The HackRange Cyber Security Mentorship Program

A 13 week, mentor led path from networking basics to a real security career.

September 10, 2024

HackRange is a cyber security mentorship program built for people in South West Florida who already know their way around a computer and want to move into security work for real. It runs for 13 weeks. It is led by people who do this job for a living and volunteer their time to teach it.

The program is free to accepted students. Tuition is covered by area companies who would rather fund trained people than keep failing to hire them. That funding is also why the class stays small and why students who stop showing up get unenrolled.

What Makes This Different From a Course You Buy Online

Most online security training is a video library. You buy access, you watch on your own, and nobody notices whether you finished. That works for a small number of very self directed people and fails for everyone else.

This is a mentorship. There are about ten students per class. You meet live once a week over Zoom with your instructor and your pod, camera on. Somebody knows your name, knows what week you are on, and notices when you go quiet.

You also get a dedicated lab. Not a shared sandbox with a time limit, but your own environment with Windows and Linux hosts you can break and rebuild. Every exercise in the program happens there, against targets we built for that purpose, which keeps the whole thing legal and lets you make mistakes freely.

The Weekly Commitment

Plan on three to five hours a week. That covers the written lessons in the learning management system, the video recaps, the hands on lab work, and the weekly quiz. The live class is on top of that.

The material is self paced inside each week, so you can do it at six in the morning or at midnight. What is not flexible is the pace across weeks. The class moves together, because the discussion in the live session only works if everyone has seen the same material.

Flow diagram of the HackRange mentorship in four phases: foundations, frameworks and risk, defence and offence, then cloud, AI and career.
Thirteen Weeks, Four Phases

What You Actually Learn

The curriculum is built in the order the knowledge is needed, not in the order that sounds exciting. It starts with how networks work, because almost every security concept downstream assumes you already understand an IP address, a route, and a firewall rule.

From there it moves into the security frameworks that decide what a company does first, the governance and audit work that pays for it, the vendor and vulnerability programs that consume most of a security team's week, and then into the hands on defensive work: log analysis, detection, and a full intrusion investigation.

The last third covers the newer surface area. Shadow SaaS and shadow AI, purple team attack simulation, generative AI in security operations, and cloud security. It closes with a capstone tabletop exercise and honest career coaching.

The full breakdown is on the week by week curriculum page.

The Tools You Will Touch

You work in Kali Linux for offensive tooling, which means the real versions of Nmap, Wireshark, Burp Suite, Metasploit, and Hashcat. Nothing is a training replica.

On the defensive side you work in Splunk, which is one of the most widely deployed SIEM platforms in the industry. You write real searches against real log data and use them to answer real questions.

You also spend time with iptables and nftables on Linux, with DNS tooling like dig, and with the shell utilities that turn a pile of messy exports into an answer an auditor will accept.

Who Gets In

The program is primarily invitation only. The baseline is a working knowledge of computers and a real willingness to put in the hours. You do not need a degree, a certification, or prior security experience.

What you do need is follow through. Students are unenrolled for missing class without a valid reason or for not doing the work. That sounds harsh, and it is deliberate. A seat that somebody is not using is a seat somebody else wanted.

There is one other rule that is absolute. Using anything you learn here against systems you do not own and do not have written permission to test gets you removed immediately. That is covered in Week 1 before you run a single tool.

What You Walk Away With

A working vocabulary, which matters more than it sounds. Security interviews are mostly people asking whether you can talk about this work without faking it.

Specific things you have done. An intrusion you reconstructed from logs. An audit evidence package you built. A cloud account you assessed. A detection you wrote and then validated by running the attack against it. Those become the answers to interview questions that most applicants answer in generalities.

And a realistic map of the field, including which certifications are worth paying for and which are not, and what the actual roles look like day to day.

Learn This at HackRange

The program is free to accepted students and runs with about ten people per class. Sign up interest goes through the site, and most placements come through LinkedIn.