Offensive / Pentesting
Ethical hacking and red teaming. Path: networking & Linux → web/network attacks → privilege escalation & Active Directory → certification → portfolio.
Certs: eJPT (INE) → HTB CPTS / TCM PNPT → OffSec OSCP → OSEP/OSWE.
Free: TryHackMe, PortSwigger Web Security Academy, Hack The Box, OverTheWire.
Defensive / Blue Team (SOC)
Detection and response. Path: foundations → logs & SIEM → incident response & threat hunting → certification → home SOC lab.
Certs: Security+ → Microsoft SC-200 → CompTIA CySA+ / BTL1 → GIAC GCIH.
Free: LetsDefend, Blue Team Labs Online, CyberDefenders, Splunk free training.
Governance, Risk & Compliance
Security as a business function. Path: frameworks & risk → audit & compliance → certification → documentation portfolio.
Certs: ISC2 CC (often free) → Security+ → ISACA CISA / CISM → ISC2 CISSP.
Free: NIST CSF, ISC2 CC training, CIS Controls, SANS policy templates.
Cloud Security
Securing AWS, Azure and GCP. Path: cloud fundamentals → IAM & hardening → certification → secured reference deployment.
Certs: Microsoft SC-900 / AWS Cloud Practitioner → AZ-500 / AWS Security Specialty → SC-100 / CCSP.
Free: Microsoft Learn, AWS Skill Builder, flAWS/CloudGoat, AWS Well-Architected.
Application Security / DevSecOps
Securing code and pipelines. Path: OWASP Top 10 → secure code & DevSecOps → certification → bug bounty portfolio.
Certs: Burp Suite Certified Practitioner → INE eWPT → GIAC GWEB / OffSec OSWE.
Free: PortSwigger Web Security Academy, OWASP Juice Shop, OWASP Cheat Sheets.
Digital Forensics & Incident Response
Investigating breaches. Path: disk/memory/log forensics → IR & malware triage → certification → case portfolio.
Certs: Security Blue Team BTL1 → INE eCDFP → GIAC GCFA / GREM.
Free: Autopsy, Volatility, 13Cubed (YouTube), CyberDefenders.
Enable JavaScript to generate a personalised, downloadable plan tailored to your experience, time and budget.