Cybersecurity is not one job. It is a set of connected career paths. A beginner usually needs one broad certification plus an entry route, not ten job titles at once. Most people start in IT support or network administration. From there they move into a security operations centre (SOC) analyst role. Later they branch toward penetration testing, security engineering, digital forensics, cloud security, governance and risk, or management. That last step usually follows years of experience. Demand for the field is well documented. The US Bureau of Labor Statistics projects 21% employment growth for information security analysts from 2025 to 2035. That growth rate is much faster than average. The median annual pay for the role in 2025 was $129,180. This article sets out how the roles connect, which certifications each one needs, and where a beginner can start.
How the roles connect
Job listings rarely explain how one cybersecurity role leads to another. The path below shows a common progression, not the only one. Each stage names the certification most often tied to it. That way you can see where a beginner enters, and what an experienced-track role expects later.

Comparing seven cybersecurity roles
The table below lists seven real, currently used job titles. Each row shows a typical entry route and core skills. It also names a confirmed certification for that role, if one exists. Two rows show no fixed certification, because the requirement varies by employer.

Try this now
Match your own background against the table. Pick the one role closest to where you are today. Open that certification's official exam page. Write down two topics from its syllabus you would need to study first. This takes ten minutes and shows whether the gap is small or large.
The SOC analyst role, and the exam behind it
A SOC analyst monitors security alerts and logs, triages incidents, and escalates confirmed threats. It is usually the first dedicated security role someone holds. The EC-Council Certified SOC Analyst (CSA) exam, code 312-39, targets current and aspiring Tier I and Tier II SOC analysts. It runs for 3 hours with 100 multiple-choice questions and a 70% pass mark. EC-Council recommends a working understanding of networking, TCP/IP and common security tools. It states no fixed number of required years of experience.
Ethnus's Certified SOC Analyst (CSA) course aligns to this exact exam. It targets SOC analyst, cybersecurity analyst and network security operator roles. The syllabus runs 150 hours across 39 lessons in six modules. These cover security operations and management, and cyber threats and attack methodology. They also cover incidents and logging, incident detection with SIEM and with threat intelligence, and incident response. Each module maps onto the SOC analyst work described above. The course includes trainer-led sessions, lab-based industry-relevant projects, and live walkthrough sessions.
Certifications: where to start
Not every certification suits a beginner. Some assume years of prior work. Start with one that states its background as recommended, not required.

CompTIA Security+, currently version 7, exam code SY0-701, is a broad entry credential. It covers network security, threat management, cryptography and risk management. CompTIA recommends Network+ plus two years of experience, but states neither as a hard requirement. Checked against the official CompTIA Security+ page on 8 September 2026.
CompTIA PenTest+, version 3, exam code PT0-003, targets penetration tester and security consultant roles. It recommends Network+ and Security+ plus three to four years in a pentest role. CompTIA also offers beginner-track preparation for candidates without that background.
Two certifications only make sense once you already hold years of security experience. The (ISC)2 CCSP certification requires five years of paid work experience. It spans cloud architecture, data security, platform security, application security, security operations, and legal and compliance. The ISACA CISM certification requires a minimum of five years of information security experience, including three years in security management. That experience must fall within the ten years before applying. Both are worth planning toward, not attempting first.
Getting your first cybersecurity job
The market data supports treating this as a genuine, growing field. Beyond that growth projection, the BLS projects about 14,100 annual openings for information security analysts. That figure covers the full decade to 2035. The BLS also lists a bachelor's degree in computer science or a related field as the typical entry education for this role, usually alongside under five years of prior IT experience. CyberSeek's heat map shows 457,398 national cybersecurity job openings as a current snapshot. That figure updates as the map refreshes.
The 2025 ISC2 Cybersecurity Workforce Study surveyed 16,029 respondents, published 4 December 2025. It frames the gap in terms of skills, not headcount. Some 59% of respondents report critical or significant skill needs. About 95% report at least one skill need. Read this as employers needing specific, current skills, not a single missing-workers number.
IT support or network administration remains a common starting point before moving into a security-specific role. It builds the systems and networking background most security jobs assume. A certification alone does not finish the job search. Pair it with a hands-on project. Try setting up a home SIEM instance, or writing up an incident response walkthrough. That way you can explain your reasoning in an interview.
Your next step with Ethnus
If the SOC analyst path above fits where you want to start, review the Ethnus Certified SOC Analyst (CSA) course. Ethnus built the course around that exact EC-Council exam and role. Codemithra's course catalogue lists CSA as its only dedicated cybersecurity course. It is the specific program to review here, not a general listing. Ethnus is an authorised training partner for EC-Council, among other providers. That status supports offering a course mapped this closely to one EC-Council exam.
Frequently asked questions
Is cybersecurity a growing field?
Yes. The BLS projects 21% employment growth for information security analysts from 2025 to 2035. CyberSeek currently lists 457,398 national openings. Neither figure guarantees any individual a job or a salary.
Do I need a degree to work in cybersecurity?
Not always. A bachelor's degree is the typical entry education for an information security analyst role, per the BLS. Other roles in the table above have different typical routes.
Which certification should a beginner start with?
CompTIA Security+ (SY0-701) is a reasonable first certification, because CompTIA states its prior background as recommended, not required. For a SOC-analyst-specific path, the EC-Council CSA exam also states no fixed required years of experience.
Who hires cybersecurity professionals?
Any organisation that runs computer systems needs some cybersecurity coverage. That spans banks, technology companies, healthcare providers, retailers and government agencies. Government is a significant employer of cybersecurity professionals, alongside private industry roles across most sectors.


