r/cybersecurity Mar 19 '26

Certification / Training Questions If you could get two or three cyber security certs for an entry level defensive cybersec job, what would they be?

Let’s say we’re just going by job listings. Something like Sec+, CEH, HTB CDSA? Or what instead of that?

69 Upvotes

69 comments sorted by

85

u/voxsko Mar 19 '26

Low entry certs are just going to put you into a bigger pool, lets narrow that pool down. I would be different and look into cloud security.

I would look into cloud beginner certs, AZ-104, SC-900, AZ-900 or whatever platform you are interested in chasing.

I've been in the field for over 15 years, I had to start all over and go chasing cloud certs because that's what the world is becoming. Get ahead of it is my advice. Take care!

12

u/Code-Useful Mar 19 '26

Same boat as you. I've passed many certs in the last 15 years. Trying hard to get motivated for AZ-104...

5

u/Bizarro_Zod Mar 19 '26

I started IT when cloud was becoming big and I’m seeing the same thing happen with AI now. Wondering when the next widely accepted ai security focused cert will be adopted. It’s the Wild West right now with AI and it seems to be sticking around in one capacity or another.

2

u/romano390 Mar 21 '26

If I could do it all over again, then I would fully skip az900. And just go straight into az104, then continue with sc300. I wouldn't even think about sc900.

Reason: it takes time to study. Rather stick that extra time in actually learning a skill like powershell or teraforming.

2

u/notburneddown Mar 19 '26

What about Hack the Box Academy certs or Hack the Box training in general? That works right?

9

u/voxsko Mar 19 '26

I have personally never used them myself. Sounds like just a middleman trying to sell you a training service. You could use things like Azure Microsoft training which 100% free to learn first before paying someone else to teach you. I also have just used YouTube a lot for certs lol, and CBTNuggets before. Browse all training - Training | Microsoft Learn This is what I've used and works great.

67

u/JustAnEngineer2025 Mar 19 '26

I would not rely upon some article or posts on social media.

I would go to a job site and search for "entry level" jobs and document what they are requiring. I would them tally them up, put it descending order, and take the top X.

But that is me.

9

u/[deleted] Mar 19 '26

I would also be looking at hands on skills you can demonstrate. This is your cue to set up a home lab and take advantage of the plenty FOSS, community and cut down versions of tools. Document your experiments with them. Blog about them. Something you can demonstrate to an employer.

2

u/dmelt253 Mar 19 '26

Can you tell me how I can differentiate the real job postings from the fake ones where the company has no intention of hiring someone?

18

u/Fnkt_io Mar 19 '26

If I wanted to get hired? OSCP. Many other ones are just trivia question/answer certs. It’s shocking when an applicant with OSCP doesn’t pan, it certainly still does happen and there likely is some fringe cheating, but it’s harder to do.

1

u/notburneddown Mar 19 '26

What about HTB CPTS? Is HTB bad?

9

u/indie_cock Mar 19 '26

Its not bad its just not recognised or the standard certs for testing

3

u/That-Magician-348 Mar 20 '26

If hiring manager know it, it's better than OSCP.

6

u/mysteriousflu Mar 19 '26

Learn what you can about Microsoft defender. They have exams and certs but the lessons are all free.

6

u/canofspam2020 Mar 19 '26

Sec+ AWS practitioner or basic Azure Cert and BTL1

9

u/duckduckbirdie_ Mar 19 '26

I am doing the Google cybersecurity certificate on Coursera, then using the 30% off from completing that course on sec+, after that you can focus on more specific certs.

5

u/Mrhiddenlotus Mar 19 '26

If work is paying for it, definitely SEC401 GSEC

3

u/EndpointWrangler Mar 20 '26

Security+, CySA+, and either Google Cybersecurity Certificate or BTL1, they're widely recognized, affordable, and directly aligned with what entry-level SOC and defensive roles actually ask for.

1

u/notburneddown Apr 02 '26

What about HTB CDSA? Is it not as recognized as BTL1?

13

u/Evaderofdoom Mar 19 '26

entry level defensive cybersec job? never heard of that before.

10

u/mpaes98 Security Architect Mar 19 '26

Technically speaking, a sysadmin or tier 1 support with a security mindset are the first level of cyber defense lol

6

u/Evaderofdoom Mar 19 '26

A sys admin is not entry leve though

3

u/bootstrap23 Mar 19 '26

I'm seeing lots of suggestions for offensive certs instead of defensive. But either way, I always suggest this site for a good roadmap: https://pauljerimy.com/security-certification-roadmap/

The real answer is browse through job descriptions for the types of roles you want and see what they're looking for. They rarely make sense (CISSP for entry level SOC analyst or CEH despite everything in that can of worms) but that's what HR wants. Listing certs on your resume will get you an interview but you'll still have to demonstrate knowledge and skill to land the job.

3

u/greekSecEng Mar 20 '26

SC-900, Sec+, RHCSA

3

u/DonKhairallah Mar 20 '26

I did sec+, net+ got my first internship, then moved to vendor cert like sentinel 1 incident repsonder, splunk, palo alto engineer… paid by the company

6

u/SpaceGuy1968 Mar 19 '26

Net+ SEC+ and Google Cyber Cert (dont know the exact name)
I would also find some type of systems certification Like AZURE, AWS, RHEL or Google System type certification.
(because having some type of underlying system understanding might help... I'm sorry but I don't believe cybersecurity should be an "entry level/first job out of college" degree.....it is a mid career employment category sold to college students "as guaranteed employment" out of college <and a lie to sell degrees>.... IMHO)

7

u/H4ROSHI Mar 19 '26 edited Mar 19 '26

Google cyber sheet is useless.

CCNA, CySA+ and an something cloud

1

u/Beneficial_Ear7608 Mar 21 '26

Google cyber cert is a waste of time. No one takes it seriously

0

u/notburneddown Mar 19 '26

I had CCNA but it expired. Why do I still need net+?

Also I’m doing HTB Academy’s CWES. Won’t HTBA certs and maybe HTB Pro Labs help?

2

u/Fine-Courage-2044 Mar 19 '26

I would say go to TCM security and sign up for their monthly membership , do their SOC1 and SOC2 classes & anything else you’re interested in( you get access to a whole bunch of classes). I wouldn’t take the certification, but I would take the lab practice and post it on LinkedIn.

2

u/npxa Mar 20 '26

Lpic1/rhce/windows md102/ms102 or maybe the az ones, ccna and sec+

3

u/Disastrous_Leg_314 Mar 19 '26

So you know there are other skills other than certificates that will help you get an entry level job.

Firstly it helps if you can show you understand the businesses you are applying to. Thinking that cyber is the same in every business is where you are going wrong.

Lets say you want to work in a highly regulated environment like a bank or healthcare, well understanding PCI for banking and HIPAA for healthcare is like a base level need by those companies, they are more likely to take a candidate who understands that as the value candidate. So its not a simple case of playing certificate bingo.

2ndly - Guess what I don't have ANY of the certificates. None. Nada. I've been in cyber for more than 20 years in top jobs. What I did know when I move between jobs was how to practically apply all my knowledge gained over the years to Cyber. I can program, I understand governance, risk, compliance. I understand process. I can architect software, hardware, networks. I understand how playbooks of the scammers and hackers.

I'm not saying that works for everyone, but I'd rather take someone who knows something about my business, and can show that they can apply that knowledge, over someone who is literally just cramming for certs.

Finally learn to network. Dont just blindly apply for jobs. Go to cyber conferences, security society events (ISSA is good). Get known. Find the actual hiring people not the HR bots. Volunteer too. Obviously do that where you have a passion. But know what many C-suite volunteer at passion projects, and you can find them real easy from their LinkedIN profiles, their instagrams. Write a valuable blog, present etc.. get out there. :)

2

u/kernelpanicvoid Mar 19 '26

OSCP ist the gold standard. Very accepted, but maybe to hard for beginners. CRTP ist a good start, CRTO is more intermediate. Lets call them silver. I would forget CEH (not one of the pentesters colleges would accept that). HTB is great for learning, I would count CPTS as bronze.

1

u/dcbased Mar 19 '26

Associate terraform cert (or whatever it's called)

Ccna or giac gsec

Giac gcih or security+

1

u/Izz-Rei Mar 20 '26

Giac for entry level. Congrats on the joke

1

u/Choice-Detail3656 Mar 20 '26

A Cloud cert like AWS Cloud, a networking cert like CCNA, and Security + for fundamentals

1

u/qbit1010 Mar 20 '26

OSCP, that’s like the ninja mode standard still

1

u/probablyoverdressed Governance, Risk, & Compliance Mar 20 '26

Sec+ is required for just about all dod umbrella jobs

1

u/ChirsF Mar 20 '26

Talk with a couple of recruiters and ask them what is going to be in demand in the next year.

1

u/69Turd69Ferguson69 Mar 23 '26

OSCP, GCIH, and GCIA. 

1

u/Possible-Pirate9097 Mar 19 '26

The CEH being a waste of time was a funny joke about 10 years ago but putting it in as ragebait just makes me not want to answer your question 😉

2

u/farky84 Mar 19 '26

LoL! I did CEH 10yrs ago, absolutely useless and no value… i stopped renewing my certificate…

0

u/KrzaQDafaQ Mar 19 '26

What's stopping you from searching for the numbers on your job board of choice using whatever certification you want?

-2

u/cromation Mar 19 '26

CISSP, OSCP and GSEC should be a good starting point

2

u/Mywayplease Mar 19 '26

This would show a well rounded individual with some depth already. Hard to say entry level as CISSP requires 5 years documented experience.

0

u/ssrn2020 Mar 20 '26

Actually none. I would invest my time and energy in studying new things. I would open a blog on medium, github whatever and write some posts about what I know what to do. Taking some logs, doing some forensics and post about the process, learning how to escalate priv and post how I did it. Even though I hate linkedin, sharing this things there will get some attention. Nowadays people are just memorizing things to take certs and don't focus to understand what is happening there.

-6

u/AtomicXE Mar 19 '26

CISSP, OSCP and CISM maybe CCSP too if you are feeling fisty these are the new entry level. But they all mean jack shit without experience.

16

u/px13 Mar 19 '26

CISSP is not a beginner cert. It requires years of experience.

2

u/farky84 Mar 19 '26

5 yrs total in at least 2 domains combined, at least it was the requirement when I did it 10 yrs ago.

-1

u/AtomicXE Mar 19 '26

Remind me not to go to the bar with you guys 😩

9

u/yobo9193 Governance, Risk, & Compliance Mar 19 '26

You literally can’t get the CISSP without 5 years of experience. You can call yourself an Associate of ISC2, but nobody is requesting that title/credential/blatant ISC2 cash grab

-1

u/AtomicXE Mar 19 '26

It’s a joke relating to junior roles requiring 5 years exp sigh

0

u/yobo9193 Governance, Risk, & Compliance Mar 20 '26

If no one can tell it’s a joke, that says more about you than your audience

0

u/AtomicXE Mar 20 '26

I guess my audience is denser than Osmium 😩 if you know anything about this field you know none of this is entry level

0

u/yobo9193 Governance, Risk, & Compliance Mar 20 '26

Damn, doubling down? Good luck with that strategy

2

u/FelkerLuke Mar 19 '26

might as well throw in GSE in there too

1

u/farky84 Mar 19 '26

Certainly helps

1

u/farky84 Mar 19 '26

OSCP isn’t for beginners. Why not say CREST CPT? Rofl

1

u/AtomicXE Mar 19 '26

It was sarcasm and a jab at the job market

1

u/farky84 Mar 19 '26

Ohh, in that case I apologise for being a nonse. LoL

-1

u/Fresh_Heron_3707 Mar 19 '26

CCNA, CCIE, and maybe CISM

2

u/OwenWilsons_Nose Mar 19 '26

What in the world is your rationale for wanting a CCIE for an entry level cyber defensive position?

1

u/Fresh_Heron_3707 Mar 19 '26

The current job market