90-Day Cybersecurity Career Plan
90-Day Cybersecurity Career Plan
Section titled “90-Day Cybersecurity Career Plan”Welcome to the GoHackersCloud Academy 90-Day Cybersecurity Career Plan.
This is not a 90-day challenge designed around collecting badges or completing as many labs as possible.
It is a structured professional development plan designed to help you progress from:
Cybersecurity Foundations → Hands-On Practice → Security Analysis → Job Readiness
The primary career target for this roadmap is:
SOC Analyst / Junior Security Analyst
However, the technical foundation developed here also prepares you for future specialization in:
- Security Operations
- Incident Response
- Ethical Hacking
- Penetration Testing
- Cloud Security
- Security Engineering
The GoHackersCloud Learning Model
Section titled “The GoHackersCloud Learning Model”Throughout these 90 days, follow one learning cycle:
Learn → Practice → Investigate → Document → Explain → Improve
Every lab should produce more than a completion status.
You should be able to answer:
- What technology did I work with?
- What security problem was demonstrated?
- What evidence did I observe?
- Which tool did I use, and why?
- What would an attacker see?
- What would a defender see?
- How could the weakness be mitigated?
- Could I explain this during an interview?
That is the difference between completing labs and developing professional capability.
90-Day Roadmap
Section titled “90-Day Roadmap”The plan is divided into three progressive phases.
| Phase | Days | Primary Focus |
|---|---|---|
| Phase 1 | 1–30 | Foundations & Security Mindset |
| Phase 2 | 31–60 | Attacker Mindset & Core Security Skills |
| Phase 3 | 61–90 | SOC, Cloud, Portfolio & Job Readiness |
PHASE 1 — Foundations & Security Mindset
Section titled “PHASE 1 — Foundations & Security Mindset”Days 1–30
Section titled “Days 1–30”The first month establishes the technical foundation required for everything that follows.
Your objective is to become comfortable with:
- Linux
- networking
- security fundamentals
- defensive security
- SOC concepts
- logs
- alerts
- incident fundamentals
Do not rush this phase.
A strong analyst needs to understand normal technology before they can reliably identify abnormal behavior.
Week 1 — Linux Fundamentals
Section titled “Week 1 — Linux Fundamentals”Mission
Section titled “Mission”Become comfortable operating Linux from the perspective of a cybersecurity professional.
Recommended TryHackMe Practice
Section titled “Recommended TryHackMe Practice”Complete:
- Linux Fundamentals Part 1
- Linux Fundamentals Part 2
- Linux Fundamentals Part 3
- Linux Shells
- Common Linux Privesc — introductory understanding
Focus Areas
Section titled “Focus Areas”Pay particular attention to:
- filesystem navigation
- files and directories
- users
- groups
- permissions
- processes
- services
- shell fundamentals
- basic system administration
Professional Questions
Section titled “Professional Questions”By the end of the week, you should be able to explain:
- What is the Linux filesystem?
- What are users and groups?
- How do Linux permissions work?
- What is a process?
- What is a service?
- Why is Linux important in cybersecurity?
- Where might analysts look for security evidence?
Week 1 Outcome
Section titled “Week 1 Outcome”You should be able to navigate Linux confidently and explain fundamental Linux concepts without relying completely on a walkthrough.
Evidence to Create
Section titled “Evidence to Create”Create a short Linux Security Notes document containing:
- useful commands
- permission concepts
- important directories
- processes/services observations
- lessons learned
Week 2 — Networking Fundamentals
Section titled “Week 2 — Networking Fundamentals”Mission
Section titled “Mission”Understand how systems communicate across networks.
Networking is foundational for both offensive and defensive cybersecurity.
Recommended TryHackMe Practice
Section titled “Recommended TryHackMe Practice”Complete:
- Intro to Networking
- What is Networking?
- DNS in Detail
- HTTP in Detail
- Network Services
- Network Services 2
Focus Areas
Section titled “Focus Areas”Understand:
- IP addressing
- TCP
- UDP
- ports
- protocols
- DNS
- HTTP/HTTPS
- network services
- client/server communication
Think in Traffic Flows
Section titled “Think in Traffic Flows”Train yourself to visualize:
User → DNS → IP Address → TCP Connection → Service → Response
Professional Questions
Section titled “Professional Questions”Be prepared to explain:
- What is an IP address?
- TCP vs UDP?
- What is a port?
- How does DNS work?
- What happens when you visit a website?
- HTTP vs HTTPS?
- Why are exposed network services security-relevant?
Week 2 Outcome
Section titled “Week 2 Outcome”You should understand basic network communication well enough to begin interpreting security events involving IP addresses, ports and protocols.
Evidence to Create
Section titled “Evidence to Create”Build a Network Security Cheat Sheet containing:
- common protocols
- important ports
- DNS flow
- HTTP flow
- common network-security observations
Week 3 — Security Basics & Defensive Thinking
Section titled “Week 3 — Security Basics & Defensive Thinking”Mission
Section titled “Mission”Develop your cybersecurity mindset before concentrating on attacks.
Recommended TryHackMe Practice
Section titled “Recommended TryHackMe Practice”Complete:
- Pre Security
- Security Principles
- Intro to Defensive Security
- Threat Intelligence
- Vulnerabilities 101
Focus Areas
Section titled “Focus Areas”Understand the relationship:
Asset → Threat → Vulnerability → Risk → Control
Study:
- CIA triad
- vulnerabilities
- threats
- risks
- security controls
- defensive security
- threat intelligence
Analyst Thinking
Section titled “Analyst Thinking”For every security problem, ask:
What are we protecting?
What could go wrong?
What weakness exists?
What would the impact be?
What control reduces the risk?
Week 3 Outcome
Section titled “Week 3 Outcome”You should begin thinking like a security professional rather than simply a technology learner.
Week 4 — SOC Fundamentals
Section titled “Week 4 — SOC Fundamentals”Mission
Section titled “Mission”Understand how a Security Operations Center identifies and investigates security activity.
Recommended TryHackMe Practice
Section titled “Recommended TryHackMe Practice”Complete the source roadmap’s recommended SOC-focused material:
- SOC Level 1
- Intro to SIEM
- Phishing Analysis Fundamentals
- Incident Response Basics
Focus Areas
Section titled “Focus Areas”Understand:
- security events
- logs
- detections
- alerts
- triage
- investigation
- escalation
- incidents
- SIEM concepts
Learn the SOC Workflow
Section titled “Learn the SOC Workflow”Event → Detection → Alert → Triage → Investigation → Decision → Response
Investigation Questions
Section titled “Investigation Questions”Whenever you encounter an alert, ask:
- What happened?
- Which user was involved?
- Which system was affected?
- What evidence exists?
- When did it happen?
- Was the activity expected?
- What happened before it?
- What happened afterward?
- Does this require escalation?
Week 4 Outcome
Section titled “Week 4 Outcome”You should understand how alerts move through a basic SOC investigation workflow.
30-Day Checkpoint
Section titled “30-Day Checkpoint”Before entering Phase 2, perform a self-assessment.
You should now be able to explain:
- Linux fundamentals
- TCP/IP fundamentals
- DNS
- HTTP/HTTPS
- threats and vulnerabilities
- security controls
- basic SOC operations
- logs
- SIEM concepts
- alert triage
Rate yourself:
| Skill | Learning | Practised | Can Explain | Need More Practice |
|---|---|---|---|---|
| Linux | ☐ | ☐ | ☐ | ☐ |
| Networking | ☐ | ☐ | ☐ | ☐ |
| Security Fundamentals | ☐ | ☐ | ☐ | ☐ |
| SOC Fundamentals | ☐ | ☐ | ☐ | ☐ |
Do not worry about perfection.
Identify your weak areas and continue.
PHASE 2 — Attacker Mindset & Core Security Skills
Section titled “PHASE 2 — Attacker Mindset & Core Security Skills”Days 31–60
Section titled “Days 31–60”During Phase 2, you will begin understanding how attackers discover and exploit weaknesses.
This is important even if your target role is SOC Analyst.
A strong defender should understand:
What would an attacker do next?
You will practise:
- web technologies
- OWASP concepts
- reconnaissance
- scanning
- enumeration
- exploitation concepts
- Linux privilege escalation
- Windows privilege escalation
- attack-chain thinking
Week 5 — Web Fundamentals & OWASP
Section titled “Week 5 — Web Fundamentals & OWASP”Mission
Section titled “Mission”Understand how web applications work and why vulnerabilities occur.
Recommended TryHackMe Practice
Section titled “Recommended TryHackMe Practice”Complete:
- How Websites Work
- OWASP Top 10
- OWASP Juice Shop
- Burp Suite: The Basics
Focus Areas
Section titled “Focus Areas”Understand:
- HTTP requests
- HTTP responses
- headers
- cookies
- sessions
- authentication
- authorization
- user input
- OWASP vulnerabilities
Professional Mindset
Section titled “Professional Mindset”Do not memorize vulnerability names.
For every weakness, ask:
How does it happen?
What is the security impact?
What evidence demonstrates it?
How could defenders detect abuse?
How should developers fix it?
Week 5 Outcome
Section titled “Week 5 Outcome”You should understand fundamental web-security concepts and be able to explain common application-security risks.
Week 6 — Enumeration & Scanning
Section titled “Week 6 — Enumeration & Scanning”Mission
Section titled “Mission”Learn how authorized security testers systematically understand a target environment.
Recommended TryHackMe Practice
Section titled “Recommended TryHackMe Practice”Complete:
- Nmap
- Nmap Live Host Discovery
- Nmap Advanced Port Scans
- Enumeration
- Intro to Reconnaissance
Focus Areas
Section titled “Focus Areas”Develop understanding of:
- reconnaissance
- host discovery
- ports
- services
- service identification
- enumeration
- attack surfaces
Follow the Methodology
Section titled “Follow the Methodology”Discover → Identify → Enumerate → Understand → Investigate
Do not treat scanning as simply running a tool.
Ask:
- Why am I scanning?
- What am I trying to discover?
- What does this port represent?
- What service is running?
- Why does this service matter?
Week 6 Outcome
Section titled “Week 6 Outcome”You should be able to explain the purpose of reconnaissance, scanning and enumeration during an authorized security assessment.
Week 7 — Exploitation Basics
Section titled “Week 7 — Exploitation Basics”Mission
Section titled “Mission”Understand how security weaknesses can become attack chains inside controlled lab environments.
Recommended TryHackMe Practice
Section titled “Recommended TryHackMe Practice”Complete:
- Basic Pentesting
- Vulnversity
- Pickle Rick
- RootMe
Practice Methodology
Section titled “Practice Methodology”For every challenge, think:
Reconnaissance → Enumeration → Weakness → Validation → Access → Impact
Do not focus only on obtaining access.
Document:
- initial observation
- discovered services
- vulnerability
- why the weakness existed
- security impact
- mitigation
Week 7 Outcome
Section titled “Week 7 Outcome”You should understand how individual technical weaknesses can combine into a complete attack path.
Week 8 — Privilege Escalation
Section titled “Week 8 — Privilege Escalation”Mission
Section titled “Mission”Understand how initial access can sometimes lead to higher privileges.
Recommended TryHackMe Practice
Section titled “Recommended TryHackMe Practice”Complete:
- Linux PrivEsc
- Windows PrivEsc
- Privilege Escalation
- What the Shell?
Focus Areas
Section titled “Focus Areas”Study privilege boundaries involving:
- users
- groups
- permissions
- services
- scheduled tasks
- configurations
- credentials
- administrative privileges
Think Like a Defender
Section titled “Think Like a Defender”Whenever you identify a privilege escalation path, also ask:
- What configuration allowed this?
- What telemetry might detect it?
- Which security control failed?
- How should it be remediated?
Week 8 Outcome
Section titled “Week 8 Outcome”You should understand privilege escalation conceptually across both Linux and Windows environments.
60-Day Checkpoint
Section titled “60-Day Checkpoint”You have now studied both sides of security.
Defender Perspective
Section titled “Defender Perspective”Event → Alert → Investigation → Response
Attacker Perspective
Section titled “Attacker Perspective”Recon → Enumeration → Weakness → Access → Privilege
Now connect them:
ATTACKER DEFENDER
Recon Network Monitoring ↓ ↓Enumeration Security Telemetry ↓ ↓Initial Access ←──────→ Detection ↓ ↓Privilege Change ←──────→ Alert ↓ ↓Further Activity ←──────→ InvestigationPHASE 3 — Job Readiness, Cloud & Portfolio
Section titled “PHASE 3 — Job Readiness, Cloud & Portfolio”Days 61–90
Section titled “Days 61–90”The final phase converts technical learning into professional readiness.
You will concentrate on:
-
cloud-security awareness
-
logs
-
detection
-
SIEM
-
investigations
-
security scenarios
-
documentation
-
portfolio development
-
interviews
Week 9 — Cloud Security Fundamentals
Section titled “Week 9 — Cloud Security Fundamentals”Mission
Section titled “Mission”Understand how security changes when infrastructure moves into cloud environments.
Recommended TryHackMe Practice
Section titled “Recommended TryHackMe Practice”Complete the roadmap’s cloud-focused practice:
-
Cloud Computing
-
AWS Cloud Essentials
-
IAM Basics
-
S3 Security
Focus Areas
Section titled “Focus Areas”Understand:
-
shared responsibility
-
cloud identities
-
IAM
-
permissions
-
storage
-
cloud misconfigurations
-
cloud logging
Think in Cloud Relationships
Section titled “Think in Cloud Relationships”Identity → Permission → Cloud Resource → Data
Professional Questions
Section titled “Professional Questions”Be prepared to explain:
-
What is shared responsibility?
-
Why is IAM important?
-
What is least privilege?
-
What makes public storage risky?
-
Why is cloud logging important?
Week 9 Outcome
Section titled “Week 9 Outcome”You should be able to discuss fundamental cloud-security risks during entry-level interviews.
Week 10 — Detection, Logs & Analysis
Section titled “Week 10 — Detection, Logs & Analysis”Mission
Section titled “Mission”Strengthen your ability to investigate evidence.
Recommended TryHackMe Practice
Section titled “Recommended TryHackMe Practice”Complete:
-
Windows Event Logs
-
Splunk: Basics
-
Investigating with Splunk
-
Log Analysis
Focus Areas
Section titled “Focus Areas”Practise:
-
Windows logs
-
authentication events
-
SIEM searches
-
filtering
-
timestamps
-
IP addresses
-
usernames
-
process activity
-
event correlation
Investigation Workflow
Section titled “Investigation Workflow”Alert → Search → Filter → Correlate → Timeline → Conclusion
Build Timelines
Section titled “Build Timelines”For example:
09:01 — Failed authentication09:02 — Failed authentication09:04 — Successful authentication09:07 — Suspicious process09:09 — External connectionDo not view security events in isolation.
Week 10 Outcome
Section titled “Week 10 Outcome”You should be able to review security evidence and explain how you would investigate a basic alert.
Week 11 — CTF & Scenario Practice
Section titled “Week 11 — CTF & Scenario Practice”Mission
Section titled “Mission”Combine multiple skills without relying heavily on step-by-step instructions.
Recommended TryHackMe Practice
Section titled “Recommended TryHackMe Practice”Complete:
-
Blue
-
Steel Mountain
-
Simple CTF
-
Daily Bugle
Challenge Rule
Section titled “Challenge Rule”Before using a walkthrough:
-
Understand the target.
-
Perform your own reconnaissance.
-
Enumerate discovered services.
-
Research unfamiliar technology.
-
Form a hypothesis.
-
Test your hypothesis.
-
Use hints only when necessary.
-
Document your mistakes.
Week 11 Outcome
Section titled “Week 11 Outcome”You should begin solving unfamiliar security scenarios independently.
Week 12 — Interview & Career Alignment
Section titled “Week 12 — Interview & Career Alignment”Mission
Section titled “Mission”Turn 11 weeks of technical practice into evidence of professional capability.
This week is deliberately different.
Your primary objective is not completing more rooms.
Your objective is converting what you already learned into:
-
portfolio evidence
-
interview stories
-
professional explanations
-
job-aligned skills
Activity 1 — Review Weak Areas
Section titled “Activity 1 — Review Weak Areas”Return to your 30-day and 60-day assessments.
Identify your weakest areas.
Examples:
-
networking
-
Linux
-
SIEM
-
Windows logs
-
web security
-
cloud IAM
Revisit relevant exercises.
Activity 2 — Build Your Portfolio
Section titled “Activity 2 — Build Your Portfolio”Select your strongest labs.
For each one, document:
Scenario
Section titled “Scenario”What were you investigating?
Objective
Section titled “Objective”What did you need to accomplish?
Technology
Section titled “Technology”Which systems or technologies were involved?
Investigation
Section titled “Investigation”What approach did you take?
Evidence
Section titled “Evidence”What did you observe?
Finding
Section titled “Finding”What security problem existed?
Impact
Section titled “Impact”Why did it matter?
Remediation
Section titled “Remediation”How should it be fixed?
Lessons Learned
Section titled “Lessons Learned”What would you do differently next time?
Never publish credentials, flags, restricted walkthrough content or sensitive lab information.
Activity 3 — Map Skills to Jobs
Section titled “Activity 3 — Map Skills to Jobs”Find SOC Analyst / Junior Security Analyst job descriptions.
Map your experience:
| Employer Requirement | Your Evidence |
|---|---|
| Linux | Linux practice |
| Networking | Networking labs |
| SIEM | SIEM investigations |
| Log Analysis | Windows/log exercises |
| Incident Response | SOC practice |
| Security Fundamentals | Phase 1 |
| Attacker Knowledge | Phase 2 |
| Cloud Awareness | Cloud security practice |
This helps transform:
“I completed TryHackMe.”
into:
“I have practical experience investigating authentication events, analyzing logs, understanding network traffic and documenting security findings.”
That is a much stronger professional statement.
Activity 4 — Interview Preparation
Section titled “Activity 4 — Interview Preparation”Practise explaining:
-
CIA triad
-
vulnerability vs threat vs risk
-
TCP vs UDP
-
DNS
-
HTTP vs HTTPS
-
common ports
-
SIEM
-
SOC alert triage
-
false positive vs true positive
-
phishing investigation
-
Windows event logs
-
incident response
-
OWASP
-
privilege escalation
-
cloud shared responsibility
-
IAM
-
least privilege
Optional Practice
Section titled “Optional Practice”The source roadmap recommends:
-
Cyber Defense Frameworks
-
MITRE ATT&CK
Use these to strengthen your ability to discuss attacker behavior and defensive frameworks.
Your 90-Day Evidence Portfolio
Section titled “Your 90-Day Evidence Portfolio”By Day 90, aim to have evidence across five areas.
1. Foundation Evidence
Section titled “1. Foundation Evidence”-
Linux notes
-
networking notes
-
security concepts
2. SOC Evidence
Section titled “2. SOC Evidence”-
alert investigation
-
log analysis
-
SIEM investigation
-
phishing analysis
3. Offensive-Security Awareness
Section titled “3. Offensive-Security Awareness”-
reconnaissance
-
enumeration
-
web-security assessment
-
privilege escalation analysis
4. Cloud Security Evidence
Section titled “4. Cloud Security Evidence”-
shared-responsibility understanding
-
IAM analysis
-
storage-security analysis
5. Career Evidence
Section titled “5. Career Evidence”-
documented labs
-
skills matrix
-
interview notes
-
updated resume
-
updated professional profile
Weekly Professional Practice Record
Section titled “Weekly Professional Practice Record”For every week, complete this record:
Week:
Primary Skill:
Labs Completed:
Technologies Used:
Security Concepts Learned:
Tools Used:
Most Important Finding:
Most Difficult Problem:
How I Solved It:
What an Attacker Would See:
What a Defender Would See:
How the Risk Could Be Reduced:
Can I Explain This Without Notes?
Skills Requiring More Practice:
Interview Questions I Can Now Answer:90-Day Progress Tracker
Section titled “90-Day Progress Tracker”| Week | Focus | Practice | Documentation | Interview Ready |
|---|---|---|---|---|
| 01 | Linux | ☐ | ☐ | ☐ |
| 02 | Networking | ☐ | ☐ | ☐ |
| 03 | Security Fundamentals | ☐ | ☐ | ☐ |
| 04 | SOC Fundamentals | ☐ | ☐ | ☐ |
| 05 | Web Security | ☐ | ☐ | ☐ |
| 06 | Recon & Enumeration | ☐ | ☐ | ☐ |
| 07 | Exploitation Concepts | ☐ | ☐ | ☐ |
| 08 | Privilege Escalation | ☐ | ☐ | ☐ |
| 09 | Cloud Security | ☐ | ☐ | ☐ |
| 10 | Detection & Logs | ☐ | ☐ | ☐ |
| 11 | Scenario Practice | ☐ | ☐ | ☐ |
| 12 | Career Readiness | ☐ | ☐ | ☐ |
Day 30 Milestone
Section titled “Day 30 Milestone”By Day 30:
I understand the foundations.
You should be comfortable discussing Linux, networking, security concepts and basic SOC operations.
Day 60 Milestone
Section titled “Day 60 Milestone”By Day 60:
I understand how attacks happen.
You should understand reconnaissance, enumeration, web-security concepts, exploitation chains and privilege boundaries.
Day 90 Milestone
Section titled “Day 90 Milestone”By Day 90:
I can investigate, explain and document security activity.
You should be able to approach an entry-level security scenario methodically, research unfamiliar problems, analyze evidence and communicate your findings.
What You Should Achieve
Section titled “What You Should Achieve”After completing the 90-day journey, you should have developed:
-
stronger Linux fundamentals
-
stronger networking fundamentals
-
defensive-security awareness
-
SOC workflow understanding
-
SIEM familiarity
-
log-analysis experience
-
web-security awareness
-
attacker methodology awareness
-
cloud-security fundamentals
-
investigation methodology
-
documented lab experience
-
interview-ready technical explanations
The 90-day plan does not guarantee employment.
What it gives you is a structured foundation from which you can demonstrate practical capability and continue developing toward your target role.
The GoHackersCloud Standard
Section titled “The GoHackersCloud Standard”Do not measure yourself by:
“How many rooms did I complete?”
Measure yourself by:
“What can I now do without instructions?”
A lab is successful when you can:
-
explain the technology
-
understand the security problem
-
investigate the evidence
-
justify your conclusion
-
recommend remediation
-
communicate what you learned
Labs are not for completion. Labs are for thinking, investigating, explaining and defending your decisions.
What’s Next?
Section titled “What’s Next?”➡️ GoHackersCloud SOC Labs
You have completed the guided 90-day practice journey.
The next stage is to reduce the amount of guidance.
Move into practical SOC scenarios covering:
-
alert triage
-
suspicious authentication
-
phishing investigation
-
malware and endpoint investigation
-
network-security alerts
-
SIEM investigation
-
incident response
After completing those labs, continue into the GoHackersCloud SOC Runbooks, where you will practise following repeatable operational procedures similar to those used by professional security teams.
Your progression is now:
90-Day Practice → SOC Labs → SOC Runbooks → Projects → Portfolio → Interview → Career
### One structural change I recommend
Rather than placing this as a generic file under `Challenge Tracking`, I would make it a **prominent Academy roadmap page**:
```textTryHackMe│├── 00 Introduction├── 01 Beginner Cybersecurity Path├── 02 SOC Analyst Practice├── 03 Ethical Hacking Practice├── 04 Web Security Practice├── 05 Active Directory Practice├── 06 Cloud Security Practice│├── 90-Day Career Plan ← THIS PAGE├── Challenge Tracking└── LabsThat makes the 90-Day Career Plan the student’s execution plan, while 01–06 remain reusable skill-specific practice paths. It also preserves the uploaded plan’s original SOC/Junior Security Analyst orientation rather than turning it into an overly broad cybersecurity roadmap.