BelajarKoding Logobelajarkoding

Platform belajar web development Indonesia. Artikel, cheat sheets, roadmap, dan code challenges untuk developer Indonesia.

Navigasi

  • Artikel
  • Cheat Sheets
  • Roadmap
  • Challenges
  • Pricing
  • Search

Produk Lain

  • JagoHermes
  • KelasClaude
  • KilatKoding
  • BelajarVibeCoding
  • JualanKoding

Support

  • Privacy Policy
  • Terms of Service
  • Email

© 2026 BelajarKoding. All rights reserved.

Galih PratamaBagian dari ekosistem Galih Pratama

belajarkoding Logo
RoadmapArtikelCheat SheetsChallengesUpgrade
belajarkoding Logo
RoadmapArtikelCheat SheetsChallengesUpgrade
belajarkoding Logo
RoadmapArtikelCheat SheetsChallengesUpgrade
Kembali ke Roadmaps

Cybersecurity Engineer

Roadmap lengkap untuk menjadi Cybersecurity Engineer profesional. Pelajari network security, web security, ethical hacking, incident response, dan security operations untuk protect sistem dari ancaman.

7
Phases
28
Topics
13
Required
11
Resources
Loading progress...
1

Fundamental Security

Dasar-dasar yang wajib dikuasai sebelum masuk ke cybersecurity

Networking Fundamentals

required

OSI model, TCP/IP, DNS, HTTP/HTTPS, ports, protocols. Paham cara data flow di network

Resources:
HTTP Status Codes Cheat Sheet

Linux & Command Line

required

Linux fundamentals, shell scripting, file permissions, process management. Mayoritas security tools jalan di Linux

Programming Fundamentals

required

Python untuk scripting dan automation, JavaScript untuk web security, Bash untuk system tasks

Resources:
JavaScript Cheat Sheet

Git & Version Control

required

Version control untuk security scripts, IaC, dan documentation

Resources:
Git Cheat SheetGit untuk Pemula
2

Web Application Security

Security untuk web applications dan APIs

OWASP Top 10

required

Injection, broken auth, XSS, CSRF, SSRF, insecure deserialization. Paham vulnerability paling umum

Resources:
API Security untuk PemulaWeb Security Headers Cheat Sheet

Authentication & Authorization Security

required

JWT security, OAuth 2.0 flows, session management, MFA, password hashing, token rotation

Resources:
JWT & Session Management Cheat Sheet

API Security

required

Rate limiting, input validation, CORS, API gateway security, OWASP API Top 10

Resources:
REST API Best Practices

Web Security Testing

recommended

Burp Suite, OWASP ZAP, Nikto untuk vulnerability scanning dan manual testing web apps

3

Network & Infrastructure Security

Protect network infrastructure dari serangan

Firewalls & Network Security

required

iptables, UFW, cloud security groups, WAF (Web Application Firewall), network segmentation

VPN & Secure Tunneling

recommended

Tailscale, WireGuard, OpenVPN, IPsec. Secure remote access dan site-to-site connectivity

SSL/TLS & PKI

required

Certificate management, Let's Encrypt, mutual TLS, certificate pinning, cipher suite selection

Resources:
Web Security Headers Cheat Sheet

IDS / IPS

recommended

Intrusion Detection/Prevention Systems. Snort, Suricata, Fail2ban untuk detect dan block serangan

4

Offensive Security (Ethical Hacking)

Penetration testing dan vulnerability assessment

Reconnaissance & Enumeration

required

Nmap, Masscan, Subfinder, Amass. Information gathering dan port/service scanning

Exploitation

recommended

Metasploit, searchsploit. Exploit vulnerabilities, privilege escalation, post-exploitation

Password & Hash Cracking

optional

Hashcat, John the Ripper, Hydra. Password auditing, hash identification, brute force defense

Penetration Testing Tools

recommended

Burp Suite Pro, sqlmap, nuclei, ffuf. Toolkit untuk comprehensive pentest engagement

5

Defensive Security & Operations

Detect, respond, dan recover dari security incidents

SIEM & Log Analysis

required

Splunk, Elastic SIEM, Wazuh, Graylog untuk centralized log analysis dan threat detection

Resources:
OpenTelemetry Cheat Sheet

Incident Response

required

IR lifecycle (prepare, detect, contain, eradicate, recover, lessons learned). Playbooks dan runbooks

Threat Intelligence

recommended

MITRE ATT&CK framework, IOC (Indicators of Compromise), threat feeds, OSINT

Digital Forensics

optional

Disk imaging, memory forensics (Volatility), timeline analysis, evidence preservation

6

Cloud & Container Security

Security untuk cloud dan containerized infrastructure

Container Security

recommended

Docker image scanning (Trivy, Snyk), Kubernetes security, RBAC, pod security policies

Resources:
Docker untuk Developer

Cloud Security (AWS / GCP / Azure)

recommended

IAM policies, security groups, cloud trail, GuardDuty, CIS benchmarks untuk cloud hardening

Secrets Management

required

HashiCorp Vault, Doppler, cloud KMS. Secure storage, rotation, dan audit untuk credentials

IaC Security

recommended

Terraform scanning (tfsec, Checkov), misconfiguration detection, compliance-as-code

7

Compliance & Career

Standards, certifications, dan career path

Security Frameworks

recommended

ISO 27001, NIST Cybersecurity Framework, SOC 2, PCI DSS. Paham compliance requirements

Certifications

recommended

CompTIA Security+, CEH, OSCP, CISSP. Pilih certification yang sesuai career direction

Bug Bounty Programs

optional

HackerOne, Bugcrowd. Legal ethical hacking untuk earn money dari finding vulnerabilities

Security Culture & Awareness

recommended

Security training, phishing simulation, secure code review, security champion programs

Udah siap buat mulai?

Roadmap ini bakal nemenin kamu dari basic sampai jago jadi Cybersecurity Engineer. Pelajari tiap topik step by step, terus langsung praktik dengan bikin project.

Baca ArtikelLihat Cheat Sheets