- Describe the main roles in cybersecurity and their daily work
- Compare well-known certifications by level and format
- Build a personal learning plan with legal ways to practise
Murad is in the 11th grade and wants to work in cybersecurity. In films a “hacker” is one person typing fast in a dark room. In reality it is a field of dozens of different jobs: defenders, testers, engineers, analysts, auditors and even lawyers. In this lesson we will draw the map together.
Teams and roles
The blue team defends: it monitors, detects and responds. The red team imitates a real attacker under a written agreement and shows the weak spots. When the two work together, it is called a purple team. GRC (governance, risk and compliance) deals with policies, standards and risk assessment.
| Role | What they do | Key skills |
|---|---|---|
| SOC analyst | watches alerts in the SIEM and triages them | networks, logs, operating systems, a calm head |
| Incident responder (DFIR) | investigates incidents and does forensic analysis | memory and disk analysis, timelines, report writing |
| Penetration tester (ethical hacker) | tests systems with written permission and reports the findings | web, networks, Linux, programming, ethics |
| Security engineer | builds defences: firewalls, identity and access, cloud, automation | system administration, scripting, cloud platforms |
| Application security (AppSec) | reviews code, builds threat models, helps developers | programming, OWASP, communication |
| GRC specialist, auditor | writes policies, assesses risks, checks compliance with standards such as ISO/IEC 27001 | risk management, law, writing |
What does a SOC analyst's working day look like? A shift starts by reading the notes from the previous shift. Then alerts arrive: most are false alarms, but each one must be checked, the decision justified and recorded. A suspicious case is escalated to a more experienced colleague. In quieter moments the analyst tunes detection rules so that there are fewer false alarms.
A map of certifications
A certificate does not replace skills, but it structures your learning and helps you get past an employer's first screening. The table below is a neutral overview: exam formats, prices and requirements change, so check the organisation's official website before deciding.
| Certification | Organisation | Level and format |
|---|---|---|
| CompTIA Security+ | CompTIA | entry level, vendor-neutral foundations; multiple-choice and performance-based questions; valid for 3 years, renewed through continuing education |
| CEH (Certified Ethical Hacker) | EC-Council | intermediate; a multiple-choice exam on attack techniques and tools, with a separate practical exam available |
| OSCP | OffSec | intermediate to advanced, fully hands-on: a 24-hour exam in a lab network followed by a written report |
| CISSP | ISC2 | advanced and management-oriented; full status requires about 5 years of relevant work experience |
Where to start: a roadmap
- 1Foundations
Networks (TCP/IP, DNS, HTTP), Linux and Windows, one programming language — usually Python. Educora's informatics and Python courses cover this.
- 2A home lab
Set up virtual machines and install deliberately vulnerable training apps on them. All experiments happen only inside this closed environment.
- 3Legal practice
CTF competitions and training platforms such as TryHackMe and Hack The Box offer tasks you are allowed to attack.
- 4Portfolio and a first certificate
Write up the tasks you solved, share your scripts on GitHub and earn an entry-level certificate.
- 5A first job
An internship in a SOC, IT support or a system administrator job is a good start; specialise later.
Many CTF tasks start with encodings. The key lesson: Base64 is not encryption, just a way of writing data with a different alphabet — anyone can reverse it without a key. A password “hidden” with Base64 in a configuration file is effectively plain text.
import base64
secret = 'password: Xezer2026'
encoded = base64.b64encode(secret.encode()).decode()
print('Encoded:', encoded)
print('Decoded:', base64.b64decode(encoded).decode())▸ Expected output
Encoded: cGFzc3dvcmQ6IFhlemVyMjAyNg== Decoded: password: Xezer2026
A CTF task: the string RWR1Y29yYXtiYXNlNjRfaXNfbm90X2VuY3J5cHRpb259 was found in the log of a practice server. Decode it from Base64 and print the “flag”.
import base64
found = 'RWR1Y29yYXtiYXNlNjRfaXNfbm90X2VuY3J5cHRpb259'
# decode it and print the flag▸ Expected output
Educora{base64_is_not_encryption}Key points
- The blue team defends, the red team imitates attacks with permission, and GRC works with risk and standards.
- Security+ is entry level, CEH intermediate, OSCP fully hands-on and CISSP an advanced certificate that requires experience.
- No certificate replaces permission: only written consent and an agreed scope do.
- Legal practice: a home lab, CTFs and training platforms.
- Base64 is an encoding, not encryption.
Check yourself
10 questions. Every correct answer earns XP.