Rabat, MoroccoOn-site · Virtual classroom · Corporate training
contact@avnorysacademy.com

Career learning paths

One career objective.A clear and realistic path.

Choose the role you are targeting. Each path combines useful foundations, guided practice, specialisation and certification when it adds genuine value.

  • ✓ Role-based paths
  • ✓ Optional steps clearly identified
  • ✓ Labs and practical cases

Path finder

Filter by your objective.

Start with a domain or search directly for a role. All paths remain accessible without JavaScript.

11 paths available

Durations are indicative and adjusted after a readiness review.
Azure & Cloud6 to 10 days

Azure Cloud Administrator

Administer Azure identities, resources, networks, virtual machines, storage, backup and monitoring.

Recommended level : Beginner to intermediate

Skills you build

  • Azure resource administration
  • Networking, storage and continuity
  • Identity, governance and monitoring
View the roadmap
  1. 1
    Cloud foundation
    Microsoft Azure Fundamentals, AZ-900Optional

    Recommended for professionals without structured cloud experience.

  2. 2
    Role capability
    Microsoft Azure Administrator, AZ-104

    Hands-on administration of subscriptions, identities, networking, compute, storage and monitoring.

  3. 3
    Specialisation
    Cloud & AI Security Engineer, SC-500Optional

    Optional security extension for cloud administrators.

Possible validation: AZ-104. AZ-900 and SC-500 depend on your current level and objective.

Azure & Cloud8 to 12 days

Azure Solutions Architect

Design reliable, secure and governed Azure architectures aligned with technical and business constraints.

Recommended level : Intermediate to advanced

Skills you build

  • Identity and governance architecture
  • Resilience, data and infrastructure
  • Well-Architected and security decisions
View the roadmap
  1. 1
    Operational foundation
    Microsoft Azure Administrator, AZ-104

    Required through training or equivalent practical experience.

  2. 2
    Role capability
    Azure Solutions Architect, AZ-305

    Design identity, data, continuity and infrastructure solutions.

  3. 3
    Security extension
    Microsoft Cybersecurity Architect, SC-100Optional

    Optional for security architecture and Zero Trust roles.

Possible validation: Azure Solutions Architect Expert, subject to Microsoft’s current prerequisites.

Cyber defence8 to 12 days

Cloud and AI Security Engineer

Implement end-to-end security controls across Azure, hybrid environments and AI workloads.

Recommended level : Intermediate to advanced

Skills you build

  • Security posture and workload protection
  • Identity, network, data and compute security
  • Controls for AI services and agents
View the roadmap
  1. 1
    Platform prerequisite
    Microsoft Azure Administrator, AZ-104

    Azure administration capability is expected before security specialisation.

  2. 2
    Role capability
    Cloud & AI Security Engineer, SC-500

    Secure cloud, hybrid and AI workloads using Microsoft security technologies.

  3. 3
    Architecture progression
    Microsoft Cybersecurity Architect, SC-100Optional

    Optional after real security engineering experience.

Aligned with the new Microsoft Cloud and AI Security Engineer Associate credential.

Cyber defence5 to 8 days

Identity and Zero Trust Administrator

Design, implement and operate identity, authentication, access and governance with Microsoft Entra.

Recommended level : Beginner to intermediate

Skills you build

  • Identity lifecycle management
  • Authentication and conditional access
  • Identity governance and Zero Trust
View the roadmap
  1. 1
    Security foundation
    Security, Compliance & Identity Fundamentals, SC-900Optional

    Recommended for professionals new to Microsoft Security.

  2. 2
    Role capability
    Identity and Access Administrator, SC-300

    Identity, applications, access, governance and Zero Trust principles.

  3. 3
    Architecture progression
    Microsoft Cybersecurity Architect, SC-100Optional

    Optional route towards security solution design.

Possible validation: Identity and Access Administrator Associate, then SC-100 when relevant.

Cyber defence6 to 9 days

SOC and Security Operations Analyst

Triage alerts, investigate, hunt threats and respond to incidents across cloud and hybrid environments.

Recommended level : Beginner to intermediate

Skills you build

  • Microsoft Sentinel and Defender XDR
  • KQL, investigation and threat hunting
  • Incident response and detection engineering
View the roadmap
  1. 1
    Security foundation
    Security, Compliance & Identity Fundamentals, SC-900Optional

    Recommended to establish Microsoft Security concepts and vocabulary.

  2. 2
    Role capability
    Security Operations Analyst, SC-200

    Detection, investigation, threat hunting and response automation.

  3. 3
    Practical application
    Blue Team and incident response

    Realistic triage, containment, evidence and lessons-learned scenarios.

Possible validation: Security Operations Analyst Associate, reinforced with incident-response labs.

Offensive security8 to 12 days

Web, Internal and Cloud Pentest Consultant

Run authorised penetration tests, validate vulnerabilities and deliver actionable recommendations.

Recommended level : Intermediate

Skills you build

  • Pentest methodology and reporting
  • Web applications and Active Directory
  • Azure attack paths and cloud identities
View the roadmap
  1. 1
    Applications
    Web application penetration testing

    Reconnaissance, validation, controlled exploitation and reporting.

  2. 2
    Internal environment
    Internal and Active Directory pentesting

    Enumeration, privilege, lateral movement and attack paths.

  3. 3
    Cloud specialisation
    Microsoft Azure offensive securityOptional

    Cloud identities, misconfigurations and Azure attack scenarios.

Hands-on laboratory work and report quality matter more than accumulating credentials.

Offensive security7 to 11 days

Red Team Operator

Plan and execute controlled adversary-emulation operations with objectives, rules of engagement and auditable evidence.

Recommended level : Advanced

Skills you build

  • Planning and rules of engagement
  • Attack chains and internal operations
  • Technical and executive reporting
View the roadmap
  1. 1
    Technical prerequisite
    Internal and Active Directory pentesting

    Real internal pentesting experience is recommended.

  2. 2
    Role capability
    Red Team Operations

    Planning, execution, risk control and reporting.

  3. 3
    Cloud extension
    Microsoft Azure offensive securityOptional

    Optional when the scope includes Entra ID and Azure workloads.

Advanced path. A technical readiness assessment may be requested before enrolment.

Agility3 to 7 days

Scrum Master and Agile Delivery Lead

Establish Scrum, facilitate the team, improve flow and support delivery in a team or scaled environment.

Recommended level : Beginner to intermediate

Skills you build

  • Scrum framework and facilitation stance
  • Team coaching and continuous improvement
  • Agile Release Train operating context
View the roadmap
  1. 1
    Role capability
    Professional Scrum Master

    Accountability, events, artefacts, facilitation and improvement.

  2. 2
    SAFe context
    SAFe Scrum MasterOptional

    Optional when the team operates in an Agile Release Train.

  3. 3
    Scaled perspective
    SAFe Agilist, Leading SAFeOptional

    Optional to understand the wider Lean-Agile enterprise system.

The path keeps Scrum Master and Product Owner accountabilities separate, in line with the Scrum Guide.

Agility3 to 7 days

Product Owner and Product Management

Maximise value, manage the Product Backlog and work with stakeholders in a team or SAFe context.

Recommended level : Beginner to intermediate

Skills you build

  • Product vision, goals and value
  • Backlog, prioritisation and discovery
  • Product collaboration at scale
View the roadmap
  1. 1
    Role capability
    Professional Product Owner

    Value, Product Goal, backlog, trade-offs and stakeholder collaboration.

  2. 2
    Working in the ART
    SAFe for TeamsOptional

    Optional for teams working in an Agile Release Train.

  3. 3
    Lean-Agile perspective
    SAFe Agilist, Leading SAFeOptional

    Optional for product responsibilities at scale.

SAFe modules should be selected based on the enterprise context, not the job title alone.

Governance & GRC6 to 9 days

Cyber Risk Manager

Structure an ISMS, analyse risk and manage cybersecurity priorities aligned with business objectives.

Recommended level : Intermediate to advanced

Skills you build

  • ISO/IEC 27001 and ISMS governance
  • Risk analysis and treatment
  • NIST CSF 2.0 and risk communication
View the roadmap
  1. 1
    ISMS foundation
    ISO/IEC 27001 foundations

    Requirements, governance and continual improvement of the ISMS.

  2. 2
    Risk management
    ISO/IEC 27005 risk management

    Risk identification, analysis, evaluation and treatment.

  3. 3
    Governance framework
    NIST CSF 2.0 risk governance

    Profiles, priorities, governance and communication with decision-makers.

Skills and implementation path. Any vendor credential is stated separately when applicable.

Governance & GRC4 to 7 days

Compliance and Audit Readiness Lead

Organise evidence, identify gaps and coordinate an action plan before a security or compliance audit.

Recommended level : Beginner to intermediate

Skills you build

  • Requirements and control interpretation
  • Evidence collection and gap analysis
  • Remediation-plan coordination
View the roadmap
  1. 1
    Understand requirements
    ISO/IEC 27001 foundations

    ISMS structure, requirements and compliance logic.

  2. 2
    Prepare the audit
    Security and compliance audit readiness

    Evidence, interviews, gaps and action follow-up.

  3. 3
    Risk-based approach
    ISO/IEC 27005 risk managementOptional

    Optional when the role includes formal risk assessment.

This path prepares for audit readiness and does not claim a certified-auditor qualification.

Choose well

The right path depends on the actual work.

A job title is not enough. Scope, responsibilities and technical context determine the priority skills.

01

Start with the target role

Define expected decisions and deliverables, not only the name of a certification.

02

Validate prerequisites

Foundation steps can be replaced by verified experience or a technical readiness assessment.

03

Build evidence

Prioritise labs, case studies, reports, architectures and realistic scenarios.

04

Specialise at the right time

Add cloud, security, architecture or governance after mastering the core role.

Tailored path

Unsure between several directions?

Share your experience, credentials and target role. Avnorys Academy will recommend a realistic starting point and sequence.

Get a recommendation →