The guide

Security & systems

Computer Science

Defending systems from attacks — and breaking into them legally to find the holes first.

What the work actually is

What the work is actually like

Defensive work is monitoring, triage and patching: alerts arrive, most are noise, and the skill is deciding fast which one is not. Offensive work is scoped and legal — you are hired to attack a specific system in a specific window, and the deliverable is a written report that explains the hole clearly enough to be fixed. Both halves involve far more writing than students expect.

The catch

Security runs on someone else's schedule: incidents do not respect evenings, and on-call rotations are normal. It is also structurally adversarial and mostly thankless — you are measured by things that did not happen, and the day you are visible is the day something went wrong. Burnout in this corner of the industry is a well-documented problem, not a rumour.

What people get wrong about it

That it is hacking, in the film sense. Most real security work is unglamorous hygiene — configuration, permissions, patching, logging — and the majority of breaches exploit ordinary human and process failures rather than exotic technical ones.

The jobs inside this area

  • Cybersecurity analyst
  • Penetration tester
  • Security engineer
  • Cloud / network engineer
  • Digital-forensics analyst

A list, not a recommendation — you narrow it, we don’t.

What this kind of work usually offers

Earning well · SecurityA generalisation about the sphere, not a promise about a salary. Pay and security vary enormously by country and employer.

How you get there

The one-line version

CS or a security track. Capture-the-flag contests like picoCTF are the accessible way in.

Stage by stage

  1. While you are still at school

    Learn how systems work before learning to break them: networking basics, Linux, a scripting language. picoCTF and similar capture-the-flag events are free, legal and genuinely representative.

  2. What you study

    CS, or a dedicated cybersecurity programme. Certifications carry unusual weight in this field compared with others, and many employers value demonstrable lab work and CTF results as much as coursework.

  3. How the first years actually go

    Often a security operations centre: shifts, alert queues and rapid triage. It is demanding and repetitive, and it is also the fastest way to learn what real attacks look like as opposed to textbook ones.

Test it this month

Free, and finishable in a few evenings

Do the beginner track of a free CTF, and when you solve a challenge write up how — clearly enough for someone else to follow. The write-up is the actual professional artefact, and being good at it is rarer than being good at the puzzle.