Privacy Posture Review of a Fintech's Internal Service Mesh
Overview
What this challenge is about.
Privacy Posture Review of a Fintech's Internal Service Mesh. Advanced challenge in analysis. Analyzing real datasets and building models that drive decisions...
The Brief
What you'll do, and what you'll demonstrate.
Determine where personal data is exposed inside a 110-service Istio service mesh and deliver a ranked, eight-gap hardening plan that the engineering teams can execute within 90 days.
This is not a data exercise. It is the work an analyst does when stakeholders need answers from messy data. That distinction matters to every hiring manager who has seen candidates describe statistical methods and none who have extracted insight from messy, real-world data.
When you finish, you will have something most graduates do not: a real-world deliverable, verified by Ewance, that you can show to a hiring manager and say "I did this. Here is the proof."
Earning criteria — what you'll demonstrate
- Measure mutual-TLS strict-mode and authorization-policy coverage systematically across a large service mesh from a policy export
- Detect personal data leaking into service-to-service headers and payloads and tie it to data-classification metadata
- Rank privacy gaps by exposure using data sensitivity and service reach rather than gut feel
- Build a capacity-aware, dependency-ordered remediation roadmap with clear ownership
- Translate technical findings into an audit and funding narrative for executive stakeholders
Program Fit
Where this fits in your program.
Sharpens the same skills your degree expects you to demonstrate.
Aligned coursework coming soon.
Skills
Skills you'll demonstrate.
Each one shows up on your verified credential.
- Network Privacy
Apply network privacy to solve real industry problems and demonstrate production-level capability.
- Mtls
Apply mtls to solve real industry problems and demonstrate production-level capability.
- Service Mesh
Apply service mesh to solve real industry problems and demonstrate production-level capability.
- Audit
Apply audit to solve real industry problems and demonstrate production-level capability.
- Protocol Security
Apply protocol security to solve real industry problems and demonstrate production-level capability.
- Kubernetes Security
Apply kubernetes security to solve real industry problems and demonstrate production-level capability.
Careers
Career paths this challenge builds toward
Completing this challenge demonstrates skills that transfer directly to these roles:
Cloud Security Engineer
This challenge mirrors the core cloud-security task of auditing a live Kubernetes platform for misconfigured encryption and access controls, then driving fixes. You leave able to measure mesh-wide control coverage and hand engineering teams a credible hardening roadmap.
This challenge sharpens
- mtls
- service-mesh
- kubernetes-security
Security Auditor / GRC Engineer
Ranking evidence-backed gaps and shaping them into a SOC 2 audit narrative is exactly what governance and audit roles require. You practice tracing every claim to a data source and translating technical findings into executive-ready risk language.
This challenge sharpens
- audit
- network-privacy
- protocol-security
Application / Protocol Security Engineer
Hunting for personal data leaking through service-to-service headers and payloads builds the protocol-level privacy instincts these roles depend on. You learn to reason about east-west traffic confidentiality, not just perimeter defense.
This challenge sharpens
- protocol-security
- network-privacy
- mtls