| Tool | Main Purpose | Beginner Focus |
| Burp Suite | Web security testing | Requests, responses, authentication |
| OWASP ZAP | Web application scanning | Automated and manual testing |
| Nmap | Network discovery | Ports and services |
| Wireshark | Traffic analysis | Understanding network packets |
| SonarQube | Code quality/security | Code analysis |
| Semgrep | Static analysis | Finding insecure coding patterns |
| Snyk | Dependency security | Vulnerable libraries |
| Postman | API testing | API requests and responses |
| Development Stage | Security Activity |
| Planning | Threat modelling |
| Design | Security architecture review |
| Development | Secure code review |
| Testing | DAST and penetration testing |
| Deployment | Configuration checks |
| Production | Monitoring and vulnerability management |
| Role | Main Focus | Coding |
| Application Security Engineer | Securing software and APIs | High |
| SOC Analyst | Monitoring security events | Low–Medium |
| Penetration Tester | Finding exploitable weaknesses | Medium–High |
| Cloud Security Engineer | Securing cloud infrastructure | Medium–High |
| GRC Analyst | Risk and compliance | Low |
| Timeline | Target |
| 1–3 Months | Programming, Linux, networking and SQL |
| 4–6 Months | OWASP, web security, APIs and Burp Suite |
| 7–9 Months | Security labs and portfolio projects |
| 10–12 Months | Internship, resume and interview preparation |