Every pathway shows what it actually demands: coding intensity, on-call weight, promotion ceiling, entry saturation, AI resilience. Not just a salary band.
Written by James, a UK security architect.
If you read nothing else
Three pathways a practitioner would actually pick today.
Worth it if you actually enjoy adversarial problems and shift work. Skip if you wanted security because it sounded important.
Not Offensive Security as a first job, that's a mid-career pivot, not an entry route.
Editorial verdicts
Practitioner opinion, late 2026.
Most over-recommended
Cybersecurity as a first job
Half the YouTube ecosystem points beginners here. The entry queue is the longest in tech, the shifts are real, and most SOC openings quietly want a year of IT operations behind you. It's still a good career. It's a bad opening move from a standing start.
Unfashionable, stable, and the skill that makes cloud and security engineers actually competent later. Pay isn't headline-grabbing, but the work outlasts every cloud rebrand and the pivot options are excellent.
Still a strong career. The entry market is genuinely harder than the industry admits, and the bootcamp-to-job promise rarely lands in three months. Pick it because you'd write code anyway, not because the salary numbers look good on LinkedIn.
It's a great mid-career pivot from AppSec, dev or sysadmin. It's a poor first job. The junior pentest market is thin, OSCP without report-writing experience rarely converts, and most career-changers burn 18 months before a callback. Come back to this one later.
Reality check. Ratings are directional. Compensation, on-call load, and remote availability vary heavily by employer, geography, and seniority. Treat them as hypotheses to validate, not facts.