How this roadmap works
Each stage below is a stop on your journey. Read it, do the hands-on lab, then hit Mark stage done, the map at the top updates and the traveler moves along the road. The three phases are:
- Foundations - how computers, networks, and security actually work.
- Core Security - the two halves of the field: attacking (red team) and defending (blue team).
- Get Hired - specialize, certify, build proof, and land the role.
One honest note: security rewards curiosity and persistence more than raw talent. If you enjoy taking things apart to see how they work, you will do well here.
Stage 1: Networking & Linux basics
Everything in security sits on top of networks and Linux. You cannot secure or attack what you do not understand, so this is the non-negotiable first stop.
ping, nmap, and Wireshark to see real traffic on your own network. Trace what happens when you load a website.Stage 2: Security fundamentals
Now the core ideas that everything else builds on. Learn the language and mental models of security before touching tools.
Stage 3: Offensive security (red team)
Learn to think like an attacker, ethically. This is "ethical hacking": finding weaknesses before the bad guys do. It is the most famous side of security and a great way to learn deeply.
Stage 4: Defensive security (blue team)
The other half, and where most jobs are. Defenders monitor, detect, and respond to attacks. Roles like SOC Analyst are the most common entry point into the whole field.
Stage 5: Specialize & get certified
Security is wide. Once the basics click, pick a lane and back it with a respected, beginner-friendly certification. Certs matter more in security than in most tech fields, they are often a hiring filter.
Popular starting specializations: SOC Analyst, Penetration Tester, Cloud Security, Application Security, GRC (governance, risk, compliance).
Stage 6: Build proof & land the role
The final stretch: turn skills into a job. In security, visible proof of work and a clear story beat a long resume.
Entry roles & where they lead
You do not start as an elite hacker. Most people enter through one of these and grow from there:
| Entry role | What you do | Grows into |
|---|---|---|
| SOC Analyst (Tier 1) | Monitor alerts, triage incidents, analyze logs | Incident Responder, Threat Hunter |
| Security Analyst | Assess risks, harden systems, support audits | Security Engineer, GRC Analyst |
| Junior Penetration Tester | Test apps and networks for weaknesses | Senior Pentester, Red Teamer |
| IT / Helpdesk (pivot) | Support and systems, then move into security | Any of the above |
Free places to learn
- TryHackMe - guided, beginner-friendly hands-on paths (start here).
- Hack The Box - practice machines and CTFs as you level up.
- PortSwigger Web Security Academy - the best free web-hacking course.
- LetsDefend - hands-on blue-team / SOC practice.
- roadmap.sh/cyber-security - a detailed visual skill map.
- John Hammond (YouTube) - approachable security walkthroughs.
What to do next
Security overlaps with the rest of your tech skills. These guides pair well with this roadmap:
You do not need a special degree or to be a "genius hacker". Security is a craft you build stage by stage: understand how systems work, then how they break, then how to defend them. Follow the road below in order, mark each stage done as you go, and let the map track your progress. Stuck on a concept? Tap ✦ Ask AI for a plain-English explanation.