Security Certifications and Career Paths
Navigate the certification landscape strategically. Learn which certs matter for which roles, the most efficient study paths, exam strategies, and how to build a portfolio that gets you hired in the US cybersecurity job market.
Certifications vs Experience — Setting Expectations
Certifications open doors — especially in the US federal government, defence contracting, and enterprise IT markets, where they are often listed as hard requirements. But they are signals, not substitutes for real skill. A certification tells a recruiter you can pass a test; your portfolio and GitHub tell them you can do the work.
The most effective career strategy combines: one or two certifications appropriate to your target role, a home lab demonstrating practical skills, write-ups from CTFs or bug bounty programmes, and work experience (internship, junior role, or volunteer work). Each of these independently is weak; together they are compelling.
Certification Landscape Overview
| Category | Level | Top Certs | Target Roles |
|---|---|---|---|
| Vendor-neutral foundational | Entry | CompTIA Security+, Google Cybersecurity, ISC2 CC | Helpdesk, SOC Tier 1, IT security analyst |
| Vendor-neutral intermediate | Mid | CompTIA CySA+, CASP+, eJPT, CEH | SOC Tier 2, security analyst, junior pentester |
| Offensive / Pentesting | Mid-Advanced | PNPT, OSCP, OSWE, eCPPTv2 | Penetration tester, red team, AppSec |
| Cloud security | Mid-Advanced | AWS Security Specialty, GCP PCSE, Azure SC-200 | Cloud security engineer, DevSecOps |
| Defensive / Blue team | Mid-Advanced | SC-200, AZ-500, BTL1, Splunk Core Certified | SOC analyst, threat hunter, IR analyst |
| GRC / Management | Mid-Advanced | CISM, CRISC, ISO 27001 Lead Auditor | GRC analyst, security manager, compliance |
| Senior / Leadership | Advanced | CISSP, CISA, CCSP | CISO, security architect, vCISO |
| Specialised offensive | Advanced | OSED, OSMR, GXPN, OSED | Exploit developer, malware analyst, red team lead |
Entry-Level Certifications
CompTIA Security+ — The Universal Entry Ticket
Security+ is the most widely recognised entry-level security certification in the US. The US Department of Defense mandates it (DoD 8570/8140) for all personnel with access to information systems. It is frequently listed as "preferred" or "required" in junior security analyst job postings.
CompTIA Security+ SY0-701 (current exam, valid until Nov 2026): Exam format: - 90 questions (multiple choice + performance-based) - 90 minutes - Passing score: 750/900 - Cost: ~$392 USD (vouchers on sale at CompTIA store, sometimes 30-40% off) - No prerequisites (no required experience) - Validity: 3 years (renew with CEs or retake) Domain coverage: 1. General Security Concepts (12%) 2. Threats, Vulnerabilities, Mitigation (22%) 3. Security Architecture (18%) 4. Security Operations (28%) 5. Security Program Management and Oversight (20%) Study path (60-90 days, 1 hour/day): Week 1-4: Professor Messer free course (professormesser.com) — watch all videos Week 5-6: Jason Dion practice exams on Udemy (6 full practice tests) Week 7-8: Focus on weak areas; Darril Gibson SY0-701 book Week 9: CertMaster Labs for performance-based question practice Day before: Rest; review notes; sleep well Performance-based questions (PBQs) — how to approach: - Drag-and-drop network diagrams, configure firewall rules, analyse logs - Skip PBQs first pass, answer MCQs, return to PBQs with remaining time - Partial credit is awarded even for incomplete PBQ answers
ISC2 Certified in Cybersecurity (CC) — Free Entry Point
ISC2 launched the CC certification in 2022 and made the self-paced training and exam voucher free — making it the lowest-barrier entry into formal certifications. It is less recognised than Security+ in job postings but valuable as a supplement and stepping stone to CISSP.
ISC2 CC (Certified in Cybersecurity):
Cost: Free (exam voucher + self-paced course — free until supply exhausted)
Check isc2.org for current availability
Format: 100 MCQ, 2 hours, 700/1000 passing
Validity: 3 years (9 CPE credits per year to maintain)
Domains:
1. Security Principles
2. Incident Response, Business Continuity, Disaster Recovery
3. Access Controls Concepts
4. Network Security
5. Security Operations
Best use case: Complete CC while studying for Security+
- CC provides conceptual foundation
- Security+ goes deeper and is more job-market recognised
- Both together signal commitment to the fieldGoogle Cybersecurity Certificate — Beginner Friendly
Google Cybersecurity Certificate (Coursera): - 6 months at 7 hours/week (can go faster) - ~$50/month on Coursera (Financial aid available for free) - Covers: Linux, Python, SIEM, network security, IDS, security operations - Prepares for CompTIA Security+ (aligned with exam domains) - Practical labs included throughout Best for: complete beginners with no IT background Not for: replacing Security+ for job applications — use it as prep, then take Security+
Offensive Security Certifications
Penetration testing certifications are the most respected in the offensive security field — and the hardest to fake. Most top certs require you to actually compromise systems in a lab exam, not just answer multiple choice questions. Hiring managers in pentesting know which certs require real skill and which are memorisation exercises.
The Offensive Certification Path
Recommended offensive security certification progression: Entry: eJPT (eLearnSecurity Junior Penetration Tester) - Cost: $200 (includes lab access) - Format: 3-day practical exam on a lab network (72 hours) - Prerequisites: none — good for true beginners - Skills: nmap, Metasploit, basic web exploitation, pivoting - Value: demonstrates hands-on basics; shows employers you can actually hack Intermediate: PNPT (Practical Network Penetration Tester) - Provider: TCM Security (Heath Adams / The Cyber Mentor) - Cost: $400 (includes training course) - Format: 5-day practical exam + 2-day professional report writing - Skills: external/internal pentest, AD attacks (Kerberoasting, PtH, BloodHound) - Value: widely respected in the community; report requirement proves professional communication - Recommended: take the TCM Security Practical Ethical Hacking course first Gold standard: OSCP (Offensive Security Certified Professional) - Provider: Offensive Security - Cost: $1,499 (Learn One subscription with 90 days lab) — check for sales - Format: 23h 45min practical exam + 24h report writing - Prerequisites: solid networking, Linux, scripting knowledge required - Skills: manual exploitation without Metasploit (mostly), privilege escalation, AD - Value: industry gold standard for penetration testing — listed in virtually all senior pentest job postings - Prep: complete TryHackMe OSCP path, HackTheBox Pro Labs (RastaLabs, Offshore), TCM course first Advanced: OSWE, OSEP, OSED (specialisations) - OSWE: Web application exploitation (source code review, complex chains) - OSEP: Evasion techniques and advanced red team - OSED: Windows exploit development and shellcoding - OSCP is typically prerequisite for these Alternative paths: - eCPPTv2 (eLearnSecurity): practical, respected, less expensive than OSCP - CRTP (Certified Red Team Professional): AD-focused, Pentester Academy - CRTO (Certified Red Team Operator): Cobalt Strike + C2 focused
OSCP Exam Strategy
OSCP exam (23h 45min, 100 points total):
Scoring structure:
Active Directory set (3 machines): 40 points (all or nothing — must get all 3)
Standalone machines (3 machines): 20 points each (10 initial access + 10 root)
Passing score: 70 points
Recommended approach:
Hour 1: Read all machine descriptions, decide attack order
Hours 1-4: Tackle AD set first (40 points; eliminates biggest risk early)
- Enumerate with nmap, BloodHound, enum4linux
- Try common AD paths: Kerberoasting, AS-REP, ACL abuse
- Note: 3 hours on AD with no progress → pivot to standalones
Hours 4-14: Work standalone machines
- For each: nmap → service enumeration → research CVEs → exploit → privesc
- Don't rabbit-hole: 30 minutes without progress → next machine
- Document EVERYTHING as you go (screenshots + commands)
Hours 14-22: Return to stuck machines with fresh eyes
- Read all your notes again — answers often emerge from pattern matching
- Try simpler things first: default creds, version-specific exploits
Hour 22-23: Review documentation, clean up screenshots
- Verify every flag screenshot shows: flag content + proof.txt command + IP
Report (24 hours after exam):
- Write report immediately after exam — memory is fresh
- Use official OSCP report template
- Include every step: command → output → explanation
- Missing documentation = lost points (even if you got the flag)Defensive and Blue Team Certifications
Blue Team Level 1 (BTL1)
BTL1 — Security Blue Team: Cost: ~$395 (training + exam included) Format: 24-hour practical exam — investigate a simulated incident Skills: SIEM triage, phishing analysis, threat hunting, digital forensics, Splunk Value: excellent practical blue team cert; often paired with Security+ Prep: included course covers all exam topics; practice in labs Best for: SOC analysts, incident responders, those pivoting from IT to security
Microsoft Certifications — SC-200 and AZ-500
Microsoft Security certifications (high value if your org uses Azure/M365): SC-200: Microsoft Security Operations Analyst - Focuses on Microsoft Sentinel (KQL), Defender for Endpoint, Defender XDR - Cost: $165 - Format: 45-60 MCQ + case studies, 2 hours - Value: directly marketable if target orgs use M365/Azure (most enterprises do) - Prep: Microsoft Learn free path + John Christopher practice tests AZ-500: Microsoft Azure Security Engineer Associate - Focuses on Azure IAM, Key Vault, Defender for Cloud, network security - Cost: $165 - Prerequisite: AZ-104 (Azure Administrator) knowledge recommended - Value: essential for cloud security roles in Azure environments SC-300: Microsoft Identity and Access Administrator - Focuses on Azure AD, Conditional Access, MFA, PIM - Cost: $165 - Value: pairs well with IAM-focused security roles
AWS Security Specialty
AWS Certified Security — Specialty (SCS-C02): Cost: $300 Format: 65 questions, 170 minutes Prerequisites: AWS Solutions Architect Associate recommended (or equivalent experience) Skills: IAM advanced, KMS, CloudTrail, GuardDuty, Security Hub, Config, WAF, Shield Value: strong differentiator for cloud security engineer roles at AWS shops Domains: 1. Threat detection and incident response (14%) 2. Security logging and monitoring (18%) 3. Infrastructure security (20%) 4. Identity and access management (16%) 5. Data protection (18%) 6. Management and security governance (14%) Study path: - Stephane Maarek + Jon Bonso courses on Udemy - AWS Skill Builder practice exams (official) - ACloudGuru hands-on labs - Build the labs yourself: set up GuardDuty, Security Hub, Config rules in a test account
Splunk Core Certified User / Power User
Splunk certifications (free to cheap, high value for SOC roles): Splunk Core Certified User: - Free certification (exam cost: $130, or free through Splunk training) - Covers: search fundamentals, SPL, dashboards, reports - Good foundation for any SOC role using Splunk Splunk Core Certified Power User: - Builds on User cert: custom commands, subsearches, macros, lookups - Cost: $130 Splunk Enterprise Certified Admin: - For those managing Splunk infrastructure (indexers, search heads) - Less relevant for pure analysts Study path: - Splunk free self-paced courses on splunk.com (Splunk Fundamentals 1/2) - Practise SPL daily: write queries for every module 31 scenario in this course - BOTS (Boss of the SOC) — free Splunk CTF with datasets for practise
Senior and Leadership Certifications
CISSP — The Management Gold Standard
CISSP (Certified Information Systems Security Professional) is the most recognised senior security certification globally. It is primarily a management certification — it proves broad knowledge across all security domains, not deep technical skill. Most CISO roles list it as preferred or required.
CISSP (ISC2): Cost: $749 (exam) + ~$150/year membership after passing Format: 125-175 adaptive questions, 4 hours (CAT format — adapts to your level) Experience requirement: 5 years in 2+ of the 8 CISSP domains Without experience: pass exam → become Associate of ISC2 → gain experience → upgrade to CISSP Validity: 3 years (120 CPE credits) 8 CISSP Domains: 1. Security and Risk Management (15%) 2. Asset Security (10%) 3. Security Architecture and Engineering (13%) 4. Communication and Network Security (13%) 5. Identity and Access Management (13%) 6. Security Assessment and Testing (12%) 7. Security Operations (13%) 8. Software Development Security (11%) Study resources: - "CISSP All-in-One Exam Guide" by Shon Harris (definitive reference — long) - Mike Chapple & David Seidl "CISSP Official Study Guide" - Destination Certification MindMaps (YouTube — free, excellent concept map approach) - Boson Practice Exams (hardest practice questions available — worth it) - (ISC)2 Official Practice Tests CISSP exam mindset — "think like a manager": Most wrong answers come from thinking technically (what works?) Think instead: what is the best risk management decision? When in doubt: choose the answer that reduces risk first, then fixes technically
CISM — Security Management
CISM (Certified Information Security Manager) — ISACA:
Cost: $575 (member) / $760 (non-member)
Experience: 5 years in information security management
Domains:
1. Information Security Governance
2. Information Security Risk Management
3. Information Security Program
4. Incident Management
Value: strong alternative to CISSP; more management/governance focused
Common combination: CISM for GRC/management roles + OSCP for technical credibilityCCSP — Cloud Security
CCSP (Certified Cloud Security Professional) — ISC2/CSA:
Cost: $599 (exam)
Experience: 5 years IT + 3 years information security + 1 year cloud security
Domains:
1. Cloud Concepts, Architecture and Design
2. Cloud Data Security
3. Cloud Platform and Infrastructure Security
4. Cloud Application Security
5. Cloud Security Operations
6. Legal, Risk and Compliance
Value: top cloud security management cert; pairs with CISSP for cloud-focused CISOs
Note: CISSP holders can become CCSP with 1 year cloud experience (domain substitution)Study Strategies and Exam Tips
Active vs Passive Learning
Active learning beats passive learning 3:1 in retention: Passive (low retention): - Watch video lectures without pausing - Read textbook without taking notes - Review flashcards you already know Active (high retention): - Pause videos after each concept and explain it back in your own words - Build a lab and reproduce each concept (hands-on) - Do practice questions BEFORE reading the material (struggle then learn) - Teach a concept to a rubber duck or a study partner - Write your own summary after each topic — not copy/paste Spaced repetition: - Review material 1 day, 3 days, 7 days, 21 days after initial study - Use Anki (free flashcard app with built-in spaced repetition) - Download community Security+ / CISSP / OSCP decks from Anki Practice exam strategy: - Take a cold exam first (before studying) — baseline your knowledge - Review EVERY wrong answer and understand WHY it was wrong - Review correct answers you were unsure about — luck is not learning - Last week before exam: do 2 full practice exams per day - Target 80%+ on practice before sitting the real exam
Exam Day Checklist
Before exam day:
□ Schedule exam at your peak energy time (morning for most people)
□ Verify testing centre location OR ensure Pearson OnVUE/Proctorio tech works
□ Bring valid photo ID (government-issued)
□ Review exam policy: what can/cannot be brought in
□ Sleep 8 hours — sleep is the most effective last-day study aid
Exam strategy:
□ Read questions fully before looking at answers
□ For 2-option ties: pick the answer that addresses the root cause, not the symptom
□ Flag uncertain questions and return to them
□ Do NOT change your first answer unless you have new information
(first instinct is correct more often than second-guessing)
□ Time management: Security+ = 60 seconds/question max
□ Performance-based questions: skip on first pass, answer MCQs, return to PBQs
For practical exams (OSCP, PNPT, BTL1):
□ Take thorough notes and screenshots AS YOU GO — not after
□ Document every command and its output
□ Include timestamp in screenshots (or note time in documentation)
□ If stuck: take a break (15-30 min away clears the mental block)
□ Start report template before exam ends while memory is freshFree and Low-Cost Study Resources
| Resource | Cost | Best For | URL |
|---|---|---|---|
| Professor Messer | Free | Security+, Network+ | professormesser.com |
| TryHackMe | Free / $14/mo | Hands-on, all levels | tryhackme.com |
| HackTheBox | Free / $14/mo | Intermediate-advanced pentesting | hackthebox.com |
| PentesterLab | Free / $20/mo | Web application security | pentesterlab.com |
| TCM Security | $30/course | PNPT prep, practical hacking | tcm-sec.com |
| Cybrary | Free / $59/mo | Wide course library, SOC/blue team | cybrary.it |
| SANS Cyber Aces | Free | Networking/OS fundamentals | cyberaces.org |
| OWASP | Free | Web security standards, testing guide | owasp.org |
| Microsoft Learn | Free | Azure/M365 certs, SC-200, AZ-500 | learn.microsoft.com |
| AWS Skill Builder | Free / paid labs | AWS Security Specialty prep | skillbuilder.aws |
| Splunk Free Training | Free | Splunk certification prep | splunk.com/training |
| Destination Certification | Free (YouTube) | CISSP concept maps | youtube.com/c/DestinationCertification |
Career Paths by Role
SOC Analyst Path
SOC Analyst career progression: Tier 1 — Alert triage (entry): Target cert: Security+ → BTL1 Core skills: SIEM queries, phishing analysis, alert triage, basic networking Salary range: $55,000 - $75,000 (US, entry level) Tier 2 — Investigation and response (1-3 years): Target cert: SC-200, CySA+, Splunk Power User Core skills: threat hunting, DFIR basics, malware analysis, custom detection rules Salary range: $75,000 - $100,000 Tier 3 — Threat hunter / IR lead (3-7 years): Target cert: GCIH (SANS), Splunk Enterprise, CCSP Core skills: advanced hunting, incident command, threat intelligence Salary range: $100,000 - $130,000 Management — SOC Manager / Security Manager: Target cert: CISM or CISSP Core skills: team management, metrics, vendor management, executive reporting Salary range: $130,000 - $180,000
Penetration Tester Path
Penetration Tester career progression: Junior Pentester (entry, 0-2 years): Target cert: eJPT → PNPT Core skills: nmap, Metasploit, web exploitation, report writing Portfolio: TryHackMe/HackTheBox write-ups, lab documentation Salary range: $70,000 - $90,000 Mid-level Pentester (2-5 years): Target cert: OSCP (required at most shops), eCPPTv2 Core skills: AD attacks, manual exploitation, custom tooling, client management Salary range: $90,000 - $130,000 Senior Pentester / Red Team (5+ years): Target cert: OSEP, OSWE, CRTO, GPEN Core skills: C2 framework ops, evasion, advanced web, full red team ops Salary range: $130,000 - $180,000+ Red Team Lead / Principal: Target cert: CISSP or CISM for management track Core skills: programme ownership, threat intelligence integration, purple team leadership Salary range: $160,000 - $220,000+
Cloud Security Engineer Path
Cloud Security Engineer career progression: Junior Cloud Security (1-3 years, often from DevOps/SysAdmin): Target cert: AWS SAA (Solutions Architect Associate) → AWS Security Specialty Core skills: IAM, security groups, CloudTrail, CSPM basics Salary range: $90,000 - $120,000 Mid Cloud Security Engineer (3-6 years): Target cert: AWS Security Specialty + CKS (Certified Kubernetes Security Specialist) Core skills: IaC security (Checkov/tfsec), container security, runtime monitoring Salary range: $120,000 - $160,000 Senior Cloud Security Architect (6+ years): Target cert: CCSP, possibly CISSP Core skills: multi-cloud strategy, zero trust architecture, security programme design Salary range: $160,000 - $200,000+
🎯 Key Takeaways
- ✓Certifications open doors — especially in federal, defence, and enterprise markets — but demonstrate skill through labs, CTFs, and write-ups to survive the technical interview.
- ✓For US entry-level roles, CompTIA Security+ is the most impactful first certification: DoD 8570 compliant, widely listed in job postings, vendor-neutral.
- ✓Offensive certs are hard to fake: eJPT → PNPT → OSCP is the proven practical pentesting path; OSCP is the gold standard listed in nearly all senior pentest job postings.
- ✓OSCP exam strategy: tackle the Active Directory set first (40 points, all-or-nothing) then work standalone machines; document every command and screenshot as you go.
- ✓For blue team/SOC roles, BTL1 combined with SC-200 (Microsoft Sentinel) provides strong practical and vendor-specific skills that align with most enterprise environments.
- ✓CISSP is the senior leadership cert: pass it thinking like a risk manager and business leader, not a technical implementer — "what reduces risk?" not "what technically works?"
- ✓Active learning retains 3x more than passive: practise in a lab, teach concepts back to yourself, and do practice questions before reading the material.
- ✓Exam dumps are unethical and counterproductive — they let you pass without understanding, which means you fail on the job; study to understand, not to pass.
- ✓Check employer reimbursement programmes before paying for certifications — most Fortune 500 companies reimburse $1,000-$5,000 per year in professional development.
- ✓No single certification makes a career: one cert + one lab project + one CTF write-up + one networking conversation is more powerful than four certs with no demonstrated hands-on skill.
Module 38 teaches you to earn money finding real vulnerabilities. You will learn how to choose the right programmes, set up an efficient recon workflow, escalate discoveries into valid high-severity reports, and build a bug bounty reputation on HackerOne and Bugcrowd — from first submission to consistent payouts.
Discussion
0Have a better approach? Found something outdated? Share it — your knowledge helps everyone learning here.