McTaba Labs logo
Software · SW-02Enrolling Now

Software Security for Engineers

Security for Engineers

Write code attackers can’t break — webhook security, JWT auth done right, OWASP Top 10, secrets management, taught on the fintech systems you’ll actually build.

Quick Facts

Duration
4 weeks
Format
Part-time · Remote
Tuition
KES 20,000
Level
Intermediate

Get Started

4 weeks · Part-time · Remote

Apply now to secure your spot in the next cohort.

Apply Now

Security is not optional.

Every fintech app you build handles real money and real user data. One vulnerability — a broken JWT, a missing webhook signature check, an exposed secret — and you lose trust, money, or both. This course teaches you to think like an attacker so you can build like a defender.

What you will learn

  • Threat modeling for web applications
  • JWT, sessions, and password storage done right
  • OWASP Top 10 drills on real code
  • Webhook signature validation and replay protection
  • Secrets management and dependency auditing

Course Details

What is this course?

A 4-week intensive course that teaches web developers how to write secure code. Every module uses fintech systems as the teaching ground — the same kind of apps you build at McTaba.

Who it’s for

  • Web developers building apps that handle payments or user data
  • Backend engineers who want to ship with confidence
  • Freelancers who need to assure clients their code is safe
  • Marathon graduates deepening their security skills

Prerequisites

  • Working knowledge of JavaScript/Node.js
  • Basic understanding of HTTP, REST APIs, and databases
  • Familiarity with JWT and authentication flows

Why learn this

  • Security vulnerabilities in fintech apps are career-ending mistakes
  • Clients and employers pay a premium for developers who understand security
  • The OWASP Top 10 covers 90% of real-world web vulnerabilities
  • Webhook and payment security are non-negotiable for M-Pesa and Stripe integrations

Why study at McTaba Labs

  • Taught on fintech systems, not abstract examples
  • Every drill uses code patterns from production African Stack apps
  • Capstone: harden a deliberately vulnerable fintech app end to end
  • Small cohorts with direct instructor feedback

Ship code you can stand behind.

Learn to find and fix vulnerabilities before attackers do.

Apply Now

Curriculum

6 modules covering everything you need.

Week 1

  • Attack surfaces in web applications
  • STRIDE and threat trees
  • Prioritizing risks in fintech contexts

Career Outcomes

Where this course can take you.

Application Security Engineer

Audit and harden web applications against real-world attacks.

Backend Engineer (Security-Strong)

Ship backend code with security baked in from the start.

Freelance Security Reviewer

Offer security audits as a paid service to startups and SMEs.

Fintech Engineer

Build payment systems that meet security compliance requirements.

Build apps attackers can’t break.

Apply for the next Software Security cohort.

Questions? WhatsApp us at +254 727 795 603 or book a discovery call.