Graduate Programs
Advanced Cybersecurity Operations
Cybersecurity is no longer an option. In an era where adversaries include sophisticated criminal organizations, state-sponsored espionage groups, and actors with access to arsenals of military-grade exploits, the difference between a resilient organization and a victim lies in the quality of the people who build and operate its defenses.
The ISTEC Lisbon Advanced Operational Cybersecurity Graduate Program was created to train precisely those people.
This program is not an introduction to cybersecurity. It is the next level, designed for professionals already working in the field who want to master the tools, techniques, and strategic thinking that define the world’s top experts.
Duration
28 weeks
Scheduled start time
October 2026
Course load
Up to 8 hours per week | 192 contact hours
Scheme
After work
Language
English
ECTS
30
Threat-Informed Defense
A unique methodology
The program is structured around the principle of threat-driven defense. Students do not learn abstract concepts; instead, they learn to think like an attacker in order to build defenses that can withstand real-world attacks. The curriculum follows a logical and sequential progression:
- Understanding the adversary: how they think, how they act, and what their goals are
- Mastering offensive techniques: not to attack, but to know exactly what to defend against
- Designing resilient systems: security by design, not as an afterthought
- Detect and respond in real time: detection engineering and advanced SOC operations
- Investigate and preserve evidence: digital forensics with procedural rigor
- Deliver concrete results: through a project with real impact
World-class infrastructure
The program provides access to one of the most advanced cyber range platforms on the market: virtual environments that simulate attacks and replicate real-world infrastructures, including corporate networks and cloud environments. It’s learning by doing, in conditions that mimic what professionals face in the field.
The Learning Management System (LMS) combines high-quality asynchronous content with synchronous sessions, hands-on labs, and assessments based on real-world scenarios, blurring the line between training and professional practice.
Faculty members with international work experience
The faculty consists of cybersecurity professionals with active international careers. They are experts who work daily with the threats, tools, and platforms they teach. Each session takes the form of a high-level technical showcase: intensive, applied learning led by those who live and breathe the subject.
This graduate program is the most direct path to becoming a leading cybersecurity engineer, with the technical skills, strategic mindset, and academic recognition that the market demands.
Course Plan
6 sequential modules | 192 contact hours | 30 ECTS | 28 weeks
Fundamentals of applied threat intelligence: the MITRE ATT&CK framework, TTP analysis, APT group profiling, advanced OSINT, and the development of actionable threat intelligence. Students learn to think like an adversary before building any defenses.
Offensive security with direct application to defense: penetration testing methodologies, vulnerability exploitation, post-exploitation techniques, pivoting, and detection evasion. Extensive use of cyber ranges to simulate attacks in controlled environments. Based on the PTES standard and OWASP frameworks.
Designing resilient security architectures: Zero Trust principles, microsegmentation, identity and privileged access management (PAM/IAM), system hardening, and cloud-native security (AWS, Azure, GCP).
Detection engineering based on real threats: development of SIEM rules (Sigma, Splunk SPL, KQL), proactive threat hunting, behavioral analysis (UEBA), and response orchestration (SOAR).
Digital forensics with procedural rigor: memory analysis, disk forensics, network forensics, and cloud forensics. DFIR methodologies for containment, eradication, and recovery. Preservation of evidence with legal admissibility and preparation of technical and executive reports.
An integrative project that simulates a real-world security scenario, drawing on skills from all previous modules. It may include red team/blue team exercises, forensic investigation of a complex incident, or implementation of a Zero Trust architecture.
Career Opportunities
Graduates will be prepared to take on roles requiring a high level of technical expertise in the most critical areas of cybersecurity:
- Threat Intelligence Analyst
- Penetration Tester / Red Team Operator
- Security Architect
- Detection Engineer
- SOC Analyst (Level 2/3)
- Threat Intelligence Analyst
- Penetration Tester / Red Team Operator
- Security Architect
- Detection Engineer
- SOC Analyst (Nível 2/3)
The program also opens doors to technical leadership positions (CISO, Head of Security Engineering, Director of Incident Response) at national and international organizations in the financial, telecommunications, defense, energy, healthcare, and government sectors.
Academic Staff
The faculty consists of professionals with active international careers in cybersecurity. They are experts who work in the field and bring real-world cases, tools currently in use, and the perspective of those who face sophisticated adversaries into the classroom. Most faculty members operate on an international level, giving the program a global dimension that is unique within the Portuguese educational landscape.

Marcos Campos
Postgraduate Programme in Advanced Cybersecurity Operations | ISTEC Lisboa
Marcos Campos is a cybersecurity program manager with more than 20 years across public and private sector operations. At Premium Cloud he leads several teams and directs security roadmaps for clients in healthcare, government and banking. Earlier roles at Microsoft took him through more than 18 countries across EMEA, and he has designed and delivered a full Blue Team training track for in the Middle East. He holds several cybersecurity and IT certifications and is a certified trainer, a graduate of ISTEC, postgraduate and Master’s level, and is currently pursuing a PhD.

Ricardo Villanueva-Polanco
Cryptography and Post-Quantum Security Researcher
Ricardo Villanueva-Polanco is a cryptographer working on post-quantum cryptography: encryption designed to survive the arrival of quantum computers. He is an Assistant Professor at Universidad del Norte and spent two years as Senior Cryptography Engineer at the Technology Innovation Institute in Abu Dhabi, evaluating how cryptographic implementations hold up in practice. His research on side-channel and fault attacks has appeared at CRYPTO, Latincrypt and Indocrypt. He takes students from the mathematics of a cipher to the ways it actually breaks.

Khalid Al Obaidly
AI Adoption and Performance Strategist
Khalid Al Obaidly is a strategist working where people, business and intelligent systems meet. His focus is AI adoption: moving organisations from interest in these tools to a governed, working deployment, alongside performance systems and business development. He starts by listening and understanding the full organisational picture before proposing anything, with a consistent bias toward practical execution. For students, he connects technical security work to the business decisions and human behaviour that determine whether it succeeds.

Hala Aldosari
Cybersecurity Researcher
Hala Aldosari is a cybersecurity researcher and a scholar of Qatar’s National Cyber Security Agency, holding a Computer Science degree with a concentration in cybersecurity. Her interest sits where digital and physical threats overlap, and in what is arriving next: quantum computing, AI-driven attacks and advanced malware. As one of the programme’s newer voices, she brings a current view of the research frontier and of what it genuinely takes to enter this field today.

João Vaz de Carvalho
Senior Manager, Non-Financial Risks
João Vaz de Carvalho has more than twenty years of management experience leading technology project teams. Since 2019 he has held direct responsibility for the first and second lines of defence (the operational teams who own a risk, and the independent function that challenges them), and for the past two years has led second-line management of technology risk. He shows students how a security finding becomes a governance decision: the evidence, language and framing that a risk committee will actually act on.

Ivo Rosa
Cybersecurity Operations, Incident Response and Threat Intelligence Specialist
Ivo Rosa has more than 15 years in the field and is currently responsible for global security operations at a critical infrastructure organisation running across several countries. His work covers security monitoring, incident response, vulnerability management and threat intelligence, spanning IT, operational technology (the systems that control physical processes), IoT and cloud. He is an Invited Professor and an applied researcher in threat intelligence, digital forensics and the human factors behind security failures, and is active in Portugal’s national cybersecurity community.

Paulo Pinto
Senior Cybersecurity and Identity Consultant
Paulo Pinto is founder of XKONSULTING, a boutique consultancy working between Portugal and the United States. Across 27 years in IT and more than two decades in security, he has designed identity and access management programmes (deciding who can reach what, and being able to prove it) for enterprise, government and military environments, with hands-on depth in CyberArk, Delinea and SailPoint. A CISSP-certified practitioner, he advises on identity modernisation, cloud security and, increasingly, AI security and governance.

Pedro Vargues
Technical Success Manager
Pedro Vargues has been building software security practice since 2005, focused on how systems are hardened at the design and architecture stage rather than patched afterwards. He also helped establish the security operations centre at one of Portugal’s largest security companies, which gives him a view from both sides: the developers who write the code, and the analysts who defend it in production. That combination is useful for anyone trying to understand where vulnerabilities are actually introduced.

Pedro Monteiro
Senior Cybersecurity Engineer
Pedro Monteiro is a cybersecurity and IT audit specialist with over 18 years in regulated financial services, currently Senior Cybersecurity Engineer at IQVIA. He led a SOC 2 Type II certification end to end, covering control design, penetration test coordination and external audit management, and is driving an ISO 27001 implementation toward dual certification. At Haitong Bank he selected and implemented the bank’s security operations centre and presented it to the Executive Committee. He holds CEH Master, ISO/IEC 27001 Lead Auditor, Security+ and CPTE.

Ricardo Moura
Security Hardening and Resilience Specialist
Ricardo Moura works in enterprise security engineering and threat-informed defence: building defences around how real adversaries actually behave rather than around theoretical risk. He implements security baselines (DISA STIG, CIS Benchmarks) and Zero Trust controls across hybrid and cloud environments, and bridges offence and defence through adversary emulation, purple teaming and detection engineering. His work on hardened identity architectures and privileged access across Azure, Intune and Microsoft 365 gives students a concrete picture of reducing an attack surface.

João Inácio
Infrastructure and Cloud Security Engineer | Invited Lecturer
João Inácio is a computer engineer specialising in infrastructure, cloud and cybersecurity, with more than two decades across systems, networks and hybrid environments. As an Infrastructure Engineer at Marex PLC he works in an international team running critical global infrastructure spanning Azure, AWS, Microsoft 365 and on-premises data centres, covering digital identity, certificate lifecycle management (PKI), automation and platform migration. He has taught in higher education since 2020 at ISTEC and IPS, and as a certified Cisco NetAcad instructor has trained hundreds of students and teachers.

Daniele Malerba
IT Service Manager
Daniele Malerba is an IT professional with extensive experience in international organisations, currently at the European Space Agency and previously at the United Nations. He specialises in centralised IT operations, continuous improvement and complex service delivery, and has orchestrated global enterprise cybersecurity strengthening projects. He holds a Master’s in International Relations from the University of Sussex, reflecting a long-standing interest in the social impact of technology on the people using it, along with ITIL v4, Scrum and project management certifications.

António Vasconcelos
Cybersecurity Strategist and Product Leader
António Vasconcelos has over 20 years spanning security strategy, product leadership and enterprise advisory, with senior roles at Microsoft, SentinelOne, Logpoint and Zero Networks. His work covers endpoint security, XDR, SIEM, SOAR and NDR: the detection and response tooling most security teams live inside every day. As a former Field CISO and Senior Director of Product Management he has advised C-level executives across EMEA on cyber resilience and Zero Trust, and he now works in Solutions Engineering at Intezer. He brings a practitioner’s view that connects technical depth to business context.

Carlos Hilarion
Senior Information Systems Leader and Executive Coach | Humanitarian and Crisis Operations
Carlos Hilarion has over 20 years in the United Nations system, specialising in enterprise ICT infrastructure, cloud transformation and resilient service delivery. He has led large-scale technology operations in humanitarian emergencies including Sudan, Haiti and Indonesia, managing network recoveries and business continuity under conditions most practitioners never encounter. A certified ICF coach, he pairs technical governance with people-centred leadership, and is completing a Master’s in Management and Human Resources on how organisational resilience and inclusive leadership strengthen security posture.

Walid Moselhy
Microsoft Cloud Solutions Architect
Walid Moselhy is a Microsoft Cloud Solutions Architect specialising in secure cloud architecture, identity management, automation and hybrid environments, including the infrastructure that sits underneath AI workloads. Across nearly two decades he has helped large enterprise organisations worldwide adopt and secure Microsoft cloud technologies, working closely with Microsoft product teams. A Certified Trainer and Azure Solutions Architect, he has trained hundreds of IT professionals and administrators in designing and implementing secure cloud solutions.
Fees - With Protocol
- 100.00 € Application Fee
- 100.00 € Enrollment Fee
- 10.00 € School Insurance
- 3,500.00 € Annual Payment
- 1,750.00 € Semester Payment
- 350.00 € Fee per Course
Tuition and Fees - ISTEC Lisbon Graduate
- 100.00 € Application Fee
- 100.00 € Enrollment Fee
- 10.00 € Student Insurance
- 3,110.00 € Annual Payment
- 1,555.00 € Semester Payment
- 350.00 € Fee per Course
Tuition and Fees - Other Students
- 100.00 € Application Fee
- 100.00 € Enrollment Fee
- 10.00 € Student Insurance
- 4,000.00 € Annual Payment
- 2,000.00 € Semestral Payment
- 350.00 € Fee per Course

