Cybersecurity is a broad field; employers look for a mix of technical skills, soft skills, domain knowledge, and practical experience. Below is a concise, role-agnostic roadmap that maps core capabilities to common job types (analyst, engineer, pentester, incident responder, architect, risk/compliance).
Core technical skills
- Networking fundamentals: TCP/IP, OSI model, subnetting, routing, NAT, DNS, HTTP(S), VPNs, firewalls.
- Operating systems: strong Linux (command line, services, logs) and Windows internals (Active Directory, Event Logs, PowerShell).
- System administration: user/account management, patching, hardening, virtualization (VMs, containers).
- Security basics: CIA triad, authentication/authorization, cryptography fundamentals (symmetric/asymmetric, hashing, PKI).
- Threats and malware: common malware types, indicators of compromise (IOCs), basic malware analysis concepts.
- Vulnerability assessment: scanning tools (Nessus, OpenVAS, Qualys), understanding of CVE/CVSS scoring.
- Intrusion detection and logging: SIEM concepts (Splunk, ELK, QRadar), log analysis, alerts tuning.
- Scripting and automation: Python, Bash/PowerShell; automate repetitive tasks, parse logs, build small tools.
- Web application security: OWASP Top 10, input validation, session management, common vulnerabilities (XSS, SQLi).
- Penetration testing tools and techniques (for offensive roles): Nmap, Metasploit, Burp Suite, Wireshark, proxying, exploitation basics.
Specialized/advanced technical skills (role-dependent)
- Cloud security: AWS/Azure/GCP architecture, IAM, security groups, cloud-native logging, CSPM tools.
Identity & Access Management: SSO/OAuth/SAML, LDAP,...