← TOMPEARL.COM

CYBER CAREER MAP // BLUE + RED

Choose your side.
Build your craft.

A practical route from your first home lab to security leadership. No badge collecting, no fake shortcuts—learn, practise legally, and prove what you can do.

CISO / HEAD OF OFFSEC
Tom Pearl climbing the cybersecurity career ladder
FOUNDATIONS // START HERE
00

SHARED CORE

Build foundations before choosing a title

Learn TCP/IP, DNS, HTTP, Linux, Windows, Git, basic scripting, IAM, MFA, cloud fundamentals and clear technical writing.

TCP/IPLinux + WindowsPython / PowerShellIAMCloud

Portfolio proof: build an isolated home lab, diagram it, harden it and write a short risk report.

Optional first certification: ISC2 CC or Security+. Add Network+ only when networking is the gap.

DEFEND // DETECT // RESPOND

Blue Team

Turn signals into decisions, incidents into lessons, and risk into a security program.

  1. 01 · ENTRY

    SOC Analyst — Tier 1

    Tom Pearl triaging security alerts as a SOC Analyst Tier 1

    Read logs, triage SIEM/EDR alerts, investigate phishing and escalate with evidence.

    SIEMEDRMITRE ATT&CK

    Build: investigate a public log dataset and publish an incident timeline.

    Security+ · BTL1 · SC-200

  2. 02 · OPERATOR

    Incident Responder / SOC Tier 2

    Tom Pearl coordinating incident response as a SOC Tier 2 analyst

    Investigate endpoints and networks, contain threats, collect evidence and run playbooks.

    DFIRThreat huntingContainment

    Build: a ransomware response playbook with decision points.

    BTL2 · GCIH when employer-funded

  3. 03 · SPECIALIST

    Detection Engineer / Threat Hunter

    Tom Pearl hunting threats as a Detection Engineer

    Engineer detections, map ATT&CK coverage and reduce false positives with tested rules.

    SigmaKQL / SPLPurple team

    Build: a documented detection pack with test telemetry.

    SC-200 · GCIA / GCDA by specialization

  4. 04 · LEAD

    Security Engineer / Blue Team Lead

    Tom Pearl leading a blue-team security engineering session

    Design defensive architecture, IAM, cloud controls, segmentation and measurable SOC operations.

    ArchitectureCloud securityMentoring

    Build: a prioritized target architecture and risk-reduction plan.

    AZ-500 · AWS Security · CISSP with experience

  5. 05 · EXECUTIVE

    Security Manager → CISO

    Tom Pearl presenting cybersecurity strategy as a CISO

    Own governance, budget, third-party risk, crisis communication and security strategy.

    RiskGovernanceLeadership

    Build: an annual security program with objectives, scenarios and metrics.

    CISSP · CISM · CRISC—pick for the role

Enter the Blue Team Defense Manual →

TEST // EMULATE // REPORT

Red Team

Think like an attacker inside a written scope—and make the organization harder to break.

  1. 01 · ENTRY

    Junior Pentester

    Tom Pearl learning ethical penetration testing in an authorized lab

    Learn Linux, networks, HTTP, OWASP Top 10, Burp Suite, scripting and clear finding write-ups.

    WebReconReporting

    Build: assess a deliberately vulnerable lab and report fixes.

    eJPT · PNPT

  2. 02 · OPERATOR

    Penetration Tester

    Tom Pearl documenting an authorized penetration test

    Test web and Active Directory, validate manually, respect scope and communicate business impact.

    ADPivotingClient reporting

    Build: a complete legal lab pentest with action log and executive summary.

    PNPT · CPTS · OSCP

  3. 03 · SPECIALIST

    Senior Pentester / Red Team Operator

    Tom Pearl planning an authorized red-team adversary simulation

    Run controlled adversary emulation with ATT&CK objectives, OPSEC and safe infrastructure.

    Adversary emulationOPSECCloud

    Build: an emulation plan with rules of engagement and recovery steps.

    CRTO / CRTP · OSEP by specialization

  4. 04 · LEAD

    Red Team Lead

    Tom Pearl directing a professional red-team operation

    Plan campaigns, enforce stop conditions, assure quality and coordinate purple-team outcomes.

    CampaignsRules of engagementQA

    Build: an operation plan linking objectives to defensive improvement.

    Experience and leadership outweigh more badges

  5. 05 · EXECUTIVE

    Head of Offensive Security

    Tom Pearl presenting strategy as Head of Offensive Security

    Own strategy, hiring, vendors, tooling governance, legal exposure and program metrics.

    StrategyBudgetGovernance

    Build: an annual offensive program tied to priority business risks.

    CISSP / CISM may support governance—not replace operations

Enter the Red Team Field Manual →

THE REAL ENDGAME

A roadmap is a compass, not a countdown.

Certifications can open a door. Projects prove initiative. Experience, judgment, communication and ethical discipline determine how far you climb.