Skip to the content

The guide

Security & systems

Computer Science

Defending systems from attacks, and breaking into them legally to find the holes first.

This suits you if…

You stay calm in front of an alert queue, you write clearly enough that someone else can act on it, and you can accept being measured by things that didn't happen. Curiosity about how systems break, rather than a wish to break them, is the right motive here.

Look elsewhere if…

You need your evenings. Incidents don't respect them, on-call rotations are normal, and burnout in this corner of the industry is documented rather than rumoured. And if you pictured film-style hacking, most real work is configuration, permissions, patching and logging.

What the work actually is

What the work is actually like

Defensive work is monitoring, triage and patching: alerts arrive, most are noise, and the skill is deciding fast which one isn't. Offensive work is scoped and legal: you are hired to attack a specific system in a specific window, and the deliverable is a written report that explains the hole clearly enough to be fixed. Both halves involve far more writing than students expect.

The catch

Security runs on someone else's schedule: incidents don't respect evenings, and on-call rotations are normal. It's also structurally adversarial and mostly thankless. You are measured by things that didn't happen, and the day you are visible is the day something went wrong. Burnout in this corner of the industry is a well-documented problem, not a rumour.

What people get wrong about it

That it is hacking, in the film sense. Most real security work is unglamorous hygiene: configuration, permissions, patching, logging. The majority of breaches exploit ordinary human and process failures rather than exotic technical ones.

The jobs inside this area

  • Cybersecurity analyst
  • Penetration tester
  • Security engineer
  • Cloud / network engineer
  • Digital-forensics analyst

A list, not a recommendation. You narrow it, we don’t.

What this kind of work usually offers

Earning well · SecurityA generalisation about the sphere, not a promise about a salary. Pay and security vary enormously by country and employer.

How you get there

The one-line version

CS or a security track. Capture-the-flag contests like picoCTF are the accessible way in.

Stage by stage

  1. While you are still at school

    Learn how systems work before learning to break them: networking basics, Linux, a scripting language. picoCTF and similar capture-the-flag events are free, legal and genuinely representative.

  2. What you study

    CS, or a dedicated cybersecurity programme. Certifications carry unusual weight in this field compared with others, and many employers value demonstrable lab work and CTF results as much as coursework.

  3. How the first years actually go

    Often a security operations centre: shifts, alert queues and rapid triage. It's demanding and repetitive, and it is also the fastest way to learn what real attacks look like as opposed to textbook ones.

Where this work lives, and how you reach it

What you would study for it

Each says what the first year is really made of, and who should study something else instead.

16 countries · 31 cities · 36 institutions named for this field. Each one states its catch as well as its appeal.

Without leaving home

3 of the routes that need no visa and no move lead into this field.

Test it this month

Free, and finishable in a few evenings

Do the beginner track of a free CTF, and when you solve a challenge write up how, clearly enough for someone else to follow. The write-up is the actual professional artefact, and being good at it is rarer than being good at the puzzle.

Do the job for an afternoon, before you pick a degree

Employers build these to recruit, which is why they are honest about what the work is. You do the real tasks, unpaid and ungraded, and find out whether you can stand it. Free, no deadline, nothing to win.

  • Mastercardabout 3 hours

    Work a phishing report from the inside: find what was hit, decide what to shut down, and write the note that goes to people who are not technical.

  • AIGabout 3 hours

    Take a vulnerability report apart, work out what an attacker could actually reach, and rank what gets fixed first when you cannot fix everything.

These are on Forage. Search it by the employer’s name — what each one is called changes, and who built it does not.

Open Forage from the catalog

These are ways to try Security & systems before committing to it.