DEV Community

Aisalkyn Aidarova
Aisalkyn Aidarova

Posted on

7-Month Cybersecurity Engineer Roadmap

Duration: 7 Months (28 Weeks)

Each month includes:

  • Theory
  • Hands-on labs
  • Enterprise project
  • Interview preparation

By graduation, every student should have:

  • 5 enterprise projects
  • 1 capstone
  • GitHub portfolio
  • LinkedIn profile
  • Resume showing enterprise experience
  • Experience with 40–50 industry tools

Month 1 — IT & Networking Foundations

Goal

Become a junior system administrator before learning security.

Week 1

Computer Hardware

  • CPU
  • RAM
  • SSD
  • HDD
  • BIOS
  • UEFI
  • Motherboard
  • NIC

Networking

  • IP Address
  • MAC Address
  • DNS
  • DHCP
  • TCP/IP
  • OSI Model
  • HTTP
  • HTTPS
  • SSH
  • VPN

Tools

  • Wireshark
  • Nmap
  • Cisco Packet Tracer

Week 2

Linux Administration

Skills

  • Linux filesystem
  • users
  • groups
  • permissions
  • sudo
  • services
  • logs
  • SSH

Tools

  • Ubuntu
  • Kali Linux
  • Bash
  • Vim

Week 3

Windows Administration

Skills

  • Windows Server
  • Active Directory
  • Group Policy
  • DNS
  • DHCP
  • Event Viewer

Tools

  • PowerShell
  • Active Directory Users & Computers

Week 4

Git

GitHub

Python Basics

REST API

JSON

Virtualization

VMware

VirtualBox


Enterprise Project

Build a company network with

  • Windows Domain Controller
  • Linux Server
  • Active Directory
  • DNS
  • DHCP
  • File Server
  • GitHub Repository

Month 2 — Security Foundations

Goal

Learn how hackers attack systems.


Week 5

Linux Security

  • SSH hardening
  • firewall
  • ufw
  • iptables

Week 6

Windows Security

  • Group Policy
  • Windows Defender
  • BitLocker
  • Event Logs

Week 7

Network Security

  • Firewalls
  • IDS
  • IPS
  • VPN
  • NAC

Tools

  • pfSense
  • Snort
  • Suricata
  • Zeek

Week 8

Web Security

OWASP Top 10

  • SQL Injection
  • XSS
  • CSRF
  • Authentication
  • Session Hijacking

Tools

  • Burp Suite
  • OWASP ZAP
  • Postman

Enterprise Project

Secure a company network and web application.


Month 3 — SOC & Detection Engineering

Goal

Become a SOC Analyst.


Week 9

SIEM

Splunk

Microsoft Sentinel

Elastic


Week 10

Windows Logging

Sysmon

Windows Events

Event Forwarding


Week 11

Threat Hunting

MITRE ATT&CK

Sigma Rules

IOC

IOA

Threat Intelligence


Week 12

Detection Engineering

Tools

  • Sigma
  • YARA
  • Velociraptor

Students create

  • detection rules
  • dashboards
  • alerts

Enterprise Project

Build an enterprise SOC.

Generate attacks.

Detect them.

Write reports.


Month 4 — Incident Response & Digital Forensics

Goal

Become Incident Responder.


Week 13

Incident Response Lifecycle

NIST

MITRE

Playbooks


Week 14

Memory Forensics

Tools

Volatility

FTK Imager

Autopsy


Week 15

Malware Analysis

Tools

PEStudio

Any.Run

VirusTotal

ProcMon

Process Explorer


Week 16

Threat Intelligence

MISP

Shodan

AbuseIPDB

GreyNoise

AlienVault OTX


Enterprise Project

Simulate ransomware attack.

Contain.

Recover.

Write executive report.


Month 5 — Cloud Security + DevSecOps

Goal

Protect cloud infrastructure.


Week 17

AWS

IAM

VPC

EC2

CloudTrail

CloudWatch

Security Groups


Week 18

AWS Security

GuardDuty

Inspector

Security Hub

AWS Config

KMS

Secrets Manager


Week 19

Containers

Docker

Docker Security

Kubernetes

RBAC

Network Policies


Week 20

DevSecOps

GitHub Actions

Jenkins

Terraform

SonarQube

Trivy

Checkov

Semgrep

OWASP Dependency Check


Enterprise Project

Deploy secure cloud application.

Implement CI/CD.

Add security scanning.


Month 6 — Red Team + Purple Team

Goal

Understand attacker mindset.


Week 21

MITRE ATT&CK

Atomic Red Team


Week 22

Active Directory Attacks

BloodHound

Impacket

Responder

Kerberoasting


Week 23

Ethical Hacking

Metasploit

Burp

Nmap

Hydra

SQLMap


Week 24

Purple Team

Caldera

MITRE

Detection Validation


Enterprise Project

Blue Team detects attacks generated by Red Team.


Month 7 — Enterprise Experience

Goal

Work exactly like a Cybersecurity Engineer.


Week 25

Project 1

Enterprise SOC


Week 26

Project 2

Cloud Security Engineer

Secure AWS infrastructure.


Week 27

Project 3

DevSecOps Engineer

Secure CI/CD pipeline.


Week 28

Capstone

Students build an enterprise security environment.

They present to instructors acting as CIO, CISO, and Security Director.


Interview Preparation (Every Week)

Every week students practice:

  • Tell me about yourself
  • Incident response scenarios
  • SOC analyst questions
  • Windows troubleshooting
  • Linux troubleshooting
  • Cloud troubleshooting
  • Active Directory
  • Threat hunting
  • Malware analysis
  • Detection engineering
  • AWS security
  • DevSecOps
  • Behavioral interview
  • Resume review
  • LinkedIn optimization

Enterprise Projects (Portfolio)

By graduation, each student completes:

  1. Enterprise Windows Active Directory Domain
  2. SOC with Splunk/Sentinel
  3. Ransomware Incident Response
  4. Secure AWS Cloud Environment
  5. DevSecOps Pipeline (GitHub Actions, Terraform, Docker, Kubernetes)
  6. Purple Team Attack & Detection Lab
  7. Capstone Enterprise Security Architecture

Skills After Graduation

Students should be able to:

  • Build and secure Windows Active Directory environments
  • Administer Linux servers securely
  • Analyze network traffic with Wireshark and Zeek
  • Detect attacks using Splunk, Sentinel, and Sigma rules
  • Perform threat hunting and digital forensics
  • Respond to incidents using industry-standard playbooks
  • Secure AWS workloads using IAM, GuardDuty, Security Hub, Inspector, Config, and KMS
  • Build secure CI/CD pipelines with GitHub Actions, Jenkins, Terraform, Docker, Kubernetes, SonarQube, Trivy, Checkov, and Semgrep
  • Conduct vulnerability assessments and web application testing
  • Collaborate with developers, DevOps engineers, and IT teams
  • Produce executive reports and communicate technical findings to management
  • Pass technical interviews for Cybersecurity Engineer, Cloud Security Engineer, SOC Analyst, Incident Response Analyst, Security Engineer, and DevSecOps Engineer roles.

This roadmap is intentionally designed around how enterprise security teams operate, so students are learning workflows and projects that closely resemble real production environments rather than isolated labs.

Top comments (0)