Ten cybersecurity job titles, mapped to the exact missions that train for them.
Each role below breaks down what employers actually ask for, which of it SecMissions already teaches, and where the honest gaps remain. Pick the title you are aiming for and follow the starter plan.
Role library
Find your title, see what is covered.
The coverage bar on each card is not a marketing number. It is computed from how many of that role's advertised skills already map to a real mission, so a role we cover thinly says so.
SOC Analyst
A SOC analyst watches security tooling for a living: triaging alerts from a SIEM and an EDR platform, correlating logs across systems to tell a real incident from noise, and escalating with enough evidence that the next shift can act on it immediately. It is a shift-based, evidence-first role built around fast, repeatable judgment calls.
Security Engineer
Security Engineer is the broad, generalist title most specialist tracks eventually split out of: hardening endpoints and networks, prioritizing which vulnerability actually gets fixed first, reviewing code for security flaws, and covering the identity and cloud basics well enough to hand a harder problem to a specialist team. It rewards range over depth in a first security engineering job.
Cloud Security Engineer
A cloud security engineer treats identity as the primary control plane, ahead of the network perimeter: designing IAM policy across AWS, Azure, and GCP, closing container and metadata trust gaps, and reasoning about the blast radius of a single leaked credential or over-broad role. Most of the job is reading configuration precisely and reasoning about what it actually grants.
Penetration Tester
A penetration tester is hired to find and prove a real attack path before someone else does: intercepting and tampering with web traffic, chaining authorization and injection flaws into something with real impact, and writing a report a client's engineering team can act on. Manual reasoning over an automated scanner result is what separates a strong tester from a checklist runner.
Application Security Engineer
An application security engineer builds and runs the program that keeps a company's own software secure: reviewing code for the flaw class rather than a single instance of it, threat modeling a feature before it ships, and increasingly securing the LLM powered features that a deterministic security background never had to think about. Principal level postings are common once a program matures.
DevSecOps Engineer
A DevSecOps engineer moves security into the delivery pipeline itself: hardening containers and CI runners, scanning infrastructure as code before it deploys, and gating a release on a failed security check rather than catching the problem after the fact. Most people reach this title from a platform or DevOps background rather than a pure security one.
GRC Analyst
A governance, risk, and compliance analyst maps controls to a framework such as ISO 27001, SOC 2, or NIST, reviews audit evidence, assesses vendor risk, and keeps a risk register honest. It is structured, writing-heavy work rather than hands-on-keyboard testing, and it is one of the more accessible specialist entry points into the field.
Incident Responder
An incident responder reconstructs what actually happened during a suspected compromise: correlating logs across hosts and services, building a timeline from disparate evidence, scoping the blast radius, and triaging malware when one turns up. It is investigative work under pressure, and it almost always follows time already spent in a SOC.
IAM Engineer
An identity and access management engineer owns how people and services authenticate and what they are allowed to do once they have: designing single sign-on and role based access, closing cross-account trust gaps, and reasoning precisely about what a policy or a token actually proves. Platform-owning roles sit above a junior tier doing provisioning and access review work.
AI Security Engineer
An AI security engineer treats a model or an agent the way any other application security engineer treats untrusted input: testing for prompt injection, scoping what an agent's tools are allowed to touch, and questioning the provenance of a model's weights and training data the same way a supply chain review questions a dependency. It is the newest specialization in the field, built by security people rather than by ML researchers.
Prefer to browse by domain instead of by title?
Every role plan pulls from the same ten security domains. The interview prep hubs walk through each domain on its own, with a scored Interview Lab round behind a free account.
Browse interview prep by domain