Career paths

Cybersecurity career paths you can practise

Pick the role you want and train on the work it actually involves. The SOC Analyst path is available first; more roles are in development.

Choose your path

Nine roles. One way to train: doing the work.

Available first

SOC Analyst

Monitor alerts, investigate threats, respond to incidents and document your findings.

Common entry route: IT support, help desk or networking, plus security fundamentals.

Coming soon

Penetration Tester

Carry out authorised security assessments, reconnaissance, vulnerability discovery and professional reporting.

Common entry route: Networking and Linux skills, web application basics and hands-on lab practice.

Coming soon

Cloud Security

Investigate cloud misconfigurations, identity and permission issues, and security events in cloud platforms.

Common entry route: Cloud administration or DevOps experience plus security fundamentals.

Coming soon

Network Security

Analyse network traffic, firewall events, suspicious connections and infrastructure incidents.

Common entry route: Network administration or engineering, often with a networking certification.

Coming soon

Digital Forensics

Examine digital evidence, preserve it correctly and reconstruct what happened during an incident.

Common entry route: SOC or IT experience, with strong attention to detail and documentation.

Coming soon

GRC

Practise risk assessments, security controls, compliance reviews and professional documentation.

Common entry route: Audit, compliance, project or IT backgrounds, plus knowledge of security frameworks.

Coming soon

Incident Response

Lead the response to confirmed incidents: scope, contain, eradicate, recover and report.

Common entry route: Usually experienced SOC analysts moving into higher-tier response work.

Coming soon

Threat Hunting

Search proactively for attackers who have evaded existing detections, using hypotheses and data.

Common entry route: SOC or detection engineering experience and strong log analysis skills.

Coming soon

Security Engineering

Design, build and tune security controls, detections and tooling that protect an organisation.

Common entry route: Systems, cloud or software engineering backgrounds with a security focus.

How to choose your first cybersecurity role

Cybersecurity is not one job. It is a set of very different roles that share a common foundation. When you are deciding where to start, three questions help:

  • Do you prefer defending or testing? Defensive (blue team) roles such as SOC analyst and incident responder focus on detecting and responding to threats. Offensive roles such as penetration tester focus on finding weaknesses before attackers do.
  • What is your current background? Help desk and IT support experience maps naturally to SOC work. Network administrators often move into network security. Cloud and DevOps engineers are well placed for cloud security. Audit and compliance professionals often move into GRC.
  • Where are the entry-level openings? SOC analyst roles are one of the most common entry points into cybersecurity, because security operations teams need people to triage and investigate alerts around the clock.

That is why CyberOps starts with the SOC Analyst path. The investigation skills you build there — reading logs, judging evidence and documenting decisions — carry over to almost every other security role.

Why practise the role before you apply

Certifications prove you know the concepts. Employers also want evidence that you can apply them. Practising realistic tasks gives you concrete examples to discuss in interviews and helps you find out whether you actually enjoy the day-to-day work before you commit to a path.

Start with SOC

Start your cybersecurity career with the SOC Analyst path.

Investigate realistic alerts, build your skill profile and find out what you are ready for.

Start free. No experience required.