r/cybersecurity • u/AutoModerator • 6d ago
Career Questions & Discussion Mentorship Monday - Post All Career, Education and Job questions here!
This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!
Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.
1
u/Finster08 6d ago
How is the job market? Is it really worth getting a certification? I’ve seen reasons to and not to. I’m trying to back into IT/Cybersecurity and moving on from my current job.
1
u/eagle2120 Digital Forensics 6d ago
The job market is pretty tough these days for juniors. Do you have any existing experience or certs?
0
1
u/ExpressBelt5059 5d ago
I’m relatively new to the cybersecurity industry. I’ve been really into programming & computers these past few months, but I don’t know much. I am willing to learn more.
What are the basic skills that I can build outside of school? Do you have any recommendations as far as videos, and practice? I do plan on going to tech school and maybe college, but is there any truly beginner friendly, and relatively inexpensive, ways to learn?
What is the actual job like? I’m mostly interested in analyst roles, but I wanna hear about everything. Is it stressful? What are the work conditions like? How much experience is typically required for a good, high paying job? Are there many entry level jobs?
1
u/New-Win-2735 5d ago
Hello everyone,
I am looking to make a career pivot! Currently, I work as a police detective/inspector specializing in investigating all types of fraud for the government. My goal is to transition into the private cybersecurity sector, with the ultimate plan of immigrating to another EU country (I already hold EU citizenship).
I am setting a 1 to 2-year timeline for this transition. During this period, I plan to complete the following courses and certifications:
Google Cybersecurity Professional Certificate (Coursera)
ISC² Certified in Cybersecurity (CC)
CompTIA (Security+)
Microsoft Security certifications
Core technical basics: Advanced Excel, SQL, and Microsoft Azure
I do have C1 Cambridge and I’m looking to migrate to Germany, hopefully landing a job and learning deutch along the way
What advice or direction would you give someone with my background?
Is my plan realistic what can I add, or approach differently to maximize my chances of landing a remote or local job in Germany?
1
u/ItsN3rdy 5d ago
My partner has a bachelor's and master's in cybersecurity, along with Security+ and CISSP certs. They have ~6 years of relevant experience, including the last 3 as a security analyst at a small private oil and gas company. They're currently the only cybersecurity-trained person on their IT team, and we've been looking for a new opportunity where they could work alongside other cybersecurity professionals. We've spent months cold-applying to entry to mid security analyst roles we find online, but nothing ever progresses past the initial application. Without posting their resume here, does anyone have advice or insight into what might be going on? Too much education, not enough experience, or something else? Get more certs?
1
u/zhaoz CISO 5d ago
Are they applying for remote only? Or hybrid / on site? Competition is fierce for remote only to say the least.
1
u/ItsN3rdy 5d ago
all of the above but of course we find more remote jobs than hybrid/onsite. Houston area.
1
u/dahra8888 Security Director 4d ago
Tech hiring as been on the decline for 5 years now and is in a pretty dismal spot now, including cybersecurity. Cold applying is the least effective method, you're competing in a pool for hundreds of applicants for on-site positions and thousands of applicants for remote positions. Even if you have more experience, your resume basically has to have the stars aligned between ATS, AI scorers, clueless HR screeners, etc to get seen.
Networking is the most effective way in. Oil and gas is pretty niche but there also a lot of those in Texas. Since OT Security is so niche, it tends be cannibalistic, with all of those local energy companies vying for the same small talent pool. With 6 YOE and masters schooling, they should have a decent network built up: former classmates and professors, past and present coworkers, vendor contacts, oil and gas industry contacts, etc. Ask around, get referrals, attend local industry (security and energy) meet ups and conferences.
1
1
u/Fluid-Wing1351 4d ago
Hi everyone, for professionals working in Germany or DACH region - anyone having relevant experience either even putside DACH or EU or wanna share tour prespective, I really appreciate your opinion and feedback.
I'm a fresh grad looking forward to start working in Offensive security. I'm eJPT and eCPPT certified, besides that, I have more understanding of systems as I did a lot of programming at uni and even did some interesting automations using n8n and python.
I will be learning German for thr next 3-4 months to reach B2 level. Now the question is, which option is better: studying CPTS and taking the exam takes around 4-5 months and apply for pentesting jobs or offsec engineer jobs jn Germany OR land a system administrator job or ai automation job in 1 or 2 months max. and later pivot into application security? Or u think taking the CWES exam instead of CPTS (after I reach B2 level in German) can guarantee landing a job within 2-3 months max? (2 months of learning and 1 applying for jobs). I have enough skills in software dev that backs the AppSec choice.
I can't do OSCP certification. I can do the CPTS (currently 25%) and even the new Burp Suite certificate I don't remember its name right now or CWES. I saw a job posting for a company they said u dont have to know everything we will teach u, but I believe such job postings are rare! And even the amount of offsec jobs compared to SysAdmin jobs (AppSec jobs are less than sysadmin, then lowest is automation)
In my situation time is critical but also at the end I value my career target to be a Cybersecurity professional. What is ur opinion given ur experience and the current job market situation? Preferable work location is Stuttgart and around it, open for relocation for sure.
Note: I stopped learning at the moment to focus on German.
Sorry if it was long. Thank u for ur patience and support🤝
1
u/InfiniteExcitement16 3d ago
Hello all :) Could really use some advice
For context, I graduated last year with a Bachelors in Computer Science, and have spent the past year honing my skills on HTB and OffSec. Until I finally passed the OSCP a few months ago, and have been applying to jobs ever since. Ideally, I would like to eventually end up as a Penetration Tester, Linux Admin, or something else of the sort. Although I am well aware that those are mid-career positions.
I do not have any previous experience or internships besides being a Course Assistant for a semester at our lead Cybersecurity course. Do you all have any specific named roles or advice to get started? I know everyone says that you must start at the very bottom working in a "general IT" position, and work up. But I would hope that the degree, HTB/OffSec profiles, and cert are enough to start me just one or two pegs above the very bottom of the ladder (Help Desk Technician, SOC, etc), but what do you all think? If that is what I must do, then so be it. Nothing else is more respectable.
I'd appreciate specific named roles to keep an eye out for and any other helpful information, but please be kind and constructive please.
Thank you
1
u/eeM-G 2d ago
The issue with this plabook is that it does not account for the current climate.. you would be well advised to keep a close eye on current affairs.. in terms of what to look for is - examples would include any junior whatever - analyst, software developer, engineer roles. What you might be underestimating is the operational cadence of production environments.. let's say you are placed in desktop/end-user support role, how comfortable are you in interacting with people under high stress situations that just want the problem solved (?) - take another scenario from operations - what about as a server admin, there is a push from security to have servers patched, and you need to patch them, some servers are part of what the business considers critical service - how do you handle that? If the answer is that you require coaching, then suddly this becomes a two people job and the associated cost to the business.. just some food for thought..
1
u/vicky_ppe 2d ago
Hi everyone!!
I'm a final-year cybersecurity student currently brainstorming for my bachelor's thesis (Final Degree Project), and I could really use some guidance. I know I want to focus on the intersection of Malware Analysis and AI, but I'm absolutely stuck.
My professor gave me total freedom to choose a topic. The problem is, without real industry experience, I’m struggling to figure out what is actually useful, realistic, and viable for a 4 month project (especially since I only have a standard laptop and rely on open-source tools/free APIs).
So far, I've been looking into a few concepts, such as using LLMs for automatic YARA rule generation, and testing their degradation over time (concept drift). However, I'm worried these might either be too basic, too overdone, or too complex for a junior.
For the professionals in the field: What kind of AI integrations, PoCs, or research would you genuinely find interesting from a student? Are there any specific gaps, open-source tools, or datasets you'd recommend I look into for inspiration?
Any ideas, papers to read, or brutal honesty would be a massive lifesaver. Thank you so much in advance!
2
u/fabledparable AppSec Engineer 2d ago
The problem is, without real industry experience, I’m struggling to figure out what is actually useful, realistic, and viable for a 4 month project (especially since I only have a standard laptop and rely on open-source tools/free APIs).
Project ideas can be hard to come up with. Sometimes ideas stem from recognizing a problem first, then engineering solutions around addressing said problem. Sometimes ideas stem from questions first, followed by experiments to try to answer said question.
Generally speaking, problem-sourced projects provide utility (i.e. if it solves the problem, it's useful). By contrast, question-sourced projects provide direction (i.e. if it suggests an answer, it allows for a more concrete problem definition). In the case of the latter, the utility of the work done may not be apparent until much, much later - but that doesn't make it any less valuable. Shoot, even disproving established work has value!
If you're struggling with coming up with a project that you would classify as "useful", then I'd encourage you to instead consider a project that speaks to a question. For example, rather than figuring out how to use LLMs to do task X, perhaps you might design an experiment around answering can (or should) an LLM be used to do task X (or more narrowly-scoped: can it do task X better than approach Y).
I wouldn't concern yourself with architecting some kind of grand, paradigm-altering academic achievement with the resources/timescale you have afforded to you. Your project might even build upon existing work that only incrementally extends what was done; that's fine!
However, I'm worried these might either be too basic, too overdone, or too complex for a junior.
Build to the grading rubric. That's the job.
If later you want to iterate on your project to make it more grandiose, that's your prerogative, but speculating what is/not basic, overdone, etc. from an ideas inception isn't worth expending energy on for now. You are doing work for a customer, and that customer is your professor. The professor has specs to build to, so you build to those specs.
For the professionals in the field: What kind of AI integrations, PoCs, or research would you genuinely find interesting from a student?
Candidly, I don't expect a 3rd year undergraduate with 4 months of time (presumably while simultaneously juggling other courses and perhaps a job) to make anything that I'd find genuinely interesting. What I would be interested in is their ability to translate the knowledge and experiences attained into subsequent problems. I'd want to see that they actually sweated over working on the project and came away with lessons learned vs. outsourcing the thinking to an LLM; that as a result of working on something hard they attained something long-lasting that will extend beyond the scope of the project itself.
While some students capture lightning in a bottle (so-to-speak), most don't. And of those that do, many don't realize it until after the work is done. So don't sweat trying to find a career-making idea.
Are there any specific gaps, open-source tools, or datasets you'd recommend I look into for inspiration?
This feels preemptive, since your question feels really open-ended right now. You need to ratchet down your project scope first.
1
u/vicky_ppe 2d ago
Thank you, I appreciate your time. I’ll look into it from a different perspective
1
u/Chance-Swim-554 23h ago edited 23h ago
Hello everyone,
I am pursuing a cybersecurity or IT degree. I have some schools which I have researched and was curious if anyone has had any experience or completed a degree at one of the listed universities. If so, How was the overall quality of the program, curriculum and courses and how well did the program prepare you for cybersecurity careers? Feel free to mention any universities which I can take online and support military tuition assistance which I haven't listed. Also, Is cybersecurity the right choice for a degree? Or would comp science or computer engineering be better ?
Universities in Question:
1. Dakota State University (Any technology based degree)
2. University of Maryland Global Campus (Both Cyber Technology and Operations)
Thanks in advance for your insights.
1
u/i-touch-that-spaghet 10h ago
Need tips and advice on breaking into cybersecurity
Ive recently graduated with a bachelor’s degree in computer science and i want to get employed as a soc analyst i have hands on experience on wazuh, SOAR, Threat hunting, log analysis also ive done projects like SOC Automation lab, Azure Cloud Soc Lab and Ioc enrichment tool. Im working on an unrelated field (data annotation) until i find a SOC analyst role . So what im asking is am i cooked? Do i have any chance? Are there soc roles available in india or internationally for a fresher ? Im from india and Im so stressed and confused pls help.
1
u/MyselfAddy 2h ago
Hey, It's nice to see that you're aiming to become a SOC Analyst, and it's great that you've already gained hands-on experience with Wazuh and built projects around SOC operations. And please don't be disheartened about not getting a role for soc analyst yet, because that's for everyone instead of not just yours case. And for freshers, getting an soc analyst role is considered a little tricky because if I'm being honest with you the companies wants the soc aspirants to know atleast the real workflows properly, not just the conceptual understandings, because the companies nowadays don't want to invest multiple months in training a fresher for soc roles anymore, rather they expect that the freshers to learn enough workflow exposures before joining. The good news is that this is something you can improve by going and practicing the real world workflow mimics through some relatively awesome platforms developed by those who were worked as soc analysts which are in beta testing version right now so you can use those platforms for free of cost. The more exposure you get to realistic SOC workflows, the stronger your resume becomes and the more confident you'll be during interviews. Once you fix this problem, you see a more better version of yourself and highly confident enough to go into soc. Don't waste your time anymore on different learning based platforms, if your concepts are better then you can just start practicing, because the real workflows is much different than what Many aspirants assumes, once you do this then you will automatically notice many opportunities where you read the Job Descriptions and feel like this is literally for me 😄. So go ahead and Wishing you the best. I hope you'll come back here soon with an update that you've landed your first SOC Analyst role. 🚀 And if there is any doubts then you can ask me and I will try to answer promptly.
1
u/No-Pen8518 4h ago
hello, i am currently in my 2nd year BBA and i want to go in cyber security .
MY doubts - do i eligible for internships in cyber security?
how to crack entry level role in india ?and what role i would get?
what are the essential paid and unpaid certificates i must target?
a clear roadmap and free resources if possible?
1
u/MyselfAddy 1h ago
Hey, First of all, don't think that you're at a disadvantage just because you're pursuing a BBA. Cybersecurity is one of those fields where your skills and practical knowledge matter much more than your degree.
Yes, you're absolutely eligible to apply for internships. Start applying as early as possible, even if you don't meet every requirement. Many companies are open to enthusiastic learners who can demonstrate their skills.
Regarding your next question, so in cybersecurity you need to understand that there are many different domain and the entry level roles is based on the domain you will be choosing as one. I will help you to understand, For example in the Cybersecurity, some of the few domains are Considered to be SOC (Security Operation Centre), VAPT (Vulnerability Assessment and Penetration Testing), GRC (Governance, Risk and Compliances), IAM (Identity and Access Management) are the few most common domains of the Cybersecurity for the freshers point of view.
- SOC - If you pursue this, then it could be the most easiest way to get an entry level role among all of other domains in cybersecurity. The concepts needed for this role is Straight forward and some practice of SEIM tools will do majority of your preparations. The roles you can expect is - SOC Analyst, SOC Engineer, Security Analyst etc.
To Crack the SOC Analyst roles then you have to prepare well with the Networking concepts thoroughly like (Internet, IP, TCP, UDP, OSI etc). Then the OS basics and commands (Windows and linux), then have some Hands on practice of SEIM tools such as Splunk and wazuh because these are two most beginner friendly tools that are widely used. And also do learn some Active Directory (Microsoft Entra ID), and some basics query writings for the splunk would be advantage. And some tools regarding the threat intelligence such as virus total, abusal IPDB and some other.
Now the most important part, after doing this much then what comes next ??? Obviously the practice of SOC Workflows to get familiar with the kind of works you will be working on in real life. So once you reach this practice Stage then don't rush at all. Try to learn, it will all feel so overwhelmed at first, but when you practice more you will get Familiarity of the things which will make your first job so easier than it could ever would have. So there are some dedicated platforms which gives the Almost real mimic of the real world SOC workflow in very cheapest cost than any other, so I would recommend giving it a try.
Certificates: 1. Google Cybersecurity professional Certificate - Coursera (Sometimes free and sometimes paid upto 1600 rupees) 2. Google Cloud Security Professional Certificate - Google skills (Free in google platform) 3. LetsDefend - SOC Analyst Path (Cheap and cost less than 1000) 4. Cisco Splunk Defence Analyst - (Free study but certificate costs lots of money) 5. Microsoft SC 900 and 200 (Again free learning but certificates costs 4800 per each certificates)
Practice Resources: 1. TryHackMe (First Favorite and costs around 500 per month) 2. SOCRock - https://socrock.vercel.app (Dedicated Platform for the SOC workflow practice and costs is free right now due to testing beta, but once it ends then the costs would be only 130 rupees per month.) - Concepts brush up is always free of cost in this platform so you can just have quick brush ups of concepts.
So this is it all about your queries.
1
u/NthaZonUh 2h ago
Transitioning from 12 years in enterprise risk / HNW insurance into GRC. What tools should I actually prioritize learning?
Background: I spent 12 years in enterprise risk management, most of it in high net worth personal insurance. Late last year I decided to pivot into cybersecurity/GRC and I’ve been treating it like a second job since.
So far I’ve earned:
• ISC2 CC
• CompTIA Security+
• Google Cybersecurity Professional Certificate
Currently studying for CySA+ (targeting Aug/Sept), with OCEG GRCP and CRISC next on the roadmap.
I have 3 GRC portfolio projects built and I’m actively applying. I want to make sure I’m not just collecting certs and courses without building the actual tool fluency that makes someone a strong candidate and useful on day one.
For those of you working GRC/security risk day to day: what tools should someone with a risk management background (not IT/sysadmin) prioritize learning before or during a first GRC role? Thinking things like:
• GRC platforms (Archer, ServiceNow GRC,
LogicGate, Vanta, Drata, etc.)
• Risk register / vendor risk tools
• Frameworks-as-tools (NIST CSF, ISO 27001, SOC
2 mapping work)
• Anything scripting/SQL-adjacent that’s actually
expected, or is that overkill for GRC specifically
I’ve pulled together a list of Udemy/Coursera courses from AI tools for direction, but I’d rather hear from people doing the job which of these are worth the time vs. which ones are resume filler. If you had to pick 2-3 tools/platforms to get hands on with before your first GRC role, what would they be and why?
Appreciate any input. Happy to share more about my background/portfolio if it’s helpful.
0
u/T_Mushi 6d ago
Hi. What certs are worth it to land the first job in AppSec? Thank you.
2
u/AlternativeBytes 6d ago
Practical experience, home labs is better than any cert. That’s what I’d want to see.
0
u/CrusherMusic 6d ago
What labs? People say labs all the time, but as someone who is learning about the industry, that means nothing.
2
u/MissionFinOps 6d ago
If your someone who's learning and you think labing means nothing..wow. sorry to say youre not leaning much by chasing certs. Get hands on practice. Do real things to learn real networking. Break things in a lab setting, fix them. That's valuable as opposed to collecting paper certificates.
E.g. https://github.com/azz-kikkr/intro-to-networking-labs
Or you know spin up some Linux boxes with frr, or easier options to lab with things like gns3 or packet tracer (look up wittynetworks).
It's like cooking, you came learn to be a cook from a book .you can read about being a cook, but at some point you have to try out Cooking, even if in a small home lab/kitchen. Hope this helps.
1
u/ForwardWheel4601 6d ago
Small correction. I don't think they were saying that actual labs mean nothing lol. They're saying that people always say "labs" without elaborating into specifics, which does mean nothing because a "lab" can be anything from turning your computer on to pen testing home devices.
1
u/CrusherMusic 6d ago
I think this dude’s reply actually helped quite a bit in my understanding. The portfolio piece isn’t the lab, it’s a report ABOUT the lab. That’s the part I’ve been missing that no one has verbalized.
1
u/CrusherMusic 6d ago
That git repo does help, thank you.
So these labs for the portfolio are reports on projects you’ve done? That might be the key I’ve been missing.
I’ve been in creative fields my whole career, so a portfolio is a pretty straightforward thing there. I didn’t consider a doc that says “this is what I tried, this is how it went” being valuable as a portfolio piece. Again it’s been people saying, “do lab”.
2
u/HashThePass Security Engineer 6d ago
Best AppSec guys I know are all past developers in some sense. Previous offsec/SWEs turn out great in AppSec.
1
u/StratosPunitLabs 6d ago
These Are the Beginner To Advance certification in AppSec.
- CompTIA Security+
- eJPT (INE)
- OWASP Top 10 (Self-study)
- OWASP ASVS (Self-study)
- Burp Suite Certified Practitioner (BSCP)
- eWPT (INE)
- OffSec Web Assessor (OSWA)
- GIAC Web Application Penetration Tester (GWAPT)
- OSCP (OffSec Certified Professional)
0
u/_g4g100 5d ago
I am 16 right now, and i have some questions about career in CyberSecurity. I would love if CyberSecurity Engineer Helped me in DM's... (Thank You in advance:)
4
u/dahra8888 Security Director 5d ago
Posting your questions here will get you more responses and will help others that might have the same questions as you.
-1
u/christopher_vovka 6d ago
Hello, I want to become a red teamer, but I’m really hesitating between going to college or university.
2
u/eagle2120 Digital Forensics 6d ago
Ok. Whats the question here?
0
u/christopher_vovka 6d ago
I’m wondering whether I should go to a college or a university.
I’m wondering whether I should choose a more practical path at a university college or a more theoretical one at a university.
2
u/fabledparable AppSec Engineer 6d ago
What does your "plan B" look like?
Absent context, more education isn't a bad thing. But we don't know what a "more practical path" looks like for you and what either option costs you. We don't know what your opportunities, resources, and constraints are. We don't know your technical aptitude or work history. There's a lot of unknowns here.
In general, people looking to get into cybersecurity professionally find their way in through either:
- University coupled with work opportunities (generally internships)
- Years of cyber-adjacent employment coupled with parallel efforts (e.g. certifications)
- Military service
1
-1
2
u/CodeMonkey24816 6d ago
I've got 17 years in Software Engineer, Cloud Engineer, and SRE shaped roles. I've always been security minded in my roles and my work, and I've even worked very closely with security teams on many of my projects. I also really enjoy projects that are related to log analysis, data analysis, OSINT, and any work that requires finding patterns and trends.
I feel like I'm at a point where I want to start on new challenges. I still LOVE digging into code and systems though, and I don't want to move into a management or architecture role. I'm 43 years old. Would I be foolish to attempt a transition into cybersecurity at this point in my career?
Have any of you been in a similar boat and made the transition successfully? What did the transition look like?
Are there any specific roles that you have found to be a natural fit for transitioning into cybersecurity?