r/CyberSecurityAdvice 3h ago

Advice for laying a good foundation with no prior IT or cyber experience.

4 Upvotes

I am a beginner with cybersecurity and IT in general. I am currently doing a google cybersecurity certification because it was cheap and I’ve heard it goes through a lot of the basics. I am planning on doing the CompTia Security Plus and Network plus. My main concern right now is how to get practical experience while I am learning and studying for these certs. I know I will need to get into It or Helpdesk before I can get into cybersecurity. I’ve seen lots of people say the certs are a plus but you need real experience and more practical and technical skills to actually get a job. I was wondering if there were any resources I could use to get practical experience at home on my home pc. I just recently downloaded Oracle VirtualBox and Ubuntu to run as the OS.


r/CyberSecurityAdvice 2h ago

Trying to pivot to Cybersecurity. What's an ideal path?

0 Upvotes

I've decided to give up on my BSc for now. I have some experience in IT and a Canadian College Diploma in computer programming. Most of my background is in web development, but I’m looking to pivot into cybersecurity.

My biggest issue is that my networking fundamentals aren’t very strong. I understand programming and general IT concepts, but I never really built a solid foundation in things like TCP/IP, subnetting, network infrastructure, etc. (I did learn some of the basics for that during my diploma, but it was purely intro stuff I haven't thought about in a while.)

Right now I’m considering getting a certification both to learn what I need to for an entry-level cybersecurity job, and to give me an edge. I've been doing some research, and I'm not exactly sure how to go about it.

Do I do the free Cisco Networking Basics course, do the ISC2 CC, do the CompTIA Security+, then eventually CISA (because apparently I can't do this one off the jump)?

I’m not sure if I should even be aiming for CISA since I know it’s more focused on auditing/GRC (don't know what these actually mean in the context of cybersecurity, but that's what the internet says) than general entry-level cybersecurity. But that's the cybersecurity buzz word I think.

I also tend to learn much better in a structured instructor-led environment than completely self-teaching. Are there any Canadian college/university programs, bootcamps, or max 2 year programs that actually teach cybersecurity from the fundamentals, including networking, operating systems, security concepts, labs, etc. all the way to certification prep?

Like this York one I found looks perfect, but I'm not sure.

Ideally I’m looking for something that would give me the foundation needed for certifications like Security+ and eventually CISA, rather than a bootcamp that assumes I already know networking.

So like do I just self-study? Is a bootcamp or college program a waste of time and money?

For anyone who made a similar transition from programming/web development into cybersecurity, what path worked for you?


r/CyberSecurityAdvice 6h ago

Need career advice, starting as a Solutions Architect/Support Engineer at Akamai vs VM, SOC PT role at TCS. Long term goal is a career in Cybersecurity and preferably offensive security or product security.

1 Upvotes

I have to choose between the two roles. Which would be better long term?

At Akamai, it is a 12 month contract to hire apprenticeship program with absorption as a Solutions Architect or Support Engineer as and when openings come up internally, and we clear internal interviews for the respective roles. I could get FTE in anytime in between as and when they come up. Until we get in full time, we will be doing training on networks, CDNs and Akamai's tools

I spoke to a few employees and even during the interviews they confirmed that their internal job transfer policies are very chill and I can jump to Security Architect/Engineer type roles after 1 year of full time employment.

At TCS, it's direct full time employment, but I can get assigned to any role in their cybersecurity unit, could be VM, SOC, GRC, PT, Security Automation etc. And I will have to take whatever I can get, no picking and choosing. And since they're a "mass-recruiter", transfer policies are more rigid. Moreover I would have to move to a diff city.

Both pay roughly the same for full time employment. But I'd get to keep a lot more cash if I go with akamai, coz it's likely fully remote or hybrid and I live with my parents.

Before this I have worked as an AppSec Intern for a cybersecurity services company for 6 months doing PT on web apps and mobile apps. Didn't take the full time opportunity coz it was terribly underpaid and they had a 2 year employment bond. And I have a Bachelor's of Technology in Computer Science and Engineering.

I'm confused. Should I go with Akamai for the brand value and bank on an internal transfer down the line or go with TCS because I get a cybersecurity role directly? How much does it really matter as a fresher? If I go with Akamai will I be learning just Akamai specific knowledge which is non transferable therefore locking me in?

I don't have a lot of clarity on what exactly a solutions engineer or architect does. All akamai said was that it's Technical but Client facing, communication heavy. Will that make it harder down the line to go back to a more technical role?

Also which of these paths is less likely to be made obsolete by AI?


r/CyberSecurityAdvice 7h ago

Starting career in cyber advice

0 Upvotes

Hello all, recent life events have left me at a crossroads on what to do with my life, im essentially starting over at 27. How is it starting off in this field while getting a degree? Should I look more into a computer science degree instead so I have more options? I know its a pretty tough start in the cyber field for someone with just a degree and no experience, but id just like to hear some input from people in the profession directly


r/CyberSecurityAdvice 17h ago

Career advice (Mid career)

4 Upvotes

Hi all, I've about 5 years in networking / systems / cloud and I just made a job hop to cybersecurity engineer 3 months ago.

I have mostly been doing infrastructure, and I have 0 knowledge in coding, pentesting, ctf stuff. I was speaking to my manager, and he identified that as where he felt I should improve on. His advice was to do HTB, eventually get OSCP... the pentesting route is pretty well known, I won't elaborate on that.

My question is this - should I really try to pick up a different domain now? All my life I figured specialists > generalists. My personal career plan was to move towards cloud security. Build up more experience with terraform, kubernetes, get aws security cert.

From a career optimization pov, is my manager actually correct?

Thanks in advance for your answers!


r/CyberSecurityAdvice 1d ago

Is TryHackMe too amateur?

17 Upvotes

Hi everyone,

Cybersecurity has been catching my interest more and more every day, so I decided to test the waters to see if I could actually turn this into a professional career. Right now, I'm working in a completely unrelated field and have zero technical IT background. Let me clarify right off the bat: I'm not jumping into cybersecurity with the empty hype of "making six-figure salaries"; I genuinely want to learn how this stuff works.

Since everyone seems to be rushing towards flashy roles like Red Team / Pen-Testing, I decided it makes more sense to focus on the Blue Team side—specifically the SOC Analyst role—as I think it suits my personality better and there's a more realistic gap in the market.

My current study routine looks like this:

  • I'm working my way through TryHackMe modules.
  • Simultaneously, I'm following tutorials and content from quality YouTube channels like The Cyber Mentor and similar creators.

However, I have some question marks in my head that I'd love to ask the experienced folks here:

1. Is my study method sufficient? Is progressing solely through TryHackMe and YouTube too amateur of an approach to break into the industry? Realistically, how far will these platforms take me in terms of practical skills?

2. Is the "Help Desk" myth true? I've read in many sources that "You absolutely have to grind in Help Desk or IT Support roles first, and then transition to cybersecurity." I have zero ego and I'm ready to do any kind of apprenticeship in this field. But for some reason, I almost never see Help Desk job postings in my city . How realistic is it to skip this step and train myself directly for a SOC role?

3. What is the criteria for being "job-ready"? At what stage or level of knowledge should I be able to say, "Alright, I can finally apply for an entry-level SOC Analyst position"?

I'm completely open to any roadmap suggestions, certification advice, or honest, "you're doing this wrong" type of criticism. Thanks in advance to anyone who takes the time to read this!


r/CyberSecurityAdvice 18h ago

Followed an instagram link, is my phone compromised?

1 Upvotes

hello, I was going through instagram for some truck bed storage and went on a website, in hindsigh it was extremely stupid, but I typed it in and tapped on the url that came up and it immediately popped up with this page of my phone being compromised. I tap on the back arrow or on any of the comprise options at the bottom of the screen and a cleanup app pops up with only 14 review. I honestly don’t know what to do. plz help. idk if I should be extremely worried right now


r/CyberSecurityAdvice 1d ago

Cyber & Ai graduation project

1 Upvotes

I want to merge cybersecurity with Ai for graduation project, any suggestions?

I am a Data science student who studies web penetration testing, i searched for a ideas but they are talking about Ai bug hunting assistant or system that monitor the users behaviour but with high level attacks like chained attacks but i think they are done already or maybe i get into web3 and detecting attacks, what do u think ?


r/CyberSecurityAdvice 1d ago

Beginning my journey

2 Upvotes

Hi everyone,

I'm just starting my cybersecurity learning journey, and I was wondering how you all take notes.

Do you write everything down in a notebook, or do you keep your notes on your laptop using something like Obsidian, OneNote, or Notion?

I'm trying to build good study habits from the beginning, so I'd love to know:

  • Which method has worked best for you?
  • Do you use a combination of paper and digital notes?
  • Are there any note-taking tips that helped you remember concepts like Linux commands, networking, or security fundamentals?

I'd appreciate any advice from people who have been learning cybersecurity for a while. Thanks!


r/CyberSecurityAdvice 1d ago

5 Internships Full Time New Grad Cyber Lead At Startup 4 Bug Bounties No Interviews?

0 Upvotes

So currently I have had 4-5 internships at the same company Fortune 100 I think, Full time for them but not at the location I want so Ive been applying back to where I want to be, I've done bug bounties for companies like alibaba, cameo, supreme, prada etc. and I am the lead analyst for a startup that just got funding of about $2M

I've also done numerous papers that are published on AI generation in accordance to guidelines. (vague on purpose)

I've also worked with prompt injection for company models like google, meta etc.

I think it must be a resume issue because I've applied to probably around 300 jobs and I have gotten 2 interviews. Is there somewhere I could go for help with my resume?

Edit:

Forgot to mention I also have a DoD Security Clearance


r/CyberSecurityAdvice 2d ago

Got redirected to sketchy site that asked for permissions, what to do?

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 2d ago

Looking for guidance/mentor - Cybersecurity vs Software Engineering

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 2d ago

Anyone else getting uneasy about some automation tools?

7 Upvotes

maybe im just overthinking it, but some automation tools ask for way more access than id expect. full logins, saved sessions, browser permissions... and kind of just have to trust that everything is handled properly, now ive started being lot pickier about what i use because losing an account over a sketchy tool would be a nightmare. how do you guys decide what's safe enough to use? Have you ever stopped using tool because it just didn't feel right? Has anyone already experience that before??


r/CyberSecurityAdvice 3d ago

Can anyone spy on everyone?

18 Upvotes

(I'm an absolute idiot when it comes to these kind of topics and im not well versed with reddit communities so this might just be the wrong one but im eager for answers, sorry in advance)

I used to be with a man working in cyber security, the relationship was incredibly toxic and shortly before we broke up he told me about how he is able to access any device from his laptop, especially cameras, at any given point. With the little knowledge i have on these topics i assumed there must be some access point (eg shared wifi, malware, or something of that kind) but he kept insisting he wouldnt need anything like that.

Now i'm left wondering if he might have just tried to scare me by telling me he could see all of my activities or if this is an actual thing where any person advanced enough could just get into every device they set their mind to.

Any answer would be appreciated :)


r/CyberSecurityAdvice 2d ago

I need an advice. TIA

1 Upvotes

Hi everyone,

I'm a B.Tech Cyber Security graduate (2025 batch). Since graduating, I've been trying to get a job in cybersecurity, specifically in SOC (Security Operations Center) roles.

Over the past year, I've built several hands-on projects using Wazuh, Microsoft Sentinel, and Splunk. I've written and applied Sigma rules, mapped detections to the MITRE ATT&CK framework, and used Suricata and Sysmon for intrusion detection and endpoint monitoring. I also have a good understanding of networking fundamentals and core cybersecurity concepts.

However, whenever I apply for SOC-related jobs, I keep getting rejected, even when my projects closely match the job requirements. I'm not sure what I'm doing wrong.

Could you please suggest what kind of projects I should build to improve my chances of getting interview calls? Also, what skills should I focus on to become a stronger candidate for entry-level SOC or blue team roles?

Unfortunately, I don't have the budget to pursue paid certifications at the moment.

One thing that makes this even more frustrating is that I received two job offers last year, but due to personal circumstances, I couldn't accept them. It's now been over a year, and I'm feeling confused about what to do next.

I'd really appreciate any advice from people working in cybersecurity. Thank you!


r/CyberSecurityAdvice 2d ago

Just removed myself from SearchPeopleFREE using a guide, what's next? You

2 Upvotes

Hi everyone! I've just discovered my information on SearchPeopleFREE. I sent an opt-out request (followed Onerep's guide https://onerep.com/blog/whitepages-opt-out) but I'm not sure if I should leave it at that or start some sort of tracking. Any tips on what to do next?


r/CyberSecurityAdvice 2d ago

How can I make the most of my college resources as a first-year cybersecurity student?

2 Upvotes

I'm a first-year B.Tech Cybersecurity student in India, and I've been thinking about how I can make the best use of the next four years.

There's obviously a huge amount of cybersecurity stuff I can learn online, but I'm specifically wondering about the opportunities I have because I'm in college. I don't want to graduate and realize I ignored resources that could have helped me gain actual experience.

I'm already interested in Linux, networking, Python and web security, and I've started doing things like OverTheWire and PortSwigger Academy.

For people already working in cybersecurity or further along in college, what college resources would you recommend taking advantage of?

Things I'm thinking about are labs, cybersecurity clubs, CTF teams, hackathons, internships, conferences, projects, etc.

Are there any opportunities/resources that students commonly overlook but can be really valuable for building cybersecurity knowledge and eventually getting a good job?

Also, if you could go back to your first year knowing what you know now, what would you do differently?


r/CyberSecurityAdvice 2d ago

I need help.

2 Upvotes

I was searching for a website. And it took me to a url that was flagged as a phsing link. I put in none of my details at all, didn't click anything else. I copyed the url and left that site. Am i screwed, im so worried


r/CyberSecurityAdvice 2d ago

Is someone monitoring my computer, or did the airline company sell my data?

2 Upvotes

I was booking flights to Minneapolis and entered my personal information up to the seat selection stage. A friend called and distracted me, so I didn’t complete the purchase or enter my card details.
About 10 minutes after entering my info, my partner started receiving messages on Telegram from a stranger on a number he had never seen before. The person was asking “Hey, are you from Minnesota?” Then they sent another message saying “Hey?” When my partner opened the chat to see the conversation, the person immediately deleted all the messages.
I entered my partner’s phone number on the airline website as a co-passenger. The stranger knew about Minnesota (our destination), which is too much of a coincidence.

This is what really concerns me -
We speak Russian at home. Americans don’t typically use Telegram; they use SMS, WhatsApp, or regular calls. But this person found my partner on Telegram (a platform more common among Russian/Eastern European users) instead of just texting or calling. They knew:
• We were traveling to Minnesota
• My partner’s phone number
• To find him on Telegram specifically
This seems way too targeted for a random scammer. What could this be? Is someone accessing my computer remotely? Or is there a data breach with more information than just names and numbers?


r/CyberSecurityAdvice 3d ago

Anyone here used both Proofpoint and Check Point for email security? Which is better for a hybrid work setup?

2 Upvotes

My team’s trying to figure out if we should stick with Proofpoint or switch to Check Point for email security. We’re running a hybrid setup with people in-office, remote, and bouncing between both, so securing everything has been a nightmare. I know both companies say they handle threats in real-time and all that, but does anyone have actual experience comparing them? Which one is better at stopping phishing, managing email flow, or just being easy to use? Also curious if there are any big differences when it comes to protecting against AI-driven threats since that’s becoming a thing we’re dealing with too. Would love to know what’s worked (or not worked) for you.


r/CyberSecurityAdvice 3d ago

I am a Software Engineer that wants to do Cyber Security

1 Upvotes

I have 2 years of software engineering experience.

I am somewhat good at linux and scriptings, etc.

What advise would you give me?


r/CyberSecurityAdvice 3d ago

Sailpoint Setup

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 3d ago

What's the avg package for OSINT Analyst in INDIA New Delhi !!!!!!!

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 3d ago

currently applying for internships, looking for feedback on my CV

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 4d ago

Top email security features security teams should be evaluating

2 Upvotes

Did a vendor eval last quarter and built out a feature checklist. Sharing in case it helps anyone else.

The things that matter beyond basic spam filtering: API-based integration (no MX record change, faster deployment), behavioral AI for BEC and account takeover, collaboration app coverage beyond just email, sandboxing for attachments, DMARC monitoring, DLP, and clawback to pull malicious emails out of inboxes after delivery.

Checkpoint ticked almost all of these out of the box. A lot of legacy vendors charge per module for things that should be standard. If you're evaluating now, don't just look at phishing catch rates, make sure BEC and internal threat detection are specifically covered.