P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Free advice

Career advice and road maps

Free advice for anyone building a career in IT, cyber security, AI, GRC or penetration testing. Ask, and I will help: what each road is actually like, which one fits you, and what the next step on it is.

There is no single career road map in this field; there are many, and they demand different things. Getting into IT at all, GRC, engineering and defence, penetration testing, incident response, leadership, and now AI security are separate roads. If you want advice on any of them, ask. It costs nothing, there is nothing to buy at the end of it, and the conversation starts with what actually attracts you rather than with what is hiring this quarter.

The roads we map

Into IT in the first place

Service desk, infrastructure and cloud, and the routes from there into security

GRC: governance, risk and compliance

ISO lead auditor, risk, compliance, and assurance roles

Engineering and defence

Security architecture, cloud security, detection and response

Offensive security

Penetration testing, red teaming, and adversarial research. I have not worked this road full time, and I will say who has

AI security

The newest road, and the one most people ask how to reach

Leadership

The practitioner to manager to CISO progression

How a conversation runs

  1. 1

    What attracts you

    It opens with the honest question: which parts of the work pull you in, and which you merely tolerate. Interest sustains a career; job titles do not.

  2. 2

    Road map options

    The roads that fit what attracts you, described plainly: what the work is actually like day to day, what it pays, and what it demands.

  3. 3

    Gap and evidence

    For the road you choose, what a hiring panel will look for, and what you already have that counts. Certifications are sequenced, not collected.

  4. 4

    Next step

    One concrete move to make this month: a project, a certification, a conversation, or an application. Not a five-year plan nobody follows.

  5. 5

    Come back when it helps

    Ask again as often or as rarely as is useful. Some people ask once and go; others check in through a transition. There is no clock running either way.

What you walk away with

  • A written summary of the road map we discussed
  • Certification sequence tuned to the chosen road
  • CV and LinkedIn review on request
  • Interview preparation for a specific role
  • One concrete next action, agreed before we finish

How this plays out

Example scenario

A SOC analyst three years in felt stuck, assuming the only way up was management, which held no appeal.

The work: One conversation mapped what actually engaged them, which turned out to be adversary behaviour rather than process, and set a detection engineering road with a certification sequence to match.

They moved into detection engineering inside eight months, staying technical and taking a rise with it.

Example scenario

An experienced compliance manager wanted the move into AI security but could not tell whether the interest was real or hype.

The work: Two conversations: the first tested the interest against what the work actually involves, the second built the road from their existing audit strength into AI governance.

They took ISO/IEC 42001 lead auditor training and now run AI governance for their firm, without starting over as a beginner.

Start the conversation

A question about this area, an invitation to speak, or a role you think fits: write, and you will get a straight answer.

Get in touch

Share this

Send it to whoever owns the budget or the risk.

← All areas

The problem

There is no single career road map in this field; there are many. Getting into IT at all, GRC, engineering and defence, penetration testing, incident response, leadership, and now AI security are different roads with different demands. Most people pick one by accident, then wonder why the work does not fit.

What I can help with

  • Which road actually fits what attracts you, rather than what is fashionable
  • What each one is like day to day, what it demands, and what it pays
  • Certification sequencing, so exams are taken in an order that builds toward something
  • CV and LinkedIn review, and preparation for a named role
  • What to do next week, rather than a five-year plan nobody follows

What it costs

Nothing. This is not a product, there is no scope and no quote, and there is nothing to buy at the end of it. Ask a question and you get an answer. Some people ask once and go; others come back through a transition.

The paid thing on this site is the Cyber Security Career Pathway, eight weeks of taught training with a certification at the end. Advice is separate from it. You do not need one to get the other, and I will tell you plainly when the free answer is enough.

Why ask me

I have worked several of these roads personally: IT and infrastructure, engineering, audit, leadership, and AI security. Where I have not worked a road myself, penetration testing as a full-time trade being the clearest example, I will say so and point you at somebody who has.