Updated by
Hi, I'm Jack, the owner of Cybersecurity Jobs List, and co-founder of Himalayas (himalayas.app) and Cavuno (cavuno.com). Across all my platforms, I work with application security daily: dependency vulnerability scanning, secure authentication, API security, and data protection across hundreds of thousands of users. My technical background is in computer science (UNSW), where he studied security engineering and computer networks, and worked as a research assistant on VR experiments that were published in the Journal of Experimental Psychology. I also work with cybersecurity hiring data every day, tracking which companies are posting, what certifications actually appear in listings, how salaries differ by sub-discipline and clearance level, and where the talent gaps are widest. That combination of security practice, engineering at scale, and daily immersion in the hiring data is what shapes the content on this site. I'm currently based in Sydney, Australia.

Cybersecurity doesn't require the same level of coding in every job. You can do work in risk assessment, security awareness or audit coordination without developing software. A role focused on building security tools or reviewing application code needs a different level of programming knowledge.
For a beginner, we'd start with the work you want to do. Read a few relevant job descriptions, identify the tasks involving code, and learn enough to practise one of those tasks. You don't need to finish an entire software-development curriculum before exploring security careers.
What “coding” means in a cybersecurity job
An employer asking for technical skills could mean several different things. Reading a command, searching logs and building a service are different assignments, even when all three involve text on a screen.
Reading commands or code means being able to explain what something does. An analyst might need to identify which file a command accesses, whether it connects to another system, or which account it runs under. You can develop that understanding before you can write a substantial program yourself.
Writing queries means asking questions of data. You might filter events to one account, select a time period or group results by device. Microsoft's Kusto Query Language documentation describes KQL queries as read-only requests and explains their use in Microsoft Sentinel. Learning to investigate logs with KQL is a technical skill, but it isn't the same assignment as developing a web application.
Writing scripts means expressing a repeatable task in code. For example, a short program could count events in a training dataset or format an approved export for review. Scripting is programming; the distinction here is the size and purpose of the task, not a claim that scripts are somehow exempt from testing.
Developing software involves maintaining something other people or systems depend on. That adds concerns such as design, tests, error handling, dependencies, permissions and ongoing maintenance. A security engineer responsible for an internal service needs more than the ability to run a copied script.
How coding fits different cybersecurity roles
Use these examples to choose what to investigate. They describe types of work, not universal requirements or a survey of how often employers ask for coding. A single job can combine several rows.
| Type of work | Where code can fit | What to check in an advert |
|---|---|---|
| GRC, audit coordination and awareness | Evidence review, policy writing and training may be central; some teams also automate evidence collection. | Does the role ask you to assess evidence, operate a platform or build integrations? |
| SOC analysis | Search queries, command interpretation and small scripts can support investigations. | Are you using existing detections or expected to write queries and automation independently? |
| Detection engineering and incident response | Detection logic, data processing and response tooling can involve substantial scripting. | Which tools and languages must you maintain, and who reviews changes? |
| Security engineering and DevSecOps | Integrations, deployment workflows and security services may require code ownership. | Look for software-development, version-control, testing and infrastructure-as-code duties. |
| Application security | Code review requires understanding the application; some roles also build tools or contribute fixes. | Which application languages and frameworks does the team use? |
| Penetration testing and malware analysis | Custom testing tools, script adaptation or understanding program behaviour may be needed. | Separate the target environment and testing duties from the broad job title. |
NIST's NICE Framework introduction distinguishes work roles from jobs and occupations. That's a useful reason to read the responsibilities closely: two employers can use the same title for different combinations of work.
For GRC, the important starting question is whether you can understand a control and evaluate the evidence behind it. A review of account access still requires an understanding of permissions, even if the deliverable is a written finding. Our GRC analyst career guide explains that work in more detail.
SOC work also shouldn't be dismissed as nontechnical because the team uses an existing security platform. An investigation can require you to understand processes, network connections and authentication events. The SOC analyst guide covers the wider investigation and communication skills alongside automation.
At the code-review end, OWASP's secure code review guidance describes examining application logic, data flow and implementation details. If that is the work you want, plan to read and reason about the languages used by the applications you'll review.
Already working as a developer? Our guide to moving from software engineering into application security shows how to build on that experience, with a permission-review exercise, test cases and advice for choosing your first AppSec role.
Read a job description for the level expected
Look for the action attached to a language or tool. “Familiarity with Python” leaves more uncertainty than “maintain Python integrations and write automated tests.” Also separate essential requirements from preferences.
These are fictional examples, written to show how to interpret an advert:
- “Python scripting preferred; investigate alerts using established procedures.” Scripting may strengthen an application, but this wording doesn't make it an explicit essential requirement. Check the rest of the advert for conflicting expectations.
- “Write and tune KQL detections.” Prepare to explain queries, their intended matches and how you'd check false positives. General Python knowledge alone doesn't demonstrate that task.
- “Develop and maintain security services in Go.” Treat software development as part of the core job. Running a tutorial script won't demonstrate the requested ownership.
- “Coordinate access reviews and document control gaps.” Practise evaluating evidence and explaining findings. Don't infer from this sentence alone that the whole job has no scripting or technical requirements.
For each vacancy, write down the task, the required tool, whether it is essential or preferred, and one piece of your own evidence. Leave unclear requirements marked as questions. A useful interview question is: “What would I be expected to write or modify independently during my first few months?”
A job with little coding can still require substantial security experience. Keep location, work authorization, qualifications and experience on your checklist as well. “No programming requirement” doesn't mean “no entry requirements.”
Which language should you learn first?
Choose one that supports a task you've identified. Learning several languages superficially makes it harder to show what you can do with any of them.
Python is a reasonable first choice for small data-processing tasks. You can practise reading structured data, filtering records and producing a summary without building an application interface. Its official tutorial is a useful reference once you understand basic programming concepts; the tutorial itself says it is intended for programmers new to Python, rather than complete programming beginners.
For work involving Windows administration, PowerShell deserves attention. Microsoft's PowerShell overview describes a shell, scripting language and automation platform. It also runs on Linux and macOS, so don't mistake a strong Windows association for a Windows-only limitation. For Linux-focused tasks, learn to read shell commands and build small Bash scripts when the work calls for them.
For log analysis, learn the query language used by your target platform. That could be KQL in Microsoft Sentinel or SPL or SPL2 in Splunk. SQL is useful when your task involves querying relational data, but don't assume a query will run unchanged across platforms. Check the language and version your tool uses. Start with filtering, selecting fields and grouping results in the tool you're practising with.
If you're interested in web application security, learn how web applications work and how to read their code. MDN's JavaScript learning material is one starting reference for the browser side. The server could use a different language. For low-level program analysis, you may eventually need C, memory concepts or assembly; those are specialist learning goals rather than prerequisites for every security career.
Try a small cybersecurity scripting exercise
This original exercise uses fictional login events. Its only job is to count failed events by account. It doesn't connect to a network, read real logs, change accounts or decide whether an attack occurred.
With Python 3 installed, save the following as count_failures.py in a practice folder. Run python3 count_failures.py in that folder, or py count_failures.py on Windows if you use the Python launcher. No extra packages are needed.
from collections import Counter
events = [
{"account": "alex", "result": "failure"},
{"account": "sam", "result": "success"},
{"account": "alex", "result": "failure"},
{"account": "lee", "result": "failure"},
]
failures = Counter()
for event in events:
if event.get("result") == "failure":
account = event.get("account", "unknown")
failures[account] += 1
for account, count in sorted(failures.items()):
print(account, count)
The output is:
alex 2
lee 1
The loop examines each event. The if condition keeps only records whose result is exactly failure. Counter, documented in the Python standard library, keeps a count for each account. The final loop prints those counts in account-name order.
Change one event from failure to success, predict the new output, then run the script again. Next, remove the account field from one failed event. It will be counted under unknown. Remove a result field and that event won't be counted as a failure. These choices are visible in the code; you should decide whether they would be appropriate for a different dataset.
An empty event list produces no output. That does not establish that a system had no failed sign-ins: the script has no way to know whether data was missing. It also lacks timestamps, devices and source addresses. Two failed events could have many explanations, including typing mistakes. A count alone isn't an incident finding.
To extend the exercise, make a separate count of incomplete records and explain why silently excluding them could mislead a reviewer. Keep the data fictional. A useful project note would describe the input, your counting rule, the cases you tested and the conclusions the program cannot support.
Build enough skill for a specific task
We'd use the following sequence rather than a fixed promise to become job-ready in a certain number of weeks:
- Choose one kind of work. Compare a small set of current adverts you could plausibly apply for. Record repeated tasks without treating the sample as a market survey.
- Learn the underlying system. For sign-in analysis, understand accounts, authentication and the meaning of the event fields before automating a summary.
- Complete one bounded exercise. Use a small dataset whose expected result you can calculate by hand. Keep your first program simple enough to explain line by line.
- Test what can go wrong. Try empty input, missing fields and unexpected values. Record what the program does and what you'd need to improve.
- Explain the result honestly. Label the work as a lab or personal project. State where you followed guidance, what you changed and how you checked it.
Keep the code, sample data and a short explanation together if you share the project. Exclude credentials and confidential information. Our cybersecurity resume examples show how to describe practice work without presenting it as professional experience.
For a GRC or awareness role, your first work sample may instead be an evidence review or a training explanation. Choose the output that demonstrates the job's responsibilities, then add automation when you have a useful task for it.
Can AI write the code for you?
AI can help explain syntax, suggest an approach or produce an initial draft. You still need to check what the code accesses, what it changes and whether its output answers your question. A script that runs without an error can still count the wrong records.
Use fictional data while learning and follow your employer's rules for tools and information sharing. Ask for an explanation, predict an output and test changes yourself. If you can't explain a generated script, keep working through it before presenting it as evidence of your programming ability. Follow any restrictions on assistance in recruitment assessments.
Questions about coding and cybersecurity careers
Can I start learning cybersecurity with no coding experience?
Yes. You can begin with networking, operating systems, account permissions and security concepts while learning basic programming alongside them. Starting to learn is different from meeting a particular employer's hiring requirements. Use the entry-to-cybersecurity guide to connect preparation with a role you want to pursue.
Does a SOC analyst need Python?
Read the individual role. A team might prioritize investigation and query skills, while another expects analysts to maintain Python automation. Being able to explain a small script can be useful evidence, but it doesn't replace understanding the events you're investigating.
Can I work in GRC without coding?
There are GRC tasks centred on risk, controls, evidence and communication that don't involve writing software. Look at the actual responsibilities, especially whether the team expects automated evidence collection or integrations. You'll still need enough technical understanding to assess the systems and controls in scope.
How much coding is enough?
Enough to perform the task safely, explain your choices and check the result. That threshold is very different for a practice log summary and a security service used by a team. Compare your evidence with the advert rather than counting languages or completed courses.
Choose a role on Cybersecurity Jobs List, identify one task involving code or data, and write down what you'd need to demonstrate. That gives your next learning session a concrete purpose.


