CYBER.MAP — Interactive Cybersecurity Career Roadmap

A free, interactive map of every cybersecurity function inside a modern enterprise — 8 domains, 40+ specializations, 200+ certifications, 100+ tools, and 100+ job roles. Pick a target role to get an ordered learning path, track certifications on a personal kanban board, chat with the CyAdvisor AI career advisor, and build a personalized skill profile that ranks careers by how well they fit you.

The 8 Domains of Cybersecurity

1. Foundations

Core computing and IT knowledge every security professional needs first: networking (TCP/IP, OSI, DNS), operating systems (Linux, Windows, Active Directory), programming & scripting (Python, Bash, PowerShell), and cryptography basics. Roles: IT Support, Network Engineer, Sysadmin. Certs: CompTIA A+, Network+, Security+, CCNA, LPIC-1.

2. Governance, Risk & Compliance (GRC)

Translating regulation and business risk into enforceable controls — risk management, compliance & audit, policy, third-party risk, privacy engineering, and security awareness. Roles: GRC Analyst, Risk Analyst, Compliance Auditor, Privacy Engineer. Certs: CISA, CRISC, CISM, ISO 27001 Lead Auditor, CIPP, DSCI DCPP/DCPLA.

3. Security Operations (SOC / Blue Team)

Detecting and responding to attacks — SIEM & log management, SOAR automation, incident response, threat hunting, threat intelligence, and digital forensics (DFIR). Roles: SOC Analyst, Incident Responder, Threat Hunter, DFIR Analyst, Detection Engineer. Certs: CompTIA CySA+, BTL1, EC-Council CSA, GCIH, GCFA, GCTI, OSDA.

4. Security Engineering & Architecture

Building secure systems — network, endpoint, and cloud security, identity & access management (IAM), privileged access management (PAM), data security, and cryptography/PKI. Roles: Security Engineer, Cloud Security Engineer, IAM Engineer, Security Architect. Certs: AZ-500, AWS Security Specialty, CCSP, CISSP-ISSAP, SC-300, GCLD.

5. Application & Product Security (AppSec)

Securing software — secure SDLC & threat modeling, SAST/DAST, API security, software supply chain (SCA), container & Kubernetes security, and bug bounty. Roles: Application Security Engineer, Product Security Engineer, DevSecOps Engineer, Bug Bounty Hunter. Certs: CSSLP, OSWE, BSCP, HTB CBBH, CKS, CDP (Practical DevSecOps).

6. Offensive Security & Red Team

Thinking like an attacker — penetration testing, red team operations, Active Directory attacks, adversary emulation, vulnerability management, social engineering, and exploit development. Roles: Penetration Tester, Red Team Operator, Exploit Developer. Certs: OSCP, OSEP, PNPT, CPTS, CEH, CPENT, CRTO, CRTP, CRTE, CRTM, CARTP.

7. Emerging Security (AI, OT/ICS, Mobile)

Fast-growing specializations — AI/ML security and LLM red teaming, OT/ICS & industrial security, mobile security, physical security, and cyber insurance / quantitative risk. Roles: AI Security Engineer, OT Security Engineer, Mobile Security Engineer. Certs: HTB Certified AI Red Teamer, ISACA AAIA, GICSP, ISA/IEC 62443, eMAPT, GMOB.

8. Security Leadership (CISO)

Owning the enterprise security program — strategy, risk quantification, board communication, budget, and regulatory posture. Roles: CISO, Deputy CISO, VP Security, Director of Information Security. Certs: CISSP, CISM, CCISO, CGEIT, CRISC, CISSP-ISSMP.

Popular Cybersecurity Roles

SOC Analyst, Incident Responder, Threat Hunter, Threat Intelligence Analyst, Digital Forensics Analyst, Penetration Tester, Red Team Operator, Bug Bounty Hunter, Application Security Engineer, Cloud Security Engineer, Security Engineer, Network Security Engineer, IAM Engineer, Security Architect, GRC Analyst, Risk Analyst, Compliance Auditor, Privacy Engineer, Malware Analyst, Detection Engineer, DevSecOps Engineer, AI Security Engineer, OT/ICS Security Engineer, Vulnerability Management Analyst, and CISO.

Key Certifications by Tier

Entry: CompTIA Security+, Network+, A+, ISC2 Certified in Cybersecurity (CC), Google Cybersecurity, eJPT, BTL1, EC-Council CND/CSA. Intermediate: CompTIA CySA+/PenTest+, OSCP, PNPT, CPTS, CEH, GCIH, GCFA, AZ-500, SC-200, AWS Security Specialty, CRTP, CARTP, CSSLP, CISA, CRISC. Advanced/Expert: CISSP, CCSP, CISM, OSEP, OSWE, OSED, OSCE3, CPENT, CRTO, CRTE, CRTM, CARTE, GXPN, GCTI, ISO 27001 Lead Auditor.

Loading the interactive map… If it doesn't appear, enable JavaScript. CYBER.MAP is free and built by Harsh Sharma.