux
Metasploit
NMAP
Python
PortSwigger
PowerShell
PromptBench
SQLMap
TryHackMe

Certification training

The programme fee includes the voucher for the INE Security eJPT v2 exam, a benchmark certification for junior pentesting roles recognised by employers in Spain and Latin America. The exam is 100% practical, has lifetime validity, and includes one retake within 14 days if you do not pass on your first attempt. The programme covers the official syllabus, updated by INE in March 2026 to include web application testing and the use of generative AI in pentesting.

The specialisation serves as the first step in a pathway of increasingly advanced certifications:

  • eJPT v2 (INE Security): included in the programme. Ready to take upon completion of the first modules.
  • OSCP / OSCP+ (OffSec): the industry standard. Modules 2 to 4 build the technical foundation required.
  • BSCP (PortSwigger): web specialisation, directly covered in Module 3.
  • OSAI+ (OffSec): the new standard in AI red teaming, aligned with Module 5.
eJPT v2
OSCP
OSCP+
BSCP
OSAI+

Curriculum for the Expert Programme in Offensive Security and Red Teaming

The specialisation is organised into six modules and a final project (66 synchronous hours / 300 total hours / 12 ECTS). Each module combines live sessions with independent lab work. The total workload amounts to 300 hours across classes, study and practical work.

Assessment: 25% weekly labs + 20% intermediate CTF + 25% module challenges + 30% Capstone.

Module 0 – 1 ECTS

Offensive Security Fundamentals and Lab

Set up a professional offensive security environment with Kali Linux, PTES and OWASP Testing Guide methodologies, and the legal framework of an engagement (contracts, scope and rules of engagement). Offensive scripting in Python and Bash forms a core foundation that runs throughout the rest of the programme.

Module 1 – 1,5 ECTS

Reconnaissance and OSINT

Passive and active information gathering before an attack: WHOIS, DNS, Google Dorking, Shodan, Censys and subdomain enumeration, with advanced use of Nmap and its NSE scripts. The deliverable is a complete map of the external attack surface.

Module 2 – 1,5 ECTS

Network and Systems Exploitation

Exploitation of vulnerabilities in network systems and services, privilege escalation in Linux and Windows, pivoting and post-exploitation. Weekly hands-on practice on Hack The Box, with an introduction to antivirus and EDR evasion techniques.

Module 3 – 2 ECTS

Web Application Pentesting

Web security auditing following the OWASP Top 10 and WSTG, using Burp Suite Pro. SQL injection, XSS, CSRF, and security testing for REST and GraphQL APIs. Preparation of a professional-quality web pentesting report.

Module 4 – 2 ECTS

Active Directory and Corporate Environments

Advanced attacks against Microsoft infrastructure: BloodHound for mapping attack paths, Kerberoasting, Pass-the-Hash, DCSync and persistence. GOAD (Game of Active Directory) lab to simulate a real corporate domain.

Module 5 – 2 ECTS

AI Red Teaming

Offensive security for Artificial Intelligence systems. OWASP LLM Top 10, direct and indirect prompt injection, jailbreaking, attacks on RAG systems, and evaluation of autonomous agents. Hands-on practice with Gandalf (Lakera), Garak and PromptBench.

Capstone – 2 ECTS

Red Team Engagement

Over several weeks, you will act as an external red teamer for a simulated company with hybrid infrastructure. You will receive only the domain and the signed contract. You will deliver an operations plan, reconnaissance and exploitation reports, a two-page executive report, and a technical report with CVSS scoring for each finding, and you will defend your results before an assessment panel of instructors.

Career opportunities

Demand for offensive security professionals exceeds the available talent pool in both Spain and Latin America. Upon completing the programme, you can pursue roles such as:

According to industry data, a junior pentesting professional in Spain typically starts on around €24,000–€36,000 per year; professionals with experience and certifications such as the OSCP can earn more. Remote work for European and North American companies is common in this field, opening up the market to professionals in Latin America.

Career Readiness

During the programme, you will have access to IMMUNE’s Career Readiness service: a personalised employability pathway that includes support with preparing your technical CV and LinkedIn profile, mock technical interviews, connections with companies in the IMMUNE ecosystem, and access to our job board.

The aim is for you to complete the specialisation with solid knowledge and be able to demonstrate it during a recruitment process. The portfolio you build throughout the programme — including write-ups, reports and the eJPT certification — is one of the elements that carries the most weight in a technical security interview.

A comprehensive training experience

The programme includes a Human Sciences component: skills that complement your technical profile. In offensive security, particular emphasis is placed on communicating findings to non-technical stakeholders, writing reports, and defending technical decisions under pressure. Being able to explain to a CISO why a finding matters can make all the difference compared with someone who only knows how to execute the attack.

FAQs about the Expert Programme in Offensive Security and Red Teaming

What qualification will I receive upon completion?

Upon completing the specialisation, you will receive the IMMUNE Technology Institute qualification in Offensive Security and Red Teaming, a proprietary, non-regulated qualification recognised within the tech industry. In addition, the programme includes the voucher for the INE Security eJPT v2 exam.

Do I need prior experience in cybersecurity?

Yes. This is an advanced programme aimed at professionals who already have a solid foundation in cybersecurity, demonstrated through a certification or Master’s degree. It is not designed for those starting from scratch in the field.

Can I enrol if I haven’t completed IMMUNE’s Master’s in Cybersecurity?

Yes, provided you can demonstrate equivalent knowledge through a recognised certification or previous cybersecurity training. The admissions team reviews the documentation on a case-by-case basis.

Is the AI Red Teaming module too advanced?

It is designed as a specialisation within the programme, not as a prerequisite for everything that comes before it. By the time you reach this module, you will already have completed four modules of traditional pentesting, and the focus shifts to systematically testing AI systems using professional methodologies and tools.

Is the eJPT certification included?

Yes. The voucher for the INE Security eJPT v2 exam is included in the programme fee at no additional cost. The programme covers the official syllabus. Passing the exam is not guaranteed, although one retake is included within the timeframe set by INE.

Is it 100% online?

Yes. Classes are delivered live with the group and are recorded so you can review them afterwards. Lab work and assignments are completed independently.

What is the Capstone Project?

It is the final project: a complete red team engagement against a simulated company with hybrid infrastructure. You receive only the domain and the signed contract, and you deliver both the executive and technical reports, which you defend before an assessment panel. It forms part of the portfolio you can showcase in interviews.

Is there a career guidance service?

Yes. All students have access to IMMUNE’s Career Readiness service, which includes CV preparation, career guidance, mock interviews and access to our job board.

What technical requirements does my computer need to meet?

A laptop with a camera and microphone, at least 8 GB of RAM, and an i5 processor or equivalent with virtualisation support. A stable internet connection is recommended for live classes and lab sessions.

Are scholarships available?

Financing options and discounts are available for certain profiles. Our admissions team can provide information on the options available at the time of your application.

Financing

Full payment

Check the discounts available for upfront payment.

IMMUNE

BBVA

If you are a resident in Spain, you can finance your programme through BBVA.

Sequra

Pay in installments, even if you are unemployed and cannot guarantee the loan.

Sequra

Quotanda

Pay in installments, even if you are unemployed and cannot guarantee the loan.

Quotanda

Fundae

Pay for your training through the Spanish Employment Training Foundation. Aimed at active workers who wish to finance their program through the subsidized training program.

Fundae

Book a personalised academic consultation

Flor Biscardi

Flor Biscardi

Agustina Ruíz

Admissions Process

Our students are characterized by their passion for technology. Our admissions process focuses on who you are, how you think, what you have accomplished, and then sharing your goals.

Our aim is to get to know you better, see what makes you unique and ensure that the IMMUNE educational model adapts to your profile.

Application for admission
1. Application
Personal interview
2. Personal interview
Academic committee
3. Academic committee
Registration number
4. Enrollment

Challenge-Based Learning Methodology

Each module begins with a challenge (“How would you do this?”) that you solve throughout the sessions and labs. The live classes focus on conceptual introductions and guided problem-solving, while independent work is dedicated to hands-on practice on the platforms and completing the required deliverables.

You will train on the same platforms used by professional teams: Hack The Box, PortSwigger Web Security Academy, GOAD for Active Directory, TryHackMe and, for AI red teaming, Gandalf (Lakera), Garak and PromptBench. You will document each engagement in GitHub, Notion or Obsidian, creating a portfolio of evidence that showcases your work.

The groups are kept small, with a maximum of 20 students, and mentoring takes place every two weeks. The instructor can review each student’s write-up and provide individual, technical feedback rather than generic comments.

Download brochure