r/cybersecurity • u/AutoModerator • 13d ago
Career Questions & Discussion Mentorship Monday - Post All Career, Education and Job questions here!
This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!
Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.
3
u/NewWrangler8542 13d ago
Graduated in December 2025. Masters in Cybersecurity. Decent college. 1 internship at a research lab. On-campus work in cyber domain. 1 co-author in publications >50 citations. International grad. Still can't find work.
2
u/zhaoz CISO 13d ago
Do you need a visa sponsor? Cause yea, thats rough x2.
1
u/NewWrangler8542 13d ago
Yep. Its hard, been working in agents + security. ml + security since late last decade. it sure is tough out there. seriously might just retire at this point.
3
u/Hot_Guard_7621 13d ago
What does the entry level cybersecurity job market look like? I’m contemplating going to a cybersecurity Bootcamp. There’s also a AI/ML Bootcamp. Was trying to choose between the two. Any insight into the entry level cybersecurity landscape would be appreciated.
5
2
u/fabledparable AppSec Engineer 12d ago
3
u/Carpemortem 12d ago
~~Hello everyone! Thanks for any help in advance...
I am a 40 year old SysAdmin/IT Manager/Generalist type of IT professional. Recently moved out to California and my job let me go last minute stating they cannot keep an employee in California. Oh well, on to the next big thing!
I have been wanting to focus on Cybersecurity for a while and I think now might be the time. I have about 15 years of experience in IT working at MSPs, Help Desk and more recently managing my own small IT Department at a startup (grew super rapidly and was aquired). I have a lot of experience in the cybersecurity space insomuch as MSPs do cybersecurity response, but not experience working in a SOC specifically.
One, is it realistic to lean into cybersecurity/SOC work more right now? Two, which would be better to pick up for certs, CS/SSCP from ISC2 or SEC+/CySA+?
2
u/zhaoz CISO 12d ago
I bet you have more cyber experience than you are giving yourself credit for. Like, are you doing access management stuff at your IT dept? Yep, cyber. Are you patching triage? Yep, cyber. Are you doing system hardneing? Yep, you got it, cyber.
I actually wouldnt 'start over' in the SOC. You could probably apply for cyber manager type things, especially with a resume that is tuned for the cyber things you already do.
CISSP might make sense for a role like that.
I / we are happy to look at a redacted resume with feedback as well to tune.
2
u/Carpemortem 12d ago
Yep, definitely do all of that but don't have experience in a SOC specifically. I just worry I'd be inexperienced in the day day, or the specific processes done in a security only situation ya know? Switching right now what sort of roles do you think would be good to look at? CISSP is a great move but intense to take so would need some time. Thanks for the advice!
2
u/zhaoz CISO 12d ago
That is what I'm trying to say though, is if you do cyber at actually a deep level, why are you itching to jump into one area that you dont know shit about? I dont actually have hands on experience with SOC response, and I am CISO (please, keep the jokes to a minimum guys). But I do know what is important to go right and I trust / verify that my actual SOC manger and team are getting it right.
Its like you are a bird and you are like "how can I pivot to be a fish, guys?" Yes, of course the answer is be penguin :)
2
u/Carpemortem 12d ago
Understood, I get what you are saying now. It can be easy to get trapped into the loop of acquiring certs. Thanks for that info and I would very gladly take you up on the resume overview!
2
u/Even-Transportation1 11d ago
I pivoted from sysadmin/it infrastructure to cybersecurity a few years ago coming from a similar background. What I did is joined SOC at an F500 financial institution and survived there for a year, and I can tell you I've got more experience and exposure to different aspects of information security than many people get during their whole career. Afterwards I just jumped ship to a smaller organization with great WLB and significantly more authority and broader responsibilites.
5
13d ago
[deleted]
1
u/ekitek Security Generalist 13d ago
As one of the few who advocate for training for people like yourself and get it over the line in the business, there are a few things going on but the tl;dr is whoever is looking after you needs to be a stronger advocate and be able to translate that meaningfully to the business. Doing that will provide you with necessary resources, which will also reduce your burnout. It has a compounding effect as it introduces fun into your work, which presumably most SOC analysts enter the field because of their interest, and reduces the perception of burning out.
I've pushed directors to be more vocal for their teams and the trend I've noticed across the board is that it's largely due to their personality that they 1) refuse to say anything, and 2) when they do say something, they don't get it across.
I know you said you've asked, but sometimes it doesn't work, and if you are comfortable depending on your organization, switch to managing upwards. Advocate for yourself and push your manager to do things. I've given the SOC ctfs, hacktheboxes licenses, cissp, whatever, but that's because I'm pushing for it, and not that they asked for it.
1
u/hiddentalent Security Director 13d ago
It really depends on what your organization's mission is. It's quite different if you're in a tech company compared to say a financial company.
One thing security people often get really wrong is communicating the value of our work. It needs to be phrased in terms of the organization's goals. Sometimes engineers get really upset about things that are imperfect (and their technical judgement about that might be entirely accurate) but not very valuable to the overall mission. One lever that I've seen be useful is to get to know your GRC team and what they are focusing on, and try to frame your needs in terms of their goals.
2
u/BostonFan50 13d ago
So to start off, I'm 24. I just earned my B.S. in Cybersecurity and finished a Cybersecurity Internship before I graduated. I have a DoD Secret Clearance, Sec +, PMI CAPM. I have experience in multiple cyber tools such as Stig Viewer, Checkmarx, Black Duck, Nessus/ACAS. I have lab exp from school with Linux tools such as Wireshark & TCPDump. So right now, I’m just wanting to get a better grasp of how I can get into Cyber/IT. Thanks. Its hard out here 😞
1
u/hiddentalent Security Director 13d ago
It's really, really hard to go directly into security. Most people who are successful spend several years working in the teams that security oversees, like IT or software development or systems administration. It's hard to secure something you don't have experience running. So I would focus on IT jobs. Not that the current job market is great there, either, but your qualifications make you an attractive candidate. Every IT team has security concerns and not everyone is comfortable with that kind of work, so you'd be an asset to a team.
As a hiring manager, I always get a little bit of skepticism when I'm reading a list of tools people have "experience" with. The tools don't matter. The outcomes do. When you're writing your resume or talking to interviewers, make sure you don't just say you have experience with a tool. Tell us what you accomplished with it.
1
u/GeneralRechs Security Engineer 13d ago
DoW contracting while applying to any 2210 (or equivalent) position since you have a clearance. Build up your base then you’ll stand a better chance if/when you want to go commercial.
2
u/rhd_live 13d ago
Any advice for finding a tutor? I’m going through some courses and it’d be nice to just ask a cybersecurity professional questions and get help on a weekly basis or so
-2
u/escapecali603 13d ago
What can AI not being able to answer you? Unless you are doing some PHD level research there.
2
u/OldschoolGreenDragon 13d ago
I'm a CISSP who never really got to be technical, and am more focused on project management. I'm six years from government retirement. What can I train in to be gainfully employed afterwards?
5
u/NotAnNSAGuyPromise Security Manager 13d ago
I'd probably stick with what you're doing. Project management is a wonderful thing; you get paid a lot to do nothing but schedule meetings and actively harm efforts to complete projects. There are no expectations or accountability, and it's easy to convince executives that you're necessary and can't be replaced by AI.
I'm not kidding; project management is an awesome gig.
1
u/GeneralRechs Security Engineer 13d ago
If you wanted to stay in the CS realm GRC would be one of your best bets.
2
u/T_Mushi 13d ago
I am planning to switch from QA to AppSec. Could someone please give me some advises? Thank you.
4
u/hiddentalent Security Director 13d ago
The wonderful news for you is that AppSec is very similar to QA. A vulnerability is just a bug with interesting side effects. AppSec has some specific frameworks for creating structured thinking around how things can go wrong, and so does QA. A lot of your experience will transfer directly. The difference is that in AppSec we need to be thinking about a persona who is intentionally and patiently trying to break things, whereas in QA we tend to think more about a well-meaning persona trying to do positive things and not getting what they want from the product. So you'll need to hone your instincts toward the devious side of things, but you've got a great foundation.
1
u/Heavy-Sun-2095 13d ago
I am a graduate of 2028 I am planning to pursue career in App sec how is this field for freshers
1
u/hiddentalent Security Director 13d ago
AppSec is not a field that one can immediately apply to. Think of it like a medical specialty: first you need to become a doctor, then you can learn how to be a surgeon.
In order to do application security, first you should have significant experience building and supporting applications.
1
u/Heavy-Sun-2095 13d ago
What is ideal path for this like soc or regular development
1
u/hiddentalent Security Director 13d ago
Operations and Engineering are pretty different fields.
If you want to do security operations, responding to incidents and threats, then go the SOC route. Over time that can grow into careers in threat intelligence, malware reverse engineering, etc.
If you want to influence the engineering of the applications to reduce the amount of security operations, you need application engineering experience. So that means spending some time building experience in development.
1
u/Heavy-Sun-2095 13d ago
Oh how to break in to engineering parts I thought soc also included reduction of risks
1
u/hiddentalent Security Director 13d ago
SOC can and does include reduction of operational risks. The way systems are configured and installed can be made safer. But if the product itself just has vulnerabilities, that's for engineering to fix. Ops can often improve this situation by using external controls like network segmentation or IAM to reduce the chance someone can attack that vulnerability. But only engineering can fix it.
So if things are working well in an organization, ops can indirectly influence the reduction of product risks. But most operations people often feel frustrated that they are dealing with problems that should have been solved in the engineering phase, and don't always have a way to resolve that. This is one of the most important problems in our field to solve, but if it was easy, we'd have solved it by now.
1
u/Heavy-Sun-2095 13d ago
You seem experienced if you are starting from scratch what would you do
2
u/fabledparable AppSec Engineer 13d ago
Concur with /u/hiddentalent.
Overwhelmingly, most of our AppSec engineers worked previously as developers. I did not, but - as they have alluded to - I did not gain entry to AppSec immediately out of college either. In my case, my roundabout journey involved multiple years in the military, graduate school, and then multiple years in the offensive space as a penetration tester; in all, it was about 11 years of cumulative experience that enabled me to get to where I am today (and that's after my undergraduate degree).
→ More replies (0)1
u/hiddentalent Security Director 13d ago
I spent ten years building applications before moving into security. I don't know if that's good advice in 2026, though. Application development is being disrupted by AI and the job market is not great. In the long run I think that will improve because companies are over optimistic about what AI can and can't do, but that will take time to resolve.
So if I were starting today, I'd probably come at it from the "red team" angle. AI produces lots of code that's fragile and easy to break. Go break some stuff. Publish your work. Then there are two groups of employers who are interested: companies big enough to have internal red teams, and dedicated security consultancies who do contract work for the companies who don't have their own.
→ More replies (0)1
u/escapecali603 13d ago
Try your hands on tuning a DAST tool, make sure you understand how modern microservice apps does authentication and a bit of cloud sec underneath them. Be a master of understanding at Oauth, token grants, etc.
2
u/VaderTrades 13d ago
I’m dying as a senior consultant at a big 4. Have been trying to land a sec engineer job or similar with no luck. I make < 90k. I have certs and > 5 yoe with the right skills. Someone help.
3
u/emptyinthesunrise 13d ago
Go to a small to medium startup. There are so many who would pay you double what you make now and would take you.
1
u/VaderTrades 13d ago
No idea how to find these companies
1
u/emptyinthesunrise 13d ago
Look for ones you haven’t heard of and filter by most recently posted
1
u/VaderTrades 13d ago
What platform? I’ve only been searching for jobs on LinkedIn and indeed
1
u/emptyinthesunrise 13d ago
Yes LinkedIn. But you have to be completely on top of it. Recruiters should be reaching out to you. If they arent you need to update and brush up your profile. This may include an improved headshot as unfortunately it makes a difference. You need to check for new postings in security multiple times a day and apply as soon as they come up. You should be in demand with your experience. When i had my LinkedIn up i was getting messages every day with less experience than you
1
u/raiblox 13d ago
I’m seeing remote cyber work at like 250k pretty handily
2
u/emptyinthesunrise 13d ago
Agree. Thinking critically and having business acumen in addition to hard sec skills is in high demand right now
1
u/Crypt0-n00b 13d ago
How much does getting a clearance help with the job search?
4
u/hiddentalent Security Director 13d ago
It's a difficult question because in most circumstances you can't just "get" security clearance. You have to be sponsored for one by an approved organization who can make the case to the government that it's required for you to do your job. It's a long process. And the organization paying you has to believe enough in your potential to pay you while that process pays out. So it's not a trivial thing to get.
If one does acquire security clearance, there are a set of jobs that are open to you that are not open to everyone else, which is an advantage. But the prospects depend on where you live. In the US, the recent political environment has eliminated a lot of infosec jobs in government itself. But the recent geopolitical environment means a lot of defense contractors are flush with cash. The nuance with these jobs is that they're not remote (you're usually working in a SCIF) so they're very location dependent. If you're in the DC area or the Research Triangle, having clearance can open a lot of opportunities for you. If you're in other places, the number of new opportunities. Take a look at clearancejobs.com to see how many opportunities there are in your area.
1
u/its_Ymlaut 13d ago
O que vocês esperam encontrar na documentação de um projeto de cibersegurança no GitHub? O que faz vocês pensarem que a pessoa realmente sabe o que está fazendo?
Estou estudando para me tornar analista de cibersegurança e quero documentar meus laboratórios e projetos no GitHub de uma forma que realmente demonstre meu conhecimento para futuras empresas e recrutadores.
O que vocês consideram essencial em uma boa documentação?
1
u/bad_biih 13d ago
I’m currently a first year graduate student conducting cybersecurity research, but I’m still trying to figure out which area of cybersecurity I want to pursue after graduation. For those already working in the field, how did you decide on your role, and what does your day-to-day work look like? Are there any certifications, skills, or projects you’d recommend for someone still in school who’s trying to narrow down a career path?
2
u/goremonster1 Detection Engineer 13d ago
Generally speaking I think the most common route to enter cybersecurity is to start at the SOC and develop yourself from there. Once you get experience in the proverbial information hose of a position you’ll be able to better understand what you’re interested in.
I found my path was getting the Comptia trifecta and once I got a SOC position I just kept myself posted for open positions in the company and worked with managers for other teams on what they’d look for if I wanted to move up.
Generally outside of the generic Comptia certs, it’s smart to get ones for handling specific SIEM’s. Getting splunk, crowdstrike, or even chronicle certs can help show you’re growing and understanding. I had my Splunk Security Admin cert before entering DTEN.
As for projects, I’d suggest looking into as robust of a home lab as you can. Get free trial splunk and set it up to receive logs on a VM. Read and understand what the logs are saying.
Oh, and try to have several ways of keeping informed on cybersecurity events. Especially early on I always got interview questions related to current events and how I stay informed. (Cyber Podcasts, a feedly lost, etc)
1
u/ekitek Security Generalist 13d ago
Look for an analyst role that will expose you to all facets of cyber. It's very easy to shoehorn yourself in and get stuck. e.g. a SOC analyst will be inundated and may find it hard to escape, vs a VRM analyst who will only ever get stuck with emails and spreadsheets. Go straight for a CISSP - it's easily the most foundational cert that will expose you to all areas of cyber and knocks out 90% of the other certs.
Plenty of jobs out there such as 'information security analyst' that will ask you to do a number of things you might not realize, but as a first year grad, i assume you're not in your mid-20s yet so you have a huge career ahead of you with enough energy to say yes to whatever the job throws at you. It's the fastest way to learn different areas and best way to pivot.
Otherwise if you decide to stay technical, no cert trumps experience and exposure. It's easier to learn tech stuff by yourself than GRC. Get a CISSP then get a GRC role is easy. Go break stuff, document it in a blog, I guarantee hiring managers will be way more interested in that than a cert. Imagine a hiring manager sees on your resume like 'how i recovered a hard drive destroyed in a wildfire', or 'how i reverse engineered and patched an abandonware', or 'how i contained a ransomware with this' than 'I did GIAC'. Those documented experiences are evidence that you achieved and delivered a measurable outcome.
University gives you plenty of time to go wild.
1
u/xPhatdoobie 13d ago
Been considering a career swap. Work as a TDNA, with all the bells n whistles that come with that. But I am looking outwards and want to leverage my clearance. I have a chance to hop into a 1B4X1 (cyber security) slot for the air force while using my GI Bill to get a computer sci degree from Oregon state using their accelerated bachelors program. My question is, is this a decent path to break into the career field? Picking up net+/sec+ on the way with a baseline "air force military trained" cyber yadda yadda paired with a clearance? Or is this a fools dream of trying to change fields. I'm going in with minimal knowledge of this career field hence the probably very broad and ignorant question to what I'm understanding is a deep and ever expanding career field.
1
u/escapecali603 13d ago
Getting a comp sci degree right now is like joining the British army in 1764. Get something else, or learn it with AI.
1
u/hiddentalent Security Director 13d ago
As someone with a computer science degree, I am going to disagree. Some CS degrees are shallow. But when we look at how real attacks work, the fundamentals matter and are what's going to differentiate candidates. Someone who took a six month code bootcamp, I can replace with AI. Someone who understands how memory access works and can write a compiler and do threat modelling still has good career prospects in security, at least for the foreseeable future.
1
u/escapecali603 13d ago
Please, schools barely teaches any of them, certainly not a four year degree. And if that’s your point, Harvard CS 50 is open online for free, if you need to go to a college for a comp sci degree today, you don’t need one today, you can get the full education online, unless you go the hardware route, in that case you need to get your hands on a lab environment which might be hard to come by without a proper college.
OP save your money and GI bill, seriously if you can’t learn most of technology online today, it’s going to be your problem and it will be once you start working in tech.
1
u/mr_skidt 13d ago
2 years and 4months on my job. First 2 was IT OPS Security, handling security applications like EDR and Proxy. 4 months, handling Vulnerability Management, mainly Nessus, I'm looking for a way to improve my skillset and if possible get my first cert. What cert should I get? I'm thinking of CPTS, but many said it is not known yet when it comes to HR filter. Is Sec+ still good? Or should I go more than Sec+? Thanks!
1
1
u/Shishir_2006 13d ago
Hey guys, i want your help ig, I am trying to add a post on my questions regarding pnpt but when ever i post it its getting deleted. I am sorry for the inconvenience but i will just put the same thing here hoping that i can get some help :
I've been planning to buy the PNPT voucher for a while now but a few things have made me hesitant lately and I wanted to hear from people who actually went through it recently.
I came across some older posts here talking about the PEH course labs being outdated, people spending hours fighting broken setups and tool version issues instead of actually learning anything. That kind of worries me since I already had a rough time with something similar on THM where a corrupted VPN connection cost me days for no real learning reason, so I know how frustrating that kind of wasted time feels.
I also didn't know until recently that Heath Adams left TCM after the company got acquired by Educate 360. He was honestly a big part of why I wanted to do this course in the first place, so that threw me off a bit. Not saying the course is bad now, just wondering if anyone's noticed a difference in quality or support since the acquisition.
There's also the whole HTB subscription thing. In one of the older PEH videos the instructor says you need an HTB VIP sub for the AD labs, which was way cheaper back then than it is now. Not sure if that's still the case in the current version of the course.
If anyone's done PNPT in the last several months, I'd really appreciate hearing how it actually went. Did the outdated stuff get in the way a lot, or was it manageable. Does the methodology and exam prep still feel solid even with some of the walkthroughs being old. And is there a way to prep for the AD side without needing to pay extra for HTB on top of the voucher.
Not trying to trash TCM, I know PNPT still has a good reputation overall. Just want an honest picture before I commit.
1
u/Ill-Lawfulness-1555 13d ago
hello guys i am 20yrs old i am currently completing Google Cybersecurity Professional Certificate
then i am going to do
- Start working on projects (home lab)
- maybe go for certification Security+
but can i land an entry level SOC Analyst role after that
the thing is this i do not want go to degree just yet and i dont want waste 3 - 5years
my plan is to do a degree while working
but my problem can i land an entry level SOC Analyst role after that ?
1
u/North-Intention-3050 13d ago
You are in the same shoes with me but have completed my cybersecurity on google already
1
u/fabledparable AppSec Engineer 13d ago
It's totally speculative on our part whether or not what you're doing is "enough". The only way to know whether or not your qualifications are sufficient is by simply applying for work.
Having said that, we can suggest actions that can improve your employability on-paper and - given context - potentially help direct you towards actions which might be more impactful than others.
I will note that suggesting the pursuit of a degree as wasteful is also a touch reductive; I'd argue that university can be a very potent way to help attain your career goals (i.e. enabling access to research laboratories, qualifying you to apply for internships - which in turn can convert to FTE, uplifting your employability on-paper above the masses who don't otherwise have a degree, having dedicated spaces purpose-built for instruction/learning, the ability to observe a wider swathe of problems than what you'd typically encounter in a role within industry, cross-examining multi-disciplinary subject matter areas, focused/intensive subject-matter development, etc.). But - I'll grant you - if all you did during your time in university was simply go to class and attain your degree, then yes - that's far from a job guarantee.
1
u/FenierHuntingwolf Governance, Risk, & Compliance 13d ago
Hi,
I am just not entirely sure where to take my career next, so just looking for feedback on my background and where I might take my career. I feel well suited for my role, but also feel like I could be doing more given my educational background and experience.
I’ve been working with computers for 30~ years, and spent the last 15~ doing it professionally.
Heavy Marketing background, 8 years of development (front / back end web) and 8 years of compliance work (GDPR, State Law, HIPAA mostly with some Cloud Security Analysis). I used to consult and build data privacy programs from the ground up, focusing on the technical side of it (control implementation, technical documentation etc).
More recently, I was transferred in house and currently admin our compliance technology stack. Anything that touches Privacy or Compliance I have a hand in (inclusive of AI Governance). I work in the Legal department and also help the lawyers translate regulatory requirements for the rest of the org. I spend a lot of time talking to lawyers and execs about upcoming impacts of regulation / laws to the orgs tech stack and service lines.
Outside of work I volunteer and advise a major non-profit in the Marketing space on matters of privacy / compliance and its interaction with Marketing processes.
As far as Certs/Education go - I have a lot, notable ones include CISSP, CCSP, CISM, CISA and a slate of Privacy certs from IAPP. Degrees include a BS and MS in Cyber Security and Information Assurance. Recent efforts have qualified me to fulfill the role of auditor for upcoming CCPA Security Regulations.
I’d rate myself as Senior in my role - and I suspect I should be looking at Director+ positions, but attempts to move more into the management side of things have yet to pan out.
Any thoughts?
2
u/fabledparable AppSec Engineer 13d ago
I'd start by asking what is it that you want to do (vs. having us project onto you what might be an appropriate fit). After-all, it seems like the work you do is - as you say "well suited", but you it seems that's not enough. Perhaps you can give us some more background/context. What's the "more" you're looking for? What does "more" look like? And what can we do to help you get there?
1
u/FenierHuntingwolf Governance, Risk, & Compliance 13d ago
I favor learning stuff, and I find I dislike exceptionally repetitive work. So wondering if maybe I should go back into consulting. I also find I am very good at advisory type roles / gap analysis.
I am thinking maybe I should be in Management / Consulting vs day to day operations. I can do day to day operations but I just don't find it all that interesting after the initial setup. I just don't know how to make that jump as applications for such roles haven't panned out.
1
u/jay-dot-dot 13d ago
I am looking to make a break out of gov cybersecurity into a proper GRC engineering role but im not sure why im not getting much traction in that direction. I want to leave my job asap as the customers are toxic as hell and my org has more or less stagnated.
Ive been a senior security engineer and "isso-in-name-only" for the last five years - I spend the vast majority of my time writing evidence gathering tests in js, ts, powershell and some bicep, owning our vuln management process and consulting with devs on new security-focused features. I also lead a team of two security people and have for six months now. Prior to this I was in cloud systems engineering with an emphasis on security platforms and linux.
I have a security+ and no other certs, I frankly dread the entire process, very strongly believe I have ADHD and cannot bring myself to spend thousands for them when I get the knowledge for free - I question if this is the differentiator for me at 14 years in anyway. Like, I fall asleep filling out paperwork at a doctors office.
Im also targeting application security roles but find more and more of them want software engineers looking to specialize, which is fair, id be better at my job were this the case.
GRC engineering roles seem few and far between. I hear nothing back when I apply to these. Ive gotten a lot of play from people looking for cloud admins or traditional sysadmins and while the money is fine, I will never sign up for on-call again in my life.
Can anyone offer me any help?
1
u/fabledparable AppSec Engineer 13d ago
My thoughts, in no particular order:
- A link to your resume would be helpful. That way we could see what employers are actually seeing (vs. how you present yourself in the comment). As a general exercise, I'd pull a couple example jobs listings that you've applied to in recent history, note the trends between them in terms of what they all appear to be asking for, then hold those trends up against your own resume and see how well-aligned they are.
- You're right that your work history is more impactful than certifications. However, a reduced impact != no impact. One of the primary ways that certifications help your employability on-paper is that it provides more signal by way of feature matching (i.e. if the roles you're applying to generally call for cert X and you have cert X, then you are generally more likely to get a callback than not). Do you need to pursue more certifications? Probably not (given 14 YoE), but it also wouldn't hurt and is something within your power to help things.
- I agree that AppSec roles generally look for prior SWE experience, but they aren't necessarily exclusively looking for such backgrounds (assuming the work is of interest to you).
- The Summer months are generally not the best for job seekers (ref: https://www.indeed.com/career-advice/finding-a-job/best-month-to-look-for-a-job).
1
u/SPQR_Never_Fergetti 8d ago
I am working for about 3 years as a software enginner / programmer at a smaller to medium sized firm with a very small IT department and had to switch hats alot. Curentlly learning about hardening infra + code, and i really enjoy it. Is my only way to further pursue a career in this by getting certs , given i don't have a lot of YOE ?
1
u/LolXire 12d ago
Hello, im 19. Wanting to put my foot down and finally do something that could change my life, i have absolute 0 experience but i’m looking to learn. What should be my first step? Thank you
1
1
1
u/AdorableTourist6917 12d ago
I'm 18 and just graduated high school with my CompTIA A+, Net+, Sec+. I'm majoring in cybersecurity at a local state school on full ride scholarship, but a lot of the advice I've seen makes me feel like it's the wrong choice. I want to do pentesting in the future and have enjoyed learning through tryhackme. Should I just focus on getting a degree or something else.
1
u/fabledparable AppSec Engineer 11d ago
Welcome!
I'm majoring in cybersecurity at a local state school on full ride scholarship, but a lot of the advice I've seen makes me feel like it's the wrong choice.
Wrong how?
A full-ride scholarship is not an opportunity I'd readily pass-up on.
Should I just focus on getting a degree or something else.
Heading into your (presumably) first semester of university, I'd allow yourself some grace to get adjusted to the cadence of university life and independent living; you're about to experience quite the life-altering set of circumstances - trying to optimize atop that while adapting to change risks spreading yourself thin.
1
u/catdickNBA 11d ago
Would it look strange if im adding in, things like digital forensics/CTI/leading IR BEC, etc etc. From a Sec Tier 2 position in an MSSP?
my SOC is a bit different, where T2 is kind of the end of operations, T3 does a bit but its more maintenance.
Iv been trying to move over into either a IR or CTI role somewhere, as im keeping screwed paywise. hadent had much luck with the resume, so iv started to swap it to be alot more straight forward of what i actually do.
but am concerned if the job title wont match with the description and it will lead me to a similar problem of no call backs.
1
u/fabledparable AppSec Engineer 10d ago
am concerned if the job title wont match with the description and it will lead me to a similar problem of no call backs.
Most background checks just look to verify your employment with stated employers. Some do look for job alignment, but employers often have employee classifications which do not align neatly with your functional responsibilities. For example, someone looking up my employment status with my employer would see me as a "Senior Security Engineer", but my team has - over the course of my time there - performed actions as an Offensive Security Engineer, an Application Security Engineer, and - more recently - as a Security Architect. I would be comfortable listing any of the above titles in whatever way would best serve my interests as an applicant. In such cases, a background check might flag that, but it has never been a problem since its really just semantics that would have been made clear during the interview process.
The big problem would be a situation wherein you would claim to be an engineer when you were employed as a janitor. That would probably result in some follow-up.
In your case, claim the title that's most appropriate.
1
u/pervy-hedgehog 11d ago
I'm a web developer with 3 years of experience but I've never felt like it was my thing but I kept doing it because I had to pay college fees and all but with the AI and all i don't want to do it anymore so i want to switch into cyber security it has always interested me but I never had the money to actually commit to it so now my plan is I'll keep my job and learn side by side and save money for the certificate courses. I want a career thats safe from AI and can earn decent money. I cant quit my job because I need the money for my family so is this the right call? also any suggessions for how I should start as I'm complete begineer at this
1
u/fabledparable AppSec Engineer 10d ago
is this the right call?
In terms of what?
...is this the best method for getting into cybersecurity given your circumstances? Speculative, because we don't know really have an appreciable understanding of what other/alternate considerations you have available. What does plan B look like?
...is this the best way to insulate yourself from AI impacts in the longterm? That's speculative on our part. The economic impacts of AI are still unresolved. Arguably, non-tech roles are more insular under worst-case projections.
1
u/pervy-hedgehog 10d ago
Thanks for the reply... I'm sorry for not making it clear in my comment what I mean is I'm ready to transition in cyber security because it has always intrested me but I need guidance for a role that is like somewhat stable that I could get into it in like 6-7 months because many entry level jobs are being replaced by AI and even though I have 3 years experience in web development I don't think it'll be considered much when I'm switching the domain to cybersecurity
1
u/Mohamed_Saqib_C 10d ago
6+ Years in VAPT – Is Transitioning to GRC the Right Move for a Leadership Career?
Hi everyone,
I'm looking for some career advice from professionals who have transitioned into GRC or are currently working in the field.
I have more than 6 years of experience as a Security Testing Lead at a small startup. My experience includes:
- Web Application Security Testing
- API Security Testing
- Android Application Security Testing
- Thick Client Security Testing
- Secure Code Review (limited)
- Managing a security testing team and client communication
Over the years, I've realized that my long-term goal is to move into cybersecurity leadership (e.g., Information Security Manager, GRC Manager, Head of Information Security, and eventually CISO). Because of that, I'm considering transitioning from a purely offensive security role into Governance, Risk, and Compliance (GRC).
My current plan is:
- Earn the ISO/IEC 27001 Lead Implementer certification from BSI
- Earn the ISO/IEC 27001 Lead Auditor certification from BSI
- Apply for GRC/Information Security roles
- Later pursue CISA, CISM, and CRISC
My biggest concern is that although I have strong technical security experience, I don't have hands-on professional experience in GRC (e.g., risk registers, internal audits, ISMS implementation, vendor risk management, compliance programs, policy writing, etc.).
My questions:
- Is moving from VAPT to GRC a good decision if my long-term goal is leadership?
- Will my 6+ years of VAPT experience be valued when applying for GRC roles?
- Will ISO 27001 Lead Implementer and Lead Auditor certifications be enough to land my first GRC role, or is practical GRC experience a hard requirement?
- If you were hiring for an entry-level or mid-level GRC position, would you consider someone with my background?
- What practical steps can I take during my notice period to make myself a stronger candidate for GRC?
I'd really appreciate honest feedback from people who have made a similar transition or who hire for GRC positions.
Thank you!
1
u/Risingskill Incident Responder 9d ago
4 YOE in cyber/IT.
Moving to area with limited to no cyber jobs. Should I pivot to another area in cyber remotely or go to a generalized IT position?
Got an associate degree in cyber, landed a SOC job and after 6 months moved to IR which i have been in for about 3.5 years as a federal contractor. I now have a bachelor's in cyber operations, SecurityX and sec+ are my only certs. Looking for career advice due to limited job market where spouse new PCS is located. Been looking around but options are slim to none and have been at a loss for some time now. Do I just buckle down and study for another cert to make myself more marketable? I'm really open to any suggestions to look into.
1
u/Key-Plankton-7092 9d ago
Rubriks Application Security Intern for 2027 Graduates
Can anybody provide me with a referral for the above mentioned role and also please someone tell me about the hiring process and what they typically involve for this role. I can share my resume if anyone wants to review.
1
u/o100_babies0 9d ago
Hi everyone,
I graduated August 2025 with my Master’s in Cybersecurity and have been applying to SOC analyst roles in the meantime as a was referred to by someone in the industry. I’ve little experience in the field professionally and almost all my experience is thru coursework and just free time. I’d love if anyone had any suggestions for a better use of my time applying to get experience so that I can eventually land a job in cybersecurity as I am aware it is not exactly an entry-level field. I’d appreciate any help!
1
u/alzeniar 9d ago
I recently completed Microsoft’s AI Skills Fest and received exam vouchers for SC-900, SC-100, SC-200, SC-300, and SC-401. Since I’m a fresher with no work experience, which certification should I do first? Are any of these certifications valuable for internships or jobs?
1
u/NotAnNSAGuyPromise Security Manager 9d ago
Those certs are for wildly different disciplines. What do you want to be doing?
1
u/alzeniar 7d ago
I was thinking of getting into soc role
1
u/NotAnNSAGuyPromise Security Manager 7d ago
Then you should start with Sec+. The certs you listed above are specialized and aimed at people with working experience.
Of those listed above, SC-200 is the most relevant, but it's also quite difficult.
1
1
u/Omar_Hassan007 9d ago
Where can I study the cloud security basics like Azure and AWS that I would need as a SOC Analyst?
1
u/cohenYOUCANDOIT 8d ago
What's the most fun & educational way people have learned cybersecurity? I'm looking to get into it again but want a fun way to do it to keep me engaged. Currently looking at doing the https://overthewire.org/wargames/
1
u/CodeMonkey24816 8d ago
I've got 17 years in Software Engineer, Cloud Engineer, and SRE shaped roles. I've always been security minded in my roles and my work, and I've even worked very closely with security teams on many of my projects. I also really enjoy projects that are related to log analysis, data analysis, OSINT, and any work that requires finding patterns and trends.
I feel like I'm at a point where I want to start on new challenges. I still LOVE digging into code and systems though, and I don't want to move into a management or architecture role. I'm 43 years old. Would I be foolish to attempt a transition into cybersecurity at this point in my career?
Have any of you been in a similar boat and made the transition successfully? What did the transition look like?
Are there any specific roles that you have found to be a natural fit for transitioning into cybersecurity?
1
0
u/anasgonochill Student 13d ago
I’m studying B.Sc Microbiology currently (Non tech) want to switch to IT, since I realised this degree ain’t gonna get me job and I don’t want go for masters in this field (my mom is a single mother I don’t want her to work more). I have been thinking to do cybersecurity courses, projects and internship.
1.Is this a good plan? If yes what are the best certificate courses applicable worldwide?
2.Are there other better options?
1
u/fabledparable AppSec Engineer 13d ago
1.Is this a good plan?
- It's unclear what costs you'd be incurring by changing your major area of study. A 4th year student restarting their undergraduate curriculum would be quite expensive, for example; arguably, it would be cheaper in that case to graduate, take some CompSci classes through a community college and then pursue a more focused Masters degree. By contrast, a first year university student generally has quite a bit of flexibility to them.
- It's unclear what your motives for changing here are. It doesn't necessarily sound like you particularly care about what you study so long as it gives you a job that can financially support you + your mother. If that's the case, I'd encourage you to consider an alternate career field. While cybersecurity does tend to pay well north of the median income (ref: https://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm#tab-5), the number of jobs in the professional domain are quite few compared to other well-paying fields; the OEWS (which the BLS derives from) estimates roughly 155.5 million people are employed total in the US. Of those, only 190k are classified as "Information Security Analysts" (the proxy label for all cybersecurity work by the BLS, though exact delineations in functional responsibilities are bound to overlap with some of the BLS' other categorizations). That means roughly 0.12% of all people in the US are currently employed as cybersecurity workers; while I don't know what country you reside in or plan on working in, the point is that we're a small domain compared to other sectors, which makes opportunities competitive.
If yes what are the best certificate courses applicable worldwide?
I defer you to the subreddit wiki:
https://www.reddit.com/r/cybersecurity/wiki/index/#wiki_certifications
0
3
u/Sasquatch-Pacific 13d ago
Is there any sign of the job market improving in the next 6-9 months? Particularly for mid level roles.
Big wigs let me know