Offensive Security
Adversarial thinking, penetration testing, red team practice, technical reconnaissance, exploitation, and the disciplined use of offensive methods to understand real security weaknesses.

The College of Information Security brings together cybersecurity, cryptology, offensive and defensive practice, intelligence, governance, privacy, and secure development within one academic environment.
Modern security work sits at the intersection of computing, human behavior, organizational risk, law, intelligence, and rapidly changing technology. A vulnerability can begin in code, architecture, process, identity, infrastructure, or governance; defending against it requires more than knowing how to operate a security tool.
The College of Information Security is structured around that broader view. Its academic direction connects technical depth with the strategic and professional context in which security is actually practiced, while allowing individual programs to focus on different audiences, skill levels, and areas of specialization.
These are areas that inform curriculum development and current or future academic work within the College. They are not presented as separate departments.
Adversarial thinking, penetration testing, red team practice, technical reconnaissance, exploitation, and the disciplined use of offensive methods to understand real security weaknesses.
Detection, protection, incident response, security operations, architecture, and the technical decisions that help systems withstand and recover from attacks.
The concepts, technologies, and practical uses behind cryptography, secure communication, authentication, integrity, and the protection of information in transit and at rest.
Threat information, adversary behavior, technical context, open-source intelligence, and the transformation of security data into decisions that improve awareness and preparedness.
Security governance, risk management, privacy, policy, compliance, and the organizational structures that turn technical security into accountable institutional practice.
Secure development practices, application security, technical design, and the integration of security throughout the systems and software development lifecycle.
The College currently supports programs ranging from structured introductory study to long-form professional and mentorship experiences.
An intensive program spanning the technical, strategic, and professional dimensions of information security, designed to develop broad competence across modern cybersecurity practice.
Program DetailsA structured introduction to cryptology, exploring the concepts, techniques, technologies, and real-world applications behind modern cryptography and secure communication.
Program DetailsA practical introduction to cybersecurity competitions through guided challenges, technical exercises, and foundational methods used to solve Capture the Flag problems.
Program DetailsA long-form mentorship experience centered on offensive security, combining structured technical development, practical work, and sustained guidance throughout the program.
Program DetailsA specialized program connecting software development and information security, focused on helping developers understand and apply secure practices throughout the development lifecycle.
Program DetailsThe exact balance changes by program, but the College approaches information security as both a technical subject and a professional discipline.
Students build the concepts and vocabulary needed to understand security mechanisms, systems, threats, and the reasoning behind technical decisions.
Where the program calls for it, learning moves into tools, challenges, demonstrations, technical environments, projects, and problem-solving rather than remaining purely conceptual.
Live classes, mentoring, discussions, feedback, and sustained academic interaction can be built into programs whose objectives require a more guided learning experience.
Security is studied not only as a collection of tools, but as work performed inside organizations, products, teams, regulatory environments, and broader systems of risk.
The College is currently coordinated by Prof. João Góes, who is responsible for its academic direction, program development, and the connection between security education, applied technical work, and institutional growth.
As the College expands, its academic structure is intended to grow through additional faculty, programs, and areas of study while preserving a coherent approach to the field.
View leadership profilePrograms within the College may use Open Admissions, Selective Admissions, or other program-specific eligibility requirements. A course intended for students entering the field may evaluate a very different profile from a mentorship program designed for participants with existing technical experience.
Explore the current program portfolio or return to SJIT Academics to see how Information Security connects with the institution’s other technology fields.