find your lane · then start studying

Career
paths

Six role-based routes through this site. Each one connects the certification decks, glossary categories, and frameworks that matter for that job.

Not sure which certification to chase? Pick the role that fits where you are headed, then work the decks in order, look up the language as you go, and read the frameworks that the role lives in. Everything here is free and stays in your browser.

Foundations (start here)

Brand new to security, or switching in from IT? Build the vocabulary and the mental model first, then everything else gets easier. Start with fundamentals, then earn a broad entry certification.

Glossary categories
Frameworks & tools

SOC analyst & blue team

Detection, triage, and response: the people watching the alerts and running down incidents. Grow from the Security+ base into analyst and hands-on defensive certifications, with forensics for when things go wrong.

Glossary categories

Governance, risk & compliance (GRC)

Audit, risk management, and the policies that hold a program together. This track is heavy on management certifications and on frameworks; the tools here (assessments, roadmap, the CMMC scorer) are the day job.

Practice decks
Glossary categories

Cloud security

Securing workloads and identities across AWS, Azure, and GCP. Pair a broad base with the two vendor-neutral cloud certifications, and lean hard on identity and protocol fluency.

Practice decks
Glossary categories
Frameworks & tools

Offensive security & pentesting

Red team, ethical hacking, and hands-on penetration testing. This track runs from the survey-level certifications into the practical, exam-in-a-lab credentials, with attack and app-security vocabulary throughout.

Practice decks
Glossary categories
Frameworks & tools

Security leadership & management

The CISO track: strategy, risk in business terms, and running the program. Management certifications carry this path, and the frameworks and planning tools here are what leadership actually operates.

Glossary categories

Certifications appear on more than one path on purpose: a CISSP serves both GRC and leadership, and Security+ underpins almost everything. Follow the path, not the exact order.