Cybersecurity Career Paths Nobody Explains Properly
As a security manager, part of the job is working alongside — and sometimes hiring — people in the more specialist corners of cybersecurity. I’m not a penetration tester, a forensic investigator, or a cryptographer myself, but I’ve sat across the table from all of them, reviewed their output, and worked out where each one actually fits in a real security programme. That’s a different, useful vantage point from “here’s a job title and a certification list,” which is what most career guides give you.
Penetration testing: adversarial, but structured
The public image is “ethical hacker.” The reality I’ve seen is closer to structured, scoped adversarial testing — you’re not freelancing an attack, you’re working to an agreed scope, methodology, and reporting standard. The value to the organisation isn’t the exploit itself, it’s the clear, evidenced report that tells a non-technical board what’s actually exploitable and what it would take to fix it. The pen testers I trust most are the ones whose reports I can hand straight to leadership without translation.
If this path interests you: depth in one platform (web apps, cloud, internal network) beats broad-but-shallow coverage, and writing skills matter more than people expect — a finding nobody can act on because the report is unreadable isn’t worth much.
Digital forensics: patience over speed
Forensic investigation is the specialism most people picture wrong. It’s slower and more procedural than the drama suggests — chain of custody, evidence handling that would survive scrutiny, methodical documentation. The investigators I’ve worked with treat speed as the enemy of admissibility. If you’re drawn to this path because you want fast-paced incident response, this probably isn’t it; that’s closer to SOC/detection work. Forensics rewards people who are comfortable being thorough when everyone around them wants an answer immediately.
What the work actually involves. A digital forensics investigator’s core job is finding, preserving, and interpreting digital evidence — from computers, mobile phones, laptops, servers, or any other digital device — in a way that would hold up to scrutiny later, whether that’s an internal disciplinary process, a regulatory investigation, or a criminal case. That last part is what separates forensics from general incident response: an incident responder’s priority is getting systems back to normal quickly, while a forensic investigator’s priority is preserving evidence in a defensible state, even if that means working slower. Those two goals genuinely conflict in the moment, which is exactly why organisations that do this well keep the two functions distinct rather than expecting one person to do both under pressure.
How you’d actually become a computer forensic investigator. There’s no single accepted path, but the common thread across the investigators I’ve worked with is a solid foundation in how operating systems, file systems, and networks actually work under the hood, before specialising into forensics-specific tooling and methodology. Some come up through law enforcement or military digital forensics units; others move into it from general IT or security roles after building the underlying technical foundation first. Formal certifications exist and matter for credibility (particularly ones tied to specific forensic tools or methodologies), but employers in this space weight demonstrated rigour and attention to procedure at least as heavily as the certificate itself — a candidate who can explain exactly why chain-of-custody matters, and demonstrate they’d follow it under pressure, stands out more than one who can only recite the checklist.
Does this work happen in every industry? Not evenly. Law enforcement and legal/eDiscovery firms are the most obvious employers, but large enterprises — particularly regulated ones in finance, healthcare, and critical infrastructure — increasingly keep in-house forensic capability or a retained external provider on call, because the cost of getting evidence handling wrong during a real incident (a breach, an insider threat case, a regulatory inquiry) is high enough to justify it. Smaller organisations almost never have this in-house; they bring in specialist consultancies on the rare occasions they need it, which is one reason the specialist consulting path (below) and forensics overlap more than people expect.
How forensic work actually solves a hacking case. It’s rarely a single dramatic discovery — it’s methodical reconstruction. Investigators image storage media (creating an exact, verifiable copy so the original evidence is never touched directly), then work through file system artefacts, logs, memory captures, and network traffic to build a timeline of what actually happened: what was accessed, when, from where, and by what. The “how forensic scientists solve computer hacking” question people ask is really asking about this reconstruction process — it’s closer to careful archaeology than to the fast, dramatic hacking-back people picture.
Malware analysis: the deep-technical end
This is the most technically specialised of the group — reverse engineering, understanding how malicious code actually behaves rather than just detecting that it exists. It’s less about breadth and more about a genuine appetite for very deep technical rabbit holes. In my experience it’s also one of the harder paths to break into without a strong technical foundation already in place; it’s rarely anyone’s first cyber role.
Cryptography: the smallest, most specialised path
Realistically, the cryptography path is niche — most organisations aren’t hiring dedicated cryptographers, they’re hiring engineers who understand cryptographic principles well enough to implement them correctly. If deep cryptography genuinely interests you, it tends to sit closer to research or specialist vendor roles than general security-team career paths. Worth knowing before you plan a job search around it specifically.
Consulting: the same skills, a different pressure
Security consulting isn’t a separate skill set so much as the same expertise under a different pressure model — you’re proving value to a new client repeatedly instead of one organisation over years. The consultants I rate highest are the ones with real in-house delivery experience first; consulting on decisions you’ve never had to actually implement and live with tends to show.
Final Thoughts
None of these paths are “better” than the generalist route — they’re different trade-offs between depth, pace, and how directly your work gets consumed by non-technical stakeholders. Figure out which trade-off you actually want before you pick certifications to chase. Got questions? ping me on LinkedIn.