Free Learning Roadmap

How to Become a Cyber Security Engineer

Threat modelling, IAM, network security, incident response, offensive vs defensive craft. The role that keeps everyone else's mistakes from becoming headlines.

Topics
11
Resources
38
Cost
Free
Most resources are free or freemium
Format
Self-paced

1. Security Foundations

core
CIA Triad & Core Concepts

Confidentiality, integrity, availability. Threat vs vulnerability vs risk. The conceptual scaffold everything else hangs on.

Threat Modelling

STRIDE, PASTA, attack trees. Design-time security is 100x cheaper than incident-time.

2. Network Security

core
Networking Fundamentals

TCP/IP, HTTP, DNS, TLS, VPNs, VLANs. You can't secure a network you don't understand.

Firewalls, IDS/IPS

Perimeter and internal segmentation. Snort, Suricata, cloud WAFs. Reading rules is a daily skill.

3. Identity & Access Management

core
AuthN vs AuthZ

OAuth2, OIDC, SAML, RBAC vs ABAC. Get identity wrong and everything else is decoration.

Least Privilege & Zero Trust

Modern IAM assumes breach. Zero Trust architecture per NIST SP 800-207 is the reference model.

4. Application & Web Security

core
OWASP Top 10

The most common web vulnerabilities. Injection, broken auth, XSS, IDOR, SSRF. Every appsec engineer knows them cold.

Secure Coding

Input validation, output encoding, cryptography basics. Shift security left into the SDLC.

5. Cloud Security

core
AWS / GCP / Azure Security

IAM policies, KMS, GuardDuty, Security Hub. Cloud misconfigs are the modal breach vector.

Container & K8s Security

Image scanning, admission control, network policies, secrets management. Falco, Trivy, Kyverno.

6. Offensive Security (Red Team)

recommended
Pentesting Fundamentals

Recon, enumeration, exploitation, post-exploitation. HackTheBox and TryHackMe are the practical entry points.

MITRE ATT&CK

The canonical framework for adversary tactics and techniques. Read it, map alerts to it, quiz interviewers on it.

7. Defensive Security (Blue Team)

core
SIEM & SOC Operations

Splunk, Elastic Security, Sentinel, Chronicle. Detection engineering, alert triage, runbooks.

Detection Engineering

Writing detection rules that catch attacks without drowning in false positives. Sigma, YARA, KQL.

8. Incident Response

core
IR Lifecycle

Prep, detect, contain, eradicate, recover, learn. NIST SP 800-61 is the reference playbook.

Digital Forensics Basics

Disk imaging, memory analysis, chain of custody. Autopsy and Volatility are the classic open-source tools.

9. Compliance & Governance

recommended
ISO 27001, SOC 2, PCI, NIST CSF

The alphabet soup enterprise security engineers navigate. Which applies when, evidence collection, audit prep.

10. Credentials

recommended
Security Certifications

Security+, CISSP, OSCP, CEH. Different specialisations, different weights in different markets.

11. Career & Voices

optional
Voices to Follow

Where working security people learn what's actually happening.

Want a personalised version?

This roadmap is the same one our platform uses internally, but the logged-in version lets you tick off topics as you complete them, track a personalised First 90 Days plan, and see your AI-durability score against this role. All free.

Open the interactive roadmap →
Curated by WhatTNext Ai · methodology · all roadmaps · last updated 2026-07-29