Track A · Master’s spine · RA-oriented
Cybersecurity roadmap
Stay months ahead of classmates and become hireable as a research assistant.
Structure inspired by roadmap.sh/cyber-security,
with nested tracks from Network Engineering, DevSecOps, AI Engineer, and
AI Red Teaming — filtered for your Aqua / systems profile, not a career restart from CompTIA A+.
Software / supply-chain lane
AI app & agent security
RA · stage recherche
Your unfair starting point
Production work at Aqua (dependency scanning, secret detection, auth hardening, distributed scanners)
already maps to AppSec, DevSecOps, and supply-chain security research. This roadmap closes academic gaps
(networks theory, crypto rigor, papers) and adds AI-era attack surface so you don’t graduate into 2019.
How AI changed this field
Account for these shifts in every module and project.
Attack & defense
- Attackers use LLMs for phishing, malware variants, recon speed
- New product surface: chatbots, RAG, agents, MCP/tool calling, plugins
- Prompt injection, data exfil via tools, model/system prompt leakage
- AI-assisted code → more volume of insecure diffs; need automated review
Your job as a strong student / RA
- Treat “AI features” as ordinary software with weird trust boundaries
- Learn evaluation harnesses (not only jailbreak screenshots)
- Keep classical systems security — AI stacks still run on Linux, TLS, IAM, CI
- Use AI tools to accelerate learning; never skip verification
Progressive path
Follow top → bottom. Nested tracks deepen a node; they are not a second career.
0 · Foundations — leverage, don’t relearn
Leverage
roadmap.sh starts at hardware / A+ / basic IT. Skip that. Confirm only gaps:
- Linux fluency: processes, permissions, systemd, journals, networking tools
- Git + CI: you already have this — document it as security-relevant (signed commits, OIDC, least privilege tokens)
- Programming: Go + Python are the daily drivers; Bash for ops glue; C for systems/memory literacy (see note below); C++ optional
- Virtualization: comfortable with VMs/containers for labs
Resources
- BookNemeth et al. — UNIX and Linux System Administration Handbook (selective)
- LabBuild a personal homelab VM (Ubuntu + Docker) used for every later project
C vs C++ on the cyber track
C — yes, lightly. You need enough C to read vulnerable patterns, follow CSAPP labs, and understand memory/layout when professors talk exploits.
Write small programs; you do not need to become a C systems programmer.
C++ — usually no for AppSec / supply-chain / AI-security / RA in software security. Only pick it up if a lab’s codebase is C++ or you pivot hard into reverse engineering / malware.
Keep shipping security tools in Go/Python.
1 · Networking (nested: Network Engineer)
Nested
Required
Adapted from roadmap.sh/network-engineer —
security-relevant slice only.
- Core: OSI/TCP-IP, subnetting, routing vs switching, DNS, DHCP, NAT, VPN
- Security lens: TLS handshake, certs, MITM, DNS attacks, segmentation, Zero Trust ideas
- Cloud networking: VPC, security groups, private endpoints, egress control
- Modern edge: API gateways vs load balancers; why WebSockets/gRPC change inspection
- AI-era add-on: exfil over model APIs; egress allowlists for agent tool traffic
Resources
- BookKurose & Ross — Computer Networking (TCP/IP + security chapters)
- LabWireshark: capture TLS ClientHello, DNS, HTTP/2; write notes
- CoursePractical Networking / Professor Messer Network+ videos (gap fill only)
- Refroadmap.sh/network-engineer
2 · Systems, OS & memory model
Required
This is the academic gap most ECE → cyber transitions underestimate — and what RA supervisors expect.
- Processes, threads, virtual memory, syscalls, file descriptors
- Permissions, capabilities, containers vs VMs isolation limits
- Exploit concepts (for literacy): buffer issues, ASLR/NX/DEP, privilege escalation classes
- Hardening: least privilege, seccomp/AppArmor awareness, patch discipline
Resources
- BookBryant & O’Hallaron — CSAPP (chapters on machine-level, memory, concurrency)
- Labpwn.college — do a short module set, don’t live there forever
- RefLinux man pages: clone, mmap, namespaces, cgroups (skim)
3 · Applied cryptography
Required
- Symmetric vs asymmetric, hashes, MACs, AEAD, KDFs, randomness
- PKI, certificates, TLS properties — what TLS does not guarantee
- Common misuse: ECB, nonce reuse, “roll your own”, weak RNG
- Password storage, secret management (ties to your secret-detection work)
- AI-era: encrypting embeddings/logs; key access for RAG data stores
Resources
- BookJean-Philippe Aumasson — Serious Cryptography
- FreeCrypto 101
- CourseDan Boneh Coursera Crypto I (optional depth)
4 · Application security & web
Leverage + deepen
- OWASP Top 10 deeply (not flashcards): injection, XSS, SSRF, authn/z flaws
- API security: auth, IDOR, mass assignment, rate limits
- Secure SDLC: threat modeling (STRIDE), security requirements, code review
- SAST/DAST/SCA concepts — map to Aqua experience with precise vocabulary
- AI-era: LLM-generated code review checklists; insecure AI-suggested patches
5 · DevSecOps (nested)
Nested
Leverage
From roadmap.sh/devsecops — prioritize what matches your CI/CD hardening story.
- Pipeline security: secrets, OIDC federation, ephemeral creds (you’ve done PAT → GitHub Apps)
- Artifact trust: signing, provenance, SBOM generation, policy gates
- IaC security: Terraform/K8s misconfigs, admission controllers (concepts)
- Policy as code: OPA/Conftest awareness
- AI-era: scanning AI-assisted PRs; blocking secrets in generated code; model-supply-chain in CI
6 · Cloud security
Leverage PCA
- IAM deep: least privilege, service identities, confused deputy
- Data protection: KMS, encryption at rest/in transit, key policies
- Logging/monitoring: CloudTrail/Cloud Audit, detections, retention
- Workload identity for K8s / serverless
- AI-era: securing model endpoints, training data buckets, vector DBs, GPU instance exposure
Resources
- PathGCP Security / AWS Security learning paths (gap fill vs your PCA)
- BookPractical Cloud Security (Chris Dotson) — selective
- LabsCloudGoat / insecure cloud labs (authorized environments only)
7 · Detection, IR & blue literacy
Recommended
- IR phases: prepare → detect → contain → eradicate → recover → lessons
- Logs that matter; false positive/negative intuition
- Sigma rules / basic detection engineering
- ATT&CK as a map, not a religion
- AI-era: detecting abuse of AI features (unusual tool calls, prompt-injection payloads in tickets/docs)
Resources
- FrameworkMITRE ATT&CK
- SpecSigmaHQ
- BookIncident Response & Computer Forensics (overview chapters)
8 · Offensive security — selective
Selective
Enough to think like an attacker and pass class labs — not a full OSCP detour unless you want that career.
- Rules of engagement, ethics, legal boundaries
- Recon → exploit → post-exploit literacy
- One web offensive track (PortSwigger) beats random CTF addiction
- Optional: basic binary exploitation literacy via pwn.college
Resources
- PlatformTryHackMe / HackTheBox — time-boxed paths only
- Refroadmap.sh cyber: roles of red/blue/purple, kill chain, RoE
9 · AI security & AI red teaming (nested)
AI-era
Nested
Required for 2026
Nested from AI Red Teaming +
AI Engineer (application layer only).
This is how you look “current” to labs and employers.
- LLM app stack: prompts, context windows, RAG, tools/agents, evals, observability
- Threats: direct/indirect prompt injection, jailbreaks, data leakage, training-data extraction awareness, insecure output handling, supply chain of models/plugins
- Agent risks: tool misuse, privilege escalation via tools, SSRF-like tool calls, persistent memory poisoning
- Defenses: isolation, allowlisted tools, human-in-loop, output validation, DLP on RAG corpora, authz on tool APIs
- Practice: build a tiny RAG app → attack it → patch it → write eval cases (garak/PyRIT awareness)
- Governance lite: OWASP LLM Top 10, model cards, logging for abuse
Resources
- StdOWASP Top 10 for LLMs
- Roadmaproadmap.sh/ai-red-teaming
- Toolgarak, Microsoft PyRIT (explore, don’t only screenshot)
- LabGandalf / prompt injection CTFs — then graduate to your own app
- PapersSearch arXiv cs.CR + “prompt injection”, “LLM agent security” — 1/week
10 · Software supply-chain security ★ your specialty lane
Career wedge
RA bait
This is where industry experience + master’s research can meet.
- Dependency graphs, version resolution, transitive risk (your Aqua narrative)
- Malicious packages, typosquatting, dependency confusion
- SBOM, VEX, provenance, reproducible builds
- Secret leakage in repos/artifacts; entropy + pattern detectors (you’ve built related systems)
- CI as trust boundary; build-server compromise models
- AI-era: poisoned datasets/models, malicious LoRA/adapters, “AI package” ecosystems, generated code introducing vulnerable deps
Resources
- StdSLSA, in-toto, Sigstore, OpenSSF Best Practices
- ReadGoogle/OpenSSF blogs on supply chain; academic papers on npm/PyPI malware
- DataOSV, GHSA, ecosystems advisories — use in project metrics
11 · Research methods & RA playbook
Goal path
- How to read a paper: problem, threat model, method, evaluation, limits
- Reproducibility culture: artifacts, seeds, baselines, ablations
- Scientific writing: 2–4 page notes with citations
- Lab targeting: IRISA / CyberSchool / Paris labs / whatever uni you join
- Outreach: critique + extension idea + offer a 4–6 week reproduction trial
Resources
- VenuesIEEE S&P, USENIX Security, CCS, NDSS abstracts weekly
- PreprintarXiv cs.CR
- BookThe Craft of Research (Booth) — short
- FRANSSI publications; French cyber campus pages linked from your programme
Projects (build these)
Prefer one excellent artifact with metrics over five demos.
P1 · Flagship / RA
Supply-chain or secret-detection research tool
- Dataset + precision/recall/F1
- Compare against a naive baseline
- 2–4 page write-up with related work
- Optional AI angle: detect risky deps introduced by AI-generated PRs
P2 · AI-era
Secure-by-default mini RAG / agent
- Indirect prompt injection test cases
- Tool allowlisting + authz
- Before/after eval harness (even a spreadsheet is fine)
- Threat model document
P3 · Systems
Hardened service + CI gate
- Insecure → secure progression
- SBOM + SCA + secret scan in CI
- OIDC-style machine identity notes
P4 · Academic
Paper reproduction
- Pick 2023–2026 software/AI security paper
- Reproduce one figure/table
- Blog gaps — gold for RA emails
Resource library (quick index)
| Area | Primary | Secondary |
| Systems |
CSAPP |
pwn.college (limited) |
| Networks |
Kurose & Ross |
Wireshark labs · roadmap.sh/network-engineer |
| Crypto |
Serious Cryptography |
Crypto 101 · Boneh Crypto I |
| AppSec |
PortSwigger Academy |
OWASP Top 10 / ASVS |
| DevSecOps |
SLSA + Sigstore |
roadmap.sh/devsecops |
| AI security |
OWASP LLM Top 10 |
garak · PyRIT · roadmap.sh/ai-red-teaming |
| Research |
arXiv cs.CR + big-4 abstracts |
Craft of Research |
| Class ahead |
Syllabus − 4–6 weeks pre-read |
Personal course wiki |