🟒 Now in early access β€” join free

Stop guessing.
Map your path into
cybersecurity.

Role-specific roadmaps for SOC Analyst, Pentester, GRC, Cloud Security, and more β€” with curated resources from TryHackMe, LetsDefend, BTLO, DetectionStream, Level Effect, Scrimba, TCM Security Academy, Simply Cyber Academy, Pluralsight, and beyond.

6 Role Paths
164+ Skill Nodes
400+ Curated Resources
15 Resource Platforms

❌ The problem today

  • πŸŒͺ️"Where do I start?" β€” 400 conflicting Reddit opinions
  • πŸ“„Static flowcharts with no resources or guidance
  • πŸ’Έ$10,000+ bootcamps that don't map to real jobs
  • 🎯No path tailored to your background, time, or goals
  • πŸ“ŠNo way to track progress or know what's next

βœ… What CyberMap does differently

  • πŸ—ΊοΈRole-specific roadmaps: SOC, Pentest, GRC, Cloud, IR, Detection
  • πŸ“šExact resources on every node β€” TryHackMe, LetsDefend, TCM Academy, Simply Cyber, Pluralsight, Scrimba & more
  • πŸ†“Free to start β€” no $10k bootcamp required
  • ⚑AI personalization for your specific background and timeline
  • πŸ“ˆProgress tracking, streaks, and cert mapping built in

Everything you need to break in

Five differentiators that no static flowchart or generic YouTube playlist gives you.

πŸ—ΊοΈ

Role-Specific Paths

Not one generic map β€” distinct interactive roadmaps for SOC Analyst, Penetration Tester, GRC, Cloud Security, Incident Responder, and Detection Engineer.

πŸ“š

Curated Resources on Every Node

Exact TryHackMe rooms, LetsDefend labs, BTLO challenges, DetectionStream rules, Level Effect quests, Scrimba courses, and YouTube tutorials β€” not generic descriptions.

πŸ“œ

Certification Mapping

Filter the entire roadmap by target certification β€” Security+, CySA+, OSCP, BTL1, AWS Security Specialty β€” and see only what's relevant to your goal.

πŸ“Š

Progress Tracking

Mark nodes as Learning, Done, or Skipped. Dashboard shows completion %, current focus node, streak, and estimated time remaining on your path.

πŸ€–

AI Personalization Coming Soon

Input your background, available hours, target role, and timeline. Get a filtered, ordered path built specifically for you β€” not a beginner template.

🏷️

Resource Provider Tabs

Browse resources by platform β€” switch between TryHackMe, LetsDefend, HackTheBox, DetectionStream, Level Effect, Scrimba, and more inside every roadmap node.

Resources from the best platforms in the field

Every roadmap node links directly to curated content from these providers β€” filtered and organized so you never have to search.

πŸ›‘οΈ
LetsDefend
// letsdefend.io
Blue Team SOC Simulation Free Tier

The most realistic SOC analyst training platform. Work inside a simulated Security Operations Center with a live alert queue, phishing investigations, SIEM analysis, and real escalation workflows β€” exactly like day-one SOC work.

SOC Analyst Incident Responder Threat Hunter Detection Engineer
πŸ”΅
Blue Team Labs Online
// blueteamlabs.online
Blue Team Forensics Free Challenges

Downloadable investigation labs: memory dumps, packet captures, phishing emails, log files. BTLO builds methodical defensive investigation skills. 257 unique labs across forensics, threat hunting, SIEM, and IR.

SOC Analyst Incident Responder Threat Hunter
πŸ“‘
DetectionStream
// detectionstream.com
Detection Eng Sigma / YARA Free

Unify detection engineering across Sigma, YARA, Suricata, and Nova. Search 3,100+ curated rules with MITRE ATT&CK context, convert Sigma across Splunk/Elastic/Sentinel/QRadar, and build new detections with AI assistance.

Detection Engineer SOC Analyst Threat Hunter
βš”οΈ
Level Effect
// leveleffect.com
All Roles Gamified NICE Mapped

Gamified quests with XP, streaks, and AI-graded challenges mapped to the NICE framework. Completed skills build a Skill Sheet verified portfolio β€” shareable proof of real capability for employers.

SOC Analyst Pentester GRC Analyst Incident Responder
πŸ’»
Scrimba
// scrimba.com
Python JavaScript Interactive

Interactive coding screencasts β€” pause and edit the instructor's code directly in the browser. The coding foundation for Security Engineers and Detection Engineers: Python automation, JavaScript, and scripting courses with real projects.

Security Engineer Detection Engineer Cloud Security SOC Analyst
🎯
TryHackMe
// tryhackme.com
All Roles Beginner Friendly

Guided, browser-based hacking rooms. The best starting point for absolute beginners. Pre-configured labs for SOC, pentesting, forensics, and more β€” no setup required.

SOC Analyst Pentester Incident Responder
πŸ’€
TCM Security Academy
// academy.tcm-sec.com
Red Team PNPT Prep Affordable

Practitioner-built offensive security courses by Heath Adams (The Cyber Mentor). The most affordable path from zero to PNPT or OSCP β€” Practical Ethical Hacking, Active Directory Attacks, Web Hacking, and PrivEsc courses all under $60.

Penetration Tester Security Engineer
πŸŽ“
Simply Cyber Academy
// simplycyber.io β€” Gerald Auger
GRC Career Focused Compliance

Gerald Auger's structured GRC curriculum β€” turning his YouTube content into job-focused paid courses. The GRC Analyst Professional course maps to real hiring criteria: NIST, risk management, audit, policy, and compliance in real business contexts.

GRC Analyst SOC Analyst Career Changers
🎬
Pluralsight
// pluralsight.com
GRC Enterprise Skill IQ

Enterprise-trusted security training with Skill IQ assessments. GRC and compliance library covers NIST, ISO 27001, SOC 2, HIPAA, and PCI DSS β€” with before/after skill benchmarks you can share with employers as proof of competency.

GRC Analyst Cloud Security Security Engineer
πŸ“¦
HackTheBox
// hackthebox.com
Red Team CTF / Labs

Real machine hacking and structured academy modules. Best for intermediate-to-advanced offensive security learners. HTB Academy covers web attacks, AD, and more with structured courses.

Penetration Tester Detection Engineer
πŸ›‘οΈ

LetsDefend β€” SOC Simulation Platform

The closest thing to a real SOC job before you have the job.

Best for these roadmap nodes

  • SIEM & Log Analysis
  • Alert Triage & Investigation
  • Phishing Analysis
  • Malware Analysis Basics
  • MITRE ATT&CK for Defenders
  • IR Lifecycle & Playbooks
  • Live SOC Simulation

What makes it stand out

  • Real alert queue β€” not just quizzes
  • Simulated SOC environment with actual SOC tools
  • Phishing, SIEM, malware, forensics in one place
  • VIP+ includes mentorship and career tracking
  • Used by professionals to keep skills sharp
πŸ”΅

Blue Team Labs Online β€” Investigation Labs

Download real artifacts. Investigate like a pro.

Best for these roadmap nodes

  • Digital Forensics Fundamentals
  • Memory Forensics (Volatility)
  • Phishing Analysis
  • Malware & Threat Actor Analysis
  • Threat Hunting Methodology
  • YARA Rule Writing

What makes it stand out

  • 257+ unique investigation labs in Pro tier
  • Real artifacts: memory dumps, PCAPs, email files
  • No guided hand-holding β€” builds real investigative thinking
  • Leaderboard and scoring for accountability
  • Free challenges for everyone β€” no paywall to start
πŸ“‘

DetectionStream β€” Detection Engineering Hub

Search, convert, and create detections across every major SIEM.

Best for these roadmap nodes

  • Sigma Rules β€” Universal Detection Language
  • YARA Rules β€” Malware Detection
  • Suricata & Network Detection
  • MITRE ATT&CK Framework
  • Threat Hunting Methodology
  • CSPM & Cloud Detection

What makes it stand out

  • 3,100+ curated Sigma rules with ATT&CK mappings
  • One-click conversion: Sigma β†’ Splunk, Elastic, Sentinel, QRadar
  • YARA and Suricata frameworks in one tool
  • AI-assisted rule creation with validation
  • Completely free β€” community-supported
βš”οΈ

Level Effect β€” Gamified Career Training

Find your career path. Build a Skill Sheet employers can verify.

Best for these roadmap nodes

  • Networking & OS Foundations
  • Security Fundamentals
  • Alert Triage & Investigation
  • GRC Frameworks & Compliance
  • IR Process & Playbooks
  • Penetration Test Report Writing

What makes it stand out

  • 41 cybersecurity career paths discoverable via quiz
  • NICE framework mapping on every competency
  • Skill Sheet = verified employer portfolio
  • Quests, XP, and streaks for retention
  • 1-on-1 coaching available at advanced tier
πŸ’»

Scrimba β€” Interactive Coding for Security Pros

Pause. Edit the code. Build the skill. No passive video watching.

Best for these roadmap nodes

  • Python Scripting for SOC
  • Python for Pentesting
  • Python & Scripting for Detection
  • Python & Scripting for Cloud Security
  • Infrastructure as Code concepts
  • JavaScript for web security context

What makes it stand out

  • Interactive screencasts β€” edit code mid-lesson in browser
  • Full Python course free β€” 140+ challenges
  • Projects build real scripts, not just exercises
  • AI-powered learning paths adapt to your pace
  • JavaScript, React, TypeScript available for full-stack security
πŸ’€

TCM Security Academy β€” Practical Red Team Training

Affordable, practitioner-built offensive security. No fluff, no filler.

Best for these roadmap nodes

  • Linux Command Line Mastery
  • Python for Pentesting
  • Reconnaissance & Enumeration
  • Vulnerability Exploitation
  • Web Application Hacking
  • Active Directory Attacks
  • Privilege Escalation (Linux & Windows)
  • Pentest Report Writing / PNPT
  • OSCP Preparation

What makes it stand out

  • Built by Heath Adams β€” working pentester, not just an educator
  • Practical Ethical Hacking widely rated best OSCP prep available
  • PNPT cert respected by employers at a fraction of OSCP cost
  • $30–60/course β€” no expensive subscription required
  • AD Attacks, Web Hacking, Mobile, PrivEsc all separate deep-dives
πŸŽ“

Simply Cyber Academy β€” GRC Career Training by Gerald Auger

The most trusted GRC educator on YouTube, now with structured paid courses.

Best for these roadmap nodes

  • Security Fundamentals + Business Context
  • NIST CSF & Risk Management Framework
  • ISO 27001 & SOC 2
  • PCI DSS & HIPAA
  • Risk Assessment Methodology
  • Security Auditing & Assessment

What makes it stand out

  • Gerald Auger is a CISO with decades of real-world experience
  • GRC Analyst Professional course maps to actual hiring criteria
  • Free YouTube channel has 300+ GRC-specific videos as entry point
  • Explains the business context behind every framework
  • Best single resource for career changers targeting GRC roles
🎬

Pluralsight β€” Enterprise GRC & Cybersecurity Training

Skill IQ assessments + the deepest GRC library trusted by enterprise security teams.

Best for these roadmap nodes

  • NIST CSF & Risk Management Framework
  • ISO 27001 & SOC 2
  • PCI DSS & HIPAA Compliance
  • Risk Assessment Methodology
  • Security Auditing & Assessment
  • Cloud Security Posture Management

What makes it stand out

  • Skill IQ measures competency before & after β€” shareable with employers
  • Broadest GRC library: NIST, ISO 27001, SOC 2, HIPAA, PCI DSS
  • Enterprise-trusted β€” used by Fortune 500 security teams
  • 10-day free trial covers a full GRC course
  • Structured learning paths guide multi-course sequences logically

Pick your target role

Six complete career paths β€” from first certificate to first job offer. Each has its own skill nodes, curated resources, and cert mapping.

πŸ›‘οΈ
SOC Analyst
Blue Team

Monitor and respond to security alerts. The most common entry-level cybersecurity role with clear pathways from beginner to hired.

⏱ 6–12 months πŸ“œ Security+, CySA+
βš”οΈ
Penetration Tester
Red Team

Legally hack systems and networks. Find vulnerabilities before attackers do. The most technical and most sought-after offensive role.

⏱ 12–18 months πŸ“œ eJPT, PNPT, OSCP
πŸ“‹
GRC Analyst
GRC

Govern security programs, manage risk, and ensure compliance. A business-facing role with premium salaries in regulated industries.

⏱ 6–10 months πŸ“œ Security+, CISM, CISA
☁️
Cloud Security Engineer
Blue Team

Secure AWS, Azure, and GCP infrastructure. The highest-demand specialty with the highest average salaries in the field right now.

⏱ 12–18 months πŸ“œ AWS Security, AZ-500
πŸš’
Incident Responder
Blue Team

Lead active breach investigations. Contain attacks, investigate intrusions, coordinate recovery. High-pressure, high-impact, highly paid.

⏱ 9–15 months πŸ“œ BTL1, GCIH, CySA+
πŸ“‘
Detection Engineer
Blue Team

Build and tune detection logic. Write Sigma rules, YARA signatures, and SIEM queries. Bridges security engineering with threat intelligence.

⏱ 12–18 months πŸ“œ GDET, CySA+

How we compare to everything else

Feature Paul Jerimy Security Chart Generic YouTube Playlists TryHackMe/HTB CyberMap
Role-specific pathsβœ—βœ—Partialβœ“ 6 roles
Curated resources on nodesβœ—βœ—Own content onlyβœ“ 13 platforms
Certification mappingβœ—Image onlyβœ—βœ“ Filterable
Progress trackingβœ—βœ—Per-course onlyβœ“ Per node
AI personalizationβœ—βœ—βœ—βœ“ Coming Soon
Provider tabs in nodesβœ—βœ—βœ—βœ“ Per node
LetsDefend / BTLO integrationβœ—βœ—βœ—βœ“ Linked
TCM Academy / Simply Cyber / Pluralsightβœ—βœ—βœ—βœ“ Linked
Free to startβœ“βœ“Limitedβœ“

Zero to job-ready in four steps

🎯

Pick Your Target Role

Choose from 6 role-specific roadmaps β€” SOC Analyst, Penetration Tester, GRC, Cloud Security, Incident Responder, or Detection Engineer.

πŸ“Š

Work Through Skill Nodes

Click any node to see its description, time estimate, cert mappings, and curated resources from 13 integrated platforms β€” all in one place.

🏷️

Browse by Provider

Filter resources inside each node by platform β€” TryHackMe, LetsDefend, BTLO, DetectionStream, Level Effect, Scrimba, and more.

πŸ“ˆ

Track Your Progress

Mark nodes as Learning, Done, or Skipped. Watch your completion percentage grow. Know exactly what to study next.

🟒 Free to get started

Stop googling. Start mapping.

Join hundreds of career changers, students, and IT professionals navigating into cybersecurity with a clear, curated path.

Create Free Account Browse Roadmaps