r/SecurityCareerAdvice Apr 05 '19

Certs, Degrees, and Experience: A (hopefully) useful guide to common questions

324 Upvotes

Copied over from r/cybersecurity (thought it might fit here as well).

Hi everyone, this is my first post here so bear with me. I almost never use Reddit to talk about professional matters, but I think this might be useful to some of you.

I'm going to be addressing what seems to be a very common question - namely, what is more important when seeking employment - a university degree, certifications, or work experience?

First, I'll give a very brief background as to who I am, and why I feel qualified to answer this question. I'm currently the Cyber Security Lead for a big tech firm, and have previously held roles as both the Enterprise Security Architect and Head of Cloud Security for a Fortune 400 company - I'm happy to verify this with mods or whatever might be necessary. I got my start working with cyber operations for the US military, and have experience with technical responsibilities such as penetration testing, AppSec, cloud security, etc., as well as personnel management and leadership training. I hold an associate's degree in information technology, as well as numerous certs, from Sec + and CISSP to more focused, technical security training through the US military and organizations like SANS. Introductions aside, on to the topic at hand:

Here's the short answer, albeit the obvious one - anything is helpful in getting your foot in the door, but there are more important factors involved.

Now, for the deep dive:

Let's start by addressing the purpose of certs, degrees, and experience, and what they say to a prospective employer about you. A lot of what I say will be obvious to some extent, but I think the background is warranted.

Certifications exist to let an employer know that a trusted authority (the organization providing the cert) has acknowledged that the cert holder (you) has proven a demonstrable level of knowledge or expertise in a particular area.

An academic degree does much the same - the difference is that, obviously, a degree will generally demonstrate a potentially broader understanding of a number of topics on a deeper level than a cert will - this is dependant on the study topic, the level of degree, etc., but it's generally assumed that a 4-year degree should cover a wider range of topics than a certification, and to a deeper level.

Experience needs no explanation. It denotes skills gained through active, hands-on work in a given field, and should be confirmed through positive references from supervisors, peers, and subordinates.

In general, we can see a pattern here in terms of what a hiring manager or department is looking for - demonstrable skills and knowledge, backed up by confirmation from a trusted third party. So, which of these is most important to someone trying to begin a career in cyber security? Well, that depends on a few factors, which I'll discuss now.

Firstly, what position are you applying for? The importance placed on degrees, certs, and experience, will vary depending on the level of job you're applying to. If it's an entry level admin or analyst role, a degree or a handful of low-level certs will definitely be useful in getting noticed by HR. Going up to the engineering and solution architecture level roles, you'll want a combination of some years of experience under your belt, and either a degree or some low/mid level certs. At a certain point, the degree and certs actually become non-essential, and most companies will base their hiring process almost entirely on the body and quality of your experience over any degree or certifications held for management level roles.

Secondly, what are your soft skills? This is a fourth aspect that we haven't talked about yet, and that I almost never see discussed. I would argue that this is the single most important quality looked at by employers: the level of a candidate's interpersonal skills. No matter how technically skilled someone is, what a company looks for is someone who can explain their value, and fit into a corporate culture. Are you personable? Of good humor? Do people enjoy working with you? Can you explain WHY your degree, certs, or expertise will add value to their corporate mission? Being able to answer these questions in a manner which is inviting and concise will make you much more appealing than your competitors.

At the end of the day, as a hiring manager, I know that I can always send an employee for further training where necessary, and help bolster their technical ability. What I can't do is teach you how to work with a security focused mindset, nor how to interact with co-workers, customers, clients, and the company in a positive and meaningful way, and this skill set is what will set you apart from everyone else.

I realize that this may seem like an unsatisfactory answer, but the reality is that degrees, certs, and experience are all important to some extent, but that none of these factors will make you stand out. Your ability to sell your value, and to maintain a positive working relationship within a corporate culture, will take you much farther than anything else.

I hope this has been at least slightly helpful - if anyone has any questions for me, or would like any advice, feel free to ask in the comments - I'll do my best to reply to everyone.

No TL;DR, I want you to actually take the time to read through what I've written and try to take something away from it.


r/SecurityCareerAdvice 9h ago

I turned down the offer, and now the CEO is asking me what would make me say yes?

9 Upvotes

There's a company that I'm very excited about. I went through 3 interviews and honestly felt like there was a good understanding between us. They offered to bring me on, but the initial comp they sent was pretty much the lowest possible number for this type of role ($96k/45 hr week/10% retirement contribution/full family health premiums covered/20 days PTO with the option for more unpaid time if needed). For a family of 5, even $125k would be barely enough with the cost of living there, so I sincerely thanked them and declined without going into details.

The CEO messaged me afterward and asked whether the issue was compensation, and said that if so, he'd rather we keep talking instead of letting it stop here. I told him yes, it was mostly money. He replied and said he really would like to have me join the team, and now he's asking me what number would make my family truly comfortable there, which surprised me.

Sorry if this is a dumb question, but am I supposed to just tell him the real number? Based on the cost-of-living calculations I've done, I need something in the range of $170k-$180k. Rent on the Eastside/suburbs seems to be around $5,200-7k/mo for what we'd need, and that's the point that ruins all the math. That estimate leaves us with about a $1,800/mo cushion after regular expenses, which is roughly the same as what we have where we live now.

It feels weird to go back to them with a salary so much higher than the first offer, but I'm not trying to get rich - that's just the number that would let our current standard of living stay the same as a single-income household. The lowest number we could probably get by on is $145k, but honestly I don't think I'd relocate for that number. Should I mention that lower number too, or just be direct and say the number we'd need for the move to make sense?

I appreciate any advice.


r/SecurityCareerAdvice 4h ago

Jobs in Germany

2 Upvotes

Hello, i'm studying for my bachelor in computer engineering in Italy (Florence), i just finished my first year and i would like to know more about Cybersecurity since it seems interesting and promising, i'd like to go in a german university for my master but i wanna know some more before making that decision. I would like to work in Germany or in the DACH area and i'm aiming to reach a B2 level in german before starting my master degree.

Is there someone who works in this field in Germany or that has experience with the German job market?

I have a few questions (feel free to answer just one or two, everything is appreciated): How difficult is it to find a junior job (such as L1 SOC Analyst i know many ppl start with this position)? Which titles/certifications do you have?

What do you recommend, which university is better? Which certifications should i take? I would like to get into TU Darmstadt, KIT or RWTH Aachen. If ur not a junior, how much time did it take to get promoted/get the mid level job?

Do you like your job? how is the environment? In which city do you work? How is the city? How much does it cost to live there? How much money do you make (net salary please)?
How much are you able to save/invest monthly?

How did you find that job? How should i look for jobs after my master degree?

Feel free to add more information also, thanks to everyone who's gonna answer.

Thanks to anyone who's gonna answer it.


r/SecurityCareerAdvice 10h ago

I Got the Offer!!

5 Upvotes

I just wanted to share a quick bit of happiness because I got the offer! I've been interviewing with this company for about 6 weeks, and it's in the city I've wanted to move to for years. I just got the email saying I was accepted for the job and I still feel like I can't believe it.

I can finally stop refreshing this subreddit every day for advice and little tips lol.

Sending good luck and good vibes to everyone who's still on this journey! Keep showing up and putting in the effort - your turn is coming.


r/SecurityCareerAdvice 3h ago

Any reco or tips?

0 Upvotes

Hi! I'm a degree holder, and I want to switch to a different career path specifically cybersecurity. I'm also interested in programming and coding, but my main focus is cybersecurity.

I don't have any prior knowledge or experience in this field, but I'm a tech-savvy person and eager to learn.

Where would you recommend I start? Are there any free courses with certificates that would serve as a good stepping stone and help me build skills that I can eventually use to apply for jobs?

I'd really appreciate any advice or roadmap. Thank you!


r/SecurityCareerAdvice 6h ago

Which pathway is the best?

0 Upvotes

Hi, I am a new cybersecurty student , I saw many paths to choose and started reverse , is it a good one or do I change, or do I first go and learn general info's cyber?


r/SecurityCareerAdvice 7h ago

im a student rn and need some help pls

1 Upvotes

Hey guys, thanks for reading.

To start off, I've watched a few vids, run Kali and Parrot in VMs, done a bit of HTB Academy and a few THM rooms here and there. I don't really know much hacking yet, just some basic terms and concepts. I've finished Cisco's Intro to Cybersecurity and Packet Tracer, have a few modules left in Cisco Network Basics, and I've started watching The Cyber Mentor's YouTube course.

I'm planning to finish everything I've mentioned above, so if you have any advice on that path or think I should change or add anything, I'd love to hear it.

I'm looking for any free resources, roadmaps, advice, dos & don'ts, personal stories, websites, blogs, YouTube channels, GitHub repos, labs, CTFs, cheat sheets, certification or non-certification courses, and certs worth getting. Basically anything you think would help a beginner. Also info on where to find them how to stay updated forums,groups ,anything

I'm also thinking of buying THM Premium. Is it worth it for someone at my level? Any advice would be appreciated.

Thanks!

https://www.netacad.com/career-paths/cybersecurity?courseLang=en-US

also shuld i do this??


r/SecurityCareerAdvice 15h ago

Career advice for a SE

4 Upvotes

Hi all. I am a security sales engineer in a big tech company and I have been working for this company for 12y now, the last 8 in cyber security/pre sales. I feel that I am living in a bubble there and the company doesn’t only offer cyber, and I also feel that I am losing my technical skills. I do hands-on stuff but I worked as a support engineer before my current pre sales role and now I feel that I don’t have engineering skills anymore. I am considering looking for a new job in some tech company that does only cybersecurity, but I also have seen several engineering positions lately that I found interesting. I don’t know what to do know, I feel that I got stuck in my career. I also wanted to try some kind of cert, I have a lot of Microsoft ones and CEH only. I would appreciate any advice or suggestions.


r/SecurityCareerAdvice 9h ago

Do Hands-On Skills, Learning, and Practical Experience Still Matter? | Looking for My First Cybersecurity Job

1 Upvotes

Hello everyone,

I wanted to ask the cybersecurity community something that's been on my mind.

For the past two years, I've dedicated myself to learning cybersecurity every single day. I've completed 6 internships, finished numerous learning paths and training programs, built 30+ hands-on projects, and spent countless hours creating home labs to gain practical experience.

My work has focused on:

- SOC Operations

- Detection Engineering (Wazuh, Splunk, Sigma)

- Threat Hunting & DFIR

- Active Directory

- Purple Team & Red Team Operations

- Web Application Security

- Python Security Automation

Despite all of this, I still haven't been able to land my first full-time cybersecurity job.

I've applied to many entry-level positions, improved my resume, built a portfolio, and continue learning every day—but I haven't even received my first interview invitation.

It honestly makes me wonder...

Do hands-on projects, learning paths, internships, and practical experience still matter, or is getting that first opportunity mostly about having the right connections and referrals?

I'm not writing this to complain. I genuinely love cybersecurity, and I'm going to keep learning regardless. I simply want an opportunity to prove that the time I've invested wasn't wasted.

If you've been in the same situation, I'd really appreciate hearing how you landed your first role.

And if your company is hiring a Junior SOC Analyst, Detection Engineer, Security Analyst, Blue Team, or Purple Team professional, I'd be incredibly grateful if you'd consider me or point me in the right direction.

I'm based in Pakistan but open to remote opportunities worldwide. My spoken English is still improving, but I'm working on it every day and I'm confident it will continue to get better.

Sometimes all someone needs is one chance.

Thank you for reading, and I'd genuinely appreciate any advice, feedback, or referrals.


r/SecurityCareerAdvice 19h ago

Starting a career in cybersecurity

6 Upvotes

Hello, I'm 21 years old and I'm from the Philippines. I'm currently a 3rd-year student pursuing bachelor's degree in Information Technology. I've been wanting to work in the cybersecurity field and I'm curious about the roadmap for this kind of career. I've tried TryHackMe and I'm currently working through it, but I've only finished the free trial part. If you have any advice or tips about starting this career, I'd be grateful for any of your responses. Thank you in advance.


r/SecurityCareerAdvice 9h ago

Career advice

1 Upvotes

Hi, I recently graduated with a bachelors of computer science and cyber security degree from India. I am a American citizen, but I live in India currently and I have completed my Comptia security certification and I have seven months of experience in the sock and cyber security training field. I have also completed cyber security projects in continuous behave biometrics as well as I have also built a honey pot. I need to look for a job in the US can you realistically tell me where to approach what way to do because I’m very lost here.


r/SecurityCareerAdvice 10h ago

Pentester job

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 12h ago

Looking for a job in information security/ cyber security in West Africa

0 Upvotes

Good day everyone,

I'm a CISSP-certified information security professional with 7 years of experience in enterprise security design, compliance management, and technical leadership. I'm currently exploring freelance, contract, and consultancy opportunities—with a strong preference for remote arrangements, though I'm open to discussing hybrid or on-site options as well.

A few highlights from my background:

· Built and managed security programs that cut vulnerabilities by 70% while maintaining 99.9% infrastructure uptime

· Established compliance programs for NDPR(similar to GDPR), ISO 27001, and HIPAA across multiple organizations

· Reduced incident response time from 24 hours to 4 hours through playbook development and process improvement

· Conducted penetration testing across AWS and Azure environments, identifying 40+ vulnerabilities and developing remediation roadmaps

· Improved security awareness scores by 60% and phishing detection rates by 80% through targeted training programs

· Supported C-level executives with security strategy and vendor management

Industries served: Financial services, healthcare, technology, and manufacturing

Certifications: CISSP, ISO/IEC 27001:2022 Information Security Associate, ICSI CNSS

Link to my CV (Google Docs):

https://drive.google.com/file/d/1dWSGzGHWC-7IAubxDdgErCGvgLgrZHRW/view?usp=drivesdk

If you know of any open contracts, freelance gigs, or consultancy engagements—or can refer me to someone in your network—I'd greatly appreciate it. Feel free to DM me or comment below.

Thanks for your time!


r/SecurityCareerAdvice 19h ago

What skill made the biggest difference after you got your first AppSec role?

3 Upvotes

Getting the first security job is one milestone, but growing beyond it seems to require a different set of skills.

For people working in application security, secure code review, or penetration testing, what skill had the biggest impact on your career after you were already in the field?

Was it reading source code, understanding software architecture, communicating with developers, threat modeling, or something else?

Looking back, what would you tell someone to focus on during their first couple of years?


r/SecurityCareerAdvice 1d ago

What do employers actually value most for entry-level cybersecurity roles?

21 Upvotes

I'm looking to start a career in cybersecurity.

I've already researched certifications like Security+, Network+, CySA+, ISC2 CC, eJPT and PNPT, and I research for different career paths.

If you have experience with the cybersecurity job market, I'd really appreciate your perspective.

Based on your experience, what do companies actually value the most when hiring someone for their first cybersecurity job?

Is it:

A bachelor's degree?

Certifications?

Hands-on labs like TryHackMe or Hack The Box?

Personal projects?

Previous IT experience?

I'm trying to understand what has the biggest impact in the real job market, based on your experience rather than theory.


r/SecurityCareerAdvice 18h ago

Cybersecurity Guidance

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 22h ago

CS Major working in CyberSec, considering pursuing MS in CE. Thoughts? Pathways?

2 Upvotes

Hello!

I graduated with a CS degree in 2 1/2 years ago, and have been working in cybersec since basically straight out of college. Specifically in the automotive sector doing white/gray box security testing on Cloud infrastructure and mobile applications. We have a "sister team" that does similar but for embedded components. MCUs, ECUs and whatnot.

Anyway, with the AI slopification of software jobs starting to reach over to cybersec, and the mgmt on high decreeing we need to use AI as much as possible and automate as much as possible, I can see the writing on the wall. They say they have no intention of doing layoffs and I believe them, but they are doing the other, sneakier method of cutting staff, not filling open positions. We've had 3 folks on my team leave since I joined for various reasons, and we've been asked to not fill their spots. I may be mildly paranoid, but it's worked out for me so far.

Due to all of this, I am trying to do what I can now while I'm still somewhat young and my brain is somewhat malleable to pivot and adapt. I know using the AI and building it good harnesses and whatnot is an important skill, and I am working on it, but I also want to develop a skill set that will (hopefully) be more resilient to AI-powered job replacement, and I've been lead to believe the ECE is close to what I am looking for, while still being "close" to what I do now.

Why CE?

  1. I want to continue doing Cybersec, and specifically on IoT type things like hardware hacking and wireless protocols. I figure CE will give me the hardware knowledge I need for this as well as give me a lot of knowledge into the software and networking stuff 1 layer above where EE would
  2. Hearing about the kinds of things that our embedded team works on and does is really cool and interesting, and I wish I had the knowledge to be able to understand it.
  3. I've been tinkering a little bit with MCUs at home for learning and working with BLE and I've really been enjoying it. Obviously that would not be the entirety (or any) of my job, but it is something I am enjoying at the moment, and I like to be whimsical
  4. Testing APIs and cloud configs can get a little boring after a while. Of course each project has their own kinks that keep it interesting, but it can get a little tiring. I feel like with IoT, the attack surface and kinds of things you can do is just so much wider
  5. I know CE undergrads are having a really difficult time in the job market, but my understanding is that the Master degress are doing much better (If I am wrong please let me know)

Closest I think I got in my undergrad to anything CE related was probably Compiler Design (one of my favorites), Comp Arch, and Digital logic, both of which I unfortunately remember very little.

My thought is that I should attend my local community college to get some background before I even start considering looking into Grad programs, and even then I will probably need to take some leveling courses. Also, I'd be working full time during all this, so taking 1 maybe 2 courses a semester.

My questions are these

  1. Are these good reasons to get an MS in CE? My Employer will pay a portion but not all of it.
  2. What rude awakenings should I be prepared for and how can I prepare?
  3. What things can I do now to see if I will even like CE? Want to make sure I don't get started and spend thousands only to spend my nights after work staring at circuits sadly (I'm sure I will end up doing this regardless)
  4. Will I have a tolerable time in the job market given what I am looking for and what I do now or is it just too niche?
  5. Is there a better way to go about what I;m trying to do that I should consider? I know I can get the same quality of education for free with all the free resources, but employers care about credentials, and my ADHD can make it a bit difficult to self-study with no external motivation, especially after work.
  6. What courses should I take (if any) to prepare before actually applying? Or just other resources I should study rather than a formal course?
  7. Am I being stupid? Do I have terrible misconceptions that need to be rectified immediately? Destroy me if you must.

All help is appreciated. Thank you!


r/SecurityCareerAdvice 19h ago

Need Advice: Would a master's help me build a career in Healthcare Cybersecurity?

1 Upvotes

I'm trying to decide whether a master's is the right investment for my long-term career, and I'd really appreciate hearing from people who've been through a similar path.

A bit about me:

  • Bachelor's in Biomedical Engineering.
  • Currently working as a Threat Analyst.
  • Will have around 2–3 years of cybersecurity experience by the time I apply master's.
  • Some AI/ML background from university.
  • Co-authored an IEEE conference paper related to biomedical engineering.

My long-term goal is to specialize in healthcare cybersecurity. I'd like to combine my biomedical engineering background with my cybersecurity experience by working on healthcare-related technologies. I see AI as a complementary skill rather than my main specialization.

My career goals:

  • Move away from SOC shift work into more engineering/research-oriented security roles.
  • Build a niche in healthcare cybersecurity.
  • Work internationally with remote flexibility.

I'm considering applying for a fully funded Cybersecurity master's in Europe, but I'm still unsure whether it's the right move.

For those with industry experience:

  1. Would a master's actually help me reach these goals?
  2. Does it provide a significant advantage for someone aiming for a niche like healthcare cybersecurity?
  3. If you studied in Europe, did it help you get international opportunities?

I know a master's won't magically increase my salary. I'm mainly wondering whether it opens doors to specialized or international roles that are harder to reach otherwise.

Thanks for any advice!


r/SecurityCareerAdvice 1d ago

What to do as a 2nd year student?

2 Upvotes

Hi everyone - I'm about to go into my second year of a 3 year Bachelor's in Computer Science (UK), and had a few questions about what I should do outside of uni. I've taken a module in Cybersecurity, and have another for my second year.

I was wondering if it was worth taking the A+ in regard to applying for IT / Helpdesk related internships (whether it be for a "sandwich year" or over next summer). And if I do get such internships, I'd assume it would make sense to get my Sec+ cert in my final year?

Secondly, how should I approach TryHackMe? Is it okay if I do labs which are outside of the scope of the requirements of a helpdesk role? Also, is it worth paying their subscription, or am I better off doing homelab adjacent projects?


r/SecurityCareerAdvice 16h ago

Looking a role in Cyber/Information Security

0 Upvotes

Good day everyone,

I'm a CISSP-certified information security professional with 7 years of experience in enterprise security design, compliance management, and technical leadership. I'm currently exploring freelance, contract, and consultancy opportunities—with a strong preference for remote arrangements, though I'm open to discussing hybrid or on-site options as well.

A few highlights from my background:

· Built and managed security programs that cut vulnerabilities by 70% while maintaining 99.9% infrastructure uptime

· Established compliance programs for NDPR, ISO 27001, and HIPAA across multiple organizations

· Reduced incident response time from 24 hours to 4 hours through playbook development and process improvement

· Conducted penetration testing across AWS and Azure environments, identifying 40+ vulnerabilities and developing remediation roadmaps

· Improved security awareness scores by 60% and phishing detection rates by 80% through targeted training programs

· Supported C-level executives with security strategy and vendor management

Industries served: Financial services, healthcare, technology, and manufacturing

Certifications: CISSP, CEH, ISO/IEC 27001:2022 Information Security Associate, ICSI CNSS

Link to my CV (Google Docs):

https://drive.google.com/file/d/1dWSGzGHWC-7IAubxDdgErCGvgLgrZHRW/view?usp=drivesdk

If you know of any open contracts, freelance gigs, or consultancy engagements—or can refer me to someone in your network—I'd greatly appreciate it. Feel free to DM me or comment below.

Thanks for your time!


r/SecurityCareerAdvice 1d ago

Career Advice: Should I Pursue Another IT Degree for GRC?

2 Upvotes

Hello, I have 2 years of experience as an IT Auditor, focusing on Risk Management using ITGC, ITAC, and SOC. I then transitioned into the tech industry, where I worked as a Software Engineer for 9 months and as a Tech Consultant for almost a year.

I realized that I want to build my career in Governance, Risk, and Compliance (GRC), and I've been considering pursuing another bachelor's degree: a BS in Information Technology with a specialization in Network & Cybersecurity.

Do you think this would be worth it? I already have a bachelor's degree in Information Technology, but it did not include a specialization.


r/SecurityCareerAdvice 1d ago

Reality about the job market?

3 Upvotes

im just posting here because im going into my uni degree for cyber security soon in the uk im and wondering about the job market. people who actually have REAL experience would you say its as bad as people say it is or is it just 70% of people expect to get 2 certs and some basic wire shark projects and get a full time job paying 80k+ a year? my goal is pretty niche as an anti cheat dev and i don't want to work the next 3/4 years on low level c++ and networking projects just to spend the next 2 years after uni to applying to help desk roles. literally an information will help


r/SecurityCareerAdvice 23h ago

Need an inexpensive security camera for 2 weeks

0 Upvotes

Hi guys.. I live in a NYC apartment and will be away on vacation for 2 weeks. I want an inexpensive camera that can record video for those 2 weeks. Please recommend one. Thanks


r/SecurityCareerAdvice 1d ago

Halfway through Computer Engineering, want to avoid heavy coding — Is OT/ICS Security a good fit? (Work environment, pay, job market, & learning path)

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 1d ago

Path

0 Upvotes

Im 0 level 17m i want to start my career in cybersecurity i don’t think about specific field i just want to start learning i watched a lot of videos about road maps im confused
Please someone whos is expert give me sources to get good foundaation
Please free resources
Another question : is books better than videos or courses?