Learning roadmaps
There’s no single path in cybersecurity: there are several roles, each with different skills and certifications. This card helps you get oriented —what to learn, in what order, and which certification fits each goal— so you don’t get lost or collect titles aimlessly.
First: choose a role
Section titled “First: choose a role”Red Team / Pentest offense: web, networks, AD, exploitation (OSCP, PNPT, OSWE, CRTO)Blue Team / SOC defense: detection, SIEM, IR, hunting (BTL1, etc. + def-*)DFIR forensics and response (GCFA, GCIH + DFIR area)AppSec / DevSecOps development security (BSCP, OSWE + DevSecOps area)GRC / Compliance governance, risk, regulation (ISO 27001 LA, CISM, CISSP + GRC area)Cloud security cloud security (AWS/Azure/GCP certs + Cloud area)Common fundamentals (base for everything)
Section titled “Common fundamentals (base for everything)”- networks (TCP/IP, DNS, HTTP), Linux and Windows at admin level- a scripting language (Python/Bash) -> automate and understand exploits- security concepts (CIA, basic crypto, threat models)- constant lab practice (see ctf-plataformas): theory without practice isn't enoughTypical progression (offense, as an example)
Section titled “Typical progression (offense, as an example)”1. Fundamentals networks + Linux/Windows + scripting + Security+ (optional, base/HR)2. Entry hands-on eJPT / PNPT / HTB Academy -> first real pentest3. Pentest OSCP (the industry standard for pentester)4. Specialize OSWE (web), CRTO (red team AD), OSEP (evasion), cloud...Certification vs skill
Section titled “Certification vs skill”- the certification OPENS DOORS (HR filters, requirements), but SKILL is what matters- a portfolio (writeups, GitHub, bug bounty) complements and sometimes beats the paper- choose HANDS-ON (practical) certs over purely theoretical ones for technical roles- don't collect titles: each cert should serve a concrete career goalBlue Team / career
Section titled “Blue Team / career”- Choose the role first, then the certifications that serve it; not the other way around.
- Build solid fundamentals (networks/OS/scripting) before advanced certs.
- Prioritize hands-on certs for technical roles; complement with a portfolio (How to write writeups, bug bounty).
- Certification is a means, not the end: real, demonstrable skill is what gets hired.
Tips and common mistakes
Section titled “Tips and common mistakes”- Don’t collect certs: choose by goal (eJPT → PNPT/OSCP for offense; Security+ → CISSP for GRC).
- Build a portfolio in parallel (HTB, writeups, bug bounty); it’s worth as much as the paper.
- Common mistake: attempting OSCP with no base; go through fundamentals and a junior cert first.
Testing checklist
Section titled “Testing checklist”- Define the target role (red/blue/DFIR/AppSec/GRC/cloud)
- Consolidate fundamentals (networks, Linux/Windows, scripting)
- Choose hands-on certs aligned with the role
- Practice in labs (Platforms (HTB, THM…)) consistently
- Build a portfolio (writeups, GitHub, bug bounty)
- Plan the progression (entry → core → specialization)
- Prepare for interviews (Preparing for interviews)