A Career in Cyber Security: Certifications and a Roadmap for Getting Started
Cyber security isn't one job but a broad field of specialties. We cover where to start, which certifications genuinely count, and how to combine practice with theory.
From the outside cyber security looks like one job; inside, it's a broad field of very different specialties. A penetration tester's work is nothing like a SOC analyst's or a GRC consultant's. So "how do I get into cyber security?" has no single answer, but there is common ground for a good start.
Foundations first: don't rush
Cyber security is an upper floor; you can't build it without solid IT foundations. Before chasing "hacking", get comfortable in three areas:
- Networks: TCP/IP, DNS, HTTP, routing, firewalls.
- Operating systems: Linux (CLI, permissions, processes) and Windows (Active Directory, registry, event logs).
- Programming and scripting: at least one language, ideally Python. Reading code and writing small tools turns you from a tool user into a problem solver.
This foundation can take six months to a year and may feel dull, but those who skip it hit the "the tools work and I don't know why" wall. A solid base is the fastest route long term.
Choose a specialty
| Area | What it does | Suits |
|---|---|---|
| Offensive (Red Team / Pentest) | Authorised testing to find flaws | Curious, patient, asks "how does it break?" |
| Defence (Blue Team / SOC) | Detects and responds to attacks | Analytical, detail-oriented |
| Application security | Secure software development | People who like code |
| Cloud security | Securing AWS/Azure/GCP | Infrastructure and automation lovers |
| Governance & compliance (GRC) | Policy, risk, audit | Process and communication focused |
| Digital forensics (DFIR) | Post-incident investigation | Patient, methodical |
Certifications: what are they really worth?
Certifications open doors and give structure, but aren't proof of skill alone. As people who hire, we can say: a cert signals "this person built a foundation and can study with discipline". The real difference is showing it in practice.
Entry level
- CompTIA Security+: a broad foundation, good for newcomers and defence.
- TryHackMe / HackTheBox paths: free or low-cost practice before certs.
Offensive
- eJPT: practical, affordable entry to pentesting.
- OSCP: one of the most respected hands-on certs; its 24-hour practical exam measures doing, not memorising. Hard, and needs serious practice first.
Defence and SOC
- BTL1 (Blue Team Level 1): hands-on and accessible.
- Vendor security certs for the SIEM/EDR you use are valued in the field.
Senior and management
- CISSP: broad, managerial; meaningful after a few years' experience and important for security leadership.
- Cloud security certs matter in cloud-heavy careers.
CEH is well recognised and appears in some HR filters, but its mostly multiple-choice format measures practical skill less than OSCP. If your goal is hands-on pentesting, consider spending your budget on practice-focused certs first.
More important than certs: practice
- HackTheBox and TryHackMe: solve realistic machines in legal, isolated labs and write up your solutions.
- Your own lab: build a small network of VMs; an Active Directory, a web app, a monitoring stack. Building teaches as much as breaking.
- CTF competitions: fun, and they sharpen specific skills.
- Write and share: a blog reinforces learning and gives employers a live portfolio.
Only apply what you learn on systems you own or purpose-built legal labs (HTB, THM, your own VMs). Unauthorised access is a crime and ends a career before it starts. Ethics is the foundation of this profession, not an option.
A sample roadmap (about 12–18 months)
- Months 0–4 — Foundations: networks, Linux, Windows, Python; TryHackMe intro paths.
- Months 4–7 — Pick a direction: target an entry cert like Security+, BTL1 or eJPT.
- Months 7–12 — Go deeper: solve machines regularly, write them up, prepare for a hands-on cert.
- Months 12–18 — Portfolio and jobs: build a portfolio and apply for internships and entry roles.
Soft skills: where you stand out
Technical skill gets you in the door; communication often shapes your career. Finding a flaw matters, but so does explaining it to leadership. Reporting, presenting and explaining complexity simply decide between two technically equal candidates.
Conclusion
A cyber security career is a marathon and a culture of constant learning. A solid foundation, well-ordered certifications and, above all, regular practice within ethical boundaries take you a long way. If you have questions or your organisation needs security consulting, get in touch or browse our other posts.
Are your systems truly secure?
Message us today for a free initial consultation. Let's assess your needs together.