How to become a Cybersecurity / AppSec Engineer

Find and fix what attackers would exploit: networking, systems, web vulnerabilities and secure development.

24-32 weeks4 phases17 steps30 free resources3 checkpoint tests

Best for

Students who are curious about how things break, enjoy depth, and are patient enough to learn systems thoroughly.

Maybe not for you if

Anyone looking for a quick route in. Security is typically a harder FIRST job than development. Many practitioners arrive after a development, ops or support role, and fresher openings are fewer.

The 4 phases

What each phase gets you to. The steps, resources and checkpoint inside each one open with a free account.

  1. Phase 1 - Systems and networking foundations

    6-8 weeks

    Goal: Explain, at packet and process level, what happens when a browser logs into a server, and harden the host that server runs on.

    4 steps · ends in a scored checkpoint (65% to clear) · assumes basic programming

  2. Phase 2 - Build before you break

    6-8 weeks

    Goal: Ship a real web application with authentication you wrote yourself, then produce a threat model that names exactly where you would attack it.

    4 steps · ends in a build deliverable

  3. Phase 3 - Vulnerabilities and secure development

    7-9 weeks

    Goal: Exploit and then correctly fix the main web vulnerability classes on systems you are authorised to test, and prove the fixes hold in a pipeline.

    5 steps · ends in a scored checkpoint (70% to clear)

  4. Phase 4 - Clear the process

    5-7 weeks

    Goal: Pass the coding, aptitude and security rounds, and be ready for the SOC-shaped job that most fresher security offers actually are.

    4 steps · ends in a scored checkpoint (60% to clear)

Open the full Cybersecurity / AppSec Engineer roadmap

Free account, no card. It takes about a minute and you do not need to verify your email to start.

  • All 17 steps, in order, with why each one is there
  • 30 hand-picked free resources, no paid course upsells
  • The specific mistake people make at each stage
  • 3 scored checkpoint tests, so progress is earned not ticked
  • Progress saved per step, so a break does not cost you the thread
  • Adaptive start, phases your test history already clears are skipped

What hiring actually looks like here

Security is commonly reported among the most in-demand areas, but dedicated fresher openings are typically fewer than in development. Where they do exist in India they are most often L1 SOC analyst seats in managed-services firms, often on rotating shifts. AppSec and penetration testing titles usually arrive a year or two later, and a common route is to enter as a developer or ops engineer and specialise once you understand systems from the inside.

We claim no placement outcome, salary or success rate. This describes what is commonly reported about the role, nothing more. Linked resources are credited to their authors.

Comparing paths?