Find your next career path.

Browse 42 roadmaps across 7 families. Free guide, no signup required.

All Roadmaps

42 paths, grouped by family.

07 ROADMAPS

Security Operations

Detect, investigate, and respond to threats. SOC analysts, incident responders, threat hunters, threat intelligence.

06 ROADMAPS

AppSec & Software

Build secure software, review code, find and fix vulnerabilities. AppSec engineers, code reviewers, vulnerability researchers, bug bounty hunters.

02 ROADMAPS

Identity & Access

Control who accesses what. IAM engineers, PAM administrators, zero-trust engineers.

05 ROADMAPS

Specialized & Emerging

Cloud security, DevSecOps, AI security, OT/ICS, malware analysis, security architecture — specialized tracks and fast-moving areas.

09 ROADMAPS

IT Operations

Keep infrastructure running. Help desk, sysadmins, network admins/engineers, DBAs, SREs, IT managers.

IT Ops

Database Administrator (DBA)

The professional who installs, configures, secures, tunes, and maintains database management systems. Ensures data is available, performant…

18–24 months2–3 years

IT Ops

Help Desk / IT Support Technician

The first point of contact between users and the IT department. Diagnoses and resolves hardware, software, networking, and account issues,…

3–6 months6–12 months

IT Ops

IT Manager / Team Lead

The manager who leads a team of IT professionals. Hires, develops, directs, and retains engineers, analysts, and administrators while ownin…

5–7 years7–10 years

IT Ops

IT Project Manager

The professional who plans, executes, and delivers technology projects on time, within budget, and within scope. Coordinates developers, en…

2–3 years3–5 years

IT Ops

ITSM / Service Desk Manager

The manager who owns the IT service management function. Leads the service desk team, designs and enforces ITIL-aligned processes for incid…

4-6 years5-8 years

IT Ops

Network Administrator

The professional who designs, implements, and maintains an organization's network infrastructure. Manages routers, switches, firewalls, wir…

18–24 months2–3 years

IT Ops

Network Engineer

The senior networking professional who designs, architects, and implements complex network infrastructure. Moves beyond day-to-day administ…

3–4 years4–6 years

IT Ops

Site Reliability Engineer (SRE)

The engineer who applies software engineering principles to operations problems. Builds the automation, observability, and reliability syst…

18–24 months2–3 years

IT Ops

System Administrator

The engineer who keeps servers, operating systems, and core infrastructure services running. Manages Windows Server and Linux environments,…

18–24 months2–3 years

04 ROADMAPS

Data & Analytics

Turn raw data into insight. Data analysts, BI analysts, data engineers, data scientists.

09 ROADMAPS

GRC, Risk & Compliance

Governance, risk, regulatory compliance. GRC analysts, compliance officers, IT auditors, privacy engineers, risk analysts, CISOs.

GRC

CISO / Security Director

The executive who owns the organization's information security strategy, program, and risk posture. Reports to the CEO, board, or CIO; mana…

15–20 years18–25 years

GRC

Compliance Officer

The professional who owns regulatory compliance for the organization. Translates legal and regulatory requirements into practical policies…

18-24 months2-3 years

GRC

Cybersecurity Program Manager

The leader who designs, builds, and manages an organization's cybersecurity program. Translates security requirements into actionable initi…

6-8 years8-12 years

GRC

GRC Analyst

The professional who sits at the intersection of cybersecurity, business strategy, and regulatory compliance. Translates complex requiremen…

12–18 months18–24 months

GRC

IT Auditor

The professional who independently verifies that IT controls are designed correctly and operating effectively. Tests whether what the organ…

18-24 months2-3 years

GRC

Privacy Engineer

The technical privacy specialist who translates data protection law into engineering implementations. Builds systems that respect user priv…

2-3 years3-5 years

GRC

Risk Analyst

The professional who identifies, assesses, quantifies, and communicates risks to information systems and organizational operations. Conduct…

2–3 years3–5 years

GRC

Security Awareness & Training Manager

The professional who designs, operates, and continuously improves the organization's security awareness and training program. Reduces human…

2-3 years3-5 years

GRC

Vendor / Third-Party Risk Manager

The specialist who designs, operates, and matures the organization's third-party risk management (TPRM) program. Assesses the security, fin…

2–3 years3–5 years

Building your own portfolio?

SEE PRICING →