* memory safety and exploitation (the "buffer overflow" section is about 20 years out of date, though super appropriate for a first course)
* the WebPKI/certificates thing
* messaging security and messaging cryptosystems,
* microarchitectural security and hardware side channels.
Multiple full courses on each of these subjects would bring you up to "practitioner" levels of expertise.