Cyber career guide What do people in cyber security actually do? “Cyber security” is not one job. It is around 40 different jobs — some deeply technical, many not technical at all. This page explains every one of them in plain English: what you do all day, who it suits, what you need to learn, and what it pays. Show me the jobs → I’m completely new No experience assumed · No jargon left unexplained · Free, always 🛡 40Jobs explained 6Areas of the field 9Entry-level starting points 0Degrees required Read this first Three things people get wrong about cyber security. If you have ever thought “this field isn’t for someone like me”, start here. Most of what puts people off is simply not true. ✓ Myth — you must be a hacker Most of the field is defence, not attack. Fewer than one in five cyber jobs involve breaking into anything. The rest are about watching, protecting, organising, explaining and fixing. Attacking systems is one small speciality — not the entrance exam. ✓ Myth — you must be able to code Several strong roles need no programming at all. Governance, risk, auditing, privacy, awareness training and vendor security are built on writing, asking good questions and being organised. Coding helps in some roles and is irrelevant in others. ✓ Myth — you need a computer science degree Most people arrive from somewhere else. Teachers, nurses, soldiers, accountants, help-desk staff, translators and shop managers all move into cyber every year. Employers care that you can demonstrate the skill — through a certificate, a home lab, or a project. Jargon buster Every confusing word on this page, translated. Cyber security has a vocabulary problem. Here is the whole thing in one screen. Come back to it any time a job card uses a word you don’t know. Blue teamThe defenders. People whose job is to protect an organisation and catch attackers. Red teamThe friendly attackers. People paid to break in legally so the real criminals can’t. SOCSecurity Operations Centre — the team (often a room, often just a chat channel) that watches for attacks 24/7. GRCGovernance, Risk & Compliance — the rules, the decisions about what to worry about, and proving you follow the law. AlertAn automatic warning that something suspicious happened. Most turn out to be harmless. Someone has to check. IncidentA real security problem that is actually happening — a hacked account, stolen data, ransomware. VulnerabilityA weakness in software or a setup that an attacker could use. Think of an unlocked window. ExploitThe specific trick or piece of code that takes advantage of that weakness. MalwareAny harmful software — viruses, ransomware, spyware, data stealers. PhishingA fake message designed to trick someone into clicking, paying or giving away a password. SIEMA giant searchable diary of everything happening on the computers. Analysts search it to investigate. EDRSecurity software installed on laptops and servers that spots and stops bad behaviour. FirewallA gate that decides which network traffic is allowed in or out. LogA record of something that happened — a login, a file opened, a website visited. IAMIdentity & Access Management — making sure the right people, and only them, can open the right doors. CloudSomeone else’s computers, rented over the internet. Amazon (AWS), Microsoft (Azure) and Google (GCP) are the big three. The pipeline / CI-CDThe automated conveyor belt that takes code from a developer’s laptop to a live product. FrameworkA published checklist of good security practice — e.g. NIST CSF, ISO 27001, SOC 2. AuditSomeone checking, with evidence, that you really do what your policies claim. Threat actorThe person or group doing the attacking — criminals, spies, activists, insiders. Start with an area The field splits into six worlds. Almost every cyber job lives in one of these. Tap one to filter the job list further down the page. 10 jobs🛡️Defensive — “Blue team”Watch for attacks, investigate them, and clean up afterwards.Like being hospital emergency staff for computers. 6 jobs🔑Offensive — “Red team”Break in legally, with permission, to find the holes first.Like a locksmith paid to test your locks. 8 jobs📋Governance, Risk & ComplianceSet the rules, decide what to worry about, prove you follow the law.Like being the safety inspector and the rulebook author. 8 jobs🛠️Engineering & CloudBuild, install and run the actual protections and systems.Like the builder who fits the locks, alarms and cameras. 5 jobs🤖Specialised fieldsNiche corners: factories, artificial intelligence, products, fraud, writing.Where cyber meets another industry entirely. 3 jobs🧭LeadershipLead the people, set direction, answer to the board.Where technical judgement meets running a team. All 40 jobs Find the one that sounds like you. Every card opens up into a full explanation. Nothing here assumes you already work in technology. 💡How to use this list: pick an area and a level below to narrow things down, then click any job title to expand it. Each one tells you what the work really involves, whether it would suit you, and the first thing to do if you want it. Filter by areaAll areasDefensive / BlueOffensive / RedGRC & RiskEngineering & CloudSpecialisedLeadership Filter by experience levelAll levelsEntry — start hereMid — 2–5 yearsSenior — 5+ yearsLeadership Pay figures are rough United States ranges for guidance only. Real salaries swing widely with city, employer size, industry and how much you can prove you can do. 🛡️Defensive / BlueEntrySOC Analyst (Tier 1)The front door. Warnings arrive all day; you decide which ones are real.▾ In plain EnglishSecurity software fires off warnings constantly — someone logged in from an odd country, a strange file appeared, an email looked fake. Almost all of them are harmless. Your job is to look at each one, work out whether it is nothing or something, and pass the real ones up. It is the single most common way people get their first cyber job. What you actually do all dayWork through a queue of alerts, oldest or most severe first.Search the log system to answer “is this normal for this person?”Message the employee: “did you really just sign in from Brazil?”Close the false alarms with a short written explanation.Escalate anything genuinely suspicious to a senior analyst. You’d enjoy this if you…Like puzzles with a clear answer, are comfortable with routine, stay calm when something looks alarming, and don’t mind shift work. Curiosity beats genius here — the best Tier 1 analysts are the ones who ask “but why?” one more time. Skills that matterReading logsHow networks workWindows & Linux basicsClear writingAttention to detailStaying calm Tools you’ll use — and what they doSplunk — searches the logsMicrosoft Sentinel — same, in the cloudEDR — laptop protection consoleWireshark — inspects network traffic Certifications that helpCompTIA Security+Google Cybersecurity CertificateBlue Team Level 1 (BTL1)CompTIA CySA+ Your first step from zeroLearn networking and Security+ level fundamentals, then practise on free hands-on platforms until you can explain a suspicious login from start to finish. Being able to talk through one real investigation out loud beats a stack of certificates with no practice. Typical US range: $55k–$80kFind related internships → 🌱Defensive / BlueEntryJunior Security AnalystA bit of everything, while you work out what you love.▾ In plain EnglishA general-purpose first security job, usually in a smaller company that doesn’t have specialists. You’ll touch monitoring, patching, user questions, small investigations and paperwork. That breadth is the point: within a year you’ll know which part of security you actually enjoy. What you actually do all dayCheck dashboards and follow up on anything odd.Chase teams to fix known weaknesses.Answer “is this email a scam?” questions from staff.Help gather evidence when an auditor asks for it.Write up simple reports for your manager. You’d enjoy this if you…Are still deciding what you want, like variety more than depth, and enjoy being useful to lots of different people. Excellent for career changers — helpfulness and organisation carry you a long way here. Skills that matterSecurity fundamentalsNetworking basicsBeing organisedExplaining things simplyWillingness to ask questions Tools you’ll use — and what they doA SIEM — log searchNessus/Qualys — finds weaknessesJira — tracks the workExcel — more than you’d expect Certifications that helpCompTIA Security+CompTIA Network+ISC2 Certified in Cybersecurity (CC) Your first step from zeroTake the free ISC2 CC or Google certificate to prove commitment, then apply widely to small and mid-sized employers. They hire on attitude far more often than big corporations do. Typical US range: $55k–$85kFind related internships → 🩹Defensive / BlueEntryVulnerability Management AnalystFind the unlocked windows, then nag until someone shuts them.▾ In plain EnglishSoftware has flaws, and new ones are published every day. A scanning tool tells you which of your company’s thousands of computers are affected. Your job is to decide which flaws genuinely matter, tell the right teams, and keep track until they are fixed. It is more coordination than hacking — and it is one of the easiest doors into the field. What you actually do all dayRun and review scans across servers, laptops and cloud systems.Sort thousands of findings into “fix this week” and “fix eventually”.Explain to an IT team why a patch can’t wait another month.Track progress and report the numbers to management.Confirm fixes actually worked by re-scanning. You’d enjoy this if you…Are patient, methodical and comfortable chasing people politely but persistently. If you have ever run a project, managed a schedule or coordinated a team, those skills transfer directly. Skills that matterPrioritising by riskReading scan outputNetworking basicsDiplomacySpreadsheets & reporting Tools you’ll use — and what they doNessus / Tenable — scans for flawsQualys — same ideaJira — tracks the fixesCVSS — scores severity Certifications that helpCompTIA Security+CompTIA CySA+Vendor training (Tenable, Qualys) Your first step from zeroInstall a free scanner at home, scan your own network, and write a one-page report explaining the top three findings to a non-technical reader. That document is a genuinely strong interview piece. Typical US range: $65k–$100kFind related internships → 🔍Defensive / BlueMidSOC Analyst (Tier 2)The one Tier 1 escalates to when it looks genuinely bad.▾ In plain EnglishWhen a junior analyst can’t explain something away, it lands with you. You dig deeper, work out how far an attacker got, decide whether to cut a machine off the network, and either resolve it or hand it to the incident response team. You also improve the alerts so the same false alarm doesn’t waste everyone’s time again. What you actually do all dayTake over escalated cases and investigate them properly.Trace what an attacker touched across several machines.Decide when to isolate a device or lock an account.Tune noisy detection rules so the queue stays sane.Mentor Tier 1 and write up lessons learned. You’d enjoy this if you…Like getting to the bottom of things, can make a decision with incomplete information, and enjoy teaching. It is the natural next step after a year or two on Tier 1. Skills that matterDeep log analysisAttack techniques (MITRE ATT&CK)Basic scriptingWindows internalsDecision-making under pressure Tools you’ll use — and what they doSIEM — deep log searchingEDR — endpoint investigationSandbox — safely opens suspicious filesSOAR — automates repeat steps Certifications that helpCompTIA CySA+GIAC GCIHBlue Team Level 2 Your first step from zeroGet hired at Tier 1 first. Then volunteer for the messy investigations nobody wants — that is genuinely how people get promoted here, faster than any certificate will do it. Typical US range: $75k–$115kFind related internships → 🚨Defensive / BlueMidIncident Responder (DFIR)The fire brigade. Called when a company is actively being attacked.▾ In plain EnglishSomething has gone wrong — ransomware is spreading, or data is leaving the building. You take charge of the technical response: stop the bleeding, work out how they got in, get the business running again, and write the honest account of what happened. High pressure, high impact, and deeply satisfying work. What you actually do all dayBetween incidents: prepare, run practice drills, improve playbooks.During one: contain affected machines, preserve evidence, find patient zero.Brief anxious executives in language they understand.Coordinate with IT, legal, communications and sometimes police.Write the report that stops it happening again. You’d enjoy this if you…Get calmer as everyone else gets more panicked. Former paramedics, military and emergency service workers do extremely well here — the technical part is learnable, the temperament is rarer. Skills that matterDigital forensicsMalware triageMemory analysisScriptingCrisis communicationReport writing Tools you’ll use — and what they doVelociraptor — collects evidence at scaleVolatility — reads computer memoryKAPE — grabs key forensic filesEDR — isolates machines remotely Certifications that helpGIAC GCIHGIAC GCFACompTIA CySA+ Your first step from zeroCome through SOC work or forensics. In the meantime, work through free DFIR challenges where you’re given a disk image and asked what happened — and practise writing the summary a manager would read. Typical US range: $85k–$135kFind related internships → 🌐Defensive / BlueMidThreat Intelligence AnalystStudy the criminals so your defenders know what’s coming.▾ In plain EnglishAttack groups have habits, favourite tools and preferred targets. You track them — through reports, criminal forums, leaked data and your own incidents — and turn that into practical advice: “this group is targeting our industry, here is exactly what to watch for.” It is closer to journalism or research than to hacking. What you actually do all dayRead widely: vendor reports, government advisories, forums, social media.Track which groups are active and what they’re using.Turn raw information into short, useful briefings for your team.Feed technical indicators into the detection tools.Answer “should we be worried about this news story?” from leadership. You’d enjoy this if you…Love research and writing, follow geopolitics, and enjoy connecting scattered dots into a story. Journalists, historians, librarians and intelligence-background people transition into this role remarkably well. Skills that matterOpen-source research (OSINT)Analytical writingMITRE ATT&CKSource evaluationLanguages are a bonus Tools you’ll use — and what they doMISP — shares threat dataVirusTotal — checks suspicious filesMaltego — maps connections visuallyShodan — searches exposed devices Certifications that helpGIAC GCTICompTIA Security+Free intelligence-writing courses Your first step from zeroStart a public blog or newsletter summarising one threat report each week in plain English. Hiring managers in this field genuinely read those — it demonstrates the exact skill they need. Typical US range: $80k–$130kFind related internships → ⚙️Defensive / BlueMidDetection EngineerWrite the rules that spot attacks automatically, so humans don’t have to.▾ In plain EnglishEvery alert an analyst sees came from a rule somebody wrote. You are that somebody. You study how attacks work, then build the logic that catches them — and just as importantly, tune out the noise so your colleagues aren’t drowning in false alarms. Part security, part software engineering. What you actually do all dayRead about a new attack technique, then build a rule to catch it.Test the rule by simulating the attack safely.Measure how many false alarms it produces and refine it.Automate repetitive analyst steps so cases close faster.Keep detection code in version control like real software. You’d enjoy this if you…Like building things that keep working after you go home, enjoy precision, and get frustrated by repetitive manual work. If you have ever automated a boring task, this is your instinct exactly. Skills that matterWriting detection rulesPythonSigma & YARACloud & system loggingTesting mindset Tools you’ll use — and what they doSplunk / Sentinel / Elastic — where rules runSigma — portable rule formatAtomic Red Team — safely simulates attacksGit — version control Certifications that helpGIAC GCDACompTIA Security+Cloud platform certs Your first step from zeroBuild a small home lab, generate suspicious activity on purpose, and write your own rule to catch it. Publish the rule publicly. That single project explains your capability faster than any CV bullet point. Typical US range: $95k–$150kFind related internships → 🔎Defensive / BlueMidDigital Forensics AnalystReconstruct exactly what happened on a device — and prove it.▾ In plain EnglishComputers remember far more than people realise. You recover deleted files, read what was in memory, rebuild timelines of activity, and produce findings solid enough to stand up in court or an employment tribunal. Careful, patient, evidence-driven work — and often quite emotionally weighty. What you actually do all dayTake a forensic copy of a device without altering the original.Recover deleted or hidden files and reconstruct a timeline.Document every action so the evidence stays admissible.Write findings clearly enough for lawyers and non-technical readers.Sometimes explain your work in a legal setting. You’d enjoy this if you…Are extremely meticulous, comfortable with slow deliberate work, and like the idea that your findings carry real consequences for real people. Legal, audit and laboratory backgrounds fit naturally. Skills that matterDisk & memory forensicsFile systemsChain of custodyTimeline buildingPrecise documentation Tools you’ll use — and what they doAutopsy — free forensic suiteFTK / X-Ways — commercial equivalentsVolatility — memory analysisWrite blockers — protect originals Certifications that helpGIAC GCFEGIAC GCFAEC-Council CHFI Your first step from zeroDownload free practice disk images, examine them with Autopsy, and write a full report for each. A portfolio of three careful reports is a legitimate route into this speciality. Typical US range: $80k–$130kFind related internships → 🔭Defensive / BlueSeniorThreat HunterAssume the alarms missed something. Go looking anyway.▾ In plain EnglishAlerts only catch what someone already thought to look for. A threat hunter starts from a hunch — “if an attacker were hiding here, what trace would they leave?” — and searches the data to prove or disprove it. Most hunts find nothing, which is a good result. The ones that find something usually find something serious. What you actually do all dayForm a specific hypothesis about attacker behaviour.Query enormous volumes of log and endpoint data to test it.Investigate anything unexplained, however small.Turn every successful hunt into a permanent detection rule.Document the hunt so it can be repeated by others. You’d enjoy this if you…Are self-directed, deeply curious, and content working on something that may yield nothing for weeks. Research, data-analysis and investigative backgrounds fit this beautifully. Skills that matterAttacker techniquesData analysis at scaleScripting & queriesDetection engineeringHypothesis thinking Tools you’ll use — and what they doSIEM — the searchable haystackEDR — endpoint detailJupyter notebooks — data analysisSigma — turns hunts into rules Certifications that helpGIAC GCTIGIAC GCFAGIAC GDAT Your first step from zeroThis is not an entry role. Spend a few years in a SOC or detection engineering first, then start proposing hunts to your manager. Nobody stops you doing this before it’s your job title. Typical US range: $110k–$160kFind related internships → 🧬Defensive / BlueSeniorMalware Analyst / Reverse EngineerTake the harmful software apart and work out exactly what it does.▾ In plain EnglishA suspicious program lands on a machine. Nobody knows what it does. You pull it apart — running it in a sealed environment, then reading its underlying instructions — until you can say precisely what it steals, where it sends data, and how to detect it everywhere else. One of the most technically demanding jobs in the field. What you actually do all dayRun the sample in an isolated lab and record its behaviour.Read its machine-level code to understand hidden functions.Defeat the tricks it uses to avoid being analysed.Extract indicators so defenders can find it elsewhere.Publish a technical write-up of the findings. You’d enjoy this if you…Are stubborn in the best way, comfortable with very low-level detail, and enjoy problems that take days rather than hours. Strong programming interest is essentially required. Skills that matterAssembly languageC / C++Reverse engineeringDebuggingWindows internalsPersistence Tools you’ll use — and what they doGhidra — free code disassemblerIDA Pro — industry standardx64dbg — steps through code liveSandboxes — safe detonation Certifications that helpGIAC GREMFree Ghidra & RE coursesProgramming background Your first step from zeroLearn C and how computer memory works, then follow free reverse-engineering courses using safe practice samples in a virtual machine. Expect this to take a couple of years — and never analyse real malware outside an isolated lab. Typical US range: $110k–$170kFind related internships → 🧩Offensive / RedEntryJunior Security TesterYour first paid seat on the attacking side.▾ In plain EnglishYou run the well-understood tests on websites and networks under supervision — the checks that come up in almost every job — while a senior tester handles the creative parts. Much of the role is careful note-taking and clear reporting, because a finding nobody understands never gets fixed. What you actually do all dayMap out what a client actually has exposed to the internet.Run standard checks against websites and applications.Confirm findings are real, not scanner noise.Write clear, reproducible descriptions of each issue.Shadow senior testers and learn their thinking. You’d enjoy this if you…Like taking things apart to see how they work, are happy being wrong repeatedly on the way to being right, and can accept that documentation is half the job. Skills that matterLinux comfortHow websites workNetworkingBasic scriptingClear written EnglishEthics & discipline Tools you’ll use — and what they doBurp Suite — inspects web trafficNmap — finds what’s runningOWASP ZAP — free web testerKali Linux — toolkit OS Certifications that helpeJPTCompTIA PenTest+PNPT Your first step from zeroWork through free hands-on hacking labs until the basics are automatic, then take eJPT. Only ever practise on systems you own or platforms that invite testing — unauthorised testing is a crime, not a shortcut. Typical US range: $60k–$95kFind related internships → 🔑Offensive / RedMidPenetration TesterPaid to break in, with a signed contract saying you may.▾ In plain EnglishA company hires you to attack their systems for a couple of weeks and then tell them everything you found. You chain small weaknesses into serious ones, prove the impact, and hand over a report explaining how to close each gap. Genuinely creative work — and the report matters more than the hack. What you actually do all dayAgree exactly what is in scope and what is off-limits.Investigate the target thoroughly before touching anything.Find a foothold, then work out how far it can be pushed.Capture evidence carefully at every step.Write and present the report, then answer follow-up questions. You’d enjoy this if you…Are relentlessly curious, enjoy variety (a new client every fortnight), and can explain a complex failure kindly to the person who caused it. Ego makes people bad at this job. Skills that matterWeb application attacksNetwork exploitationPrivilege escalationActive DirectoryScriptingReport writing Tools you’ll use — and what they doBurp Suite — web testingMetasploit — exploit frameworkBloodHound — maps Windows privilege pathsNmap — discovery Certifications that helpOSCPPNPTCompTIA PenTest+CEH Your first step from zeroPractise constantly on legal platforms, document each machine you solve as though it were a client report, then work towards OSCP. The reporting habit is what separates people who get hired from people who just enjoy the labs. Typical US range: $90k–$150kFind related internships → 🧵Offensive / RedMidApplication Security EngineerHelp developers write safer code, instead of finding the flaws too late.▾ In plain EnglishYou sit alongside software teams. You review designs before they’re built, check code for dangerous patterns, run automated security testing as part of the build process, and coach developers so the same mistake doesn’t reappear. Half security specialist, half trusted teammate. What you actually do all dayReview a proposed feature and ask “how could this be abused?”Read code changes for security problems.Configure automated scanners in the build pipeline.Triage findings so developers only see the real ones.Run short training sessions for engineering teams. You’d enjoy this if you…Already write software, or want to, and prefer preventing problems to responding to them. Developers who drift into security land here more often than any other role. Skills that matterAt least one programming languageOWASP Top 10Threat modellingCode reviewAPIsTeaching & patience Tools you’ll use — and what they doSemgrep — scans source codeSnyk — checks third-party librariesBurp Suite — tests running appsOWASP ZAP — free alternative Certifications that helpOSWECSSLPGIAC GWAPT Your first step from zeroLearn to build a simple web application yourself. Then deliberately introduce the classic vulnerabilities, exploit them, and fix them. Understanding both sides of that loop is the whole job. Typical US range: $110k–$165kFind related internships → 🥷Offensive / RedSeniorRed Team OperatorImitate a real criminal group, quietly, over weeks — and see who notices.▾ In plain EnglishWhere a penetration test asks “what weaknesses exist?”, a red team engagement asks “could we be robbed without anyone realising?” You pick a goal — reach the payroll system, say — and pursue it as stealthily as a genuine attacker would, testing the defenders as much as the technology. What you actually do all dayStudy how a specific real-world attack group operates.Build tooling and infrastructure that won’t be recognised.Gain access slowly and move without triggering alarms.Record precisely what the defenders did and didn’t spot.Debrief the blue team so they learn from every step. You’d enjoy this if you…Think several moves ahead, have real patience, and understand that the goal is making defenders better — not humiliating them. Poor communicators fail in this role regardless of technical skill. Skills that matterAdversary emulationEvading detectionActive Directory attacksCommand-and-controlCustom tool developmentOperational discipline Tools you’ll use — and what they doCobalt Strike — commercial C2 platformSliver / Mythic — open-source equivalentsBloodHound — privilege path mappingCustom code Certifications that helpCRTOOSEPOSCP first Your first step from zeroBecome a strong penetration tester first — there is no shortcut. Then study detection from the defensive side, because you cannot evade something you don’t understand. Typical US range: $120k–$180kFind related internships → 🐞Offensive / RedSeniorVulnerability ResearcherFind flaws in software that nobody in the world has found yet.▾ In plain EnglishRather than using known weaknesses, you discover brand-new ones in widely used products — browsers, phones, routers, industrial equipment. You then report them responsibly so they get fixed before criminals find them. Many researchers earn substantial additional income through bug bounty programmes. What you actually do all dayChoose a target product and learn how it works internally.Throw enormous volumes of malformed input at it to force crashes.Investigate each crash to see whether it is genuinely exploitable.Report findings responsibly to the vendor.Publish once a fix is available. You’d enjoy this if you…Can work alone on something with no guaranteed result, tolerate long dry spells, and find deep technical rabbit holes genuinely enjoyable rather than exhausting. Skills that matterReverse engineeringFuzzingMemory-safety conceptsC / C++Source code reviewExtreme patience Tools you’ll use — and what they doGhidra / IDA — disassemblyAFL++ — automated fuzzingDebuggers — inspect crashesBurp — for web targets Certifications that helpOSWEOSEDReputation matters more than certs Your first step from zeroStart with bug bounty programmes on web applications, which need far less low-level knowledge. Your public track record of accepted reports is your qualification in this field. Typical US range: $110k–$180k+ plus bountiesFind related internships → 💥Offensive / RedSeniorExploit DeveloperTurn a theoretical flaw into something that reliably works.▾ In plain EnglishKnowing software has a bug is not the same as being able to use it. Exploit developers do the second part — working at the level of memory addresses and processor instructions, defeating the protections modern systems build in. It is one of the smallest and most specialised job markets in security. What you actually do all dayAnalyse a crash to understand exactly what went wrong in memory.Work out how to steer that failure into controlled behaviour.Defeat modern operating-system protections.Make the result reliable across versions and machines.Document it thoroughly for the team that will use it. You’d enjoy this if you…Genuinely enjoy computer architecture, can spend a fortnight on one problem without losing heart, and are drawn to constraints rather than frustrated by them. Skills that matterAssembly languageCMemory corruptionBypassing mitigationsOperating-system internalsDebugging Tools you’ll use — and what they doDebuggers — step through executionGhidra / IDA — static analysispwntools — exploit scripting Certifications that helpOSEDOSEEComputer-science depth Your first step from zeroLearn C and assembly properly, then work through free binary-exploitation courses and capture-the-flag challenges in order. Expect years, not months — and only pursue it if the low-level detail genuinely delights you. Typical US range: $130k–$200kFind related internships → 📋GRC & RiskEntryGRC AnalystWrite the rules, check they’re followed, prove it to outsiders.▾ In plain EnglishEvery organisation needs written security rules, a way of deciding which risks matter, and evidence for customers and regulators that it takes security seriously. That is your job. Almost no coding involved — it runs on clear writing, good questions and organisation. It is the single best entry point for people coming from a non-technical background. What you actually do all dayWrite and update security policies people can actually follow.Interview teams about how they really work, not how the document says.Record risks in a register and track what’s being done about them.Gather evidence for certifications like ISO 27001 or SOC 2.Answer long security questionnaires from customers. You’d enjoy this if you…Write clearly, enjoy structure, and are comfortable asking people to explain their work. Backgrounds in law, accounting, project management, teaching, healthcare administration and public service transfer exceptionally well. Skills that matterClear writingFrameworks (NIST, ISO 27001)Risk assessmentInterviewing peopleSpreadsheetsFollow-through Tools you’ll use — and what they doVanta / Drata — automate compliance evidenceExcel — risk registersJira — tracks remediationSharePoint — policy storage Certifications that helpCompTIA Security+ISC2 CCISACA IT Risk FundamentalsISO 27001 Lead Implementer Your first step from zeroRead the NIST Cybersecurity Framework end to end — it’s free and readable. Then write a complete set of security policies for an imaginary small company. That document set is a superb portfolio piece and costs nothing but time. Typical US range: $65k–$105kFind related internships → 🎓GRC & RiskEntrySecurity Awareness SpecialistTeach thousands of colleagues to spot the scam before they click.▾ In plain EnglishMost successful attacks start with a person being tricked. You run the programme that changes that — training, simulated phishing emails, posters, videos, newsletters and culture work. It is a communication and teaching job that happens to live inside a security team. What you actually do all dayDesign training that people don’t immediately resent.Send safe fake phishing emails and measure who clicks.Coach, never shame, the people who fall for them.Create posters, short videos and internal campaigns.Report on whether behaviour is actually improving. You’d enjoy this if you…Are a natural explainer, creative, and patient with people who find technology stressful. Teachers, trainers, marketers and communications professionals are ideal candidates — this is one of the friendliest doors into cyber. Skills that matterCommunicationTraining designContent creationEmpathyBasic security knowledgeMeasuring impact Tools you’ll use — and what they doKnowBe4 — training & phishing simulationProofpoint — similar platformCanva — visual contentAn LMS — delivers courses Certifications that helpCompTIA Security+SANS Security Awareness trainingAny teaching qualification Your first step from zeroMake a five-minute video or one-page guide explaining phishing to someone’s grandparent. If it’s genuinely clear and warm, you have already demonstrated the core skill of this job. Typical US range: $60k–$100kFind related internships → 🤝GRC & RiskEntryThird-Party / Vendor Risk AnalystYour company is only as safe as the suppliers it trusts.▾ In plain EnglishModern organisations rely on hundreds of outside suppliers who hold their data. You assess how secure each one is before a contract is signed, and keep watching afterwards. It is investigative, conversational, deadline-driven work — and one of the fastest-growing entry points in the whole field. What you actually do all daySend security questionnaires to prospective suppliers and read the answers critically.Review their audit reports and certificates for real substance.Check external security ratings and flag concerning changes.Negotiate security wording into contracts alongside legal teams.Re-assess key suppliers on a schedule and after any breach news. You’d enjoy this if you…Ask good follow-up questions, notice when an answer dodges the point, and can be firm without being difficult. Procurement, insurance, audit and customer-service backgrounds fit this naturally. Skills that matterReading audit reportsFrameworks (SOC 2, ISO 27001)Questioning & interviewingContracts basicsOrganisation at volume Tools you’ll use — and what they doBitSight / SecurityScorecard — outside-in security ratingsOneTrust — assessment workflowExcel — tracking at scale Certifications that helpCompTIA Security+ISACA CRISCISO 27001 foundations Your first step from zeroLearn what a SOC 2 report contains and what its exceptions mean, then practise summarising a public one in a single page. That skill alone makes you immediately useful to a vendor risk team. Typical US range: $65k–$105kFind related internships → ✅GRC & RiskMidIT Auditor / Compliance AnalystDon’t tell me it’s secure. Show me the evidence.▾ In plain EnglishPolicies mean nothing if nobody follows them. Auditors test whether the controls a company claims to have really exist and really work — by sampling records, watching processes and demanding proof. The findings feed certifications, regulators and the board. What you actually do all dayPlan which controls to test and how you’ll test them.Request evidence and sample records from teams.Interview staff about how a process really runs.Document findings factually, without exaggeration.Agree realistic remediation dates and follow up. You’d enjoy this if you…Are detail-obsessed, comfortable being the person who says “that isn’t sufficient evidence”, and enjoy seeing how an entire organisation actually functions. Accountants and quality-assurance professionals adapt quickly. Skills that matterControl testingSOC 2 / ISO 27001 / PCI DSSEvidence samplingPrecise writingIndependence & integrity Tools you’ll use — and what they doGRC platforms — track controls & findingsExcel — sampling and testingEvidence repositories Certifications that helpISACA CISAISACA CRISCISO 27001 Lead Auditor Your first step from zeroStart in GRC or internal audit, then work towards CISA — it is the qualification hiring managers in this field look for first, and it opens doors internationally. Typical US range: $70k–$115kFind related internships → ⚖️GRC & RiskMidRisk AnalystAnswer the hardest question in security: what should we worry about first?▾ In plain EnglishNo organisation can fix everything, so someone must decide what gets attention and budget. You identify what could go wrong, estimate how likely and how damaging it would be, and translate that into business language leaders can act on. Technical issues in, financial decisions out. What you actually do all dayIdentify risks by talking to technical and business teams.Estimate likelihood and potential financial impact.Maintain the risk register and keep it honest.Present the top risks to leadership with recommended options.Track whether agreed actions actually happen. You’d enjoy this if you…Enjoy structured thinking with numbers, are comfortable with uncertainty, and can hold your position in a room full of senior people. Finance, insurance and consulting backgrounds map cleanly onto this role. Skills that matterRisk frameworksQuantitative estimationBusiness communicationPrioritisationPresenting to executives Tools you’ll use — and what they doFAIR — puts money values on riskGRC platforms — risk registersExcel — modelling Certifications that helpISACA CRISCOpen FAIRISACA CISM later Your first step from zeroTake one real risk — a laptop being stolen, say — and write a full one-page analysis: what could happen, how likely, what it would cost, and three options with prices. That is the job in miniature. Typical US range: $75k–$120kFind related internships → 🔏GRC & RiskMidPrivacy / Data Protection AnalystLook after other people’s personal information as the law requires.▾ In plain EnglishSecurity asks “is the data safe?” Privacy asks “should we have it at all?” You map where personal data lives, make sure it is collected lawfully, handle requests from people who want their data deleted, and keep the organisation on the right side of laws like GDPR and CCPA. Part legal, part technical, entirely people-focused. What you actually do all dayMap what personal data the company holds and why.Assess new projects for privacy impact before launch.Handle requests from individuals about their own data.Review supplier contracts for data-handling terms.Train teams on what they may and may not do with data. You’d enjoy this if you…Enjoy reading regulation and translating it into practical guidance, and care about people’s rights over their own information. Legal, compliance and policy backgrounds fit this immediately. Skills that matterGDPR / CCPA knowledgeData mappingImpact assessmentsPolicy writingDiplomacy Tools you’ll use — and what they doOneTrust — privacy management platformData discovery tools — find personal dataRecords of processing spreadsheets Certifications that helpIAPP CIPP/E or CIPP/USIAPP CIPMIAPP CIPT Your first step from zeroRead a plain-English GDPR guide, then write a privacy notice for a fictional small business. Follow it with the CIPP certification — it is well recognised and does not require a technical background. Typical US range: $80k–$130kFind related internships → 🧰GRC & RiskMidCyber Security ConsultantA different company, a different problem, every few weeks.▾ In plain EnglishConsultants are hired to assess, advise and sometimes build. One month you might review a hospital’s security programme; the next, help a startup prepare for certification. You learn very fast because you see how dozens of organisations do things — well and badly. What you actually do all dayMeet clients and work out what they actually need.Assess their current position against a recognised framework.Write recommendations that are realistic for their budget.Present findings to people who may not want to hear them.Sometimes stay on to help implement the fixes. You’d enjoy this if you…Like variety, present well, and adapt quickly to unfamiliar industries. Be aware it often involves travel and firm deadlines — and that likeability genuinely matters as much as knowledge. Skills that matterBroad security knowledgeFrameworksPresentingReport writingAdaptabilityClient relationships Tools you’ll use — and what they doVaries by clientAssessment templatesPowerPoint — genuinely central Certifications that helpCompTIA Security+ISC2 CISSPFramework-specific certs Your first step from zeroConsultancies hire graduates and career changers more openly than most employers and train them properly. Look at the large professional-services firms and specialist boutiques alike. Typical US range: $85k–$150kFind related internships → 🏗️GRC & RiskSeniorBusiness Continuity & Resilience ManagerPlan for the day everything stops — before it stops.▾ In plain EnglishIf ransomware locked every system tomorrow, could the organisation still serve customers? You work out which activities absolutely cannot stop, how quickly they must be restored, and what has to be in place to make that possible. Then you run the rehearsals that prove the plan works. What you actually do all dayIdentify the processes the business genuinely cannot live without.Agree how long each can be down before serious harm occurs.Build recovery plans with IT and operations teams.Run realistic exercises — including with executives.Fix the gaps every exercise exposes. You’d enjoy this if you…Think in scenarios, plan well, and can persuade busy senior people to take a rehearsal seriously. Operations, logistics, emergency planning and military backgrounds fit strongly. Skills that matterBusiness impact analysisScenario planningFacilitationCrisis coordinationDocumentation Tools you’ll use — and what they doContinuity planning platformsBackup & recovery systemsExercise scripts & playbooks Certifications that helpISO 22301 trainingCBCPISACA CRISC Your first step from zeroCome through GRC, risk or operations. Practise by writing a recovery plan for a small organisation you know, then walking someone through it as a tabletop exercise. Typical US range: $100k–$150kFind related internships → 🛠️Engineering & CloudEntryIT Security TechnicianKeep the everyday protections running properly.▾ In plain EnglishSomeone has to make sure every laptop has protection installed, accounts are created and removed correctly, updates are applied, and the security tools are actually switched on. That is this role. It sits between the IT help desk and the security team and is a very common way in for people already working in IT support. What you actually do all dayDeploy and check security software on company devices.Create, change and remove user accounts and permissions.Apply updates and confirm they installed successfully.Help staff with multi-factor authentication and lockouts.Escalate anything that looks like a real attack. You’d enjoy this if you…Like hands-on practical work with visible results, and enjoy helping colleagues directly. If you have done any help-desk or technical support, you are already most of the way here. Skills that matterWindows & macOS administrationBasic networkingAccount managementPatchingCustomer service Tools you’ll use — and what they doIntune / Jamf — manage devices remotelyActive Directory — user accountsEDR consoles — endpoint protectionTicketing systems Certifications that helpCompTIA A+CompTIA Network+CompTIA Security+Microsoft SC-900 Your first step from zeroGet any IT support role, do it well, then volunteer for every security-related task on the team. Internal moves into security are far more common than people expect. Typical US range: $50k–$80kFind related internships → 🔧Engineering & CloudMidSecurity EngineerBuild and run the protections everyone else relies on.▾ In plain EnglishAnalysts use security tools; engineers choose, install, configure and maintain them. You design how identity works, how devices are protected, how logs get collected, and how it all fits together — then automate as much of it as possible. Broadly technical and consistently in demand. What you actually do all dayEvaluate and deploy security tools across the organisation.Harden servers and cloud systems against known weaknesses.Write scripts to automate repetitive security tasks.Fix things when a control breaks something else.Support analysts by getting them better data. You’d enjoy this if you…Like building and fixing, enjoy owning systems end to end, and don’t mind being the person called when a protection blocks something important. Systems administrators move into this role naturally. Skills that matterNetworkingLinux & Windows administrationPython or PowerShellIdentity managementCloud basicsAutomation Tools you’ll use — and what they doSIEM — log platform you maintainEDR — endpoint protectionFirewalls — network gatesTerraform — builds infrastructure from code Certifications that helpCompTIA Security+Cisco CCNAAWS or Azure associate certs Your first step from zeroBuild a home lab with a few virtual machines, install free security tools, break it, fix it. Employers hiring engineers want to hear about things you have built, not courses you have watched. Typical US range: $100k–$155kFind related internships → 🌐Engineering & CloudMidNetwork Security EngineerGuard the roads the data travels on.▾ In plain EnglishEvery message between computers travels a route. You design and defend those routes — deciding what may talk to what, blocking the rest, separating sensitive systems from ordinary ones, and inspecting traffic for signs of attack. Deep networking knowledge is the foundation. What you actually do all dayWrite and review firewall rules, and remove the outdated ones.Segment the network so a breach in one area can’t spread.Manage remote access and VPN systems.Investigate unusual traffic patterns.Plan network changes without breaking the business. You’d enjoy this if you…Enjoy diagrams, logical structure and precision, and like understanding how information physically moves. Network administrators can move into this role with very little retraining. Skills that matterTCP/IP deeplyRouting & switchingFirewall administrationVPNsNetwork segmentationTraffic analysis Tools you’ll use — and what they doPalo Alto / Fortinet / Cisco — firewallsZeek — analyses network trafficWireshark — packet inspection Certifications that helpCisco CCNA then CCNP SecurityPalo Alto PCNSECompTIA Security+ Your first step from zeroLearn networking properly — CCNA level — and build a virtual network at home with a free firewall. Networking knowledge never goes out of date, whatever else changes. Typical US range: $95k–$150kFind related internships → 🪪Engineering & CloudMidIdentity & Access (IAM) EngineerDecide who holds which keys — for every door, everywhere.▾ In plain EnglishStolen passwords cause more breaches than anything else, which makes identity the most important control most organisations have. You run the systems that verify people are who they claim to be, grant exactly the access they need, and remove it the day they leave. What you actually do all dayConnect applications to single sign-on so people log in once.Roll out and troubleshoot multi-factor authentication.Design what each job role should and shouldn’t be able to access.Automate joiners, movers and leavers so nothing is forgotten.Review who has powerful access and take back what isn’t needed. You’d enjoy this if you…Like clean logical structures, care about getting details exactly right, and enjoy work with obvious, measurable security value. Demand for this skill currently outstrips supply. Skills that matterSingle sign-on (SAML, OIDC)Multi-factor authenticationDirectory servicesLeast privilege designScriptingCloud permissions Tools you’ll use — and what they doOkta / Entra ID — identity platformsActive Directory — traditional user storeSailPoint — access reviews & joiner-leaver Certifications that helpOkta certificationsMicrosoft SC-300CompTIA Security+ Your first step from zeroSet up a free identity provider trial and connect a couple of sample applications to it. Understanding how single sign-on actually works puts you ahead of most candidates immediately. Typical US range: $100k–$160kFind related internships → ☁️Engineering & CloudSeniorCloud Security EngineerSecure the rented computers the whole company now runs on.▾ In plain EnglishAlmost everything now runs in Amazon, Microsoft or Google’s data centres, where a single wrong setting can expose millions of records to the internet. You design safe defaults, hunt for dangerous misconfigurations, and build automatic guardrails so engineering teams can move fast without opening holes. What you actually do all dayReview cloud accounts for risky settings and excessive permissions.Write infrastructure code that is secure by default.Build automated checks that block unsafe changes before deployment.Secure containers and the systems that orchestrate them.Advise development teams designing new cloud services. You’d enjoy this if you…Like automation, prefer fixing a problem class rather than an instance, and enjoy a fast-moving field. This is currently one of the strongest areas of demand in all of security. Skills that matterAWS, Azure or GCP in depthCloud permissionsTerraformContainers & KubernetesPythonNetworking Tools you’ll use — and what they doWiz / Prisma — scan cloud for riskTerraform — infrastructure as codeAWS Security Hub — native findingsKubernetes Certifications that helpAWS Security SpecialtyMicrosoft AZ-500ISC2 CCSPKubernetes CKS Your first step from zeroOpen a free-tier cloud account, build something small, then deliberately misconfigure it and find the problem with free scanning tools. Cloud skills are learnable at home for almost nothing. Typical US range: $120k–$175kFind related internships → ♾️Engineering & CloudSeniorDevSecOps EngineerPut the safety checks on the conveyor belt, not at the end of it.▾ In plain EnglishSoftware goes from a developer’s laptop to customers through an automated pipeline. You add security checks into that pipeline so problems are caught in minutes rather than months — without slowing developers down so much that they route around you. Diplomacy is a real part of the job. What you actually do all dayAdd code, dependency and container scanning to build pipelines.Set sensible thresholds so builds fail only for real problems.Manage secrets so passwords never end up in source code.Build secure base images and templates teams can reuse.Work with developers to make the secure path the easy path. You’d enjoy this if you…Have a software or operations background, like tooling and automation, and enjoy improving how other people work rather than doing the work yourself. Skills that matterCI/CD pipelinesInfrastructure as codeContainersScriptingCloud platformsDeveloper empathy Tools you’ll use — and what they doGitHub Actions / Jenkins — the pipelineSnyk — dependency scanningTrivy — container scanningVault — secrets storage Certifications that helpCloud platform certsKubernetes CKSCompTIA Security+ Your first step from zeroBuild a small project with a public code repository, add an automated pipeline, then add free security scanning to it. That repository becomes your interview demonstration. Typical US range: $120k–$175kFind related internships → 🏛️Engineering & CloudSeniorSecurity ArchitectDesign how security works before anything gets built.▾ In plain EnglishArchitects work on paper and in meetings before work starts. You decide how systems should be structured, set the standards everyone builds to, review major designs, and make the trade-offs between security, cost and speed explicit rather than accidental. Wide experience is essential. What you actually do all dayReview proposed system designs and identify weaknesses early.Set organisation-wide security standards and patterns.Run threat modelling sessions with engineering teams.Choose between competing technologies and justify the choice.Mentor engineers and translate strategy into design. You’d enjoy this if you…Enjoy the big picture, communicate exceptionally well in writing, and are comfortable making decisions whose consequences appear years later. Rarely a first security job — it is built on experience. Skills that matterSystem architectureThreat modellingCloud & network depthStandards & frameworksInfluence without authorityWriting Tools you’ll use — and what they doDiagramming tools — the core artefactReference architecturesCloud consoles Certifications that helpISC2 CISSPISC2 CCSPSABSACloud architect certs Your first step from zeroSpend several years as an engineer first. Practise now by drawing the architecture of any system you use and marking where it could be attacked — that habit is the whole discipline in miniature. Typical US range: $140k–$200kFind related internships → 🔐Engineering & CloudSeniorCryptography EngineerWork on the mathematics that keeps secrets secret.▾ In plain EnglishEncryption is what makes online banking, private messaging and stored passwords safe. Cryptography engineers choose, implement and manage it correctly — which is far harder than it sounds, because almost all real-world failures come from good algorithms used badly. A small, specialised, well-paid field. What you actually do all daySelect the right cryptographic approach for a given problem.Review code for subtle but fatal implementation mistakes.Design how encryption keys are created, stored and rotated.Prepare systems for post-quantum cryptography.Advise product teams who want to invent their own — and stop them. You’d enjoy this if you…Enjoy mathematics for its own sake and precision under pressure. This is one of the few security roles where a relevant degree genuinely helps. Skills that matterApplied cryptographyMathematicsSecure codingProtocol designKey management Tools you’ll use — and what they doOpenSSL — core crypto libraryHSMs — hardware key storageCloud key management services Certifications that helpFew certifications existDegree or research background Your first step from zeroWork through a free applied-cryptography course and the classic online crypto challenge sets. If you find them fascinating rather than frustrating, this path may genuinely be for you. Typical US range: $130k–$200kFind related internships → ✍️SpecialisedEntrySecurity Technical WriterTurn expert knowledge into something everyone can follow.▾ In plain EnglishSecurity teams produce policies, procedures, reports, customer documentation and training that must be understood by ordinary people. Most engineers write these badly. If you write well and are willing to learn the subject, this is a real, paid, in-demand job — and an unusually gentle entrance to the industry. What you actually do all dayInterview engineers and turn their explanations into clear documents.Write and maintain policies, standards and step-by-step procedures.Edit incident reports so non-technical readers understand them.Build documentation that customers and auditors will read.Keep everything current as systems change. You’d enjoy this if you…Write well, ask good questions, and enjoy making complicated things simple. Journalists, editors, teachers and translators are natural fits — the security knowledge can be learned on the job. Skills that matterExcellent writingInterviewing expertsStructure & editingCuriosity about technologyVersion control basics Tools you’ll use — and what they doConfluence / SharePoint — document homesMarkdown & Git — docs-as-codeDiagram tools Certifications that helpCompTIA Security+ for credibilityISC2 CCTechnical writing courses Your first step from zeroTake three complicated security topics and write a clear one-page explanation of each for a complete beginner. Publish them. That portfolio is exactly what a hiring manager needs to see. Typical US range: $60k–$105kFind related internships → 📦SpecialisedMidProduct Security EngineerMake sure what your company sells is safe for its customers.▾ In plain EnglishIf your employer builds and sells software or devices, someone must ensure those products are secure for the people who buy them. You review features before launch, test them, handle reports from outside researchers, and coordinate fixes and disclosures. What you actually do all dayThreat model new product features while they’re still designs.Test releases before customers get them.Run the process for outside researchers reporting bugs.Coordinate fixes and honest customer communication.Answer security questions from prospective buyers. You’d enjoy this if you…Like being close to a product people actually use, and can balance security against launch deadlines without becoming the department of no. Skills that matterApplication securityThreat modellingCode reviewCloudCoordination & communication Tools you’ll use — and what they doBurp Suite — product testingSemgrep — code scanningBug bounty platforms Certifications that helpOSWECSSLPCloud certs Your first step from zeroCome from application security or software development. Participating in public bug bounty programmes gives you the reporting and coordination experience this role runs on. Typical US range: $120k–$175kFind related internships → 🎯SpecialisedMidFraud & Trust and Safety AnalystStop the people abusing the platform, not just the ones hacking it.▾ In plain EnglishBanks, marketplaces, gaming and social platforms face a different threat: real accounts used dishonestly. Stolen cards, fake sellers, coordinated scams, harassment campaigns. You spot the patterns, build rules to block them, and investigate the cases the rules miss. What you actually do all dayInvestigate suspicious accounts and transactions.Spot patterns linking apparently unrelated bad actors.Build and tune rules that block abuse automatically.Balance blocking criminals against inconveniencing honest users.Work with legal, support and sometimes law enforcement. You’d enjoy this if you…Like investigation with a human element and enjoy pattern-spotting in data. Banking, insurance investigation, customer support and content moderation backgrounds transfer well. Note that some areas of this work involve distressing content. Skills that matterData analysis & SQLPattern recognitionInvestigationRule writingJudgement & fairness Tools you’ll use — and what they doSQL — queries the dataFraud rules enginesCase management systemsLink analysis tools Certifications that helpCFE (Certified Fraud Examiner)CompTIA Security+SQL & analytics courses Your first step from zeroLearn SQL — it is the single most useful skill here and can be learned free in a few weeks. Then look at trust and safety or fraud openings at any online platform. Typical US range: $70k–$120kFind related internships → 🏭SpecialisedSeniorOT / Industrial Systems Security SpecialistProtect the systems that run factories, power grids and water plants.▾ In plain EnglishPhysical machinery is controlled by computers, many of them decades old and impossible to switch off for updates. Here a security failure doesn’t just leak data — it can stop a production line or endanger lives. Safety and availability come before everything, which turns normal security advice upside down. What you actually do all dayBuild an accurate inventory of equipment nobody fully documented.Separate industrial networks from ordinary office ones.Monitor passively, because active scanning can crash old equipment.Plan updates around rare, precious maintenance windows.Work closely with engineers who know the machinery, not the computers. You’d enjoy this if you…Have an engineering or manufacturing background, respect physical safety, and enjoy solving problems within genuinely hard constraints. Demand far exceeds supply and pay reflects that. Skills that matterIndustrial control systemsIndustrial protocolsNetwork segmentationSafety awarenessRisk assessmentPatience with legacy tech Tools you’ll use — and what they doNozomi / Claroty — passive OT monitoringWireshark — protocol inspectionPurdue model — the reference design Certifications that helpGIAC GICSPGIAC GRIDIEC 62443 training Your first step from zeroIf you already work in manufacturing, energy or utilities, you have the rarer half of this skill set. Add security fundamentals and you become extremely employable very quickly. Typical US range: $110k–$165kFind related internships → 🤖SpecialisedSeniorAI Security SpecialistSecure the artificial intelligence systems everyone is rushing to deploy.▾ In plain EnglishOrganisations are embedding AI into products faster than they are securing it. This role covers new problems — tricking a model with carefully crafted input, leaking the private data it was trained on, poisoning its training, or an AI assistant being manipulated into taking harmful actions. A genuinely new field where nobody has decades of experience. What you actually do all dayTest AI features for manipulation and prompt injection.Check what data models can be persuaded to reveal.Set boundaries on what an AI system is permitted to do.Assess third-party AI tools before the business adopts them.Write the internal guidance nobody has written yet. You’d enjoy this if you…Are comfortable with ambiguity, enjoy being early to a subject, and like writing the rulebook rather than following one. Because the field is young, thoughtful newcomers can contribute quickly. Skills that matterHow machine learning worksAdversarial testingPythonData protectionThreat modellingClear writing Tools you’ll use — and what they doModel testing frameworksOWASP Top 10 for LLMs — the reference listStandard AppSec tooling Certifications that helpStill emergingML fundamentals coursesAppSec background Your first step from zeroLearn the basics of how large language models work, then read the OWASP Top 10 for LLM applications and try each attack against your own test application. Document what you find publicly. Typical US range: $130k–$200kFind related internships → 🤝LeadershipLeadershipSecurity Team LeadStill hands-on, but now responsible for other people’s work.▾ In plain EnglishThe first step into leadership. You still do technical work, but you also set priorities, run the rota, review your team’s output and represent them elsewhere in the business. Many people discover here whether they prefer leading or building. What you actually do all dayDecide what your team works on this week.Review work and coach junior colleagues.Run handovers, rotas and on-call arrangements.Remove obstacles and shield the team from noise.Still investigate the hard cases yourself. You’d enjoy this if you…Get satisfaction from other people succeeding, communicate well, and are willing to let go of some technical depth in exchange for wider influence. Skills that matterTechnical credibilityCoachingPrioritisationDifficult conversationsWritten communication Tools you’ll use — and what they doTicketing & metrics dashboardsWhatever your team uses Certifications that helpISC2 CISSPISACA CISMAny leadership training Your first step from zeroBecome genuinely good at a technical role first, then start mentoring, documenting and taking on coordination nobody else wants. Leadership usually arrives before the title does. Typical US range: $115k–$160kFind related internships → 🧭LeadershipLeadershipSecurity ManagerRun the programme, the budget and the people.▾ In plain EnglishYou own an entire area of security — hiring, budget, strategy, and the relationship with the rest of the business. Much of the work is translation: explaining technical reality to executives, and business reality back to engineers. What you actually do all dayPlan what the security programme will deliver this year.Hire, develop and occasionally part with staff.Defend and manage a budget.Report progress and incidents to senior leadership.Take responsibility when something goes wrong. You’d enjoy this if you…Enjoy building teams and systems of work, are comfortable with accountability, and accept that your calendar will belong largely to other people. Skills that matterPeople managementProgramme managementBudgetingRisk communicationStrategyStakeholder management Tools you’ll use — and what they doGRC platforms — programme trackingReporting dashboardsRoadmaps & plans Certifications that helpISACA CISMISC2 CISSPPMP Your first step from zeroLead a small team first. Practise explaining a technical risk to a non-technical audience in three sentences — that skill is most of what separates good managers from frustrated ones. Typical US range: $130k–$190kFind related internships → 👑LeadershipLeadershipCISO — Chief Information Security OfficerOwn security for the whole organisation, and answer for it.▾ In plain EnglishThe most senior security role. You set the direction, decide what level of risk the organisation will accept, answer to the board and regulators, and carry personal responsibility when something serious happens. Far more about business, communication and judgement than about technology. What you actually do all daySet security strategy and secure the funding for it.Present risk honestly to the board and executive team.Build and lead the leaders beneath you.Handle regulators, insurers, auditors and major customers.Take charge, publicly, during a serious incident. You’d enjoy this if you…Are an excellent communicator with strong nerves and sound judgement, and are willing to be accountable for outcomes you cannot fully control. It typically takes fifteen years or more to reach. Skills that matterExecutive communicationRisk strategyGovernanceBusiness acumenCrisis leadershipBuilding teams Tools you’ll use — and what they doBoard reporting packsRisk registersBudget models Certifications that helpISC2 CISSPISACA CISMCCISOBusiness qualifications Your first step from zeroBuild depth in one area, then breadth across several, then lead people. Learn to read a balance sheet — understanding the business is what elevates a security leader beyond a technical manager. Typical US range: $200k–$400k+Find related internships → Nothing matches that combination. Leadership roles only exist at leadership level, and the other areas don’t have leadership-titled jobs of their own. Reset one of your filters to see the full list again. Show all areasShow all levels How careers usually grow You don’t have to know your destination yet. Most careers follow a rough shape: start broad, find what you’re good at, go deep, then choose between staying technical or leading people. Very few people follow it exactly — treat it as a map, not a timetable. 01Get inYear 0–2SOC Analyst (Tier 1)GRC AnalystVulnerability ManagementIT Security TechnicianAwareness Specialist 02SpecialiseYear 2–5Penetration TesterSecurity EngineerIncident ResponderRisk or Privacy AnalystDetection Engineer 03Go deepYear 5–10Threat HunterRed Team OperatorCloud Security EngineerSecurity ArchitectResilience Manager 04LeadYear 8+Security Team LeadSecurity ManagerCISOOr stay technical — principal engineer roles pay just as well Still not sure? Match what you already like to a job. Find the sentence on the left that sounds most like you. The role on the right is where people with that instinct usually thrive. I liked puzzles and detective stories as a child.→SOC Analyst, then Incident ResponderInvestigating what happened, and why. I’m the organised one who keeps everything on track.→GRC Analyst or Vulnerability ManagementStructure, follow-through and clear records. I take things apart to see how they work.→Penetration Tester, later Malware AnalystUnderstanding systems by breaking them. I’m the person friends ask to explain things.→Security Awareness or Technical WriterTeaching and translating for real people. I automate anything I have to do twice.→Detection Engineer or DevSecOpsBuilding tools that work while you sleep. I stay calm when everything is going wrong.→Incident ResponderLeading the response while others panic. I read news, politics and history for fun.→Threat Intelligence AnalystResearch, context and clear briefings. I’m good with people and good at asking questions.→Vendor Risk or ConsultantAssessment through conversation. I care about fairness, law and people’s rights.→Privacy Analyst or IT AuditorHolding organisations to their promises. I already work with machinery, plants or utilities.→OT / Industrial Security SpecialistYour existing knowledge is the rare half. Certifications, explained Which certificate, and when. You do not need all of these — almost nobody has more than three or four. Pick one to get started, then one aimed at the role you actually want. Experience always beats collecting certificates. Step oneAbsolute beginnerStart here if you have no background at all. These prove you understand the basics and are serious.ISC2 CC (free to study)Google Cybersecurity CertificateCompTIA Security+CompTIA Network+ Defensive trackMonitoring & responseFor SOC, incident response and forensics roles. Hands-on ones carry the most weight.CompTIA CySA+Blue Team Level 1GIAC GCIHGIAC GCFAGIAC GCTI Offensive trackTesting & red teamPractical exams only — multiple-choice hacking certificates impress nobody in this area.eJPT (start here)PNPTOSCP (the benchmark)CRTOOSEP Engineering trackCloud & buildCloud certificates currently carry more hiring weight than almost anything else.AWS Security SpecialtyMicrosoft AZ-500 / SC-300ISC2 CCSPKubernetes CKS GRC trackRisk, audit & privacyThe strongest route for non-technical entrants. Widely recognised internationally.ISACA IT Risk FundamentalsISACA CRISCISACA CISAISO 27001 Lead AuditorIAPP CIPP / CIPM Leadership trackManaging & strategyBoth require several years of verified experience — they are milestones, not starting points.ISC2 CISSPISACA CISMCCISO If you’re starting today Five steps, in order, from nothing. This works whether you’re a student, changing career at forty, or studying between shifts. None of it requires money you don’t have. 01Learn the languageSpend a few weeks on free fundamentals until the jargon above stops feeling foreign. Understanding beats memorising. 02Pick one directionUse the matcher above. You can change later — but scattered effort in six directions gets you hired nowhere. 03Do something realBuild a home lab, solve practice challenges, or write policies for an imaginary company. Proof beats claims. 04Take one certificateOne recognised entry certificate is enough to get past screening. Take it once you already have something to show. 05Get in any doorHelp desk, internship, junior analyst, apprenticeship. The first role is the hardest; moving inside the field is far easier. Honest answers The questions people are afraid to ask. No sales pitch. These are the answers we would give a friend. Do I really need a degree?+No, for most roles. A degree helps get past automated screening at large corporations and is genuinely useful for cryptography and research work. Everywhere else, employers care about what you can demonstrate. Many strong practitioners have no degree at all — but they do all have something concrete to show. I’m 40 (or 50). Is it too late?+No. Career changers are common and often preferred, because most of this work is about judgement, communication and reliability under pressure — things earlier careers teach well. Your previous industry is an advantage: a nurse understands healthcare risk, an accountant understands audit, a teacher understands training. Is it true there’s a huge shortage of cyber staff?+Partly. There is a real shortage of experienced people, and considerable competition for entry-level jobs. That gap is why step three matters so much: the candidates who get hired are the ones who arrive with something they have actually built, tested or written, rather than only a certificate. How much programming do I actually need?+It varies enormously. GRC, audit, privacy, awareness and vendor risk need essentially none. SOC and vulnerability management benefit from light scripting. Engineering, detection and application security need real coding. Malware analysis and exploit development need deep programming ability. Choose your direction accordingly — and if you want to learn one language, learn Python. Which single certificate should I start with?+For most people, CompTIA Security+ — it is widely recognised and covers everything at a sensible level. If cost is a barrier, ISC2’s Certified in Cybersecurity is periodically free to study and sit, and the Google Cybersecurity Certificate is low-cost. If you already know you want GRC, ISACA’s IT Risk Fundamentals is an excellent, cheaper start. Are the salaries on this page realistic?+They are broad United States ranges intended for comparison between roles, not promises. Pay varies hugely by city, industry, company size and country. Use them to see relative differences — for example that GRC and engineering pay comparably at senior level — then check local sources for your own market. Is cyber security stressful?+Some roles genuinely are. Incident response involves unpredictable hours and real pressure, and some SOC roles run night shifts. Many other roles — GRC, audit, privacy, awareness, architecture — keep ordinary hours. If your circumstances need predictability, choose accordingly. Burnout in this field is usually the result of role mismatch, not the industry itself. Can I learn all of this for free?+Almost all of it. Frameworks, documentation, virtualisation software, cloud free tiers and many practice platforms cost nothing. The paid parts are usually exam fees. That is exactly why Oluma exists — the knowledge should never be the barrier. Your next step Found one that sounds like you? Learn the skills free in our Learning Hub, test yourself with the practice quizzes, then browse live internships and entry-level openings. Everything on Oluma is free, and always will be. Start learning → Browse internships