Threat-Model the Patient-Intake App for a Telemedicine Startup
Overview
What this challenge is about.
Threat-Model the Patient-Intake App for a Telemedicine Startup. Intermediate challenge in design. Designing real products under real constraints, earn a bloc...
The Brief
What you'll do, and what you'll demonstrate.
Build a STRIDE-based threat model of MapleCare's patient-intake web app, rank the top 10 risks with a documented scoring method, and propose mitigations that each map to a specific SOC 2 control.
This is not a design exercise. It is the work a product designer does between a brief and a shipped interface. That distinction matters to every hiring manager who has seen candidates redesign Spotify's homepage and none who have worked under real product constraints.
When you finish, you will have something most graduates do not: a real-world deliverable, verified by Ewance, that you can show to a hiring manager and say "I did this. Here is the proof."
Earning criteria — what you'll demonstrate
- Decompose a real web application into processes, data stores, data flows, and trust boundaries suitable for threat modeling.
- Apply STRIDE systematically so that coverage is complete and gaps are visible.
- Score and rank risks with a consistent, defensible method (DREAD or likelihood-impact).
- Translate threats into specific, testable mitigations that map to recognized SOC 2 controls.
- Write security documentation that a non-security engineering manager can act on directly.
Program Fit
Where this fits in your program.
Sharpens the same skills your degree expects you to demonstrate.
Aligned coursework coming soon.
Skills
Skills you'll demonstrate.
Each one shows up on your verified credential.
- Threat Modeling
Apply threat modeling to solve real industry problems and demonstrate production-level capability.
- Stride
Apply stride to solve real industry problems and demonstrate production-level capability.
- Risk Assessment
Apply risk assessment to solve real industry problems and demonstrate production-level capability.
- Soc2
Apply soc2 to solve real industry problems and demonstrate production-level capability.
- Secure Design
Apply secure design to solve real industry problems and demonstrate production-level capability.
- Documentation
Apply documentation to solve real industry problems and demonstrate production-level capability.
Careers
Career paths this challenge builds toward
Completing this challenge demonstrates skills that transfer directly to these roles:
Application Security Engineer
This challenge mirrors the core of an application security role: decomposing a live app, finding where it can be attacked, and prescribing fixes. You leave with a portfolio-ready threat model and the habit of tying every risk to a testable control.
This challenge sharpens
- threat-modeling
- stride
- secure-design
Security Governance, Risk & Compliance Analyst
Mapping mitigations to SOC 2 controls and producing audit-ready evidence is the daily work of a governance, risk, and compliance analyst. You practice translating technical risk into the documented, defensible artifacts auditors and leadership expect.
This challenge sharpens
- risk-assessment
- soc2
- documentation
Product Security Engineer
Product security engineers embed risk thinking into how features are built. By scoring threats and proposing concrete, prioritized mitigations a sprint can absorb, you learn to influence engineering roadmaps with secure-by-design recommendations.
This challenge sharpens
- threat-modeling
- risk-assessment
- secure-design