Security Engineer
Design and build the security systems that protect organisations at scale.
What does a Security Engineer do?
Security engineers go beyond analysis — they build tools, write secure code, and architect defences from the ground up. Where analysts detect and respond, engineers build the systems that prevent problems. It requires strong programming skills on top of security knowledge.
Who it fits
Experienced developers who want to specialise in security, or security analysts who enjoy building tools and systems.
Best for experienced technical learners who want to build security systems, not just monitor them.
Skills you need
Tools you will use
Starter projects
Good projects to practise and add to a portfolio.
- Secure authentication system from scratch
- Automated vulnerability scanner
- Secrets management tool
- Security CI/CD pipeline
// ROADMAP
Security Engineer career roadmap
Estimated time: 12–18 months
Badges show what each resource is. Only items marked certification lead to a professional credential — everything else is learning material.
Programming & Linux
8–10 weeksSecurity engineers need to write code. Python or Go are standard choices. Combine this with deep Linux skills — you need to be comfortable on the command line for hours.
Web Security Fundamentals
6–8 weeksLearn the OWASP Top 10 — the ten most critical web security risks. Understand SQL injection, XSS, CSRF, and authentication flaws. Portswigger Web Academy is the best free resource for this.
Cloud Security
6–8 weeksMost modern infrastructure runs on AWS, GCP, or Azure. Learn how to configure IAM, secure S3 buckets, set up security groups, and use cloud-native security services.
CTF Practice & Red Team Skills
OngoingSecurity engineers often need to think offensively to defend effectively. Work through HTB machines, CTF challenges, and study real vulnerability disclosures.
Certifications & Specialisation
12–16 weeksOSCP is the gold standard for offensive security. AWS Security Specialty or CISSP for defensive/cloud engineering. Choose based on which direction you want to go.
// START LEARNING
Security Engineer learning resources
Videos first — they're the fastest way to get moving — then reading, hands-on practice and courses. Only resources badged professional certification award a formal credential.
The Hacker's Roadmap: Getting Started in Cybersecurity
NetworkChuck · 25 minutes
A current orientation to the certifications, practical skills and experience needed to enter cybersecurity.
Learning resource. This does not award a professional certification.
Networking Basics
Cisco Skills for All
A free foundational course covering network devices, protocols, addressing and basic troubleshooting.
Certificate availability depends on the course provider.
Linux Journey
LabEx
Short progressive lessons on the command line, permissions, processes, networking and system administration.
Certificate availability depends on the course provider.
OWASP Top 10
OWASP
The industry-standard awareness guide to the most important web application security risks.
Learning resource. This does not award a professional certification.
Introduction to Cyber Security
TryHackMe
Guided browser-based labs introducing offensive security, defensive security, networking and web concepts.
Learning resource. This does not award a professional certification.
Web Security Academy
PortSwigger
Free learning paths and realistic labs for web vulnerabilities, testing methodology and exploitation.
Learning resource. This does not award a professional certification.
// PRACTISE
Gain Security Engineer work experience
Build practical evidence before your first role. Provider terms and eligibility can change.
Forage · Employer job simulations
virtual-job-simulation · REMOTE
Complete self-paced tasks designed by employers and compare your work with example solutions.
GitHub · Good first issues
open-source · REMOTE
Find newcomer-labelled issues and build evidence of collaboration in public repositories.
PortSwigger Web Security Academy · Web security practice labs
hands-on-lab · REMOTE
Solve realistic web-vulnerability labs and document methodology and results as practical security evidence.
// FIND WORK
Find Security Engineer jobs
Start with “Security Engineer”. Platforms without stable public search URLs open with this suggested phrase.
LinkedIn Jobs
Broad professional job search with keyword, location, experience-level and remote filters.
Wellfound
Startup and technology roles with company and compensation context.
Dice
Specialist technology roles across engineering, data, security and infrastructure.
Built In
Technology and startup job discovery, including remote and city-focused listings.
UK visa and international opportunities
Sponsorship depends on the employer, vacancy and current immigration rules. Use the linked official guidance and verify every role before applying.
Going independent
Security engineering skills command some of the highest freelance rates in tech. Penetration testing and AppSec consulting are particularly lucrative.
Penetration Testing Consulting
Medium effortProvide professional penetration testing services to companies who need to test their security before attackers do.
Examples
- Web application penetration tests
- Network penetration tests for SMEs
- Red team exercises for larger enterprises
- Social engineering assessments
Getting started
- 1. Obtain CREST CRT or OSCP certification for credibility
- 2. Build a professional scope-of-work and report template
- 3. Partner with an established firm initially for subcontracting experience
- 4. Join CREST or CHECK scheme for government and enterprise access
Security Tool Development
High effortBuild and sell security tools — scanners, monitoring solutions, or developer security libraries.
Examples
- SaaS security scanning tools for developer workflows
- Security dependency auditing tools
- Open source security libraries with paid enterprise tiers
Getting started
- 1. Identify friction in security workflows you have personally experienced
- 2. Open source the core tool, charge for cloud hosting or team features
- 3. Launch on GitHub and Hacker News simultaneously
Communities & tools
// EARNING POTENTIAL
Earning potential
2025One of the highest-paid engineering specialisms. Strong engineering skills combined with security knowledge create a rare and highly valued profile.
Freelance rates
Day rate
£400–£900
Hourly rate
£50–£115
What affects salary
- Application security (AppSec) experience at senior level is scarce and highly paid
- OSCP and cloud security certifications are strong differentiators
- Penetration testing experience adds significant value
- Security engineering at fintech or Big Tech firms pays well above average
- Bug bounty track record signals real practical ability
🌍 US security engineers at major tech companies earn $150k–$250k+. Remote security engineering roles are increasingly available.
Based on: ITJobsWatch · Glassdoor UK · LinkedIn Salary · Security BSides job board. All figures approximate.
// RESOURCES
Free resources to get started
Recommended starting points — no payment required.
- Reading
- Course
- Lab
- Lab
- Course
Paid courses worth considering
These are not required — free resources above can get you far.
- Professional certification
- Professional certification
Browse all resources
Resource directory.
Free and paid resources across every tech career path — searchable and filterable.
Not sure this fits?
Take the assessment.
Answer a few short questions and get your top matches — with reasons why they fit you.
Wondering if you are ready for this path? Analyse your CV →
Related careers
Compare paths that share skills, tools or ways of working.


