Skip to main content
Roadmap

The enterprise security roadmap

Five stages between being interested in security and being someone a team wants to hire. This is genuinely useful whether or not you ever enrol with us — that is why it is published in full.

014–6 weeks

Understand the environment you will defend

You cannot investigate a system you cannot picture. Before any security content, you need a working mental model of how an enterprise is actually assembled — identity, endpoints, networks, applications and the logging that sits underneath all of it.

Covered in SOC Analyst Foundation

You can do this when you leave the stage

  • Describe how a user, a device, an identity provider and an application interact during a single sign-in
  • Explain what a domain controller does and why it matters to an attacker
  • Trace a network request from a laptop to a SaaS application and name what logs it on the way
  • Identify which systems in an environment produce security telemetry and which do not

Where people get stuck

Starting with attack techniques. Learning what Kerberoasting is before understanding what Kerberos does produces someone who can name attacks but cannot investigate one.

Proof you are ready to move on

You can draw an enterprise environment on a whiteboard from memory and point to where the logs come from.

024–6 weeks

Learn to read telemetry

Security work is reading evidence. Every tool is ultimately a view over log data, and analysts who depend on the tool's verdict stall quickly. This stage is about becoming comfortable with raw telemetry and the questions it can and cannot answer.

Covered in SOC Analyst Foundation

You can do this when you leave the stage

  • Read a Windows event log and reconstruct what a user or process did
  • Interpret authentication, DNS, proxy and firewall logs together rather than separately
  • Write queries that answer a specific investigative question
  • Recognise when the absence of a log is itself the finding

Where people get stuck

Treating the SIEM as an oracle. When a tool says 'malicious', the analyst's job is starting, not finishing.

Proof you are ready to move on

Given raw logs and no alert, you can determine whether something happened and say what evidence would settle the question.

038–10 weeks

Work real investigations

This is the stage that produces analysts, and the one most training skips. You work a queue of alerts with realistic noise, incomplete evidence and time pressure, and you defend every decision you make.

Covered in Threat Detection & Incident Response

You can do this when you leave the stage

  • Triage a queue and justify the order you worked it in
  • Build an investigation timeline from scattered, partial evidence
  • Scope the blast radius of a phishing campaign or endpoint compromise
  • Decide true positive, false positive or benign positive — and defend the call under questioning
  • Write analyst notes another person can act on without asking you anything

Where people get stuck

Practising only on clean, single-answer lab exercises. Real queues are ambiguous, and comfort with ambiguity is the skill being built.

Proof you are ready to move on

You have documented investigations that a practitioner has reviewed and returned with comments — and you have revised them.

048–10 weeks

Go deep where the estate actually is

Generalist knowledge gets you into the room. Depth in cloud, identity, detection engineering or AI security is what makes you worth hiring over the other twelve candidates with the same certification.

Covered in Cloud Security Foundation

You can do this when you leave the stage

  • Investigate a cloud-native intrusion across control and data planes
  • Design identity controls that hold up against real bypass techniques
  • Write detection logic and tune it against production-like noise
  • Threat-model an AI application and monitor it in production
  • Measure detection coverage honestly rather than aspirationally

Where people get stuck

Specialising too early. Depth without the investigation foundation of Stage 3 produces someone who can configure a tool but cannot work a case.

Proof you are ready to move on

You have shipped something durable — a tuned detection set, a hardened identity design, a documented hunt — not just completed exercises.

054 weeks

Convert capability into an offer

Capability does not translate itself. This stage is about evidence, presentation and interview performance — the part where genuinely skilled candidates most often lose to less skilled ones who prepared for the conversation.

Covered in Threat Detection & Incident Response

You can do this when you leave the stage

  • Present an investigation as evidence of judgement, not as a course deliverable
  • Reason aloud through an unfamiliar alert while being watched
  • Write a resume that maps to a specific job description
  • Handle 'I don't know' without losing the room
  • Evaluate an offer and understand what the first ninety days will demand

Where people get stuck

Leaving this until after the technical work is finished. Interview skill is built by repetition and feedback, which takes weeks, not a weekend.

Proof you are ready to move on

You have sat recorded mock interviews with practitioners, received written feedback, and improved measurably between the first and the second.

Before you start

Four things we would rather you hear now

None of this is designed to discourage you. It is designed to stop you six months in, wondering why nobody mentioned it.

It takes six to seven months of consistent work

Not six weeks. Anyone selling a faster route to a security operations role is selling the certificate, not the capability.

Reading and writing are half the job

Analysts spend enormous time reading documentation and writing findings. If you dislike both, this career will be harder than the marketing suggests.

Your first role will be less glamorous than the content you have seen

Tier 1 is a queue, a clock and a lot of repetition. It is also the fastest way to build pattern recognition, which is what everything after it depends on.

The market is competitive at entry level

Entry-level security roles attract far more applicants than mid-level ones. Demonstrable, documented work is how you separate from that field.

Next cohort enrolling

Work out which stage you are actually at

Most people place themselves a stage ahead of where they are. Forty-five minutes with a mentor will give you an honest answer and a plan from there.

Prefer email? connectbluelayersacademy@gmail.com

What the call actually is

  • 45 minutes, with a mentor rather than a sales team
  • A written recommendation you keep either way
  • An honest answer if a program is not right for you yet

We do not guarantee placement, and we will say so on the call. What we are accountable for is whether you finish able to do the work.