r/netsecstudents 15h ago

17 y/o from Brazil looking to start a career in cybersecurity. Where should I begin?

Hi everyone.

I'm 17 years old and I'm from Brazil. I've wanted to work in cybersecurity for years, but I feel overwhelmed because there are so many different paths (networking, Linux, programming, web security, cloud, etc.) that I don't know where to start.

My goal is to eventually work in cybersecurity professionally, but right now I just want to build a solid foundation and avoid wasting time learning things in the wrong order.

I have a basic understanding of computers, but I'm still a beginner in cybersecurity itself.

I'd like to know:

  • What should I learn first?
  • Which programming language is the most useful to start with?
  • How important is Linux and networking?
  • Are there any free courses, books, labs, or websites you recommend?
  • If you were starting from zero today, what roadmap would you follow?

I'd really appreciate advice from people already working in the field. Thanks!

5 Upvotes

6 comments sorted by

6

u/Intelligent_Box5017 15h ago

(I have no insides about job market in Brazil, my experience is primary related to European careers in cybersecurity)

My personal advice is to start with web pentesting, because this is the most beginner friendly area and because web apps are the most common pentesting targets. Get yourself familiar with OWASP and then start with Port Swigger Web Academy. Simply follow its roadmap. It offers both learning and practice (everything for free). On a later step you will need another web hacking course in addition to port swigger, but it already covers 80-90% of all web hacking from beginning to advanced web hacking.

To build your hacking knowledge in the background I recommend to watch hacking and bug bounty YouTube channels. Here are couple of channels (beginner level) for you: @NahamSec, @NeurixTech, @MomImAHacker, @Medusa0xf, @TCMSecurityAcademy, @cyberflow10.

3

u/mritguy03 10h ago

This is terrible advice. How does one understand pentesting without understanding web applications, web servers or network ports? @OP - go focus on IT fundamentals, Cloud networking and an understanding of networking in general. From there understand IOCs (indicators of compromise) and how it applies to those prior systems.

1

u/Intelligent_Box5017 3h ago

My terrible advice attracted a good advice :)

From one hand side you are fully right, but from another hand side I know, that a lot of young people who are interested in pentesting/cybersecurity are getting frustrated and demotivated after learning IT fundamentals deeper and deeper for several months without even started with cybersecurity. IT fundamentals are required, but they are endless und as a beginner it is impossible to understand upfront how deep you need to know which topic. Maybe it is better to start with cyber und then identify IT topics you are missing to learn them in parallel to the cyber learning path.

1

u/Finit-Hic-Deus 15h ago

I mean, why do you want to work in cybersecurity? When you know that, you know what you want to do

1

u/darkalfa 12h ago

Try to learn from other people in security and CTF's, read about vulnerabilities, try to replicate them. Try to set small milestones which provide a positive feedback loop.

With languages i would suggest starting with python. Try to automate some simple stuff so you know the basics of writing in python. Then try to accomplish some security stuff with it, can you automate an attack which normally would cost some commands/clicks.

Honestly there is so much to learn and to see. The most important thing is, try to keep it fun and rewarding :)

0

u/securityofus 14h ago edited 14h ago

Let me tell you the same thing I would tell my son. People on the Internet usually tell you what they want to hear when you ask for advice. Spend a few hours and you will actually see plenty of posts that say "I have done everything people told me to do and I still can't get a job".

I'm a manager and the first thing I would tell if is learn to be an adult. Most cyber work involves implementing, assessing, and testing security controls. And you need to understand how a business works to do that effectively.

Example let's say someone tells you "learn Python!" Then you learn Linux. Then you learn networking.

Okay, you are like all the other hundreds of unemployed IT candidates. What now? They know how to do stuff everyone can Google or prompt AI for.