"Cybersecurity" is not a job — it's a category. The six tracks that hire most consistently:
- SOC analyst / threat detection — alert triage, SIEM, IR. Strong entry path.
- AppSec / product security — code reviews, threat modeling, vulnerability remediation. Best for people with software engineering background.
- Cloud security — IAM, configuration, container hardening. Strong demand, fast-growing.
- Offensive security — penetration testing, red teaming, bug bounty. Hardest to break into; most romanticized.
- GRC (governance, risk, compliance) — policy, audit, framework work. Often overlooked, very hireable.
- Detection & response engineering — building the pipelines and detections that SOC analysts use. The fastest-growing track.
Pick one to start. You can move laterally later — the field rewards generalists, but you need depth somewhere first.