# Twenty-five security study plans and the checkbox problem they share

> A markdown-only repository of role-based cybersecurity curricula, from web pentesting to Kubernetes and GenAI security, built for someone starting from a tech job.

**jassics/security-study-plan** — Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...

- Repository: https://github.com/jassics/security-study-plan
- Website: https://cybercloud.guru/
- Stars: 5,097 · Forks: 638
- Language: Unknown
- License: not declared
- Published: 2026-10-07 · Updated: 2026-10-07 · Language: en
- Canonical page: https://hysenlabs.com/projects/jassics-security-study-plan

## What the repository is actually made of

The tree is the honest description of the project. Twenty-five markdown files sit next to a README, an `images/` directory, a `useful-security-scripts/` directory, a `.gitignore`, and a `.DS_Store` that should not have been committed. That is the whole thing. There is no tooling, no site, no progress tracking beyond what GitHub's task list markdown gives you for free.

The twenty study plans marked as done cover common skills, AWS, GCP, Azure, web penetration testing, application security, API security, threat modeling, GRC, DevSecOps, Docker, Kubernetes, network security, cryptography, software supply chain, secure code review, secure SDLC, security architecture, GenAI security and product security. Five more sit under additional plans: identity and access management, blue team detection and response, mobile application security, reverse engineering and malware analysis, and OSINT with social engineering.

The spread tells you what the author thinks the job market looks like. Cloud is covered on all three major providers, containers get two plans, and both supply chain and AI security have dedicated files, which are two areas that would not have appeared in a curriculum five years ago.

## An explicit model of time, prerequisites and repetition

The README is unusually direct about effort. It states that studying three to four hours a day for six months can lead to well-paid jobs, conditional on coming from a tech background, doing substantial hands-on work, and going through each topic more than once. It also hedges the same claim in the other direction, saying it may take months or sometimes a year, and that someone already familiar with a lot of the material will move faster.

The prerequisites list reads like a warning: ready to devote time daily, a tech background though not a strict requirement, never giving up, a hacker mindset, and willingness to explore on your own. That last one is the load-bearing item. A checklist cannot tell you what you missed, so the plan assumes you will go looking for gaps yourself.

The recommendation to learn git and clone the repository rather than reading it on the site is the practical tip in the README. With checkboxes, a clone gives you diffs when a plan is revised, and git history shows which topics were added late, which is a decent signal about where the field is moving.

## Checkboxes as a self assessment rather than a syllabus

Each plan is a list of topics in GitHub's task list markdown, ordered top to bottom. The author's stated intent is diagnostic: tick what you already know, and what remains is what you need. That framing is the repository's main strength and its main trap.

It works well when you are pivoting from adjacent work. An infrastructure engineer already has networking, Linux and cloud IAM, so the AWS plan becomes short and the parts they lack stand out. The same person reading the cryptography plan from zero is in for a different experience, because the plan cannot tell them how deeply to go before moving on.

Overlap is handled by the common skills plan. The README flags this directly, telling readers that some topics are common for any of the listed roles and pointing to `common-skills-study-plan.md`. It is a polite instruction that deserves to be taken literally, since the alternative is reading the same foundational material three times across cloud, DevSecOps and architecture plans. The repository also says material will be added from a beginner perspective while still covering advanced topics, which is an ambitious pairing in the same file.

## Where the README stops and what it cannot give you

The repository is honest about its own limits, though it does not always say so in those words. It has no labs, no vulnerable machines to practice on and no way to verify that you can actually do the thing you ticked. It points at a companion YouTube video on a cybersecurity roadmap for beginners and another on making a career in cybersecurity, and describes those as the explanation of why to use the plan and how to use it.

Beyond the plans there is a resume section, which is a good sign of what the repository is optimising for. It asks you to fix the target job title first, check whether your experience matches the band, read the skills the posting wants, and decide on location or remote, then links to several sample security resumes and to open-source and AI-assisted builders including rxresu.me. The ATS statistics quoted there, covering hundreds of employers and portals, are the author's own sourcing.

There is no license recorded in the repository metadata, so treat the text as readable rather than reusable. There is also no per-plan progress page, so the only measure of completion is your own clone. The last push was 2026-09-14, so the newer plans such as GenAI security are the ones most likely to still be growing.

## Conclusion

The unusual thing about this repository is that it is not a course. There is no code, no tool and no artifact to install, just twenty-five markdown files that each turn a vague job title into a checklist you can mark off. That design has a specific consequence worth understanding before you start: because the author is explicit that material is common across roles and defers it to a separate common skills plan, following more than one plan means resolving overlaps yourself. Read common-skills-study-plan.md first, then pick the single role closest to a job you have seen advertised, and treat the checkbox column as a diagnostic rather than a syllabus. The repository has 5086 stars, no recorded license, and was pushed on 2026-09-14.

## FAQ

### How long does it take to complete a security study plan?

The README suggests three to four hours a day over six months, assuming a tech background, lots of hands-on work and revisiting topics more than once. It also says the journey may take months or a year, and faster if you already know a lot of the material.

### Which security roles does this repository cover?

Twenty plans are marked done, including web pentesting, application security, API security, threat modeling, GRC, DevSecOps, Docker, Kubernetes, cryptography, supply chain, secure code review, secure SDLC, security architecture, GenAI, product security, plus AWS, GCP and Azure cloud security. Five more cover IAM, blue team, mobile, malware reverse engineering and OSINT.

### Do I need a cybersecurity background to use it?

No, but a tech background is expected and the README says it makes a career in cybersecurity take a little longer without one. It also lists readiness to explore topics on your own, since the plans are outlines and checklists rather than guided instruction.

### How do I track my progress through the plans?

The plans use GitHub task list markdown, so the suggested approach is to clone the repository and tick items in your own copy. Git history then shows you which topics were added or revised later, which is a useful hint about what is currently in demand.

## Sources

- [Issues](https://github.com/jassics/security-study-plan/issues)
- [jassics/security-study-plan on GitHub](https://github.com/jassics/security-study-plan)
- [Project website](https://cybercloud.guru/)
- [README](https://github.com/jassics/security-study-plan/blob/main/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/jassics-security-study-plan
