Created Certification Roadmaps (markdown)
parent
617ddf4bbd
commit
769d1f8112
|
|
@ -0,0 +1,237 @@
|
|||
# Certification Roadmaps
|
||||
|
||||
Role-based certification paths for cybersecurity careers. Each roadmap progresses from entry-level to expert.
|
||||
|
||||
## Quick Navigation
|
||||
|
||||
| Role | Entry Cert | Target Cert |
|
||||
|------|------------|-------------|
|
||||
| [SOC Analyst](#soc-analyst) | Security+ | CISSP |
|
||||
| [Penetration Tester](#penetration-tester) | Security+ | OSCP/OSEP |
|
||||
| [Security Engineer](#security-engineer) | Security+ | CISSP |
|
||||
| [Incident Responder](#incident-responder) | Security+ | GCFA/GREM |
|
||||
| [Security Architect](#security-architect) | Security+ | CISSP/SABSA |
|
||||
| [Cloud Security Engineer](#cloud-security-engineer) | Security+ | CCSP |
|
||||
| [GRC Analyst](#grc-analyst) | Security+ | CISA/CRISC |
|
||||
| [Threat Intelligence](#threat-intelligence-analyst) | Security+ | GCTI |
|
||||
| [Application Security](#application-security) | Security+ | OSWE |
|
||||
| [Network Security](#network-security-engineer) | Network+ | CCNP Security |
|
||||
|
||||
---
|
||||
|
||||
## SOC Analyst
|
||||
|
||||
Security Operations Center analyst monitoring and responding to security events.
|
||||
|
||||
```
|
||||
Security+ ──> CySA+ ──> GCIH ──> CEH ──> GCIA ──> CISSP
|
||||
Entry Core Incident Ethical Intrusion Senior
|
||||
Handler Hacking Analysis
|
||||
```
|
||||
|
||||
| Level | Certification | Organization |
|
||||
|-------|--------------|--------------|
|
||||
| Entry | [Security+](https://www.comptia.org/certifications/security) | CompTIA |
|
||||
| Core | [CySA+](https://www.comptia.org/certifications/cybersecurity-analyst) | CompTIA |
|
||||
| Intermediate | [GCIH](https://www.giac.org/certifications/certified-incident-handler-gcih/) | GIAC |
|
||||
| Intermediate | [CEH](https://www.eccouncil.org/train-certify/certified-ethical-hacker-ceh/) | EC-Council |
|
||||
| Advanced | [GCIA](https://www.giac.org/certifications/certified-intrusion-analyst-gcia/) | GIAC |
|
||||
| Senior | [CISSP](https://www.isc2.org/Certifications/CISSP) | (ISC)² |
|
||||
|
||||
---
|
||||
|
||||
## Penetration Tester
|
||||
|
||||
Offensive security professional testing systems for vulnerabilities.
|
||||
|
||||
```
|
||||
Security+ ──> PenTest+ ──> CEH ──> OSCP ──> OSEP/GXPN
|
||||
Entry Entry Mid Gold Expert
|
||||
Pentest Standard
|
||||
```
|
||||
|
||||
| Level | Certification | Organization |
|
||||
|-------|--------------|--------------|
|
||||
| Foundation | [Security+](https://www.comptia.org/certifications/security) | CompTIA |
|
||||
| Entry Pentest | [PenTest+](https://www.comptia.org/certifications/pentest) | CompTIA |
|
||||
| Intermediate | [CEH](https://www.eccouncil.org/train-certify/certified-ethical-hacker-ceh-v12/) | EC-Council |
|
||||
| Advanced | [OSCP](https://www.offsec.com/courses-and-certifications/oscp-certification) | OffSec |
|
||||
| Expert | [OSEP](https://www.offsec.com/courses-and-certifications/osep-certification) | OffSec |
|
||||
| Expert | [GXPN](https://www.giac.org/certification/exploit-researcher-advanced-penetration-tester-gxpn/) | GIAC |
|
||||
|
||||
---
|
||||
|
||||
## Security Engineer
|
||||
|
||||
Building and maintaining security infrastructure.
|
||||
|
||||
```
|
||||
Security+ ──> CySA+ ──> SecurityX ──> CISSP ──> CCSP
|
||||
Entry Mid Advanced Expert Cloud
|
||||
```
|
||||
|
||||
| Level | Certification | Organization |
|
||||
|-------|--------------|--------------|
|
||||
| Foundation | [Security+](https://www.comptia.org/certifications/security) | CompTIA |
|
||||
| Intermediate | [CySA+](https://www.comptia.org/certifications/cysa) | CompTIA |
|
||||
| Advanced | [SecurityX](https://www.comptia.org/certifications/securityx) | CompTIA |
|
||||
| Expert | [CISSP](https://www.isc2.org/Certifications/CISSP) | (ISC)² |
|
||||
| Cloud | [CCSP](https://www.isc2.org/Certifications/CCSP) | (ISC)² |
|
||||
|
||||
---
|
||||
|
||||
## Incident Responder
|
||||
|
||||
Responding to and investigating security incidents.
|
||||
|
||||
```
|
||||
Security+ ──> CySA+ ──> GCIH ──> GCFA ──> GREM
|
||||
Entry Core Handler Forensics Malware
|
||||
```
|
||||
|
||||
| Level | Certification | Organization |
|
||||
|-------|--------------|--------------|
|
||||
| Entry | [Security+](https://www.comptia.org/certifications/security) | CompTIA |
|
||||
| Core | [CySA+](https://www.comptia.org/certifications/cybersecurity-analyst) | CompTIA |
|
||||
| Core IR | [GCIH](https://www.giac.org/certifications/certified-incident-handler-gcih/) | GIAC |
|
||||
| Forensics | [GCFA](https://www.giac.org/certifications/certified-forensic-analyst-gcfa/) | GIAC |
|
||||
| Malware | [GREM](https://www.giac.org/certifications/reverse-engineering-malware-grem/) | GIAC |
|
||||
|
||||
---
|
||||
|
||||
## Security Architect
|
||||
|
||||
Designing enterprise security architecture.
|
||||
|
||||
```
|
||||
Security+ ──> SecurityX ──> CISSP ──> CCSP ──> SABSA/TOGAF
|
||||
Entry Advanced Required Cloud Architecture
|
||||
```
|
||||
|
||||
| Level | Certification | Organization |
|
||||
|-------|--------------|--------------|
|
||||
| Foundation | [Security+](https://www.comptia.org/certifications/security) | CompTIA |
|
||||
| Advanced | [SecurityX](https://www.comptia.org/certifications/securityx) | CompTIA |
|
||||
| Required | [CISSP](https://www.isc2.org/Certifications/CISSP) | (ISC)² |
|
||||
| Cloud | [CCSP](https://www.isc2.org/Certifications/CCSP) | (ISC)² |
|
||||
| Architecture | [SABSA](https://sabsa.org/sabsa-chartered-architect-programme/) | SABSA Institute |
|
||||
| Enterprise | [TOGAF](https://www.opengroup.org/certifications/togaf-certifications) | The Open Group |
|
||||
|
||||
---
|
||||
|
||||
## Cloud Security Engineer
|
||||
|
||||
Securing cloud infrastructure across AWS, Azure, GCP.
|
||||
|
||||
```
|
||||
Security+ ──> AWS/Azure Security ──> CCSK ──> CCSP ──> CISSP
|
||||
Entry Vendor-Specific Neutral Advanced Expert
|
||||
```
|
||||
|
||||
| Level | Certification | Organization |
|
||||
|-------|--------------|--------------|
|
||||
| Foundation | [Security+](https://www.comptia.org/certifications/security) | CompTIA |
|
||||
| AWS | [AWS Security Specialty](https://aws.amazon.com/certification/certified-security-specialty/) | AWS |
|
||||
| Azure | [Azure Security Engineer](https://learn.microsoft.com/en-us/certifications/azure-security-engineer/) | Microsoft |
|
||||
| Neutral | [CCSK](https://cloudsecurityalliance.org/education/ccsk) | CSA |
|
||||
| Advanced | [CCSP](https://www.isc2.org/Certifications/CCSP) | (ISC)² |
|
||||
| Expert | [CISSP](https://www.isc2.org/Certifications/CISSP) | (ISC)² |
|
||||
|
||||
---
|
||||
|
||||
## GRC Analyst
|
||||
|
||||
Governance, Risk, and Compliance specialist.
|
||||
|
||||
```
|
||||
Security+ ──> CISA ──> CRISC ──> CISSP ──> ISO 27001 Lead Auditor
|
||||
Entry Audit Risk Advanced Compliance
|
||||
```
|
||||
|
||||
| Level | Certification | Organization |
|
||||
|-------|--------------|--------------|
|
||||
| Foundation | [Security+](https://www.comptia.org/certifications/security) | CompTIA |
|
||||
| Audit | [CISA](https://www.isaca.org/credentialing/cisa) | ISACA |
|
||||
| Risk | [CRISC](https://www.isaca.org/credentialing/crisc) | ISACA |
|
||||
| Advanced | [CISSP](https://www.isc2.org/Certifications/CISSP) | (ISC)² |
|
||||
| Compliance | [ISO 27001 Lead Auditor](https://pecb.com/en/education-and-certification/iso-iec-27001-lead-auditor) | PECB |
|
||||
|
||||
---
|
||||
|
||||
## Threat Intelligence Analyst
|
||||
|
||||
Analyzing and reporting on cyber threats.
|
||||
|
||||
```
|
||||
Security+ ──> CySA+ ──> GCTI ──> GCIA ──> GOSI
|
||||
Entry Core Intel Intrusion OSINT
|
||||
```
|
||||
|
||||
| Level | Certification | Organization |
|
||||
|-------|--------------|--------------|
|
||||
| Foundation | [Security+](https://www.comptia.org/certifications/security) | CompTIA |
|
||||
| Core | [CySA+](https://www.comptia.org/certifications/cysa) | CompTIA |
|
||||
| Intel | [GCTI](https://www.giac.org/certification/cyber-threat-intelligence-gcti/) | GIAC |
|
||||
| Intrusion | [GCIA](https://www.giac.org/certification/certified-intrusion-analyst-gcia/) | GIAC |
|
||||
| OSINT | [GOSI](https://www.giac.org/certification/open-source-intelligence-gosi/) | GIAC |
|
||||
|
||||
---
|
||||
|
||||
## Application Security
|
||||
|
||||
Securing software and web applications.
|
||||
|
||||
```
|
||||
Security+ ──> CEH/CySA+ ──> CSSLP ──> OSWE ──> GWAPT
|
||||
Entry Foundation SDL Web App Web Pentest
|
||||
```
|
||||
|
||||
| Level | Certification | Organization |
|
||||
|-------|--------------|--------------|
|
||||
| Foundation | [Security+](https://www.comptia.org/certifications/security) | CompTIA |
|
||||
| Foundation | [CEH](https://www.eccouncil.org/train-certify/certified-ethical-hacker-ceh/) | EC-Council |
|
||||
| SDL | [CSSLP](https://www.isc2.org/Certifications/CSSLP) | (ISC)² |
|
||||
| Web Expert | [OSWE](https://www.offensive-security.com/web-expert-oswe/) | OffSec |
|
||||
| Web Pentest | [GWAPT](https://www.giac.org/certifications/web-application-penetration-tester-gwapt/) | GIAC |
|
||||
|
||||
---
|
||||
|
||||
## Network Security Engineer
|
||||
|
||||
Securing network infrastructure.
|
||||
|
||||
```
|
||||
Network+ ──> Security+ ──> CCNA ──> CCNP Security ──> CISSP
|
||||
Entry Security Cisco Advanced Expert
|
||||
```
|
||||
|
||||
| Level | Certification | Organization |
|
||||
|-------|--------------|--------------|
|
||||
| Foundation | [Network+](https://www.comptia.org/certifications/network) | CompTIA |
|
||||
| Security | [Security+](https://www.comptia.org/certifications/security) | CompTIA |
|
||||
| Cisco | [CCNA](https://www.cisco.com/c/en/us/training-events/training-certifications/certifications/associate/ccna.html) | Cisco |
|
||||
| Advanced | [CCNP Security](https://www.cisco.com/c/en/us/training-events/training-certifications/certifications/professional/ccnp-security.html) | Cisco |
|
||||
| Expert | [CISSP](https://www.isc2.org/Certifications/CISSP) | (ISC)² |
|
||||
|
||||
---
|
||||
|
||||
## Study Resources
|
||||
|
||||
### Free
|
||||
- [Professor Messer](https://www.professormesser.com/) - CompTIA video courses
|
||||
- [Cybrary](https://www.cybrary.it) - Free courses
|
||||
- [TryHackMe](https://tryhackme.com/) - Hands-on labs
|
||||
|
||||
### Paid
|
||||
- [Udemy](https://www.udemy.com/) - Jason Dion, Mike Meyers courses
|
||||
- [INE](https://ine.com/) - Security specialization
|
||||
- [CBT Nuggets](https://www.cbtnuggets.com/) - Video training
|
||||
|
||||
### Practice Exams
|
||||
- [Boson](https://www.boson.com/) - Premium practice tests
|
||||
- [ExamCompass](https://www.examcompass.com/) - Free practice
|
||||
- [Pocket Prep](https://pocketprep.com/) - Mobile app
|
||||
|
||||
---
|
||||
|
||||
See the main [README](https://github.com/CarterPerez-dev/Cybersecurity-Projects) for complete certification tables with all links.
|
||||
Loading…
Reference in New Issue