MarzleyTech Learn

Home / Learn / Career roadmaps (step-by-step paths to a tech job) / Cybersecurity roadmap: networking, Linux, security skills, labs and certifications

Cybersecurity roadmap: networking, Linux, security skills, labs and certifications

Cybersecurity professionals protect organisations from attacks: phishing, ransomware, stolen passwords, fraud, data leaks and SIM-swap scams. Kenyan banks, SACCOs, telcos, fintechs, insurers, government agencies, hospitals and universities all need security people, and so do the companies that serve them.

Security is not an entry-level skill on its own. You protect systems you understand. That is why this roadmap starts with IT basics, networking and Linux before any "hacking".

The main job families

PathWhat they doTypical entry route
SOC analyst (defensive / "blue team")Watch alerts, investigate suspicious activity, respond to incidentsThe most common first security job
Penetration tester (offensive / "red team")Legally attack systems to find weaknesses before criminals doUsually after 1–3 years of IT, networking or SOC experience
GRC (governance, risk, compliance)Policies, audits, risk assessments, data protection complianceGood for people from audit, law or business backgrounds
Security engineerBuild and configure firewalls, identity systems and secure cloud setupsAfter networking or system administration experience
Digital forensics and fraudInvestigate incidents and fraud, preserve evidenceBanks, telcos, audit firms, law enforcement

Stage 1: IT foundations (4–6 weeks)

You must be comfortable with computers before you can secure them.

Checkpoint: you can install Windows or Linux in a virtual machine (VirtualBox is free) and explain what RAM, CPU, storage and the operating system each do.

Stage 2: Networking (6–8 weeks): the most important foundation

Most attacks travel over networks. You must know how traffic flows.

Checkpoint: you can subnet a /24 into four networks, name the ports for HTTP, HTTPS, SSH, DNS and RDP, and explain what happens when you type a website address into a browser.

Stage 3: Linux and the command line (4–6 weeks)

Most servers and almost all security tools run on Linux.

Checkpoint: you can SSH into a server, read /var/log/auth.log and use grep to find failed logins.

Stage 4: Security fundamentals (4–6 weeks)

The whole Cybersecurity subject:

Stage 5: Scripting (3–4 weeks)

Security people automate: parsing logs, checking lists of IPs, calling APIs.

Checkpoint: a Python script that reads a log file and lists the top 10 IP addresses with failed logins.

Stage 6: Web security (3–4 weeks)

Websites are the most attacked surface. Understand how they're built (do at least HTML, a little JavaScript and PHP/SQL from the web developer roadmap), then:

  • Web security: SQL injection, XSS, CSRF, broken authentication
  • Forms and security in PHP: how developers prevent them
  • The OWASP Top 10 (free at owasp.org): the industry list of the most critical web risks
  • Practise legally on deliberately vulnerable apps such as OWASP Juice Shop or DVWA, running on your own machine

Stage 7: Hands-on labs (ongoing, start in stage 3)

PlatformCostGood for
TryHackMeMany free rooms; paid plan optionalGuided beginner paths (pre-security, SOC level 1)
Hack The Box (Academy and labs)Free tier + paidDeeper practice, both offensive and defensive
PicoCTFFreeBeginner capture-the-flag challenges
OverTheWire (Bandit)FreeLinux command line skills through games
Blue Team Labs Online / LetsDefendFree tiersSOC-style investigation
Your own home labFree (VirtualBox)Kali Linux + a vulnerable VM + a Windows VM

Write a short write-up for each lab you finish (what you found, how, how to fix it). Don't publish write-ups for active competition challenges.

Stage 8: Certifications

Certifications matter more in security than in web development, because many employers and government tenders ask for them. Start with one entry-level certificate:

CertificationLevelNotes
ISC2 Certified in Cybersecurity (CC)EntryISC2 has run free training and exam offers for this; check the current terms on isc2.org
Google Cybersecurity CertificateEntryOnline (Coursera); financial aid is available
CompTIA Security+Entry-to-midWidely recognised by employers; the exam is paid
Cisco CCNANetworkingExcellent foundation; Cisco Networking Academy courses are offered at many Kenyan universities and colleges
CompTIA CySA+ / Blue Team Level 1SOCAfter some experience
eJPT, then OSCPPenetration testingOSCP is advanced and respected

Prices change; check the official sites and beware of "exam dump" sellers (cheating gets certificates revoked).

Stage 9: Portfolio and first job

Your security portfolio:

  1. A home lab write-up with a network diagram.
  2. 5–10 lab write-ups (TryHackMe rooms, PicoCTF challenges).
  3. A Python security tool, e.g. a log analyser or a password-strength checker, on GitHub.
  4. A security audit of your own website project: what you tested, what you fixed.
  5. A security awareness guide for a small business (see small business security): shows you can communicate.

Entry routes: IT support or helpdesk → SOC analyst; network technician → security engineer; graduate trainee programmes at banks and telcos; attachments in ICT departments. See cybersecurity careers and networking careers and certifications. Many people enter security after a year or two in the IT support roadmap; that's a normal, sensible path.

Summary

  • Foundations first: IT basics → networking → Linux → security fundamentals → scripting → web security.
  • Practise only on legal labs and your own systems.
  • One entry certificate (ISC2 CC, Google, Security+ or CCNA) plus a lab portfolio.
  • SOC analyst is the most common first security job; IT support is a common stepping stone.

Check yourself

  1. Which Kenyan law makes unauthorised access to computer systems a crime? Name it without the year.

    Show answer

    Computer Misuse and Cybercrimes Act

  2. What does SOC stand for? (three words)

    Show answer

    Security Operations Centre

  3. Which list from OWASP covers the most critical web risks? (OWASP Top __)

    Show answer

    10

  4. What port does SSH use by default?

    Show answer

    22

  5. In the CIA triad, what does the C stand for?

    Show answer

    confidentiality

Lesson 4 of 6 in Career roadmaps (step-by-step paths to a tech job) · Written by · Course notes