Average Salary
Average Hike
Median Salary
Median Hike
Hiring Partners
Achieve your career goals
Program feature
Build a lucrative career path in Cybersecurity with the M.Tech. in Cybersecurity program. This is a 100% outcome-driven and skill-based program exclusively designed for working professionals in mid and senior positions to accomplish a smooth career transition into the highly rewarding cybersecurity field. The 24-month program is recognised by AICTE and focuses on hands-on learning using proprietary or open software tools in the Cybersecurity market today.
Industry Thought Leaders
as Mentors
Our industry mentors have decades of experience in the industry and hence participants will receive hands-on experience with various analytics applications to solve real-time business issues.
LMS with the best in
Class Resources
An integrated Learning Management System (LMS) that provides 24/7 access support to aspirants with in-class reading support, interactive resources, real case database datasets, recordings of sessions, and other resources.
Industry Grade
Projects
Real-time case studies with labs and simulations provide hands-on learning opportunities that help participants gain a thorough understanding of the subject and how it is applied in the real world.
Placements
Opportunities
The lateral placement services such as career guidance, resume building, and mock interviews with industry mentors and alumni help our participants to transition their careers and bag lucrative offers.
Why Cybersecurity with RACE?
- Complete Cybersecurity Lifecycle: Learn how enterprises prevent, detect, respond, recover, govern and improve cybersecurity posture.
- Built for the Modern Threat Landscape: The curriculum covers Zero Trust, AI-enabled defense, adversarial AI, DevSecOps, cloud-native security, identity risk, cyber resilience and privacy.
- Learn from Industry Practitioners: The program brings together academic depth and industry mentoring through case discussions, labs, cyber range exposure, SOC workflows, capstones and research.
- Cyber Range and SOC-Oriented Learning: Practice real-world attack-defense scenarios, alert triage, SIEM workflows, detection logic and incident response.
- Global Certification-Aligned Curriculum: Learning aligned to CEH, OSCP and Microsoft SC-200, helping learners build practical and industry-relevant skills.
- Capstone and Research Focus: Complete three capstone components and one research publication to build a strong professional portfolio.

Hurry! Limited Seats Available
Curriculum Highlights
- 72 Credits
- 4 Semester
- 15 Modules
- CEH + OSCP + SC-200 aligned learning
- 3 Capstone Components
- 1 Research Publication
Semester- I
Modern enterprises no longer have a perimeter — they have identities, devices, workloads and data spread across on-prem, cloud and hybrid estates. This module starts with the fundamentals every security professional is expected to own: OSI and TCP/IP, switching, routing, VLANs, DNS, DHCP, NAT and VPNs. It then moves into firewalls, IDS/IPS, secure network design, endpoint hardening and secure baselines, before going deep into identity: MFA, least privilege, conditional access, privileged access management and device trust. Learners finish by designing a complete Zero Trust architecture for a sample enterprise — continuous verification, micro-segmentation, policy enforcement and workload security — and presenting it with logging, monitoring, resilience and board-level reporting built in.
Frameworks: NIST SP 800-207 (Zero Trust Architecture), NIST CSF 2.0, CIS Controls v8, Microsoft Zero Trust Guidance
Toolkits: Cisco Packet Tracer, pfSense, Wireshark, Nmap, Microsoft Entra ID (Conditional Access), CIS Benchmarks
You will walk out with a Zero Trust reference architecture you can put in front of your own CISO.
Most breaches still start at the application layer. This module covers secure application design, secure SDLC, application threat modeling and secure design principles, then works through the OWASP Top 10 in a live lab — injection, XSS, broken access control, SSRF, insecure deserialization and insecure configuration. Learners go on to authentication, authorization, session management, password security, MFA and identity flows, and then to the area most enterprises are weakest in: API security — REST API risks, JWT, OAuth2, rate limiting, API gateway controls and secure integration. The module closes with SAST, DAST and SCA tooling, vulnerability reporting, remediation tracking and secure release practice.
Frameworks: OWASP Top 10, OWASP API Security Top 10, OWASP Web Security Testing Guide, NIST SSDF (SP 800-218)
Toolkits: Burp Suite, OWASP ZAP, DVWA, OWASP Juice Shop, Postman, SonarQube, Dependency-Check, Kali Linux
Break it, then fix it — every vulnerability class is exploited in a lab before it is remediated in code.
This is the module that turns an engineer into an advisor. It covers cyber risk fundamentals — assets, threats, vulnerabilities, likelihood, impact and business consequence — and then the structured methods used to reason about them: STRIDE, attack trees, the cyber kill chain, the Diamond Model and MITRE ATT&CK. Learners build a risk register, map controls, prioritise and select treatment options using recognised frameworks. The resilience half covers BCP, DR, backup strategy, incident readiness, crisis response and recovery objectives. It ends where security actually gets funded: enterprise risk reporting, dashboards, residual risk, risk acceptance and a board-facing improvement roadmap.
Frameworks: STRIDE, Attack Trees, Cyber Kill Chain, Diamond Model, MITRE ATT&CK, NIST SP 800-30, ISO/IEC 27005, NIST CSF 2.0
Toolkits: Microsoft Threat Modeling Tool, OWASP Threat Dragon, MITRE ATT&CK Navigator, enterprise risk register and BIA templates
Threat modeling now sits in Semester I — so every later module is done with a risk lens already switched on.
Structured around EC-Council’s CEH domains, this module builds the attacker’s mindset inside ethical and legal boundaries. It covers ethical hacking foundations, legal limits, responsible conduct, the attack lifecycle and threat actor profiles; then footprinting, reconnaissance, scanning, enumeration and vulnerability discovery; then system hacking concepts, malware basics, sniffing, social engineering and wireless risk. The second half is the part enterprises actually hire for: the vulnerability management lifecycle — CVE, CVSS, CWE, asset prioritisation, remediation tracking, retesting, exception handling and vulnerability governance. Learners close with a professional vulnerability assessment report.
Aligned Certification: EC-Council Certified Ethical Hacker (CEH) — theory exam mandatory
Frameworks: CVSS v4.0, MITRE CVE and CWE, OWASP Testing Guide
Toolkits: Nmap, Nessus, OpenVAS, Kali Linux toolkit, OSINT toolset, CVSS v4.0 calculator
★ Certification-aligned module — the CEH exam is a programme requirement, not an optional extra.
Semester- II
Aligned to OSCP / PEN-200 style practical outcomes, this module is deliberately hands-on. Learners work the full lifecycle: scoping and rules of engagement; enumeration, service discovery, vulnerability validation and exploit research; web exploitation including file upload flaws, command injection, SQL injection and authentication bypass; then Linux and Windows privilege escalation, password attacks and post-exploitation. The deliverable is the one that separates a hobbyist from a professional — evidence collection and an OSCP-style penetration testing report with remediation guidance and a retest plan.
Aligned Certification: Offensive Security OSCP / PEN-200 aligned — lab-based preparation, exam conducted internally
Frameworks: MITRE ATT&CK Enterprise Matrix, PTES-style engagement methodology
Toolkits: Kali Linux, Metasploit, Burp Suite, Hydra, John the Ripper, ExploitDB, GTFOBins, LOLBAS, Pwntools
Penetration testing now follows CEH rather than preceding it — attack theory first, then supervised exploitation.
The largest taught module in the programme, and the one that maps most directly to open roles. Learners build real SOC analyst capability: SOC operations, alert lifecycle, incident response phases and SOC roles; SIEM fundamentals covering log sources, normalisation, correlation and dashboards; then Microsoft Sentinel and Defender XDR across identity, endpoint and cloud alerts. The detection engineering block covers KQL queries, analytics rules and SOAR playbooks. The module closes on full incident handling — containment, eradication, recovery, reporting and lessons learned — including phishing and endpoint malware investigations end to end.
Aligned Certification: Microsoft SC-200: Security Operations Analyst — mandatory exam
Frameworks: NIST SP 800-61 (Incident Handling), MITRE ATT&CK Defender
Toolkits: Microsoft Sentinel, Defender XDR, KQL, SOAR playbooks, Splunk, Elastic SIEM
★ 6 credits · 150 hours — the deepest module in the programme, built around live SIEM investigation.
Detection catches what you already know about. Hunting finds what you do not. This module covers the CTI lifecycle across strategic, operational, tactical and technical intelligence; threat actors, malware families, campaigns, IOCs, TTPs and intelligence sourcing; and analysis using MITRE ATT&CK, the kill chain and the Diamond Model. Learners then build hypothesis-driven hunts — hypothesis creation, log analysis and anomaly detection — and hunt live for suspicious PowerShell activity in SIEM data. The module finishes with CTI reporting, intelligence sharing, STIX/TAXII and operationalising intelligence inside a SOC workflow.
Frameworks: MITRE ATT&CK, Diamond Model, Cyber Kill Chain, STIX/TAXII
Toolkits: MISP, AlienVault OTX, TheHive, YARA, Zeek, ATT&CK Navigator
Learners produce a threat actor profile and a publishable CTI report on a live campaign.
The single biggest differentiator of the 2026–28 revision. This module covers AI/ML fundamentals for security — datasets, features and evaluation metrics — then applied detection: malware classification, phishing detection, anomaly detection and user behaviour analytics. It moves into GenAI for the SOC, covering alert summarisation, incident analysis, report generation and playbook support; then Autonomous SOC concepts — agents, orchestration, SOAR integration and human-in-the-loop design. Critically, it also covers the other side of the coin: AI security risk, adversarial ML, prompt injection, data leakage and responsible AI governance. Learners build a SOC assistant workflow and stress-test a security chatbot for prompt injection.
Frameworks: NIST AI Risk Management Framework, MITRE ATLAS, OWASP Top 10 for LLM Applications
Toolkits: Python (scikit-learn, TensorFlow, PyTorch), Jupyter, Microsoft Security Copilot, agent/orchestration frameworks, Azure and AWS
Very few Indian M.Tech programmes teach both AI-for-SOC and security-of-AI in the same module. This one does.
Capstone I is where the learner picks their problem and defends it. It covers problem identification, domain selection and project scoping; literature, tool and dataset review with gap identification; research methodology, project plan, architecture and evaluation metrics; then prototype development, lab setup and initial implementation. It concludes with a proposal report, architecture diagram, working proof of concept and a panel presentation — the foundation that Capstone II scales up and Capstone III publishes.
Frameworks: IEEE research writing guidelines, NIST cybersecurity publications, MITRE ATT&CK and D3FEND, OWASP project resources
Toolkits: GitHub, architecture and diagramming tools, Zotero/Mendeley, project-specific labs and datasets
Each learner is assigned an industry mentor at this point and keeps them through to publication.
Semester- III
Security that is not in the pipeline is security that does not ship. This module covers secure SDLC, shift-left security, DevSecOps principles and maturity models; secure coding, dependency risk, secrets management and code review; CI/CD pipeline security with SAST, DAST, SCA and container scanning; Infrastructure-as-Code security, policy-as-code and deployment governance. It ends on the things that make a DevSecOps programme survive contact with engineering leadership — metrics, compliance, reporting and continuous improvement. Learners build a working pipeline, add scanning stages, detect secrets in a repository and implement a security gate that actually blocks a bad build.
Frameworks: NIST SSDF (SP 800-218), OWASP SAMM, OWASP DevSecOps Guideline
Toolkits: GitHub / GitLab CI, SonarQube, Dependency-Check, Trivy, Gitleaks, Docker, Kubernetes, Terraform, OPA
The DevSecOps Engineer role is one of the fastest-growing in the market. It is now a core module, not an option.
India’s first simulation-integrated M.Tech in Cybersecurity earns that claim here. Learners work inside a live cyber range: exercise design, rules of engagement and safety; red team tactics, adversary emulation and ATT&CK mapping; blue team monitoring, SIEM dashboards, alerts and investigation workflow; then purple team collaboration, detection validation and control improvement. Scenarios include phishing and credential attack simulation and lateral movement, with learners detecting their own attack traces in SIEM. The module closes with a cyber drill report, lessons learned and a defensive maturity improvement plan.
Frameworks: MITRE ATT&CK and D3FEND, NIST SP 800-84 (Cyber Exercise Guide)
Toolkits: PurpleSynapz Purple Range, Atomic Red Team, MITRE Caldera, SIEM dashboards, Blue Team toolset
Attack on Saturday morning. Detect your own attack on Saturday afternoon. Fix the detection gap before you leave.
Enterprises have moved to containers, Kubernetes, serverless and now AI workloads — and the security model changed with them. This module covers cloud-native architecture, shared responsibility, IAM and workload identity; container image security, registry security, runtime protection and secrets; Kubernetes security including RBAC, network policies, pod security and admission control. It then addresses what almost no curriculum covers yet: AI workload security — model supply chain, ML pipeline security and data protection. Learners secure an ML model API, configure Kubernetes RBAC and network policies, and design a secure AI workload architecture with CSPM/CNAPP monitoring.
Frameworks: CNCF Kubernetes Security Best Practices, OWASP Kubernetes Top 10, CSA Cloud Controls Matrix, OWASP ML Security Top 10, NIST AI RMF
Toolkits: Trivy, Kubernetes RBAC and network policies, admission controllers, CSPM/CNAPP tooling, AWS / Azure / GCP security services
Securing the AI stack itself — model supply chain, ML pipeline, model API — is a capability the market is only beginning to price.
The module that moves a practitioner toward the CISO track. It covers cybersecurity governance, policies, roles, accountability and board reporting; risk management, risk registers, treatment plans and control ownership; and the compliance landscape — ISO 27001, NIST CSF, CIS Controls, SOC 2 and PCI-DSS. The privacy block covers privacy principles, data classification, consent, retention, breach notification and both India’s DPDP Act and GDPR. Learners write a cybersecurity policy, build a risk register, map controls to ISO 27001 and NIST CSF, conduct a privacy impact assessment, prepare an audit evidence checklist and build a GRC dashboard.
Frameworks: ISO/IEC 27001 and 27002, NIST CSF 2.0, CIS Controls v8, SOC 2, PCI-DSS, India DPDP Act, GDPR, ISACA COBIT
Toolkits: OneTrust, Archer GRC, control-mapping workbooks, DPIA templates, GRC dashboard tooling
GRC is no longer optional now. Every graduate leaves audit-ready and DPDP-literate.
Semester- IV
The full-scale build. Learners refine the Capstone I proposal, review the architecture and plan implementation; then execute full-scale development, configuration, integration and deployment; then testing, validation, benchmarking and evidence collection; then result analysis, limitation analysis and improvement planning. It concludes with a final project report, a live demonstration and a viva-voce before an expert industry panel. At 10 credits and 300 hours, this is now the single largest component of the degree.
Frameworks: IEEE / ACM report templates, NIST and MITRE references relevant to the selected project
Toolkits: GitHub, JIRA, Docker / Kubernetes, AWS / Azure / GCP, project-specific datasets and frameworks
300 hours. One real enterprise problem. One working system. One industry mentor per learner.
Every graduate leaves with a publication. This module converts capstone work into a research paper, applied case study, conference submission, journal article or patent-oriented technical document. It covers research problem framing, novelty and contribution; literature review and citation management; methodology, experimentation and results presentation; research ethics, plagiarism, responsible disclosure and publication quality; then manuscript preparation, venue selection, submission and defence before a review panel.
Frameworks: IEEE and ACM author guidelines, Springer and Elsevier manuscript guides, REVA research and publication policy
Toolkits: Zotero / Mendeley, plagiarism-check workflow, IEEE / ACM templates, cybersecurity journals and conference proceedings
A Scopus-indexed publication with your name on it — a differentiator no bootcamp can offer.
Google Reviews
Partners
This program is powered by various globally renowned marquee organizations. RACE, REVA University is an academic partner for EC-Council, PurpleSynapz, AWS, Microsoft, CloudxLabs, and others. Cybersecurity participants will get unlimited access to our academic partners’ ecosystem which includes the Cloud labs access, Course Materials, Partners’ LMS, Placement services, mentoring sessions, and more.

EC-Council is the world’s largest certification body for Information Security professionals. EC-Council certifies individuals in information security and e-business skills. It has been certified by American National Standards Institute to meet ANSI 17024 standards and offers programs in 107 countries. The Information Security community considers EC-Council as its most trusted source for vendor-neutral Information Security.

Microsoft Azure is the leading cloud platform and productivity company for the mobile-first, cloud-first world, and its mission is to empower every person and every organization on the planet to achieve more. Through this partnership, our participants will get access to their 100’s of courses, certification opportunities, and placement services. Cloud labs with credits will be provided to practice the real-time deployment of projects.

Terralogic is a USA-based well-known software and IT services company, an expert in IoT, Cloud, DevOps, App development, Cybersecurity, and many others. Terralogic is the knowledge partner for RACE Cybersecurity programs, helping us to build cyber professionals with deep technical understanding. The Terralogic team supports us in creating the right ecosystem of industry partners, tools, platforms, domain understanding, etc.

PurpleSynapz is one of the niche cybersecurity training and solution builders, RACE programs deploy their Purple Range (Cyber Range), a hyper-realistic simulation platform designed for modern teams to learn the best Infosec skills by fighting real-world cybersecurity attacks. Our participants will get to team up on 20+ inbuilt real-world attack scenarios and launch a variety of realistic cyber-attacks to test team readiness and approach.

AWS Academy partnership provides course materials to our participants to pursue industry-recognized certifications and in-demand Cloud / Analytics / Artificial Intelligence / Machine Learning jobs. AWS curriculum helps the learners to stay at the forefront of AWS Cloud innovations. The learners will get access to the cloud environment to build and deploy cloud solutions.

Partners
This program is powered by various globally renowned marquee organizations. RACE, REVA University is an academic partner for EC-Council, PurpleSynapz, AWS, Microsoft, CloudxLabs, and others. Cybersecurity participants will get unlimited access to our academic partners’ ecosystem which includes the Cloud labs access, Course Materials, Partners’ LMS, Placement services, mentoring sessions, and more.

EC-Council is the world’s largest certification body for Information Security professionals. EC-Council certifies individuals in information security and e-business skills. It has been certified by American National Standards Institute to meet ANSI 17024 standards and offers programs in 107 countries. The Information Security community considers EC-Council as its most trusted source for vendor-neutral Information Security.

Microsoft Azure is the leading cloud platform and productivity company for the mobile-first, cloud-first world, and its mission is to empower every person and every organization on the planet to achieve more. Through this partnership, our participants will get access to their 100’s of courses, certification opportunities, and placement services. Cloud labs with credits will be provided to practice the real-time deployment of projects.

Terralogic is a USA-based well-known software and IT services company, an expert in IoT, Cloud, DevOps, App development, Cybersecurity, and many others. Terralogic is the knowledge partner for RACE Cybersecurity programs, helping us to build cyber professionals with deep technical understanding. The Terralogic team supports us in creating the right ecosystem of industry partners, tools, platforms, domain understanding, etc.

PurpleSynapz is one of the niche cybersecurity training and solution builders, RACE programs deploy their Purple Range (Cyber Range), a hyper-realistic simulation platform designed for modern teams to learn the best Infosec skills by fighting real-world cybersecurity attacks. Our participants will get to team up on 20+ inbuilt real-world attack scenarios and launch a variety of realistic cyber-attacks to test team readiness and approach.

AWS Academy partnership provides course materials to our participants to pursue industry-recognized certifications and in-demand Cloud / Analytics / Artificial Intelligence / Machine Learning jobs. AWS curriculum helps the learners to stay at the forefront of AWS Cloud innovations. The learners will get access to the cloud environment to build and deploy cloud solutions.

Mentors
Industry mentors are the assets of REVA Academy for Corporate Excellence. The industry experience of our mentors helps the participants to bridge the gap between classroom learning and the industry
Sandeep Vijayaraghavan K
A cybersecurity and cloud security expert at Terralogic Inc., with over 20 years of industry experience. Specializes in cyber (more…)
Sridhar Govardhan
With 24 years of experience in information security, he currently leads as Head of Information Security, driving data (more…)
Dr. Ram Kumar G
A digital transformation-focused cybersecurity leader with 20+ years of global experience across MNCs, (more…)
Dr. Paras Arora
With 17+ years of experience, Dr. Paras leads Microsoft’s Azure team as a coach, mentor, and business architect, driving global initiatives and ensuring real-world (more…)
Dr. Soumyo Maity
As a Distinguished Member of Technical Staff at Dell, he leads product security strategies that safeguard 10,000+ (more…)
Dhruv Kalaan
Dhruv is a dynamic cybersecurity leader with deep expertise in incident management, threat intelligence, and forensics across cloud and on-premise (more…)
Nishanth Kumar Pathi
A Solutions Architect with 15 years of experience, specializing in Cybersecurity, Data Privacy, Cloud Automation, (more…)
Manoj Sharma
With over two decades of cybersecurity expertise, he leads SISA’s training initiatives as Director of Training and (more…)
Sivakumar Subramanian
IT Leader with 25+ years of global experience in building high-impact cybersecurity business units and trusted (more…)
Vishal Pradhan
He is a Purple Team Engineer driven by a passion to deliver a 360-degree perspective on security, aiming to equip security enthusiasts with the insights (more…)
Abid Ahmed
An excellent communicator with 15+ years of experience in the IT industry, including roles as a Technical Lead, Consultant, and Corporate Trainer. (more…)
Vadivelan Sankar
Co-Founder and CEO of Cyberium Labs Pvt. Ltd., he brings 24+ years of expertise in Red Teaming, penetration testing, and digital forensics. A licensed pentester (more…)
Nishant Krishna
Nishant is the Co-founder and CTO of Computer Vision and Cybersecurity startup, “TechMachinery Labs”. (more…)
Rajiv R Chetwani
He has adorned various other coveted positions at ISRO Satellite Centre, Bengaluru. He has received ISRO’s team excellence award for 2015. (more…)
Chinmay Hegde
Chinmay has worked for global security giants including McAfee, Symantec and Cisco. Chinmay possesses expertise in (more…)
Dr. Sai Sushanth
A cyber law expert and techno-legal consultant. He is a law graduate who has completed a master’s in cyber law and cybersecurity from the National Law (more…)
Unnikrishnan P
Unnikrishnan is focused on building and delivering cybersecurity capabilities to improve the cyber risk posture of the clients across industry sectors. (more…)
Ashok Sharma
Ashok is a cybersecurity expert who has competency in shaping most of the dynamic security solutions and products. His experience is mainly in leading R & D (more…)
Mahesh Paradkar
Mahesh heads the IBM Security Labs in Pune and has the functional responsibility of Encryption and Key Management IBM Security products. He plays an (more…)
Continuous Evaluation
This is a globally accredited program to make the participants truly global citizens. At par with international standards and to provide opportunities for global mobility to our participants, we follow an outcome-based education system (OBE). Experiential learning and project-based pedagogy have been employed in the design and delivery of the program.
The objective of module assessment and evaluation is to objectively assess the learners of the program on their ability to apply the concepts, modeling techniques in various domains and verticals for different business scenarios through a continuous evaluation framework throughout the program. Detailed regulations on earning the credits and GPA’s will be shared during the program.

Admission Process
-
Register by filling up the
online application form -
Go through the documentation process and a screening call with the Director’s office.
-
If selected, you will receive an ‘offer of admission’ letter for the upcoming cohort. Secure your seat by paying the admission fee.
Merit Scholarship
for those who scored
60%
and above in their in their UG.
Early bird/group/referral
discounts are also available.
Admission Process
Financial assistance and Educational Loans from NBFC’s and Banks are available with interest rate ranging from 9 to 14%. These financial institutions will allow you to repay the educational loan in easy installments and income tax benefits.
Avail hassle-free educational loan to help you to join our Master’s programs to power up your skills to build your dream career.

























