Table of Contents

Cybersecurity is a collection of very different jobs. A security operations center (SOC) analyst investigates alerts, a security engineer builds controls, a privacy specialist works through data handling decisions, and a sales engineer explains technology to customers. Finding work you enjoy starts with understanding those daily tasks.

The video below uses all 16 personality labels as a playful way to introduce these paths. Watch it, take the linked test if you want a starting point for reflection, and then use the role descriptions and small experiments in this article to see what actually holds your interest.

Watch the video on YouTube .

Take the personality test

The video points viewers to the free 16Personalities test . Its result can give you language for preferences such as structure, experimentation, collaboration, or independence. The publisher describes it as a starting point for self-reflection, not an employment screening tool or a way to assign someone a job. 16Personalities’ own guidance

The assessment opens on 16Personalities in a new tab. Use the result to generate career questions, not to rule out jobs.

How to read the video’s 16 pairings

The pairings below are the video’s examples, not hiring rules or evidence that a personality type predicts job performance. You can succeed in any of these roles regardless of your test result. Use the “try it” column to learn whether you like the work itself.

Four career areas—defense and investigation, offensive research, governance and privacy, and engineering and response—surround a prompt to try the work

Start with a kind of work that interests you, then test that interest with a realistic task.

Defense and investigation

Video’s type and roleWhat the work involvesTry it before committing
ISFJ — SOC analystTriage alerts, investigate suspicious activity, document the result, and hand off incidents.Review a sample alert and write a short investigation note with evidence and next steps.
ISTJ — digital forensics or auditPreserve evidence, build timelines, and check that findings can be reproduced.Build a timeline from a practice disk or log set and record where each artifact came from.
INFJ — threat intelligence analystConnect reports, indicators, and behavior into a picture defenders can act on.Read two public threat reports and write a one-page brief separating facts from hypotheses.

The common thread is careful interpretation. If you like following evidence and explaining what happened, investigate these roles even if your test returns a different type.

Offensive security and research

Video’s type and roleWhat the work involvesTry it before committing
ENTP — penetration testerTest systems within an agreed scope, validate findings, and explain how to fix them.Complete a legal training lab and write a clear finding with impact and remediation.
INTP — vulnerability researcher or reverse engineerExamine software behavior and identify why a flaw exists.Analyze a deliberately vulnerable program and document the root cause.
ESFP — social engineering or physical assessmentTest human and physical controls under explicit authorization and communicate results tactfully.Design a tabletop exercise for an authorized team; assess the briefing and debriefing process.
ISFP — OSINT investigatorGather and verify information from public sources while respecting privacy and scope.Investigate a fictional organization using public records and cite every claim.

Offensive jobs involve substantial reporting and scope discipline. Enjoying puzzles is a good reason to try a lab; professional work also requires restraint, permission, and a report someone can use.

Governance, risk, and privacy

Video’s type and roleWhat the work involvesTry it before committing
ESTJ — GRC leadTrack risks, coordinate audits, and turn policy into repeatable decisions.Create a small risk register for a fictional service and explain how you ranked each risk.
ESFJ — third-party risk liaisonGather vendor evidence and help business and security teams resolve gaps.Review a sample vendor questionnaire and write three useful follow-up questions.
INFP — privacy and data protection specialistExamine how personal data is collected, used, retained, and shared.Draw a data-flow map for an imaginary app and identify where consent or retention needs review.

These roles have technical substance even when they do not spend the day in a terminal. They suit people who enjoy making decisions legible to others and working through tradeoffs across teams.

Engineering, response, and leadership

Video’s type and roleWhat the work involvesTry it before committing
INTJ — security architectDesign controls and explain how systems fit together.Diagram a small application and propose three controls tied to specific risks.
ISTP — security engineerDeploy, tune, and maintain security tools and infrastructure.Build a small lab control, test that it works, and document rollback steps.
ESTP — incident responderCoordinate investigations and containment when events are time-sensitive.Run a tabletop incident and practice a concise status update.
ENTJ — CISO or security leaderSet priorities, manage budgets, and explain risk to executives.Draft a one-page plan that funds the highest-value controls within a fixed budget.
ENFJ — security awareness or human-risk leadTeach practical habits and improve how people report suspicious activity.Turn one common phishing pattern into a brief training exercise and measure understanding.
ENFP — sales engineer or security evangelistDemonstrate products, answer technical questions, and translate features into outcomes.Give a short demo of a security tool to someone without a security background.

The video uses memorable stereotypes to make the roles easy to recognize. Real teams need many working styles within each specialty: an incident responder may be quiet and methodical, while a security engineer may spend much of the week collaborating with people.

More than one role can fit each type

The video’s match is one doorway into a specialty. The alternatives below are additional roles to explore, based on overlapping tasks and working preferences. They are not personality-test predictions. Pay attention to which activities appeal to you, even when the four-letter label beside them is not yours.

If you like evidence and careful analysis

Type in the videoOther roles to exploreWhy those roles may appeal
ISFJIdentity and access management (IAM) analyst; vulnerability management analystBoth reward consistent follow-through, clear records, and closing the loop with system owners.
ISTJSecurity auditor; incident evidence coordinatorBoth depend on traceable evidence, repeatable procedures, and explaining what a record proves.
INFJDetection engineer; security research writerThese turn patterns and adversary behavior into useful detections or understandable briefs. Detection engineering also requires substantial technical practice.
ISFPDigital forensics analyst; privacy investigatorThese emphasize patient observation, source verification, and respect for the people affected by findings.

These roles differ in their outputs. An IAM analyst may resolve access requests and investigate exceptions every day. A detection engineer writes and tunes rules, then checks what they miss. A forensics analyst may spend hours verifying a timeline. Try producing each kind of artifact before choosing a course or certification around the title.

If you enjoy experiments and breaking down systems

Type in the videoOther roles to exploreWhy those roles may appeal
ENTPApplication security consultant; purple team facilitatorBoth test assumptions, then work with defenders or developers to turn findings into improvements.
INTPMalware analyst; application security engineerBoth reward deep technical investigation and a clear explanation of why a system behaves as it does.
ISTPDetection engineer; cloud security engineerBoth involve building controls, testing them against real behavior, and fixing noisy or brittle configurations.
INTJCloud security architect; threat modeling leadBoth connect system design decisions to risks, controls, and long-term maintenance.

The most visible part of these jobs is often the least representative. A penetration test includes scoping and reporting. Reverse engineering includes notes that others can reproduce. Engineering includes maintenance and support after the exciting build. Ask yourself whether you would still want the role when those routine tasks fill half the week.

If you like translating risk for people

Type in the videoOther roles to exploreWhy those roles may appeal
ESFPSecurity awareness facilitator; customer security trainerBoth use live communication and feedback to help people change behavior.
ESTJSecurity program manager; audit managerBoth organize work across teams, make priorities explicit, and track whether commitments were completed.
ESFJCustomer trust analyst; security awareness leadBoth require patient follow-up and answers that make sense to people outside security.
INFPPrivacy analyst; human-centered security researcherBoth examine the effect of security and data decisions on the people who use a system.
ENFJSecurity training manager; security program managerBoth coordinate people, communicate clearly, and measure whether a program is useful.
ENFPSecurity developer advocate; security trainerBoth combine technical explanation, demos, and audience feedback.

Communication work is measurable work. A third-party risk analyst needs to decide whether vendor evidence answers a control question. An awareness lead needs to see whether reporting behavior improves. A sales engineer needs to handle a demo failure honestly and return with an answer. If you like people-focused work, sample those concrete deliverables rather than assuming the job is only meetings.

If you like coordinating decisions under pressure

Type in the videoOther roles to exploreWhy those roles may appeal
ESTPSOC incident lead; crisis exercise facilitatorBoth involve triage, rapid communication, and keeping a team aligned as facts change.
ENTJSecurity program manager; GRC leadBoth require setting priorities, negotiating resources, and being accountable for outcomes.

Incident response and executive leadership are not identical kinds of pressure. An incident lead works through incomplete evidence on a short clock; a program leader makes durable tradeoffs across budgets, people, and risk. If either appeals, practice both a 15-minute incident update and a one-page funding decision.

Compare the work environment, not only the job title

Pace and interruption

A SOC shift or incident-response rotation may interrupt planned work. Architecture, privacy, and research often allow longer blocks of focused analysis, though deadlines and incidents can still change the day. Ask practitioners what proportion of their week is scheduled versus reactive, and whether on-call work is part of the role.

Deliverables and feedback

Different specialties prove their value differently. Penetration testers produce findings and remediation discussions. Engineers produce working controls, runbooks, and fewer false alerts. GRC and privacy teams produce decisions and evidence that can withstand review. Choose a role whose ordinary output you would be willing to improve repeatedly.

Entry point and prerequisites

The video’s CISO and architect pairings are long-term directions for most newcomers. A first step toward architecture may be systems, networking, cloud, or security engineering. A route toward leadership may begin in operations, risk, project work, or another specialty where you learn to make and defend decisions. NIST’s NICE Framework describes work roles through tasks, knowledge, and skills; use those descriptions to identify what you can practice next rather than treating a senior title as an entry-level target.

Choose by tasks, not four letters

A useful next step is to pick two roles from different sections and run their small experiments. For each one, ask: Did I like the routine parts? Did I want to investigate further after the exercise ended? Could I tolerate the role’s communication demands and pace?

Four steps for exploring a cybersecurity career: notice preferences, try a realistic task, reflect on routine work, and check real role descriptions

Use a personality result to generate ideas, then validate them through practice and real job descriptions.

Then compare what you enjoyed with NIST’s NICE Framework , which describes cybersecurity work through tasks, knowledge, and skills. A work role is a grouping of responsibilities; actual job titles can combine several roles. A conversation with a practitioner or a realistic lab will tell you more than a personality label alone.

If you’re new to the field, use the video and test to generate possibilities. Use the day-to-day work, your existing skills, and hands-on practice to choose where to invest your time.