← All Career Paths

Technology

How to Become a Cybersecurity Analyst

Learn how to monitor, investigate, and respond to cybersecurity threats.

Intermediate6 core skills3 learning phases

What does a Cybersecurity Analyst do?

Cybersecurity analysts help organizations detect threats, investigate suspicious activity, protect systems, and respond to security incidents.

Skills you'll need

Networking

Understand how devices, applications, and networks communicate.

essential

Why it matters: Understanding how networks communicate is essential for identifying suspicious traffic and investigating security incidents.

Linux

Use the Linux operating system and command line to manage systems.

essential

Why it matters: Linux is widely used in servers and security environments, making basic command-line skills important for analysts.

Security Fundamentals

Understand core cybersecurity concepts, threats, vulnerabilities, and defensive controls.

essential

Why it matters: Security fundamentals provide the foundation for understanding threats, vulnerabilities, authentication, and defensive controls.

SIEM

Collect, search, correlate, and investigate security events and logs.

essential

Why it matters: SIEM platforms allow analysts to collect and investigate security events from across an environment.

Incident Response

Identify, investigate, contain, and respond to security incidents.

important

Why it matters: Analysts need to understand how organizations investigate and respond to security incidents.

Python

Use Python for programming, automation, data analysis, and AI.

important

Why it matters: Python can automate repetitive analysis tasks and help analysts work with security data.

Typical learning path

1

Security Foundations

~40 hours

Build the networking, operating system, and security fundamentals needed for security analysis.

Skills

NetworkingLinuxSecurity Fundamentals

Milestone: Explain common network protocols, operating system concepts, and fundamental security principles.

2

Security Monitoring

~50 hours

Learn how security analysts collect, search, and investigate security events.

Skills

SIEM

Milestone: Investigate a simulated security event using logs and a SIEM.

3

Incident Response

~45 hours

Learn the fundamentals of identifying, containing, investigating, and documenting security incidents.

Skills

Incident ResponsePython

Milestone: Complete a simulated incident investigation and produce an incident report.

Ready to build your roadmap?

See which skills you already have, what you should learn next, and how much time it could take based on your situation.

Build My Personalized Roadmap →