Olaiya · Dual Track

Track A · Master’s spine · RA-oriented

Cybersecurity roadmap

Stay months ahead of classmates and become hireable as a research assistant. Structure inspired by roadmap.sh/cyber-security, with nested tracks from Network Engineering, DevSecOps, AI Engineer, and AI Red Teaming — filtered for your Aqua / systems profile, not a career restart from CompTIA A+.

Software / supply-chain lane AI app & agent security RA · stage recherche

Your unfair starting point

Production work at Aqua (dependency scanning, secret detection, auth hardening, distributed scanners) already maps to AppSec, DevSecOps, and supply-chain security research. This roadmap closes academic gaps (networks theory, crypto rigor, papers) and adds AI-era attack surface so you don’t graduate into 2019.

How AI changed this field

Account for these shifts in every module and project.

Attack & defense

  • Attackers use LLMs for phishing, malware variants, recon speed
  • New product surface: chatbots, RAG, agents, MCP/tool calling, plugins
  • Prompt injection, data exfil via tools, model/system prompt leakage
  • AI-assisted code → more volume of insecure diffs; need automated review

Your job as a strong student / RA

  • Treat “AI features” as ordinary software with weird trust boundaries
  • Learn evaluation harnesses (not only jailbreak screenshots)
  • Keep classical systems security — AI stacks still run on Linux, TLS, IAM, CI
  • Use AI tools to accelerate learning; never skip verification

Progressive path

Follow top → bottom. Nested tracks deepen a node; they are not a second career.

0 · Foundations — leverage, don’t relearn

Leverage

roadmap.sh starts at hardware / A+ / basic IT. Skip that. Confirm only gaps:

  • Linux fluency: processes, permissions, systemd, journals, networking tools
  • Git + CI: you already have this — document it as security-relevant (signed commits, OIDC, least privilege tokens)
  • Programming: Go + Python are the daily drivers; Bash for ops glue; C for systems/memory literacy (see note below); C++ optional
  • Virtualization: comfortable with VMs/containers for labs

Resources

  • BookNemeth et al. — UNIX and Linux System Administration Handbook (selective)
  • LabBuild a personal homelab VM (Ubuntu + Docker) used for every later project

C vs C++ on the cyber track

C — yes, lightly. You need enough C to read vulnerable patterns, follow CSAPP labs, and understand memory/layout when professors talk exploits. Write small programs; you do not need to become a C systems programmer. C++ — usually no for AppSec / supply-chain / AI-security / RA in software security. Only pick it up if a lab’s codebase is C++ or you pivot hard into reverse engineering / malware. Keep shipping security tools in Go/Python.

1 · Networking (nested: Network Engineer)

Nested Required

Adapted from roadmap.sh/network-engineer — security-relevant slice only.

  • Core: OSI/TCP-IP, subnetting, routing vs switching, DNS, DHCP, NAT, VPN
  • Security lens: TLS handshake, certs, MITM, DNS attacks, segmentation, Zero Trust ideas
  • Cloud networking: VPC, security groups, private endpoints, egress control
  • Modern edge: API gateways vs load balancers; why WebSockets/gRPC change inspection
  • AI-era add-on: exfil over model APIs; egress allowlists for agent tool traffic

Resources

  • BookKurose & Ross — Computer Networking (TCP/IP + security chapters)
  • LabWireshark: capture TLS ClientHello, DNS, HTTP/2; write notes
  • CoursePractical Networking / Professor Messer Network+ videos (gap fill only)
  • Refroadmap.sh/network-engineer

2 · Systems, OS & memory model

Required

This is the academic gap most ECE → cyber transitions underestimate — and what RA supervisors expect.

  • Processes, threads, virtual memory, syscalls, file descriptors
  • Permissions, capabilities, containers vs VMs isolation limits
  • Exploit concepts (for literacy): buffer issues, ASLR/NX/DEP, privilege escalation classes
  • Hardening: least privilege, seccomp/AppArmor awareness, patch discipline

Resources

  • BookBryant & O’Hallaron — CSAPP (chapters on machine-level, memory, concurrency)
  • Labpwn.college — do a short module set, don’t live there forever
  • RefLinux man pages: clone, mmap, namespaces, cgroups (skim)

3 · Applied cryptography

Required
  • Symmetric vs asymmetric, hashes, MACs, AEAD, KDFs, randomness
  • PKI, certificates, TLS properties — what TLS does not guarantee
  • Common misuse: ECB, nonce reuse, “roll your own”, weak RNG
  • Password storage, secret management (ties to your secret-detection work)
  • AI-era: encrypting embeddings/logs; key access for RAG data stores

Resources

  • BookJean-Philippe Aumasson — Serious Cryptography
  • FreeCrypto 101
  • CourseDan Boneh Coursera Crypto I (optional depth)

4 · Application security & web

Leverage + deepen
  • OWASP Top 10 deeply (not flashcards): injection, XSS, SSRF, authn/z flaws
  • API security: auth, IDOR, mass assignment, rate limits
  • Secure SDLC: threat modeling (STRIDE), security requirements, code review
  • SAST/DAST/SCA concepts — map to Aqua experience with precise vocabulary
  • AI-era: LLM-generated code review checklists; insecure AI-suggested patches

Resources

5 · DevSecOps (nested)

Nested Leverage

From roadmap.sh/devsecops — prioritize what matches your CI/CD hardening story.

  • Pipeline security: secrets, OIDC federation, ephemeral creds (you’ve done PAT → GitHub Apps)
  • Artifact trust: signing, provenance, SBOM generation, policy gates
  • IaC security: Terraform/K8s misconfigs, admission controllers (concepts)
  • Policy as code: OPA/Conftest awareness
  • AI-era: scanning AI-assisted PRs; blocking secrets in generated code; model-supply-chain in CI

Resources

6 · Cloud security

Leverage PCA
  • IAM deep: least privilege, service identities, confused deputy
  • Data protection: KMS, encryption at rest/in transit, key policies
  • Logging/monitoring: CloudTrail/Cloud Audit, detections, retention
  • Workload identity for K8s / serverless
  • AI-era: securing model endpoints, training data buckets, vector DBs, GPU instance exposure

Resources

  • PathGCP Security / AWS Security learning paths (gap fill vs your PCA)
  • BookPractical Cloud Security (Chris Dotson) — selective
  • LabsCloudGoat / insecure cloud labs (authorized environments only)

7 · Detection, IR & blue literacy

Recommended
  • IR phases: prepare → detect → contain → eradicate → recover → lessons
  • Logs that matter; false positive/negative intuition
  • Sigma rules / basic detection engineering
  • ATT&CK as a map, not a religion
  • AI-era: detecting abuse of AI features (unusual tool calls, prompt-injection payloads in tickets/docs)

Resources

  • FrameworkMITRE ATT&CK
  • SpecSigmaHQ
  • BookIncident Response & Computer Forensics (overview chapters)

8 · Offensive security — selective

Selective

Enough to think like an attacker and pass class labs — not a full OSCP detour unless you want that career.

  • Rules of engagement, ethics, legal boundaries
  • Recon → exploit → post-exploit literacy
  • One web offensive track (PortSwigger) beats random CTF addiction
  • Optional: basic binary exploitation literacy via pwn.college

Resources

  • PlatformTryHackMe / HackTheBox — time-boxed paths only
  • Refroadmap.sh cyber: roles of red/blue/purple, kill chain, RoE

9 · AI security & AI red teaming (nested)

AI-era Nested Required for 2026

Nested from AI Red Teaming + AI Engineer (application layer only). This is how you look “current” to labs and employers.

  • LLM app stack: prompts, context windows, RAG, tools/agents, evals, observability
  • Threats: direct/indirect prompt injection, jailbreaks, data leakage, training-data extraction awareness, insecure output handling, supply chain of models/plugins
  • Agent risks: tool misuse, privilege escalation via tools, SSRF-like tool calls, persistent memory poisoning
  • Defenses: isolation, allowlisted tools, human-in-loop, output validation, DLP on RAG corpora, authz on tool APIs
  • Practice: build a tiny RAG app → attack it → patch it → write eval cases (garak/PyRIT awareness)
  • Governance lite: OWASP LLM Top 10, model cards, logging for abuse

Resources

  • StdOWASP Top 10 for LLMs
  • Roadmaproadmap.sh/ai-red-teaming
  • Toolgarak, Microsoft PyRIT (explore, don’t only screenshot)
  • LabGandalf / prompt injection CTFs — then graduate to your own app
  • PapersSearch arXiv cs.CR + “prompt injection”, “LLM agent security” — 1/week

10 · Software supply-chain security ★ your specialty lane

Career wedge RA bait

This is where industry experience + master’s research can meet.

  • Dependency graphs, version resolution, transitive risk (your Aqua narrative)
  • Malicious packages, typosquatting, dependency confusion
  • SBOM, VEX, provenance, reproducible builds
  • Secret leakage in repos/artifacts; entropy + pattern detectors (you’ve built related systems)
  • CI as trust boundary; build-server compromise models
  • AI-era: poisoned datasets/models, malicious LoRA/adapters, “AI package” ecosystems, generated code introducing vulnerable deps

Resources

  • StdSLSA, in-toto, Sigstore, OpenSSF Best Practices
  • ReadGoogle/OpenSSF blogs on supply chain; academic papers on npm/PyPI malware
  • DataOSV, GHSA, ecosystems advisories — use in project metrics

11 · Research methods & RA playbook

Goal path
  • How to read a paper: problem, threat model, method, evaluation, limits
  • Reproducibility culture: artifacts, seeds, baselines, ablations
  • Scientific writing: 2–4 page notes with citations
  • Lab targeting: IRISA / CyberSchool / Paris labs / whatever uni you join
  • Outreach: critique + extension idea + offer a 4–6 week reproduction trial

Resources

  • VenuesIEEE S&P, USENIX Security, CCS, NDSS abstracts weekly
  • PreprintarXiv cs.CR
  • BookThe Craft of Research (Booth) — short
  • FRANSSI publications; French cyber campus pages linked from your programme

Projects (build these)

Prefer one excellent artifact with metrics over five demos.

P1 · Flagship / RA

Supply-chain or secret-detection research tool

  • Dataset + precision/recall/F1
  • Compare against a naive baseline
  • 2–4 page write-up with related work
  • Optional AI angle: detect risky deps introduced by AI-generated PRs

P2 · AI-era

Secure-by-default mini RAG / agent

  • Indirect prompt injection test cases
  • Tool allowlisting + authz
  • Before/after eval harness (even a spreadsheet is fine)
  • Threat model document

P3 · Systems

Hardened service + CI gate

  • Insecure → secure progression
  • SBOM + SCA + secret scan in CI
  • OIDC-style machine identity notes

P4 · Academic

Paper reproduction

  • Pick 2023–2026 software/AI security paper
  • Reproduce one figure/table
  • Blog gaps — gold for RA emails

Resource library (quick index)

AreaPrimarySecondary
Systems CSAPP pwn.college (limited)
Networks Kurose & Ross Wireshark labs · roadmap.sh/network-engineer
Crypto Serious Cryptography Crypto 101 · Boneh Crypto I
AppSec PortSwigger Academy OWASP Top 10 / ASVS
DevSecOps SLSA + Sigstore roadmap.sh/devsecops
AI security OWASP LLM Top 10 garak · PyRIT · roadmap.sh/ai-red-teaming
Research arXiv cs.CR + big-4 abstracts Craft of Research
Class ahead Syllabus − 4–6 weeks pre-read Personal course wiki

Checklist