Concept-based certs only, no vendor-specific credentials · center = rarest · outer = foundational · ⚔ = offensive · years = work experience
By Joshua Urianza (RootReap3r), TS/SCI-cleared security engineer
The goal here is third-party, vendor-neutral certifications — AWS, Azure, GCP, and other vendor-specific credentials are excluded. That said, some included certs (notably CompTIA Security+, ISC2 SSCP/CISSP, and GIAC/SANS) are issued by commercial organizations rather than independent standards bodies; they appear because they certify concepts and skills, not vendor products. Years reflect hands-on work experience, not age or calendar time.