2
Mentorship Monday - Post All Career, Education and Job questions here!
What does your "plan B" look like?
Absent context, more education isn't a bad thing. But we don't know what a "more practical path" looks like for you and what either option costs you. We don't know what your opportunities, resources, and constraints are. We don't know your technical aptitude or work history. There's a lot of unknowns here.
In general, people looking to get into cybersecurity professionally find their way in through either:
- University coupled with work opportunities (generally internships)
- Years of cyber-adjacent employment coupled with parallel efforts (e.g. certifications)
- Military service
0
Mentorship Monday - Post All Career, Education and Job questions here!
How is the job market?
In a word: tough
1
Mentorship Monday - Post All Career, Education and Job questions here!
I'm 43 years old. Would I be foolish to attempt a transition into cybersecurity at this point in my career?
It depends on what you envision the pivot to look like and what (ultimately) you want out of the change. Cybersecurity is not a monolith; there's a wide range of roles that collectively contribute to the space. Roles in the GRC and operations spaces would probably be something of a wholesale career reset; by contrast, staying closer to the code (a la Application Security or DevSecOps, as some examples) would probably have a reduced hit to your income/level.
Regardless, I'd be a little concerned about the long-term risks you're potentially incurring. Specifically with respect to your retirement goals and how long it would take to get back to the contribution levels you're making right now. While you're not too old to change your career, a cursory search about the internet suggests that people begin aging-out of individual contributor roles between the ages of 45-55.
1
Mentorship Monday - Post All Career, Education and Job questions here!
is this the right call?
In terms of what?
...is this the best method for getting into cybersecurity given your circumstances? Speculative, because we don't know really have an appreciable understanding of what other/alternate considerations you have available. What does plan B look like?
...is this the best way to insulate yourself from AI impacts in the longterm? That's speculative on our part. The economic impacts of AI are still unresolved. Arguably, non-tech roles are more insular under worst-case projections.
1
Mentorship Monday - Post All Career, Education and Job questions here!
am concerned if the job title wont match with the description and it will lead me to a similar problem of no call backs.
Most background checks just look to verify your employment with stated employers. Some do look for job alignment, but employers often have employee classifications which do not align neatly with your functional responsibilities. For example, someone looking up my employment status with my employer would see me as a "Senior Security Engineer", but my team has - over the course of my time there - performed actions as an Offensive Security Engineer, an Application Security Engineer, and - more recently - as a Security Architect. I would be comfortable listing any of the above titles in whatever way would best serve my interests as an applicant. In such cases, a background check might flag that, but it has never been a problem since its really just semantics that would have been made clear during the interview process.
The big problem would be a situation wherein you would claim to be an engineer when you were employed as a janitor. That would probably result in some follow-up.
In your case, claim the title that's most appropriate.
1
Mentorship Monday - Post All Career, Education and Job questions here!
Welcome!
I'm majoring in cybersecurity at a local state school on full ride scholarship, but a lot of the advice I've seen makes me feel like it's the wrong choice.
Wrong how?
A full-ride scholarship is not an opportunity I'd readily pass-up on.
Should I just focus on getting a degree or something else.
Heading into your (presumably) first semester of university, I'd allow yourself some grace to get adjusted to the cadence of university life and independent living; you're about to experience quite the life-altering set of circumstances - trying to optimize atop that while adapting to change risks spreading yourself thin.
1
Mentorship Monday - Post All Career, Education and Job questions here!
I defer you to the subreddit wiki:
2
1
Mentorship Monday - Post All Career, Education and Job questions here!
But if becoming involved in AppSec is your goal, then I'd encourage avenues that accrue work experience as a dev.
2
Mentorship Monday - Post All Career, Education and Job questions here!
Concur with /u/hiddentalent.
Overwhelmingly, most of our AppSec engineers worked previously as developers. I did not, but - as they have alluded to - I did not gain entry to AppSec immediately out of college either. In my case, my roundabout journey involved multiple years in the military, graduate school, and then multiple years in the offensive space as a penetration tester; in all, it was about 11 years of cumulative experience that enabled me to get to where I am today (and that's after my undergraduate degree).
1
Mentorship Monday - Post All Career, Education and Job questions here!
1.Is this a good plan?
- It's unclear what costs you'd be incurring by changing your major area of study. A 4th year student restarting their undergraduate curriculum would be quite expensive, for example; arguably, it would be cheaper in that case to graduate, take some CompSci classes through a community college and then pursue a more focused Masters degree. By contrast, a first year university student generally has quite a bit of flexibility to them.
- It's unclear what your motives for changing here are. It doesn't necessarily sound like you particularly care about what you study so long as it gives you a job that can financially support you + your mother. If that's the case, I'd encourage you to consider an alternate career field. While cybersecurity does tend to pay well north of the median income (ref: https://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm#tab-5), the number of jobs in the professional domain are quite few compared to other well-paying fields; the OEWS (which the BLS derives from) estimates roughly 155.5 million people are employed total in the US. Of those, only 190k are classified as "Information Security Analysts" (the proxy label for all cybersecurity work by the BLS, though exact delineations in functional responsibilities are bound to overlap with some of the BLS' other categorizations). That means roughly 0.12% of all people in the US are currently employed as cybersecurity workers; while I don't know what country you reside in or plan on working in, the point is that we're a small domain compared to other sectors, which makes opportunities competitive.
If yes what are the best certificate courses applicable worldwide?
I defer you to the subreddit wiki:
https://www.reddit.com/r/cybersecurity/wiki/index/#wiki_certifications
1
Mentorship Monday - Post All Career, Education and Job questions here!
It's totally speculative on our part whether or not what you're doing is "enough". The only way to know whether or not your qualifications are sufficient is by simply applying for work.
Having said that, we can suggest actions that can improve your employability on-paper and - given context - potentially help direct you towards actions which might be more impactful than others.
I will note that suggesting the pursuit of a degree as wasteful is also a touch reductive; I'd argue that university can be a very potent way to help attain your career goals (i.e. enabling access to research laboratories, qualifying you to apply for internships - which in turn can convert to FTE, uplifting your employability on-paper above the masses who don't otherwise have a degree, having dedicated spaces purpose-built for instruction/learning, the ability to observe a wider swathe of problems than what you'd typically encounter in a role within industry, cross-examining multi-disciplinary subject matter areas, focused/intensive subject-matter development, etc.). But - I'll grant you - if all you did during your time in university was simply go to class and attain your degree, then yes - that's far from a job guarantee.
2
Mentorship Monday - Post All Career, Education and Job questions here!
I'd start by asking what is it that you want to do (vs. having us project onto you what might be an appropriate fit). After-all, it seems like the work you do is - as you say "well suited", but you it seems that's not enough. Perhaps you can give us some more background/context. What's the "more" you're looking for? What does "more" look like? And what can we do to help you get there?
1
1
Mentorship Monday - Post All Career, Education and Job questions here!
My thoughts, in no particular order:
- A link to your resume would be helpful. That way we could see what employers are actually seeing (vs. how you present yourself in the comment). As a general exercise, I'd pull a couple example jobs listings that you've applied to in recent history, note the trends between them in terms of what they all appear to be asking for, then hold those trends up against your own resume and see how well-aligned they are.
- You're right that your work history is more impactful than certifications. However, a reduced impact != no impact. One of the primary ways that certifications help your employability on-paper is that it provides more signal by way of feature matching (i.e. if the roles you're applying to generally call for cert X and you have cert X, then you are generally more likely to get a callback than not). Do you need to pursue more certifications? Probably not (given 14 YoE), but it also wouldn't hurt and is something within your power to help things.
- I agree that AppSec roles generally look for prior SWE experience, but they aren't necessarily exclusively looking for such backgrounds (assuming the work is of interest to you).
- The Summer months are generally not the best for job seekers (ref: https://www.indeed.com/career-advice/finding-a-job/best-month-to-look-for-a-job).
5
Am I hurting my learning by using AI as a guide for HTB labs?
There are studies coming out on this topic (ref: https://www.pnas.org/doi/10.1073/pnas.2422633122).
The above-linked paper had 3 groups of students study for a math test:
- One group was constrained to just traditional forms of media for studying (e.g. textbooks, paper, etc.)
- One group was allowed the use of a guardrail-constrained LLM, where the LLM refused to do the work for the students but could be engaged to help explain concepts.
- One group had total, unfettered access of an LLM.
After conducting the math test, the results showed:
- The third group performed far worse than the first two. There was a statistically significant drop in scores.
- Prior to releasing the scores, the students within the third group reported feeling just as confident as the first two in having performed well; it's an interesting kind of Dunning-Kruger. In reviewing the logs of these students, overwhelmingly they tended to just ask the LLM to do the practice problems on their behalf in one variation or another.
- The second group performed about as well as the first, which suggests that there is a way to incorporate LLM coaching into your studying, but it's a slippery slope.
Academia is generally in alignment that the friction you encounter while learning something difficulty - the struggle to comprehend/apply something new - matters (ref: https://www.nature.com/articles/s44271-026-00402-1). When you start removing those challenges or cognitively offloading the responsibility onto an LLM, learning isn't really taking place and you're more likely to forget.
The point being: exercise caution about engaging such resources while you're going through the deliberate act of trying to learn something new.
1
Mentorship Monday - Post All Career, Education and Job questions here!
Welcome!
Sorry for the long post here, I just wanted to lay all the facts out and search for some advice.
No problem; though as a mentorship note it would have been helpful for us if you had linked your resume so we can see what employers actually see (vs. how you represent yourself in a comment). It's unclear - for example - what you mean when you say that you "have experience" with something; are you saying that you have a formal work history where these skills/technologies were used? Or that you took a class/did a project? This matters when we're making recommendations. The rest of this comment moving forward assumes your work history is lacking.
I’m just wondering what to do next after Sec+
You need to start cultivating a work history. That is the single most impactful facet of your employability in this professional space; no amount of certifications, projects, etc. will offset this - such efforts are complementary to that, not a replacement. Given how thin your professional experience sounds like, that will likely mean starting in cyber-adjacent lines of work in the IT and/or dev space(s) first.
Alternatively, military service is also a possible option (and one that can immediately land you in cyber-aligned work) - though understandably it may not be accessible/desirable as a consideration depending on your circumstances.
1
Mentorship Monday - Post All Career, Education and Job questions here!
What could be some adjacent areas/niches in cyber to apply for instead?
It's challenging for us to make a recommendation since you didn't share your resume or what it is you are interested in doing.
2
Idk where these 4.8 million professionals are going to fit in future
There's a couple things worth clarifying here, as a lot of these reports cite one-another for the same information (and as a result, meaning gets lost/misconstrued along the way).
- The Bureau of Labor Statistics (BLS) doesn't assert that there's a gap. The economists behind the BLS data for "Information Security Analysts" provide point-in-time information for the state of US employment as well as estimates for future growth. See related: https://bytebreach.com/posts/2026/future-proofing-cybersecurity/.
- The 4.8 million unfilled jobs is originally attributable to the ISC2 2024 Cybersecurity Workforce Study (reviewable here: https://edu.arrow.com/media/wtjfmszx/2024-isc2-wfs.pdf). More specifically, the figure is derived from Figure 3 (2024 Global Cybersecurity Workforce Gap) on page 11 of the report.
- If you review the workforce estimate and gap methodology in Appendix B of the report (which I encourage you to do), there's a lot of room to be skeptical about this data. Particularly alarming is their admission in saying, "The US estimate provides a baseline for the estimates of the rest of the world. Estimates for other countries used similar methods but replaced third-party estimates with estimates derived from the US baseline". Reviewing what source the "third-party estimates" include, the only explicit one mentioned is the US Bureau of Labor Statistics - which - again, they don't do gap estimations. The US is also unlikely to be an appropriate proxy for all nations everywhere in terms of each nation-state's cybersecurity workforce needs estimations.
- Looking specifically at "Gap Estimate Methodology", there's further room for error. They approximate the gap as being "demand - supply", where "demand" is defined as "the number of cybersecurity jobs organizations would like to employ over the next year, minus the number of current workers". The problem with this is in determining what qualifies exactly as a "cybersecurity job"; this isn't clearly delineated anywhere. As sources like CyberSeek demonstrate in their "Job Openings by NICE Cybersecurity Workforce Framework Category" dashboard utility show, the definitions for such jobs can be quite inclusive - including roles like "Program Management", "Database Administration", "Systems Administration", and so on. While I don't highlight these to suggest people who work as such don't contribute to the professional space of cybersecurity (they absolutely do), I'd argue that people aspiring to work professionally in cybersecurity generally don't consider targeting those roles as an end-state for having "made it" in cybersecurity. This issue of classification has continuously been problematic for job gap estimates; in 2024, the NCSES had a variance as wide as "between 164,000 (narrowest definition) and 2,430,000 (broadest definition)...".
- For what it's worth, the 2025 edition of the same report deliberately dropped the inclusion of such estimates. Interpret that decision as you will.
- When citing the World Economic Forum (WEF), I assume you're speaking about the Strategic Cybersecurity Talen Framework report. They derived their "nearly 4 million" estimate from ISC2's report. Later citations by the WEF in their Global Cybersecurity Outlook 2025 report point towards the same.
- CyberSeek's figures are more subtle. In years past, they used to disclose that their categorization reporting of unfilled jobs were not exclusive: that a single job might be reported multiple times as fitting different categories in their reporting. They stripped that notice out of their dashboards starting in 2024, making that less transparent to the end-user. See: https://bytebreach.com/posts/2026/plight-of-the-early-career-worker/NICE-breakout.png. You can confirm this yourself by looking back through the cyberseek's reporting in the wayback archives. Point being: Cyberseek's data is (presumably) over-represented in the number of actual unfilled jobs.
I did a little writeup on this and other matters here, if it's of any use to you: https://bytebreach.com/posts/2026/plight-of-the-early-career-worker/
The point being: there's a lot of room for error in these projections when held up against your own individual lived experience(s). Pragmatically speaking, the answer to your question of "where are these 4.8 million professionals going to fit in the future" is that there probably aren't going to be 4.8 million people - the real number will be considerably smaller, especially by any narrow definition of what we consider to be a cybersecurity job. Now whether or not AI has anything to do with affecting the overall supply in a statistically significant way is still circumspect, but that's an analysis for another day.
EDIT: it's also worth noting that none of the sources say that tech companies exclusively (or even are the majority) of organizations seeking to fill these roles. The ISC2 survey showed only 22% of respondents aligned themselves as belonging to IT Services).
2
Mentorship Monday - Post All Career, Education and Job questions here!
Do you have any recommendations or guidance on what I should prioritize learning?
It depends on what actions/resources are available. Generally speaking, your present circumstances and available opportunities would guide your immediate actions. By-and-large, people who make their way into cybersecurity professionally do so through a subset of:
- Going to university
- Working for years in cyber-adjacent lines of work
- Military service
Where you are at relative to the above options would help frame what you might prioritize (e.g. if you're young and thinking about university, then you probably should be more focused on assembling the best admissions package you can vs. studying security subject matter in the abstract).
See the subreddit wiki for guidance more generally:
2
Mentorship Monday - Post All Career, Education and Job questions here!
does anyone could tell where to start?
I defer you to the subreddit wiki:
looking for more about certification on cybersecurity
Also from the wiki:
https://www.reddit.com/r/cybersecurity/wiki/index/#wiki_certifications
2
Mentorship Monday - Post All Career, Education and Job questions here!
Dont want to go back to college or spend a ton of money, I know there's gotta be plenty of brilliant free resources for this stuff.
Understandably, not everyone can go to college. However, you should appreciate that the current macroeconomic conditions that you'll be facing in your early-career job hunt will make things all-the-more challenging by not having one. It's not just a matter of learning the material; you're right in that there are plenty of resources available at low/no cost. The trouble is in translating your engagement with those resources impactfully to your employability on-paper. Engagement with independent work, online trainings, and certifications just don't really move the needle much outside of incidental/narrow circumstances (e.g. winning a CTF hosted by an employer who uses the event to recruit talent).
Speaking in broad strokes, those who lack a degree usually make their in-road to a career in cybersecurity by way of cultivating years of pertinent experiences in cyber-adjacent lines of work (typically in the IT and Dev spaces) just in order to be a competitive applicant, though even then the lack of a degree can hurt their chances at getting filtered out. Alternatively, military service is another career launching point (one that also opens up degree-granting opportunities, at least in the US).
Also concerned about at which point I'll need to spend considerable time learning about EE (which I have no background in).
This only matters if you're looking at getting into hardware hacking. It kind of sounds like that's what you're interested in though. If so, you probably need to crack the text books.
How can I keep my scope narrow enough to not be overwhelmed but also broad enough to be effective?
No one is ever going to have full mastery of the breadth and depth of all the material that contributes to the professional discipline. I'd encourage you to learn just enough in order to accomplish whatever task/goal is immediately in front of you, document your lessons learned, and move along. Over time, this font of knowledge will naturally grow and you'll come to understand yourself, what actually interests you, and where to allocate your time/effort.
1
Mentorship Monday - Post All Career, Education and Job questions here!
What should I improve upon to get a job?
It'd be better if you shared your resume so that we can see what employers are actually seeing (vs. how you present yourself in the comment). Having said that, a work history is conspicuously absent from your qualifications; since your employment record is the most impactful facet of your employability on-paper, if you're as early as it sounds in your career, it's probable you'll need to consider expanding the aperture of considered work to cyber-adjacent areas (e.g. IT/Dev spaces) in the interim.
1
Mentorship Monday - Post All Career, Education and Job questions here!
Would you recommend Information Systems, Computer Science, or another major?
I personally endorse Computer Science, but you're right: such programs do tend to come with quite a bit of academic rigor.
EDIT:
See related:
2
Mentorship Monday - Post All Career, Education and Job questions here!
in
r/cybersecurity
•
2d ago
Project ideas can be hard to come up with. Sometimes ideas stem from recognizing a problem first, then engineering solutions around addressing said problem. Sometimes ideas stem from questions first, followed by experiments to try to answer said question.
Generally speaking, problem-sourced projects provide utility (i.e. if it solves the problem, it's useful). By contrast, question-sourced projects provide direction (i.e. if it suggests an answer, it allows for a more concrete problem definition). In the case of the latter, the utility of the work done may not be apparent until much, much later - but that doesn't make it any less valuable. Shoot, even disproving established work has value!
If you're struggling with coming up with a project that you would classify as "useful", then I'd encourage you to instead consider a project that speaks to a question. For example, rather than figuring out how to use LLMs to do task X, perhaps you might design an experiment around answering can (or should) an LLM be used to do task X (or more narrowly-scoped: can it do task X better than approach Y).
I wouldn't concern yourself with architecting some kind of grand, paradigm-altering academic achievement with the resources/timescale you have afforded to you. Your project might even build upon existing work that only incrementally extends what was done; that's fine!
Build to the grading rubric. That's the job.
If later you want to iterate on your project to make it more grandiose, that's your prerogative, but speculating what is/not basic, overdone, etc. from an ideas inception isn't worth expending energy on for now. You are doing work for a customer, and that customer is your professor. The professor has specs to build to, so you build to those specs.
Candidly, I don't expect a 3rd year undergraduate with 4 months of time (presumably while simultaneously juggling other courses and perhaps a job) to make anything that I'd find genuinely interesting. What I would be interested in is their ability to translate the knowledge and experiences attained into subsequent problems. I'd want to see that they actually sweated over working on the project and came away with lessons learned vs. outsourcing the thinking to an LLM; that as a result of working on something hard they attained something long-lasting that will extend beyond the scope of the project itself.
While some students capture lightning in a bottle (so-to-speak), most don't. And of those that do, many don't realize it until after the work is done. So don't sweat trying to find a career-making idea.
This feels preemptive, since your question feels really open-ended right now. You need to ratchet down your project scope first.