Software, IT, Cloud & Cybersecurity
Become a Cybersecurity Analyst
A practical five-milestone plan built for your exact starting point: Software Engineer.
How much of this field do you already know?
By when do you want to get there?
Without a date, the plan below starts today at the typical pace for your level. Dates are planning guidance from this guide's practical ranges — exam-gated routes must follow the official notification calendar.
Practical range (your level)
3–6 months
Weekly time to commit
Beginner 14–18; Intermediate 10–14; IT/network professional 7–10 hours/week
Route type
Skills
First realistic roles
SOC Analyst L1 / Junior Security Analyst / Network Security Trainee
You already bring
- Coding
- web architecture
- testing
- deployment
Gaps this plan closes
- Security principles, threat modelling, network defence and incident response
Your path — five stops
Dates assume you start today — set a target date above to reshape them. Tap a stop to open it.
Eligibility, baseline and setupComplete by 16 Aug 2026 · 2 weeks
Do this: Complete a diagnostic, install the tools, create a public/private learning repository and write a one-page gap plan.
Done when: Eligibility and time plan are verified; tools work; baseline weaknesses are documented.
Complete this stop to unlock: Qualify for SOC Analyst / Junior Security Analyst interviews without relying only on certifications
NetworkingLinuxoperating systemsPython/shell basicssecurity ethicsAvoid: Do not confuse watching introductory videos with completing practical work.
Core capability buildComplete by 20 Sept 2026 · 5 weeks
Do this: Complete structured exercises and a small applied task linked to: Documented network and Linux hardening lab.
Done when: Can complete representative core tasks independently and explain errors and trade-offs.
Complete this stop to unlock: Qualify for SOC Analyst / Junior Security Analyst interviews without relying only on certifications
Threats and vulnerabilitiesidentityweb securitySOC workflowsloggingincident responseAvoid: Avoid collecting many technologies without depth in the target stack.
Portfolio proof 1Complete by 25 Oct 2026 · 5 weeks
Do this: Documented network and Linux hardening lab
Done when: Project is reproducible, documented and independently reviewed; limitations are explicit.
Complete this stop to unlock: Qualify for SOC Analyst / Junior Security Analyst interviews without relying only on certifications
Home labpacket analysisvulnerability write-upslog triageauthorised CTFsAvoid: Avoid tutorial clones, copied code and metrics without a baseline.
Advanced proof and capstoneComplete by 22 Nov 2026 · 4 weeks
Do this: SOC investigation with alerts, timeline and incident report. Then complete the capstone: Defensive security portfolio containing detections, incident playbook, secure configuration and legal/ethical boundaries.
Done when: Capstone runs end to end, includes tests/validation and survives a technical review.
Complete this stop to unlock: Qualify for SOC Analyst / Junior Security Analyst interviews without relying only on certifications
SIEMcloud securitydetection engineeringthreat modellingreporting and governanceAvoid: Avoid oversized projects that never reach a usable, documented state.
Selection sprint and end goalComplete by 20 Dec 2026 · 4 weeks
Do this: Prepare a targeted CV/portfolio, complete three mocks, apply to the first realistic roles and track conversion.
Done when: Complete at least 20 legal labs, write three clear incident reports and explain network traffic, authentication and common web risks.
Complete this stop to unlock: Qualify for SOC Analyst / Junior Security Analyst interviews without relying only on certifications
Networking and Linux testssecurity scenariolog investigationportfolio walkthroughethicsAvoid: Avoid generic applications and claiming senior titles before demonstrating entry-level competence.
Applications and selection: Use internships, campus/off-campus hiring, referrals and employer assessments. Prepare the actual selection stack: Networking and Linux tests; security scenario; log investigation; portfolio walkthrough; ethics. Verify each job description rather than assuming one universal qualification.
More about this transition — study approach, evidence, selection
How to study from your position
Preserve current-job performance, map transferable evidence and close only critical gaps. Prioritise SIEM; cloud security; detection engineering; threat modelling; reporting and governance; produce Defensive security portfolio containing detections, incident playbook, secure configuration and legal/ethical boundaries and prepare for Networking and Linux tests; security scenario; log investigation; portfolio walkthrough; ethics.
Secure and threat-model an application you understand.
Evidence that makes you credible
Project 1: Documented network and Linux hardening lab Project 2: SOC investigation with alerts, timeline and incident report Capstone: Defensive security portfolio containing detections, incident playbook, secure configuration and legal/ethical boundaries Readiness metric: Complete at least 20 legal labs, write three clear incident reports and explain network traffic, authentication and common web risks.
How selection actually works
Networking and Linux tests; security scenario; log investigation; portfolio walkthrough; ethics
The finish line
Qualify for SOC Analyst / Junior Security Analyst interviews without relying only on certifications
Eligibility and regulation
All practical testing must be conducted only on systems you own or have explicit permission to test.
Starting from somewhere else?
Every resource link on this page was opened and checked on 2026-07-26; unverifiable links were removed rather than shipped. Ranges and week counts come from the StudyBddy careers guide — confirm eligibility and selection steps in the latest official notification before you apply.