Skip to main content

12-Month Roadmap

PhaseMonthsFocusRequired outcome
Foundation1–2Windows telemetry, networking, Wazuh, GitHub workflowReliable alert triage and evidence habits
Detection & IR3–4Detection logic, ATT&CK, incident response, threat intelligenceDetection pack + incident runbook
Cloud & automation5–6Cloud-security fundamentals, Python/PowerShell basics, GitHub ActionsCloud baseline + small automation artefact
SOC depth7–8Threat hunting, rule tuning, case management, reportingMulti-stage investigation portfolio
Professional growth9–10Communication, interview preparation, cross-functional workInterview-ready CV/LinkedIn/portfolio evidence
Specialisation11–12Detection engineering, cloud security or incident responseCapstone and next-role development plan

Months 1–2 — Foundation

  • establish a repeatable Windows-event investigation method;
  • strengthen TCP/IP, DNS, authentication and endpoint-log reasoning;
  • understand Wazuh agent, manager, rules, alerts and decoder concepts;
  • use GitHub issues, branches, commits and README files professionally;
  • complete the 12-week sprint with evidence rather than attendance.

Months 3–4 — Detection and incident response

  • write and test simple detection logic;
  • document false positives and tuning decisions;
  • map common activity to MITRE ATT&CK;
  • complete incident-response tabletop exercises;
  • improve incident summaries and escalation writing.

Months 5–6 — Cloud and automation

  • learn identity, least privilege, logging, monitoring and network controls in cloud environments;
  • compare cloud controls across Google Cloud, Microsoft Azure and AWS at a fundamentals level;
  • automate one repeatable SOC task with Python or PowerShell;
  • add automated validation to a GitHub repository.

Months 7–8 — SOC depth

  • run multi-source investigations;
  • practise threat hunting from a hypothesis rather than an alert;
  • create a small SOC scorecard;
  • improve Wazuh rules and documentation;
  • produce a case-study style investigation.

Months 9–10 — Professional growth

  • refine CV, LinkedIn and GitHub portfolio around evidence;
  • practise concise written and verbal incident explanations;
  • complete mock SOC interviews;
  • participate in a cross-functional or peer-review activity;
  • improve time-management habits around focused learning blocks.

Months 11–12 — Specialisation

Choose one primary direction based on evidence and opportunity:

  • Detection Engineering;
  • Cloud Security;
  • Incident Response / Threat Hunting.

Complete a capstone that combines telemetry, detection, investigation, documentation and presentation.

Formal gates

  • Day 30: evidence workflow and first Windows/Wazuh investigations are reliable.
  • Day 60: at least one detection and one incident-response artefact are mentor-reviewed.
  • Day 90: at least 10 sprint weeks are accepted and three portfolio artefacts are review-ready.
  • Month 6: one automation and one cloud-security artefact are complete.
  • Month 12: six portfolio items and a capstone support a clear next-role story.