Lazo Lab Sign up

Guides

Starting a career in cyber

Beginner 路 6 min read

The main job paths, the skills they need, and a realistic way to begin.

The main paths

  • Security analyst (blue team): watches alerts, investigates incidents, defends networks. The most common entry job.
  • Penetration tester (red team): breaks into systems with permission to find weaknesses first.
  • Security engineer: builds secure systems, firewalls and monitoring.
  • Cloud security: protects services running on AWS, Azure and Google Cloud.
  • Digital forensics: investigates what happened after an attack.

Skills that matter most

Fundamentals beat tools. Employers want people who understand networking, Linux, how the web works, and at least one programming language, usually Python. Tools change every year; fundamentals don't.

Certifications

CompTIA Security+ is the most recognised starter certificate. Later options include eJPT for beginner pentesting and OSCP for advanced pentesting. Certificates open doors, but real projects keep them open.

A realistic plan

  • Months 1 to 3: Linux, networking and Python basics. Do the Linux and Python tracks here.
  • Months 3 to 6: TryHackMe paths, OverTheWire Bandit, your first CTFs.
  • Months 6 to 12: build a home lab, write up what you learn on a blog or GitHub, aim for Security+.
  • Ongoing: share your projects. A home server you secured yourself is a great interview story.