Veröffentlicht 1 Woche vor
84.94K followern
3.06K views
238 likes
7 comments
18 shares
Roadmap: 1. Learn how code ships - Git, GitHub Actions, Claude Code and Cursor. That's the pipeline nearly every modern team builds on - this is where you start 2. Get hands-on with the cloud - Docker, and one cloud on the free tier - AWS or Azure. You can't secure what you can't build. 3. Infrastructure as Code - Terraform. If your infra isn't code, no scanner and no AI tool can even see it to check it for risk. This is the step people skip and it's the one that matters most right now. 4. The security layer - OWASP Top 10, then the scanners: SAST (code scanning), SCA (dependency/supply-chain scanning), secrets detection, and IaC scanning. This is what "DevSecOps" actually means day to day. 5. Compliance and evidence - the half everyone skips and employers love. Learn what SOC 2 and the EU AI Act actually are, and how teams prove their controls continuously instead of scrambling before an audit - exactly the kind of thing a platform like Vanta automates - watch videos and use it. 6. Data platforms - a platform like Snowflake, and how you lock it down. Data security is where a lot of the newest roles sit. 7. Build one public project and get loud - a repo with a pipeline that scans itself and blocks bad code. Post it. Skip the pentesting hype - this is where the demand and the money actually are. Follow for the next step. (no LARP screens were harmed in the making of this video 😅) CI/CD: GitHub Actions · Containers: Docker, light Kubernetes · Cloud: AWS or Azure · IaC: Terraform · Scanning: SAST/SCA/secrets/IaC scanners · Data platform: Snowflake · Compliance/GRC: Vanta - continuous SOC 2 / EU AI Act evidence #devsecops #cybersecuritycareers #cybersecurity #techtok #careertok