CAREER PATHS
Every cybersecurity job role, mapped out.
Cybersecurity isn't one job, it's a tree of specialties. Below are all 14 branches of the field, starting with the ones companies currently need the most and working down to the ones with the fewest (but often highest-paid) seats — 63 job roles in total.
Every branch leads to a page covering each job role in it in real detail: what the work actually is, where people in that role work, what it pays (with sources), which certifications actually matter, and where you can go learn it. Each branch page also notes the other real specialties inside it that didn't get their own full write-up.
Security Operations (SOC)
Monitoring, detecting, and responding to attacks as they happen — the highest-volume branch in cybersecurity.
5 roles covered: SOC Analyst, Threat Hunter, Detection Engineer, Security Automation Engineer (SOAR), SIEM Engineer / Administrator
Cloud Security
Protecting cloud identities, workloads, and infrastructure as more companies move off physical servers.
5 roles covered: Cloud Security Engineer, DevSecOps Engineer, Cloud Security Analyst, Cloud Security Architect, AWS Security Engineer
Network Security
Protecting the networks and network traffic every other system runs on top of.
5 roles covered: Network Security Engineer, Network Security Analyst, Firewall Engineer/Administrator, Network Security Architect (Zero Trust / Segmentation), VPN & Remote Access / Wireless Security Engineer
Identity & Access Management (IAM)
Controlling who can access which systems and resources — and proving it.
5 roles covered: IAM Engineer, IAM Analyst, Privileged Access Management (PAM) Engineer, Identity Governance & Administration (IGA) Analyst, Identity & Access Management Architect
Endpoint Security
Protecting the laptops, phones, and servers where most attacks actually land first.
5 roles covered: Endpoint Security Engineer, Endpoint Security Analyst (EDR/XDR-focused), Endpoint Management Engineer, Mobile Device Security Engineer, Server/Systems Security Engineer
Application Security (AppSec)
Protecting the software and applications a company actually builds and sells.
5 roles covered: Application Security Engineer, AppSec Analyst / Security Testing, API Security Engineer, Product Security Engineer, Mobile Application Security Engineer
Vulnerability Management
Finding, assessing, and getting the fixes shipped for the flaws attackers would exploit first.
5 roles covered: Vulnerability Management Analyst, Vulnerability Management Engineer, Vulnerability Researcher, Attack Surface Management Analyst, Security Configuration / Hardening Engineer
Incident Response & Digital Forensics
Responding to breaches as they happen, then reconstructing exactly what occurred afterward.
5 roles covered: Incident Responder, Digital Forensics Analyst, Malware Analyst, Cybercrime Investigator / DFIR Consultant, Cloud / Network Forensics Analyst
Data Security
Protecting sensitive and valuable data itself, wherever it lives and however it moves.
5 roles covered: Data Security Engineer, DLP Engineer / Analyst, Database Security Administrator, Data Governance Analyst, Encryption / PKI Engineer
Governance, Risk & Compliance
Making sure security decisions match the law, industry rules, and the business's actual risk tolerance.
4 roles covered: GRC Analyst, Compliance Analyst, IT / Security Risk Manager, Security Auditor
Offensive Security (Red Team)
Thinking and acting like an attacker, on purpose and with permission, to find weaknesses first.
3 roles covered: Penetration Tester, Web Application Penetration Tester, Red Team Operator
Data Privacy
Making sure personal data is collected, stored, and used the right way.
3 roles covered: Privacy Analyst, Privacy Engineer, Data Protection Officer (DPO)
AI Security
Securing AI systems themselves — models, training data, and the applications built on top of them.
5 roles covered: AI/ML Security Engineer, GenAI/LLM Security Engineer, AI Red Team Specialist, AI Governance & Compliance Analyst, AI Risk Analyst
Security Leadership
Running the team, the budget, and the strategy once you've grown past a hands-on role.
3 roles covered: Security Manager, Security Architect, CISO (Chief Information Security Officer)