Skip to contentSkip to content
Verified credentials. On-chain. Forever.Learn more
Ewance
Sign in
Cover image for Threat-Model the Patient-Intake App for a Telemedicine Startup
Design

Threat-Model the Patient-Intake App for a Telemedicine Startup

FreeVerified credential2 weeksIntermediate

Overview

What this challenge is about.

Threat-Model the Patient-Intake App for a Telemedicine Startup. Intermediate challenge in design. Designing real products under real constraints, earn a bloc...

CredentialBlockchain-anchored
ShareableLinkedIn-ready
LanguageEnglish
PaceSelf-paced

The Brief

What you'll do, and what you'll demonstrate.

Build a STRIDE-based threat model of MapleCare's patient-intake web app, rank the top 10 risks with a documented scoring method, and propose mitigations that each map to a specific SOC 2 control.

This is not a design exercise. It is the work a product designer does between a brief and a shipped interface. That distinction matters to every hiring manager who has seen candidates redesign Spotify's homepage and none who have worked under real product constraints.

When you finish, you will have something most graduates do not: a real-world deliverable, verified by Ewance, that you can show to a hiring manager and say "I did this. Here is the proof."

Earning criteria — what you'll demonstrate

  • Decompose a real web application into processes, data stores, data flows, and trust boundaries suitable for threat modeling.
  • Apply STRIDE systematically so that coverage is complete and gaps are visible.
  • Score and rank risks with a consistent, defensible method (DREAD or likelihood-impact).
  • Translate threats into specific, testable mitigations that map to recognized SOC 2 controls.
  • Write security documentation that a non-security engineering manager can act on directly.

Program Fit

Where this fits in your program.

Sharpens the same skills your degree expects you to demonstrate.

Aligned coursework coming soon.

Careers

Career paths this challenge builds toward

Completing this challenge demonstrates skills that transfer directly to these roles:

Application Security Engineer

This challenge mirrors the core of an application security role: decomposing a live app, finding where it can be attacked, and prescribing fixes. You leave with a portfolio-ready threat model and the habit of tying every risk to a testable control.

This challenge sharpens

  • threat-modeling
  • stride
  • secure-design

Security Governance, Risk & Compliance Analyst

Mapping mitigations to SOC 2 controls and producing audit-ready evidence is the daily work of a governance, risk, and compliance analyst. You practice translating technical risk into the documented, defensible artifacts auditors and leadership expect.

This challenge sharpens

  • risk-assessment
  • soc2
  • documentation

Product Security Engineer

Product security engineers embed risk thinking into how features are built. By scoring threats and proposing concrete, prioritized mitigations a sprint can absorb, you learn to influence engineering roadmaps with secure-by-design recommendations.

This challenge sharpens

  • threat-modeling
  • risk-assessment
  • secure-design

One more thing

You can put a credential on your CV by Friday.