August 21, 2026

Secure by Design: How Software Systems and Cybersecurity Work Together

When security is an afterthought, engineers may need to rely heavily on reactive controls such as firewalls and intrusion detection systems. Secure-by-design engineering brings security into decisions about a system’s architecture, development, and deployment from the beginning.

During a recent Penn Engineering Online webinar introducing the new online Master of Science in Engineering in Software Systems and Cybersecurity (MSE-SSC Online) program, Professor Michael Hicks explains why expertise in both software systems and cybersecurity is essential for building secure software with a systems-level approach. Hicks is one of the MSE-SSC Online Program Directors, Professor in Penn Engineering’s Department of Computer and Information Science, and Director of the Schlein Center for Cybersecurity.

Why Software Systems Knowledge Matters in Cybersecurity

Modern software depends on networks, databases, cloud services, storage systems, and distributed infrastructure. Software and security engineers need to understand how these components work, how they interact, and where vulnerabilities may emerge. They must also understand the engineering tradeoffs involved in building systems that remain reliable and perform effectively at scale.

Systems knowledge helps engineers determine how components should fit together and how security decisions may affect a system’s scalability and service quality.

“By knowing both how to build really high-quality, scalable, state-of-the-art systems and knowing the state-of-the-art threats against such systems, you are in a great position to build systems that are secure by design,” Hicks says.

How Threat Modeling and Risk Analysis Support Secure Design

Threat modeling helps engineers identify where a system may be vulnerable, which attacks it could face, and which defenses could reduce those risks. It also requires engineers to examine unusual conditions and consider how an attacker might use a system differently than its designers intended.

Since no system can be completely secure, engineers must compare possible approaches and decide which risks are acceptable in a particular situation. Hicks emphasizes using data and experimental analysis to determine whether security recommendations and defenses work as intended. He explains,

“You need to do threat modeling to think about where your system might be vulnerable. You need to know about the attacks that constitute those threats. You need to know about the building blocks that make up possible defenses. And through all of this, you need to have a security mindset where you think – ‘This is the way I imagine in the best case or in the average case my system works. But what is that weird, strange corner case that no normal human being would ever think to do? What happens if that happened? What could go wrong?’ Because that’s what the attackers are doing. That’s the security mindset that you need to have.”

Hicks also shares that engineers can build logging and experimental-analysis components into a system to generate evidence about how well it performs.

AI can help with threat modeling and data analysis. According to Hicks, AI can help security engineers analyze code and identify vulnerabilities more quickly, allowing them to address weaknesses before attackers exploit them.

Why Security Engineers Need Communication Skills

Drawing on his previous experience as a Senior Principal Applied Scientist at Amazon Web Services, Hicks describes how security engineers review system designs, assess threat models, and recommend changes that can make services more resilient to attack.

Those recommendations must be communicated clearly and collaboratively to the product engineers responsible for implementing them.

“To be good at your job, you have to not only be good technically; you have to be good at explaining why a potential problem is indeed a problem,” Hicks says.

How MSE-SSC Online Connects Systems and Security

Building skills in technical judgment and clear communication is built into the MSE-SSC Online core curriculum. 

The 10-course degree includes a software systems core covering Internet and Web Systems, Software Systems and Networked Systems, along with a cybersecurity core covering Computer and Network Security, Cryptography, and Secure System Engineering and Management.

One of the core cybersecurity courses, CIS 5580: Secure System Engineering and Management covers threat modeling, security-informed system design, secure software development, and security operations. It also focuses on communicating security risks and tradeoffs to stakeholders and using empirical evidence to evaluate security choices.

As a student, you can select technical electives in areas such as software analysis, wireless and mobile networks, database systems, big data, blockchain and cloud technologies, followed by two general electives that allow you to explore additional areas such as artificial intelligence, computer architecture, or risk analysis.

The program is designed for software engineers, systems engineers, cybersecurity professionals, and others with an existing technical foundation. You should enter with knowledge of programming, algorithms and data structures, mathematical foundations, probability and statistics, and systems programming or software engineering. Relevant preparation may come from a related degree, additional coursework, or professional experience.

Hicks notes that the focus on systems can also benefit security-operations professionals who monitor logs, identify intrusions, and respond to incidents by helping them understand how vulnerabilities originate and which design choices could mitigate them.

Courses are asynchronous, so students can enroll from anywhere in the world and access class materials on their own schedule, from any time zone. Academic support is available through faculty office hours, teaching assistants, and academic coaches. Opportunities to connect with classmates are facilitated through discussion forums, study groups, and Slack channels.

The combined systems and cybersecurity curriculum can support career paths towards roles such as Security Engineer, Incident Response Specialist, Cybersecurity Architect, Cybersecurity Architect, and Systems Engineer.

For software professionals moving toward security engineering, and cybersecurity professionals seeking a deeper understanding of how systems are built, designing secure technology requires knowledge of the entire system, the threats it may face, and the engineering decisions that can make it more resilient.

Missed the webinar? Watch the full recording to hear Hicks discuss secure systems engineering, the MSE-SSC Online curriculum and related career paths.

Watch the MSE-SSC Online webinar
Explore the MSE-SSC Online degree
Review MSE-SSC Online coursework

Request Info