courses

Roles and Careers in Cybersecurity

“Cybersecurity” is not one job

One of the most common misconceptions about security is that it is a single career — a hooded figure typing furiously in a dark room. In reality, cybersecurity is an enormous, interdisciplinary field with dozens of distinct roles demanding very different skills: some deeply technical, some investigative, some legal, some people-facing, some research. A talented social engineer, a reverse engineer staring at disassembly, a privacy lawyer, and a compliance auditor are all “in cybersecurity,” and they may never use the same tool twice.

This breadth is good news: there is a path for almost any aptitude, and the field has a persistent workforce shortage — hundreds of thousands of unfilled roles in the US alone. This page maps the landscape so you can see where your interests might fit, and how the rest of this course (and the other PSU security courses) connects to real jobs.

Two ways to map the field

The team colors (the informal map)

The industry borrows military exercise terminology to describe orientation:

The NICE Framework (the formal map)

For a rigorous taxonomy, the US government’s NICE Framework (NIST SP 800-181) defines cybersecurity work in terms of work roles, competency areas, and the tasks/knowledge/skills behind them. Its 2024 revision organizes work into seven categories: Oversight & Governance, Design & Development, Implementation & Operation, Protection & Defense, Investigation, Cyberspace Intelligence, and Cyberspace Effects. It is the reference employers and curricula use to describe jobs consistently — worth knowing by name when you read job descriptions.

A tour of the roles

Defensive (blue team)

Offensive (red team)

⚠️ Offensive work is legal only with explicit authorization (a contract, a scope, a bug-bounty policy). The exact same nmap scan is a paid engagement or a federal crime depending entirely on permission — see the privacy and law material. Ethics and scope are not optional add-ons to this career.

Building secure software

Governance, risk, and the human side

Specialized and research tracks

How this maps to the PSU security courses

This course is the broad foundation; the others go deep in a direction that aligns with the roles above:

If you’re drawn to… Explore…
Defense, detection, network monitoring CS496/596 Network Security
Investigation, IR, evidence CS493/593 Digital Forensics
Building & operating secure systems CS410/510 System Administration & DevOps
Embedded / OT / device security CS410/510 IoT Security
Reversing & malicious code CS492/592 Malware Reverse Engineering

The local CyberPDX community and PSU’s Code Party are good ways to meet people working in these roles.

Getting in: building a path

You do not need to pick a specialty on day one — breadth first, then depth. What consistently works:

Key takeaways

References


Related course pages: Security Principles and Approaches · Access Control and Authorization · Social Engineering · Host Security · Application Security · Privacy · Incident Response

🛠️ Maintenance note: role titles, certification names, and workforce-gap figures shift yearly — re-verify the NICE category list (last revised 2024), certification relevance, and CyberSeek numbers before each term. The PSU course-mapping table should be updated if course numbers or offerings change.