Skip to content

Learning roadmaps

There’s no single path in cybersecurity: there are several roles, each with different skills and certifications. This card helps you get oriented —what to learn, in what order, and which certification fits each goal— so you don’t get lost or collect titles aimlessly.

Red Team / Pentest offense: web, networks, AD, exploitation (OSCP, PNPT, OSWE, CRTO)
Blue Team / SOC defense: detection, SIEM, IR, hunting (BTL1, etc. + def-*)
DFIR forensics and response (GCFA, GCIH + DFIR area)
AppSec / DevSecOps development security (BSCP, OSWE + DevSecOps area)
GRC / Compliance governance, risk, regulation (ISO 27001 LA, CISM, CISSP + GRC area)
Cloud security cloud security (AWS/Azure/GCP certs + Cloud area)
- networks (TCP/IP, DNS, HTTP), Linux and Windows at admin level
- a scripting language (Python/Bash) -> automate and understand exploits
- security concepts (CIA, basic crypto, threat models)
- constant lab practice (see ctf-plataformas): theory without practice isn't enough

Typical progression (offense, as an example)

Section titled “Typical progression (offense, as an example)”
1. Fundamentals networks + Linux/Windows + scripting + Security+ (optional, base/HR)
2. Entry hands-on eJPT / PNPT / HTB Academy -> first real pentest
3. Pentest OSCP (the industry standard for pentester)
4. Specialize OSWE (web), CRTO (red team AD), OSEP (evasion), cloud...
- the certification OPENS DOORS (HR filters, requirements), but SKILL is what matters
- a portfolio (writeups, GitHub, bug bounty) complements and sometimes beats the paper
- choose HANDS-ON (practical) certs over purely theoretical ones for technical roles
- don't collect titles: each cert should serve a concrete career goal
  • Choose the role first, then the certifications that serve it; not the other way around.
  • Build solid fundamentals (networks/OS/scripting) before advanced certs.
  • Prioritize hands-on certs for technical roles; complement with a portfolio (How to write writeups, bug bounty).
  • Certification is a means, not the end: real, demonstrable skill is what gets hired.
  • Don’t collect certs: choose by goal (eJPT → PNPT/OSCP for offense; Security+ → CISSP for GRC).
  • Build a portfolio in parallel (HTB, writeups, bug bounty); it’s worth as much as the paper.
  • Common mistake: attempting OSCP with no base; go through fundamentals and a junior cert first.
  • Define the target role (red/blue/DFIR/AppSec/GRC/cloud)
  • Consolidate fundamentals (networks, Linux/Windows, scripting)
  • Choose hands-on certs aligned with the role
  • Practice in labs (Platforms (HTB, THM…)) consistently
  • Build a portfolio (writeups, GitHub, bug bounty)
  • Plan the progression (entry → core → specialization)
  • Prepare for interviews (Preparing for interviews)