How to become a Cybersecurity Analyst

Cybersecurity analysts protect systems and data — monitoring for attacks, finding weaknesses before criminals do, and responding when something goes wrong.

Eligibility at a glance

For India (India). Conditions marked "Not required" genuinely do not apply.

Minimum education

No single mandated degree; computer science/IT degrees are common, and respected certifications can substitute at many employers.

School subjects

Not required

Degree / diploma

B.Tech/BCA in CS/IT helpful; certification-led entry also recognised

Graduation required

Not required

Minimum marks

Not required

Minimum age

Not required

Maximum age

Not required

Age relaxation

Not required

Nationality

Not required

Physical requirements

Not required

Medical requirements

Not required

Gender-specific rules

Not required

Number of attempts

Not required

  • · Background verification is common; a criminal record is disqualifying for most security roles

The path, step by step

The standard entry route. Alternative routes are listed under Education paths below.

  1. Class 12 — Science with Maths/Computer Science preferred

  2. Learn networking + Linux + one scripting language

  3. Degree (CS/IT) or certification-led path

  4. Entry certification (network/security fundamentals)

  5. SOC / junior security analyst role

  6. Cybersecurity Analyst (specialise: pentest, forensics, GRC)

What this career actually is

Security analysts defend organisations' computers, networks and data. Work ranges from watching alert dashboards (SOC analyst) to probing systems for weaknesses (penetration testing) to designing defences. It is one of the fastest-growing and most acute-skill-shortage areas of IT.

A typical day

  • · Monitoring alerts and investigating suspicious activity
  • · Running vulnerability scans and patching weaknesses
  • · Writing incident reports and improving defences
  • · Practising attack techniques in safe lab environments

Main responsibilities

  • · Detect and respond to intrusions quickly
  • · Find and fix vulnerabilities before attackers exploit them
  • · Maintain security policies and train staff
  • · Document incidents forensically for audit and learning

Work environment

Security operations centres, offices or remote; shift work is common in monitoring roles. Banks, IT firms, government agencies and consultancies all hire.

Who this suits

  • · Curious, patient investigators
  • · People who like rules, systems and out-thinking adversaries
  • · Those willing to keep learning permanently

How long the path takes

Roughly 2–5 years after Class 12 from the point the path begins.

  1. Class 12

    2 years

  2. Degree or certification path

    1–4 years

  3. Entry certification + home lab

    3–6 months

  4. SOC / junior analyst

    1–2 years

  5. Specialised security role

    ongoing

Timelines vary — few people follow the exact same schedule. Treat this as a map, not a schedule.

Exams on this path

Stage, pattern and eligibility details for each exam this career usually involves.

Conducted by National Testing Agency (NTA) · Twice a year in recent cycles (two sessions)

Purpose
Entrance test for NITs, IIITs, other centrally funded technical institutions, and the qualification screen for JEE Advanced.
Eligibility
Class 12 pass/appearing with Physics, Chemistry and Mathematics. Verify the current brochure for year-of-passing rules.
Age limits
No upper age limit in recent cycles; institutes may have their own age criteria.(may change — verify at the official source)
Attempts
A candidate may attempt JEE Main in multiple sessions per year; verify the current brochure for the limit on consecutive years.(may change — verify at the official source)
Pattern & marks
Computer-based; Mathematics, Physics, Chemistry. Negative marking applies. · 300 marks for Paper 1 in recent patterns
Duration
About 3 hours
Subjects
Mathematics, Physics, Chemistry
Stages
JEE Main Paper 1 (B.E./B.Tech) → JEE Main Paper 2 (B.Arch/B.Planning, for those routes) → Rank list and JoSAA/state counselling
Notes
Admission to IITs additionally requires JEE Advanced. Verify session dates and rules in the current brochure.
Official website ↗Fees, vacancies, cutoffs and dates change — check the official link. Information compiled 2025-01, not live-checked — how this data is compiled.

Conducted by IISc and IITs (organising institute rotates) · Once a year

Purpose
Admission to M.Tech/MS and PhD programmes, and recruitment by public sector undertakings (PSUs) and research organisations.
Eligibility
Bachelor's degree holders in engineering/technology/architecture, or master's in relevant science streams; candidates in the final year may apply per the current brochure.
Age limits
No age limit.(may change — verify at the official source)
Attempts
No attempt limit.(may change — verify at the official source)
Pattern & marks
Computer-based; discipline paper plus a general aptitude section. Question types include MCQ, multiple-select and numerical answer. · 100 marks (long-standing scheme)
Duration
3 hours
Subjects
Engineering mathematics, Chosen discipline's core subjects, General aptitude
Stages
Single computer-based paper in the chosen discipline → Score used by institutions/PSUs for their own processes
Notes
Each PSU runs its own recruitment on GATE scores; cutoffs vary by organisation and year.
Official website ↗Fees, vacancies, cutoffs and dates change — check the official link. Information compiled 2025-01, not live-checked — how this data is compiled.

What to study — complete checklist

Tick topics as you learn them. Your ticks are saved in this browser.

Skills required

Qualifications get you in; these keep you there.

Technical skills

  • Networking (TCP/IP)
  • Linux and Windows administration
  • SIEM and log analysis
  • Scripting in Python/Bash

Practical skills

  • Investigating alerts methodically
  • Safe, legal exploitation practice in labs
  • Documentation under pressure

Communication skills

  • Explaining risk to management
  • Writing clear incident reports

Tools & software

  • Wireshark
  • Nmap
  • Kali Linux toolset
  • A SIEM platform
  • Vulnerability scanners

Languages

  • Python and Bash scripting

Certifications

  • Entry: network/security fundamentals certifications
  • Intermediate: SOC and ethical-hacking certifications
  • Advanced: offensive-security and audit certifications

Portfolio

Home lab write-ups, CTF rankings, responsible-disclosure acknowledgements

Education paths

Every major route into this career — including routes that skip a degree where they exist.

Degree route

Typical duration: 3–4 years
  1. B.Tech/BCA in CS/IT
  2. Security electives and labs
  3. Internship at a SOC
  4. Junior analyst role

Certification-led route

No degree neededTypical duration: 1–2 years
  1. Learn networking + Linux
  2. Earn entry security certification
  3. Home lab and CTF practice
  4. Entry SOC/analyst role

Is college compulsory? No — recognised non-college routes exist (shown above).

Without a degree: Possible via certifications and demonstrable lab/CTF work, particularly in SOC and testing roles; some employers still prefer degree holders.

Entrance exams: Standard engineering/university entry for the degree route

Career progression

How roles typically advance. Alternative branches shown where the path forks.

  1. SOC Analyst (Tier 1)
  2. Security Analyst (Tier 2)
  3. Senior Security Engineer
  4. Security Architect / Manager
  5. CISO track
Security AnalystPenetration Tester · Digital Forensics · Governance, Risk & Compliance · Security Researcher

Where the jobs are

Private sectorGovernmentInternational rolesFreelance

Earning potential

Broad ranges only — pay is never guaranteed and varies hugely by employer, city and seniority.

Typical salary stages for Cybersecurity Analyst
Entry levelBroadly ₹3–8 lakh per year for SOC/junior roles
Mid-careerBroadly ₹10–25 lakh per year
Experienced₹25 lakh+ per year for architects and specialists

Certifications and specialisation move pay significantly; figures are market observations.

What you are up against

An honest picture of competition and effort — no fake difficulty scores.

Competition

Moderate at entry — demand outstrips supply, but roles require proven hands-on skill

Study load

Continuous and significant; the field shifts monthly

Selectivity

Employers test practical skill heavily; paper certificates alone rarely suffice

Major challenges

  • · Attackers innovate constantly
  • · On-call and shift duties in SOC roles

Time commitment

1–2 years to first role with focused study

What candidates commonly struggle with

  • · Networking fundamentals
  • · Staying calm and methodical during incidents

Documents you will need

Commonly required for applications and admissions. Exact requirements are set by each authority — always check the official notice.

  • ✓ Aadhaar card or other government photo ID
  • ✓ Class 10 and Class 12 marksheets and certificates
  • ✓ Recent passport-size photographs
  • ✓ Scanned signature (as per the notified size and format)

Recommended Books

Recommended Books

Book recommendations are being curated.

Checked for Cybersecurity Analyst — nothing is listed until it is genuinely recommended.

Frequently asked questions

Do I need to be a great programmer?

No — scripting skill is needed, but deep software engineering is not the core. Networking, systems understanding and investigative method matter more.

Is 'ethical hacking' legal to learn?

Learning attack techniques is legal; using them on systems without written authorisation is a crime. Practise only on labs, CTFs and authorised bug-bounty scopes.

Can government jobs in security exist for me?

Yes — agencies and PSUs recruit security specialists, usually requiring degrees and their own vetting processes.

What certification should be my first?

A widely recognised entry-level network/security certification is the standard first rung; choose based on the role you want (SOC vs testing).

Can I enter this career after Class 10?

Not directly. The standard entry path starts later — see the roadmap above for where it actually begins.

Can I enter this career after Class 12?

Yes — Class 12 is a genuine entry point for this career. Look at the education routes and roadmap for the exact next step.

Which stream should I choose in Class 11–12?

No single stream is mandatory. Pick the stream that keeps the subjects you will need — the eligibility section lists what matters for this career.

Is a degree compulsory?

No — this career can be entered without a degree. Possible via certifications and demonstrable lab/CTF work, particularly in SOC and testing roles; some employers still prefer degree holders.

What is the age limit?

There is no fixed age limit for the standard entry path. Where a specific exam or employer applies one, it is listed in that exam's or employer's own rules — always verify from the official source.

Is there an entrance exam?

Yes — this career commonly involves entrance exams. See the Exams section for the stages, pattern and official links.

How long does it usually take?

Roughly 2–5 years after Class 12, counting from the point where the path begins. Timelines vary — people repeat years, switch routes and start at different points, so treat this as a map, not a schedule.