A few dozen different jobs that share a vocabulary.
May 12, 2026
Cyber security is not one job. The person tuning firewall rules, the person writing a risk register, and the person reverse engineering malware all call themselves security professionals, and their days look nothing alike.
Knowing the map matters, because applying for the wrong role is one of the most common reasons capable people struggle to get in.
SOC analyst is the most common entry point. You triage alerts, investigate the ones that survive, and escalate. It is queue work with occasional intensity, often on shifts, and it teaches you an enormous amount quickly.
Incident responder is the next step in the same direction, running incidents rather than triaging alerts. Detection engineer writes and tunes the rules, which is one of the most in demand skills in defense right now. Threat hunter looks for what the alerts missed.
Covered in what a SOC does, detection engineering, and threat hunting.
Penetration tester runs scoped, authorized assessments and writes them up. It is more writing than people expect and the report is the deliverable.
Red team operator runs longer, quieter, objective based engagements against organizations that already have real defenses. Application security specialist focuses on code and design, and often sits closer to engineering than to security operations.
This is the most competitive area to enter, because it is the one everyone wants. It is also the smallest by headcount. See penetration testing explained.
GRC analyst, risk analyst, compliance manager, auditor, and third party risk analyst.
This is the most accessible path for people coming from outside technology, particularly from audit, finance, project management, or law. The work rewards clear writing and comfort asking uncomfortable questions.
It is a real security job and it is frequently dismissed by technical people, which is exactly why there are openings. See what GRC actually is.
Security engineer builds and runs the tooling: identity platforms, endpoint deployment, network security, automation. Cloud security engineer does the same in cloud environments and is one of the highest demand specialties.
Security architect designs how it all fits together and usually arrives after years elsewhere.
These roles reward people who came from system administration, networking, or software development, because the job is mostly building things.
Malware analyst and reverse engineer, digital forensics examiner, threat intelligence analyst, product security in a vendor, industrial control systems and operational technology security, and identity specialist.
Most of these are not entry level. They are places people move to after a few years, and they usually require deep knowledge in one area rather than breadth.
Be careful with published salary figures, because they vary enormously by region, sector, and how the survey was collected. What is consistent is the shape.
Entry level defensive roles pay less than experienced engineering roles. Cloud security, detection engineering, and application security tend to pay above the median because supply is short. Management pays more than individual contribution in most organizations but not all.
In South West Florida specifically, the market is smaller than a major metropolitan area, which makes local networking more valuable and remote roles more competitive.
The useful question is not which pays most, it is which kind of day you want.
If you like solving puzzles under time pressure with incomplete information, security operations. If you like breaking things and explaining how, offensive. If you like building and automating, engineering. If you like organizing, writing, and negotiating, GRC.
The mentorship covers all of these deliberately, because most people do not know which one fits until they try it. See the full curriculum.
Week 13 of the mentorship includes career coaching, and the earlier weeks are designed so you get a real taste of each area before choosing.