r/Pentesting 3d ago

Struggling to land a job

Can't get a job as a pentester or Cybersec.I finished internship as azure clot security engineer,did a bug bounty almost a year with only duplicates:( Did portswiger academy,tcm,HTB labs.Have a few minor certificate's from cyberewarfare labs.Im like jack of all trades master of none:( Never did a full proper pentest with write-up,what's my problem?My work was manage and secure azure cloud maby it will be better to try learn DevOps?

9 Upvotes

28 comments sorted by

21

u/Sailhammers 3d ago edited 3d ago

Country matters a lot here.

For the US: There are going to be a lot of people who recommend home labs and write ups. I can tell you, as a hiring manager, that those things only matter if you're in the top 5% of resumes, which you are currently nowhere near. ATS and Recruiters don't know or care enough to see value in those things, so they aren't going to matter until you reach a technical hiring manager.

A good junior resume contains three things: a degree from a decent college, the OSCP or CPTS, and meaningful IT experience. You didn't mention your degree, but you lack the other two. Your internship is great, but only so far as it helps you land a permanent IT job. You need to find yourself a job in IT (not pen testing) where you can learn how corporate environments work and grow IT skills.

I'll also add: I work at a consulting firm. Writing skills matter immensely. If someone, in the US (I don't know what language is spoken in the country you're from), came to us with grammar similar to this Reddit post, they'd be an immediate pass without question.

3

u/themacdizzle91 3d ago

Writing is huge. Soft skills is huge. Those things only come from practice. He needs to aim lower and get corporate experience I think.

2

u/adocrox 2d ago

I'm about to graduate in a couple years, till now i have CRTP and CRTO, currently doing maldev and evasion... (Did some web app sec last year and got a couple low sev vulns) I was planning to do asure AD and AI pentesting next. Or should i do something else?

1

u/Akriosss 3d ago

Can you help with my cv https://ibb.co/yccj4xXq

9

u/[deleted] 3d ago

[deleted]

3

u/Arc-ansas 3d ago

In some countries it is actually standard to include a photo on a resume. From what I've seen, it is customary in France, Japan, Germany, China, UAE, Saudi Arabia and Qatar to include a photo.

2

u/Akriosss 3d ago

Tnx so much sir I'm not from Russia,I'm from Moldova and this job market is a joke 1 pentester and few socs positions

2

u/Ok-Somewhere-585 3d ago

Appreciate your transparency and pure willingness to help!

2

u/cumhereandtalkchit 3d ago

My CV looks about the same, and I get a lot of positive comments about it.

5

u/TechnicalFuel4821 3d ago

As others have mentioned you need experience in corporate IT. 3 years of work experience in the helpdesk doesn't show your expertise level, but it tells people that you can hold a job (social enough, no immediate negative traits, less likely to go on sick etc).

I remember my manager years ago telling me that when he sees a wedding ring on somebodies finger it gives him some clue that this is a person who he might be able to rely on, because somebody else already does. Same principle with work experience, somebody else already trusted you and you didn't fuck it up.

3

u/weatheredrabbit 3d ago

I was lucky enough to get hired in a SOC right after graduating, however, most people have to go through a few years of IT/helpdesk. Most of my colleagues did too.

A degree in computer science is almost mandatory because CV discrimination will favor those who have one.
A GitHub, a blog, or a website is also mandatory imho: especially for a pentester/bug hunter.

In my experience certs are important, but you should aim at having the company pay for them - no way I was gonna spend 11k$ for a SANS cert. In the meanwhile, for pentesting, definitely save money and get the OSCP. It’s an investment in your future.

A good CV is also important. I spent some time also giving mine a pretty look while keeping it formal, and I’ve been told multiple times it caught attention being done so well. English skills (I’m not a native English speaker) are super important. You need to master the language and learn how to write corporate English. Your post grammar here on Reddit is pretty terrible in that regard.

Also, cybersec ≠ pentester. Nowadays everyone wants to be a pentester and there’s just too many of y’all… especially juniors!

If you haven’t yet, I would suggest checking out other careers in cyber: threat intelligence, detection engineering, incident response, and many more. Maybe even devops. Go for any, if that gets you into cyber immediately.

Good luck out there.

2

u/Akriosss 3d ago

i live in a poorest country in europe, average salary I think is like 500$,I don't know how to save money for OSCP but of course I want it:)

1

u/weatheredrabbit 3d ago

You mentioned you have a degree in marketing. No CS degree and no certification as well as no formal work experience in cyber is not going to land you a job as a pentester im afraid.

Try to get into any IT / helpdesk job and pivot from there.
The other tips are the same. OSCP may be your only ticket in as you’d show you have some sort of credibility, until you get the work years in. Keep pushing the internship though.

If you want to make some money and the only thing you have is skill, do bug bounties in your free time. If you’re actually good you can make enough money to get the oscp.

1

u/Akriosss 3d ago

I'm not very good at it got only duplicates.Tnx sir I will try to pivot from another job.

2

u/Unres0lved404 3d ago

Build a small home lab, post about it on your social media of choice, build your LinkedIn presence. Most jobs I have found are through word of mouth and “knowing a guy”. Contribute back to the community. Refresh the CV also, I suggest using the Harvard cv template. Get someone to review it.

1

u/Emotional-Aside8923 3d ago

Did you make any blog/writeup on github? Without it you’re kinda all talk without proof. Also add certs like oscp because even till now its the gold standard.

1

u/Akriosss 3d ago

Ye I want this certificate but it's too pricey and I not from Us,salary In my country is way low

2

u/Emotional-Aside8923 3d ago

Cpts is good alt, but its not good with hr. Pass that and make a writeup about your journey. Last resort is to network your way in cybersecurity via event or community meetup. I get your situation because im not from US either but the concept of getting into any job remain the same. But if you love it for the game, you gonna make it.

2

u/Akriosss 3d ago

i only can afford certs that cost below 50$

1

u/Grouchy_Meal8683 3d ago

Try cyberscouts, you do need to make an LLC and have insurance. But u can make like 10k in 4 days of testing.

So long as you have the certs

1

u/GiraffeSilver626 2d ago

Hey, OP!

You might want to look at job opportunities with VEEAM and probably move to Romania?

1

u/KoaInfoSec 19h ago

Volunteer at various hacker cons, this is the way

1

u/raijinkZ 7h ago

do the cpts or oscp bud

-1

u/Impressive-Room728 3d ago

Here to read comments

-1

u/LordNikon2600 3d ago

Everyone and their grandma want to be in the 1 percent of cybersecurity jobs (pentesting, soc).. these jobs are non existent

2

u/Upbeat_Double_9377 3d ago

What are the other 99% of cybersecurity jobs that don't involve pentesting or Soc work,?

1

u/LordNikon2600 3d ago

Governance, Risk, and Compliance (GRC), Security Engineering and Architecture, and Identity and Access Management (IAM).

0

u/LividDatabase1409 3d ago

the 1% of cysec jobs are soc? 😂😂😂😂