Key Takeaways
- Cyber security is not a single job — it is at least four distinct disciplines.
- Defensive roles outnumber offensive roles by roughly ten to one.
- Certifications matter more here than in most tech fields, but hands-on practice matters more.
- Communication and calm judgement decide seniority once the technical bar is met.
The Four Domains
| Domain | What It Covers | Sample Roles |
|---|---|---|
| Governance, Risk & Compliance | Policy, audit, controls, frameworks | Security Analyst, GRC Lead |
| Blue Team | Detection, response, monitoring | SOC Analyst, Incident Responder |
| Red Team | Simulated attack, penetration testing | Pentester, Red Team Operator |
| Product & Cloud Security | Secure design, code review, cloud hardening | AppSec, Cloud Security Engineer |
Most beginners start in blue team or GRC. Red team roles are prestige-heavy but few.
Core Skills Everyone Needs
- Networking fundamentals — TCP/IP, DNS, TLS.
- Operating system internals — Linux and Windows.
- Basic scripting — Python and shell.
- Reading logs and reasoning about anomalies.
- One cloud provider at intermediate level.
- Clear writing — every serious role produces reports.
A Realistic Learning Path
- Learn the basics — CompTIA Security+ level knowledge, not necessarily the exam.
- Build a home lab — a small virtualised network you can attack and defend.
- Practise on TryHackMe, HackTheBox and OverTheWire.
- Pick a direction — SOC, AppSec, GRC, cloud security.
- Earn one relevant certification — for example Security+, AZ-500, OSCP or CCSP.
- Apply widely for entry-level SOC or GRC roles.
Common Mistakes
- Watching CTF videos instead of solving them.
- Chasing the OSCP too early.
- Ignoring the writing and communication side.
- Learning tools without learning fundamentals.
- Believing that offensive security is the only real security.
Final Summary
Cyber security rewards curiosity, discipline and calm under pressure. The field is deep, the demand is steady, and the ceiling for skilled practitioners is very high.