Hey everyone,
I’m a full-stack developer with a little over 2 years of experience (Next.js, Node.js, Docker, PostgreSQL). I’ve recently developed a strong interest in cybersecurity — especially application security and bug bounties — and I’d like to shift into a security-focused engineering role (AppSec / Security Engineer / DevSecOps).
My current CTC is ₹7.4 LPA, and my target is ₹20 LPA+ within the next year. I’m okay putting in serious effort to learn and build projects.
For developer roles, the path is clear (DSA + system design + projects = better offers).
But for cybersecurity, I’m confused about what the exact roadmap looks like to reach top-tier or product-based companies like Meta, Cloudflare, Razorpay, etc.
What would you recommend focusing on first — AppSec fundamentals, DevSecOps tools, certifications (Security+, etc.), or security automation?
How realistic is a 20 LPA+ goal in 12 months?
Any guidance, roadmaps, or personal experiences from people who made this kind of transition would be super helpful 🙏
TL;DR: 2 yrs full-stack dev → want to become security engineer and 3× my salary. What’s the smartest route?