Cybersecurity
Think like an attacker. Protect like a guardian.
Security engineers find vulnerabilities, defend systems and respond to attacks.
What the work looks like
Pen testing, reviewing code for vulnerabilities, monitoring threats, investigating incidents.
Key skills
- Networking
- Linux
- Web security (OWASP)
- Scripting
- Threat analysis
Common tools
Burp SuiteWiresharkKali LinuxNmapSIEM tools
Pros
- Shortage of skilled people
- Feels like puzzle-solving
- Bug bounties possible as a student
Cons
- Constant learning
- High-stress incidents
- Some roles are monotonous monitoring
A 12-month starter roadmap
Months 1–3
- • Networking fundamentals
- • Linux
- • Python scripting
- • OWASP Top 10
Months 4–6
- • TryHackMe / HackTheBox
- • Web app pentesting
- • CTF competitions
- • Security+ level concepts
Months 7–12
- • Bug bounty attempts
- • Specialise (AppSec, SOC, Cloud Sec)
- • Certification
- • Write-ups blog
Reality check
Students like: Finding the hole nobody saw.
Students dislike: Writing reports and compliance documents.
Hardest part: Keeping up with new attack techniques.
Common myth: It's not hoodie-hacking — it's mostly methodical analysis.