HPSB
HPSB · Cybersecurity

Getting Started in Cybersecurity

A short, current path into the field. Built from a doc Zubair has maintained with friends since 2018 for people considering the move, cleaned up and updated.

Cybersecurity rewards two habits: a home lab you actually use, and a community you can ask. Pick the one career direction that pulls at you, then commit to one or two resources at a time. Breadth comes later.

If you read only one section first, read Start here. Then pick a track (red, blue, app, RE, crypto) and live in it for three to six months before adding another.

Start hereHome lab, first books, first courses+

Get a lab running locally, then learn from one book and one free course. Don't buy gear before you have outgrown free options.

Home lab

  • LabKali Linux — the attacker VM. Boot from VirtualBox or VMware Player (both free).
  • LabMetasploitable 2 — intentionally vulnerable target. Pair with Kali.
  • LabVulnHub — more vulnerable VMs to practice on.
  • LabVirtualBox — free hypervisor for the home lab. Any 8 GB laptop runs two VMs comfortably.

First reads

First course

Free training & roadmapsStructured courses without a fee+

Free, structured, recently maintained. Pick one. Finish it before starting another.

Career pathsPick one role to aim for+

Don't learn "cybersecurity." Learn one role's daily work. The big tracks:

  • RolePenetration tester / Red team — breaks into systems for clients. Hands-on, technical, travel sometimes. OSCP / PNPT path.
  • RoleSOC analyst / Blue team / DFIR — defends, investigates incidents, hunts threats. Most entry-level jobs sit here. Sec+ / CySA+ / GCIH.
  • RoleAppSec engineer — secures code and product. Sits between dev and security. Often the highest-paid track for people with dev backgrounds.
  • RoleCloud security — AWS / GCP / Azure security engineering. High demand, cert-friendly path.
  • RoleVulnerability research / RE / exploit dev — finds new bugs in binaries, browsers, kernels. Hardest path, smallest job market, highest ceiling.
  • RoleBug bounty hunter — self-employed, paid per finding. Compatible as a side income.
  • RoleGRC / risk / compliance — non-technical track. Audits, frameworks, policy. Good entry for career changers without a tech background.

Career exploration

Interview prep

Practice & CTFsHands-on labs, capture-the-flag+

Reading without practice doesn't stick. Pick one platform and finish a track.

  • LabTryHackMe — guided, free-tier-friendly. Where most beginners actually start now.
  • LabHack The Box — next step after TryHackMe. Less hand-holding.
  • Labpwn.college — ASU's free, deep dive on binary exploitation and CTFs. Excellent if you have time.
  • LabOverTheWire wargames — terminal-based CTF, the classic Linux + crypto warmup.
  • LabRoot-Me — huge catalog of challenges across every category.
  • LabpicoCTF — Carnegie Mellon's ongoing CTF. Beginner-friendly, runs year-round.
  • Labpwnable.tw  ·  pwnable.kr — for serious binary exploitation practice.
  • LabCTFtime — calendar of upcoming CTFs + a huge writeup archive. Read writeups even if you don't play.
Red TeamOffensive security+

Adversary emulation, internal red teams, and pentesting. Start with practical, move to TTPs.

Blue Team / SOC / DFIRDefense, detection, incident response+

Most entry-level security jobs are blue team. Get good at logs, detections, and investigations.

Reverse Engineering & Malware AnalysisStatic and dynamic analysis+

Slow path. Pick one tool family (Ghidra or IDA Free) and one course, and grind a sample a week.

AppSec & Bug BountyWeb, API, mobile+

The single highest-leverage track if you already write code.

CryptographyApplied + theoretical+

Hard to bluff. If you want to do this seriously, you will use math.

Community, podcasts, newsPeople + ongoing signal+

Pick one podcast and one news source. Subscribe. Don't try to read everything.

Local (Toronto / Canada)

Podcasts

News & threat intel

Newcomers to CanadaFree/funded retraining programs+

Bridge programs that retrain internationally-educated professionals into Canadian cyber jobs. Eligibility varies; read carefully.

More on coachzubair.com

Library · curated

Inspirations from other founders

Dashboards, talks, books, and resources curated for builders. Where to look when you want a window into how others operate.

Explore Inspirations ›
Framework · research

Architects of Impact

A map of the people who change the shape of the world. The archetypes, the patterns, what each looks like in practice.

Open ›
App · free

Qawi: Daily Practice

The companion app to HPSB. Build strength across five dimensions: soul, body, mind, character, and wealth.

Open Qawi ›