Your cybersecurity career roadmap
What each role actually does, what it needs, and a realistic order to learn things in. Read it free — you do not need an account.
Stage 1 · Entry level SOC Analyst The entry point into most security careers. You monitor alerts, decide what is real, and escalate what matters. The work teaches … Details
The entry point into most security careers. You monitor alerts, decide what is real, and escalate what matters. The work teaches you what normal looks like faster than any course, which is why it is such a common starting role.
What you would do
- Triage security alerts and decide what warrants escalation
- Investigate suspicious activity using logs and telemetry
- Document findings clearly for the next shift
- Tune detection rules to reduce noise
- Support incident response when something is real
Core skills
- Log analysis and query languages
- Networking fundamentals
- Operating system internals
- Threat awareness
- Clear written communication
Suggested learning order
Stage 2 · Entry level Security Analyst Broader than pure monitoring. You assess risk, review configurations, support audits and help teams make better decisions before … Details
Broader than pure monitoring. You assess risk, review configurations, support audits and help teams make better decisions before something goes wrong rather than after.
What you would do
- Assess security posture across systems and processes
- Review configurations against benchmarks
- Support compliance and audit activity
- Produce risk assessments teams can act on
- Advise projects during design rather than after
Core skills
- Risk assessment
- Security frameworks and controls
- Vulnerability management
- Stakeholder communication
- Documentation
Suggested learning order
Stage 3 · Mid level Penetration Tester Authorised offensive testing. You find weaknesses before someone unauthorised does, and — the part that actually distinguishes go… Details
Authorised offensive testing. You find weaknesses before someone unauthorised does, and — the part that actually distinguishes good testers — you explain them so they get fixed.
What you would do
- Scope and plan authorised engagements
- Test applications, networks and cloud environments
- Validate findings and eliminate false positives
- Write reports that developers can act on
- Retest fixes and confirm closure
Core skills
- Web and API security testing
- Network security
- Scripting and automation
- Methodology and discipline
- Professional report writing
Suggested learning order
Stage 3 · Mid level Incident Responder You arrive when something has already gone wrong. The job is establishing what happened, stopping it continuing, and getting the … Details
You arrive when something has already gone wrong. The job is establishing what happened, stopping it continuing, and getting the organisation back to normal without destroying the evidence.
What you would do
- Contain active incidents
- Establish the initial access vector and timeline
- Coordinate response across technical and business teams
- Preserve evidence correctly
- Produce post-incident reports and lessons learned
Core skills
- Digital forensics
- Log and timeline analysis
- Malware behaviour analysis
- Calm decision-making under pressure
- Stakeholder communication
Suggested learning order
Stage 4 · Mid level Cloud Security Engineer Securing infrastructure that changes daily and is defined in code. Increasingly the highest-demand specialisation in the field. Details
Securing infrastructure that changes daily and is defined in code. Increasingly the highest-demand specialisation in the field.
What you would do
- Design secure cloud architecture
- Manage identity and access at scale
- Automate security controls in pipelines
- Monitor for misconfiguration continuously
- Respond to cloud-specific incidents
Core skills
- Cloud platform depth
- Identity and access management
- Infrastructure as code
- Automation and scripting
- Container and workload security
Suggested learning order
Stage 5 · Senior level Security Engineer You build and run the controls rather than only assessing them. The role sits between security and platform engineering and requi… Details
You build and run the controls rather than only assessing them. The role sits between security and platform engineering and requires genuine engineering ability.
What you would do
- Design and implement security controls
- Build detection and response tooling
- Integrate security into development pipelines
- Lead technical remediation
- Mentor analysts and testers
Core skills
- Software engineering
- Security architecture
- Automation at scale
- Detection engineering
- Systems design
Suggested learning order
Stage 6 · Senior level Security Architect You decide how security works across an organisation rather than on one system. Mostly judgement, trade-offs and influence, suppo… Details
You decide how security works across an organisation rather than on one system. Mostly judgement, trade-offs and influence, supported by deep technical grounding.
What you would do
- Define security architecture and standards
- Evaluate and select technologies
- Assess architectural risk
- Guide engineering teams
- Align security with business objectives
Core skills
- Broad technical depth
- Threat modelling
- Risk management
- Influence without authority
- Business understanding
Suggested learning order
An honest note. No course guarantees a job, including ours. What a course can do is give you the knowledge, the practical evidence and the vocabulary to be credible in an interview. Hiring depends on the market, your location, your portfolio and a good deal of persistence. Anyone promising you a salary figure is selling you something.
Not sure where you fit?
Tell us what you can already do and what you want to be doing, and we will suggest a realistic starting point.
Prefer a form? Request security assistance