Skip to content

Your cybersecurity career roadmap

What each role actually does, what it needs, and a realistic order to learn things in. Read it free — you do not need an account.

Stage 1 · Entry level SOC Analyst The entry point into most security careers. You monitor alerts, decide what is real, and escalate what matters. The work teaches … Details

The entry point into most security careers. You monitor alerts, decide what is real, and escalate what matters. The work teaches you what normal looks like faster than any course, which is why it is such a common starting role.

What you would do

  • Triage security alerts and decide what warrants escalation
  • Investigate suspicious activity using logs and telemetry
  • Document findings clearly for the next shift
  • Tune detection rules to reduce noise
  • Support incident response when something is real

Core skills

  • Log analysis and query languages
  • Networking fundamentals
  • Operating system internals
  • Threat awareness
  • Clear written communication

Suggested learning order

Networking foundations Linux foundations Security fundamentals Attack awareness Log analysis practice
Recommended: Beginner plan ($100)
Stage 2 · Entry level Security Analyst Broader than pure monitoring. You assess risk, review configurations, support audits and help teams make better decisions before … Details

Broader than pure monitoring. You assess risk, review configurations, support audits and help teams make better decisions before something goes wrong rather than after.

What you would do

  • Assess security posture across systems and processes
  • Review configurations against benchmarks
  • Support compliance and audit activity
  • Produce risk assessments teams can act on
  • Advise projects during design rather than after

Core skills

  • Risk assessment
  • Security frameworks and controls
  • Vulnerability management
  • Stakeholder communication
  • Documentation

Suggested learning order

Security fundamentals Web security foundations Vulnerability assessment Professional reporting
Recommended: Beginner plan ($100)
Stage 3 · Mid level Penetration Tester Authorised offensive testing. You find weaknesses before someone unauthorised does, and — the part that actually distinguishes go… Details

Authorised offensive testing. You find weaknesses before someone unauthorised does, and — the part that actually distinguishes good testers — you explain them so they get fixed.

What you would do

  • Scope and plan authorised engagements
  • Test applications, networks and cloud environments
  • Validate findings and eliminate false positives
  • Write reports that developers can act on
  • Retest fixes and confirm closure

Core skills

  • Web and API security testing
  • Network security
  • Scripting and automation
  • Methodology and discipline
  • Professional report writing

Suggested learning order

Advanced web security API security Penetration testing methodology Professional reporting Advanced lab ranges
Recommended: Advanced plan ($250)
Stage 3 · Mid level Incident Responder You arrive when something has already gone wrong. The job is establishing what happened, stopping it continuing, and getting the … Details

You arrive when something has already gone wrong. The job is establishing what happened, stopping it continuing, and getting the organisation back to normal without destroying the evidence.

What you would do

  • Contain active incidents
  • Establish the initial access vector and timeline
  • Coordinate response across technical and business teams
  • Preserve evidence correctly
  • Produce post-incident reports and lessons learned

Core skills

  • Digital forensics
  • Log and timeline analysis
  • Malware behaviour analysis
  • Calm decision-making under pressure
  • Stakeholder communication

Suggested learning order

Linux and Windows internals Log analysis Incident response fundamentals Forensics foundations
Recommended: Advanced plan ($250)
Stage 4 · Mid level Cloud Security Engineer Securing infrastructure that changes daily and is defined in code. Increasingly the highest-demand specialisation in the field. Details

Securing infrastructure that changes daily and is defined in code. Increasingly the highest-demand specialisation in the field.

What you would do

  • Design secure cloud architecture
  • Manage identity and access at scale
  • Automate security controls in pipelines
  • Monitor for misconfiguration continuously
  • Respond to cloud-specific incidents

Core skills

  • Cloud platform depth
  • Identity and access management
  • Infrastructure as code
  • Automation and scripting
  • Container and workload security

Suggested learning order

Cloud security fundamentals Identity and access Security automation Cloud assessment practice
Recommended: Pro plan ($500)
Stage 5 · Senior level Security Engineer You build and run the controls rather than only assessing them. The role sits between security and platform engineering and requi… Details

You build and run the controls rather than only assessing them. The role sits between security and platform engineering and requires genuine engineering ability.

What you would do

  • Design and implement security controls
  • Build detection and response tooling
  • Integrate security into development pipelines
  • Lead technical remediation
  • Mentor analysts and testers

Core skills

  • Software engineering
  • Security architecture
  • Automation at scale
  • Detection engineering
  • Systems design

Suggested learning order

Advanced security across domains Security automation Security architecture Professional projects
Recommended: Pro plan ($500)
Stage 6 · Senior level Security Architect You decide how security works across an organisation rather than on one system. Mostly judgement, trade-offs and influence, suppo… Details

You decide how security works across an organisation rather than on one system. Mostly judgement, trade-offs and influence, supported by deep technical grounding.

What you would do

  • Define security architecture and standards
  • Evaluate and select technologies
  • Assess architectural risk
  • Guide engineering teams
  • Align security with business objectives

Core skills

  • Broad technical depth
  • Threat modelling
  • Risk management
  • Influence without authority
  • Business understanding

Suggested learning order

Complete Pro pathway Threat modelling Security architecture Capstone project
Recommended: Pro plan ($500)

An honest note. No course guarantees a job, including ours. What a course can do is give you the knowledge, the practical evidence and the vocabulary to be credible in an interview. Hiring depends on the market, your location, your portfolio and a good deal of persistence. Anyone promising you a salary figure is selling you something.

Not sure where you fit?

Tell us what you can already do and what you want to be doing, and we will suggest a realistic starting point.

Prefer a form? Request security assistance