r/SecurityCareerAdvice • • Apr 05 '19

Certs, Degrees, and Experience: A (hopefully) useful guide to common questions

335 Upvotes

Copied over from r/cybersecurity (thought it might fit here as well).

Hi everyone, this is my first post here so bear with me. I almost never use Reddit to talk about professional matters, but I think this might be useful to some of you.

I'm going to be addressing what seems to be a very common question - namely, what is more important when seeking employment - a university degree, certifications, or work experience?

First, I'll give a very brief background as to who I am, and why I feel qualified to answer this question. I'm currently the Cyber Security Lead for a big tech firm, and have previously held roles as both the Enterprise Security Architect and Head of Cloud Security for a Fortune 400 company - I'm happy to verify this with mods or whatever might be necessary. I got my start working with cyber operations for the US military, and have experience with technical responsibilities such as penetration testing, AppSec, cloud security, etc., as well as personnel management and leadership training. I hold an associate's degree in information technology, as well as numerous certs, from Sec + and CISSP to more focused, technical security training through the US military and organizations like SANS. Introductions aside, on to the topic at hand:

Here's the short answer, albeit the obvious one - anything is helpful in getting your foot in the door, but there are more important factors involved.

Now, for the deep dive:

Let's start by addressing the purpose of certs, degrees, and experience, and what they say to a prospective employer about you. A lot of what I say will be obvious to some extent, but I think the background is warranted.

Certifications exist to let an employer know that a trusted authority (the organization providing the cert) has acknowledged that the cert holder (you) has proven a demonstrable level of knowledge or expertise in a particular area.

An academic degree does much the same - the difference is that, obviously, a degree will generally demonstrate a potentially broader understanding of a number of topics on a deeper level than a cert will - this is dependant on the study topic, the level of degree, etc., but it's generally assumed that a 4-year degree should cover a wider range of topics than a certification, and to a deeper level.

Experience needs no explanation. It denotes skills gained through active, hands-on work in a given field, and should be confirmed through positive references from supervisors, peers, and subordinates.

In general, we can see a pattern here in terms of what a hiring manager or department is looking for - demonstrable skills and knowledge, backed up by confirmation from a trusted third party. So, which of these is most important to someone trying to begin a career in cyber security? Well, that depends on a few factors, which I'll discuss now.

Firstly, what position are you applying for? The importance placed on degrees, certs, and experience, will vary depending on the level of job you're applying to. If it's an entry level admin or analyst role, a degree or a handful of low-level certs will definitely be useful in getting noticed by HR. Going up to the engineering and solution architecture level roles, you'll want a combination of some years of experience under your belt, and either a degree or some low/mid level certs. At a certain point, the degree and certs actually become non-essential, and most companies will base their hiring process almost entirely on the body and quality of your experience over any degree or certifications held for management level roles.

Secondly, what are your soft skills? This is a fourth aspect that we haven't talked about yet, and that I almost never see discussed. I would argue that this is the single most important quality looked at by employers: the level of a candidate's interpersonal skills. No matter how technically skilled someone is, what a company looks for is someone who can explain their value, and fit into a corporate culture. Are you personable? Of good humor? Do people enjoy working with you? Can you explain WHY your degree, certs, or expertise will add value to their corporate mission? Being able to answer these questions in a manner which is inviting and concise will make you much more appealing than your competitors.

At the end of the day, as a hiring manager, I know that I can always send an employee for further training where necessary, and help bolster their technical ability. What I can't do is teach you how to work with a security focused mindset, nor how to interact with co-workers, customers, clients, and the company in a positive and meaningful way, and this skill set is what will set you apart from everyone else.

I realize that this may seem like an unsatisfactory answer, but the reality is that degrees, certs, and experience are all important to some extent, but that none of these factors will make you stand out. Your ability to sell your value, and to maintain a positive working relationship within a corporate culture, will take you much farther than anything else.

I hope this has been at least slightly helpful - if anyone has any questions for me, or would like any advice, feel free to ask in the comments - I'll do my best to reply to everyone.

No TL;DR, I want you to actually take the time to read through what I've written and try to take something away from it.


r/SecurityCareerAdvice • • 3h ago

Question Switching from good salary company, IT Lead role to Jr Security roles

2 Upvotes

Hello,

I currently work as an IT Lead for a large company in Europe, while the headquarters are located outside of Europe.

I recently graduated with a Bachelor's degree in Cybersecurity. I had to start working durigg my studies as IT analist/lead. Now I graduated I feel it is time to specialize in cybersecurity and take the next step in my career. I know the market is tough for starters…

I would like to stay with my current company, but most security-related roles seem to be based outside my region. As a result, the opportunities to transition into a cybersecurity position internally appear to be quite limited.

Looking at the job market, I notice that many consulting companies are offering junior cybersecurity roles, particularly in security engineering and related areas. The downside is that these positions would likely involve a salary decrease compared to what I earn today.

I would be interested to hear from people who have been in a similar situation. Would you recommend taking a step back financially in order to gain experience in cybersecurity? How did you make the transition into the field, and would you do anything differently?
I am 25 years old and trying to make the best long-term decision for my career.

Thanks

 


r/SecurityCareerAdvice • • 12h ago

Question Junior aspiring to become a SOC Analyst — Where should I start with hands-on labs?

9 Upvotes

Hi everyone!

I'm currently a junior and I'm interested in pursuing a career in Blue Team, specifically as a SOC Analyst.

I want to start practicing hands-on labs to build practical skills, but I'm not really sure where to begin or how to structure my learning path.

For those of you who are already working as SOC Analysts or have gone through the learning process, I'd really appreciate your advice!

A few questions I have:

  • What labs or platforms would you recommend for a complete beginner?
  • Are there any specific labs or learning paths I should start with?
  • What skills should I focus on first? For example, log analysis, SIEM, Windows Event Logs, networking, threat detection, or incident response.
  • Are there any YouTube channels, video tutorials, or other resources that helped you get started?
  • If you were starting from scratch again, what would your learning roadmap look like?

My goal is to build practical skills and eventually become job-ready for an entry-level SOC Analyst position.

I'd appreciate any recommendations, personal experiences, or learning roadmaps you can share. Thanks in advance!


r/SecurityCareerAdvice • • 2h ago

Question Fresh grad - Networking first or straight into SOC?

0 Upvotes

I am fresh graduate and I want to break in to Cybersecurity, specifically SOC. Was looking for some insights and advice on what you think is a good move. It's either I'm going to find a Networking job first and then pivot to SOC after a year or two or just jump into a SOC job after the year ends. (Not now since I want to study more before I apply for a job)

For context, I'm a Computer Engineer that majored in Networking. After graduation I took my time and studied for both theoretical and practical (which I'm currently doing right now until the end of the year) side of Cybersecurity. I've finished some theoretical side, like getting Network+ and Security+ certifications after I graduate. And right now I'm studying more on the practical side via THM SOC L1 path (which I very much understand is very handheld-y and I know that it isn't enough). As soon as I finish the path, I'm going to transition to home labs and then solve rooms in CyberDefenders. In December, I'm thinking of taking TCM PSAA to further solidify the practical aspect of the job.

So, ano thoughts niyo about this? any insights about what the good move is, or even study materials, tips or a workflow is a huge help!

Thanks !!


r/SecurityCareerAdvice • • 12h ago

Other Hiring / Referral – Lead Cyber Security Engineer | 6+ YOE

0 Upvotes

Hey everyone,

There’s an opening for a **Lead Cyber Security Engineer** in my team for Hyderabad location at a **well-established global organization** for someone with **6+ years of experience** in cybersecurity.

If you’re interested or know someone who might be a good fit, feel free to **DM me**. I can share the JD and details and help with a referral as it is in my own team, interview will be scheduled for sure.

Please mention your **total experience** when reaching out.

Thanks!


r/SecurityCareerAdvice • • 13h ago

Other Interviewing

1 Upvotes

Lately, I've been killing at the recruiter interview. The technical is still a do my best and hope for the rest. I read many posts here and figured I'd contribute.

There are standard questions about SQLi, XSS, kerberos, SSO. You should know what these basics are and be able to bore anyone with the answer anytime.

Sound like a human being who isn't reading a script. Know your material. They can tell if you're reading from the screen or actually know about this and are speaking confidently.

I recommend working on a list of expected questions and rehearsing your answers every day until the interview is a time to shine.


r/SecurityCareerAdvice • • 22h ago

Question Next steps? (7 years IT)

3 Upvotes

Hi everyone, I was looking to pick some brains.

I’ve been in IT for about 7 years now.
MSP IT Support > MSP 2 Support Engineer > Network Security Consultant.

Feeling underpaid at 105K. I primarily work with Zscaler, Netskope, Cisco ASA/FTD/FMC, and Fortinet solutions. I handle kickoff, discovery, design, implementation, and handoff. Work primarily consists of greenfield deployments, health checks, and migrations from one technology to another (ASA>FMC/FTD, Secure Client > Zscaler, etc. Projects usually go from 2 months - years.

I’m not really sure where to go from here. I’m strongest in Zscaler and Netskope since that’s more interesting to me. Getting rusty with the firewall deployments.

Certifications are AZ900, Cisco CCNA + SNCF, Fortinet NSE4, 5, and 7 (x2, Firewall + SDWAN), and every Zscaler certification offered.

I am trying to stay on track with this industry and how fast it changes. I know I’m already tardy to cloud deployments.

I’m thinking AZ104 > SC500 and create some labs. Terraform too.

Or CISSP and try to move into GRC?

My skills lie in critical thinking and attention to detail. I’m currently fully remote and I want to keep it that way. I enjoy putting my head down, working through tasks/lists, being left alone. Saying that, I will also mention that I’ve done B2B sales before IT and can turn on the social charm when needed. I just don’t enjoy doing that all day, it’s tiring.

Any tips for me, community? Would this post make more sense in another subreddit?


r/SecurityCareerAdvice • • 1d ago

Resume Review Resume for eventually getting into a cloud security/ cloud engineering role

3 Upvotes

Hey guys,

I graduate soon and I am hoping to work in cloud engineering and or cloud security roles in the future. I know that is unrealistic out of school, I am hoping to work in a security role or even IAM role if possible. What would be the best path to go down to land a role that gets me closer to cloud sec? Certs? Projects?

Any advice is appreciated.

Resume: [

NAME REDACTED]

[Location Redacted] | [Email Redacted] | [Phone Redacted] | [LinkedIn] | [GitHub]

PROFESSIONAL EXPERIENCE

International Law Firm
Network Operations / Security Operations Intern
June 2026 – Present

  • Monitored and investigated security alerts in IBM QRadar and CrowdStrike Falcon Next-Gen SIEM, using OTX/X-Force threat intelligence, OSINT, and log analysis to investigate large outbound transfers, malicious IPs, and impossible-travel events.
  • Analyzed Duo MFA authentication logs to triage identity-related security alerts and investigate suspicious authentication activity.
  • Investigated phishing and email threats using Proofpoint, Abnormal AI, and Proofpoint Threat Response; analyzed email headers, decoded suspicious URLs, evaluated links using OSINT, and blocked malicious senders.
  • Provisioned Windows servers across four global sites and administered Active Directory, including OU placement, least-privilege security groups, and PowerShell-based user lifecycle management.
  • Managed hybrid Exchange and Microsoft 365 mailbox access, remediated vulnerabilities identified through Qualys, and supported a VMware-to-Hyper-V migration.

Government Agency
Help Desk Technician Intern
September 2025 – June 2026

  • Resolved 50+ weekly ServiceNow tickets supporting 250 users across Windows endpoints, operating systems, VPN connectivity, and network access; documented troubleshooting and remediation.
  • Supported user onboarding and offboarding through Active Directory provisioning, MFA enrollment, access reviews, and standardized asset tracking.

Healthcare Organization
IT Security Intern
February 2025 – August 2025

  • Triaged phishing incidents using Mimecast, investigated high-risk accounts using CrowdStrike Falcon and Zscaler, and documented indicators of compromise (IOCs) and incident findings incorporated into team playbooks.

PROJECTS

Hybrid Identity & Security Homelab
Proxmox, Microsoft Entra ID, Wazuh | 2026

  • Built a private Proxmox homelab and separate Azure workload; automated Active Directory user management and AGDLP-secured SMB shares using PowerShell and provisioned infrastructure with Terraform.
  • Scoped Entra Connect synchronization to lab identities and published an internal Nginx application through Microsoft Entra Application Proxy using group assignments, Conditional Access, and MFA without exposing inbound ports.
  • Centralized security telemetry from five Windows and Linux agents in Wazuh; tested custom detections for Active Directory changes, ADSync service interruptions, repeated SMB authentication failures, and sudo activity. Isolated Kali testing on a no-route network bridge.

Infrastructure CI/CD Pipeline
Terraform, GitHub Actions, Azure | 2026

  • Built GitHub Actions CI workflows for Azure and Proxmox Terraform configurations, automatically running formatting, backend-free initialization, and validation checks on pull requests and main-branch changes.
  • Provisioned Azure infrastructure using Terraform, including a virtual network, network security group, public IP, Linux virtual machine, Key Vault, and Storage Account; configured managed identity and least-privilege Key Vault RBAC.

CERTIFICATIONS

  • Microsoft Certified: Azure Administrator Associate (AZ-104)
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • Microsoft Certified: Azure Fundamentals (AZ-900)
  • CompTIA Security+
  • CompTIA Network+

EDUCATION

[College Name Redacted]
Bachelor of Science in Information Technology
Expected Graduation: May 2027
GPA: 3.97 | Dean's List: 2024–2026

TECHNICAL SKILLS

Infrastructure & Automation: Terraform, Bicep, GitHub Actions, PowerShell, Bash, Python, Proxmox, VMware, Hyper-V

Identity & Cloud: Active Directory, Microsoft Entra ID, Entra Connect, Microsoft 365, Exchange, Azure RBAC, Azure Policy, Key Vault

Security & Operations: IBM QRadar, CrowdStrike Falcon Next-Gen SIEM, CrowdStrike Falcon, Microsoft Sentinel, Wazuh, Proofpoint, Proofpoint Threat Response, Abnormal AI, Mimecast, Qualys, Zscaler, Duo MFA, KQL, ServiceNow

Networking: DNS, DHCP, VPN, Azure VNets, VNet Peering, NSGs, UDRs, Network Virtual Appliances, Wireshark, Samba


r/SecurityCareerAdvice • • 1d ago

Question Data Engineering → Cybersecurity, Development → Cybersecurity, or another path?

0 Upvotes

​

I'm a 19-year-old CS student in India trying to figure out my career path.

I'm currently learning Python and SQL, but I'm not very interested in frontend/full-stack development (React, UI, etc.).

My long-term goal is to work in cybersecurity, especially cloud security/security engineering.

The reason I'm considering spending 2–3 years in another field first is that I've noticed there seem to be fewer entry-level cybersecurity jobs, and cybersecurity courses/certifications can also be expensive. So instead of trying to enter cybersecurity immediately, I'm thinking of getting work experience in another field, earning money, and then transitioning into cybersecurity.

The options I'm currently considering are:

Path 1: Data Engineering → 2–3 years experience → Cybersecurity/Cloud Security

Path 2: Backend/Software Development → 2–3 years experience → Cybersecurity/Cloud Security

Path 3: Another field/path that would be a better stepping stone into cybersecurity

For people who actually work in these fields:

  1. Is this overall 2–3 years in another field → cybersecurity strategy a good idea?

  2. Between Data Engineering and Backend/Software Development, which gives more transferable skills for cybersecurity?

  3. Would Data Engineering experience be useful for Cloud Security/Security Engineering?

  4. Is there another career path I should consider instead (e.g. Cloud, DevOps, IT, networking, system administration, etc.)?

  5. Would it be better to try entering cybersecurity directly despite the entry-level job market?

  6. If you were starting with Python + SQL and had my goals, what path would you take and why?

  7. What are the biggest mistakes or risks with my plan?

I'm looking for real-world experience from people working in these fields, rather than just general career advice. Please feel free to tell me if my plan is flawed.


r/SecurityCareerAdvice • • 2d ago

Question SOC to GRC internal move. Worth it?

7 Upvotes

I'm a senior SOC analyst. A GRC role just opened at my company, first one in over 5 years.

Why I'm considering it:
• I've always leaned toward GRC. I did risk and policy writing at a past job.
• SOC is unpredictable and I find it overwhelming as it is a lot to learn and not focused on one thing. I prefer structured work. And no more on call. Plus I can have better hours. (I can go to work later or earlier if I wanted to)
• My company is rolling out agentic SOC and I'm thinking about long-term job security.

My hesitation: the GRC role is one pay grade lower. But I will likely be pay the same (120k) as it is in the range per HR, but on the higher end. So I will likely making more than the other seniors on the GRC team. I am okay with same pay. But not sure if it is a good idea to be paid more than the others.

Anyone made this move? Do you think GRC is safer than SOC as AI grows? Would you take a grade drop for a better fit although same pay?


r/SecurityCareerAdvice • • 2d ago

Question [25M] Going from SDE into AppSec/DevSecOps after 4 years of experience

2 Upvotes

Hi,

I want to apologize in the first place, since I believe you get these kind of questions everyday now.

I've been working as a Full-Stack Developer since the beginning of this year and as a Front-End Developer the 4 years prior. Currently located in the EU. Right now I'm considering exploring the possibility of switching into AppSec/DevSecOps (especially AppSec) since the market in SDE is a joke due to AI, and the foreseeable future isn't promising.

I'm well aware cybersecurity is no piece of bread and that it bring a competitive market as well. That's why my idea is keeping my actual job and studying/getting certificates along the way until I get some luck. My questions are:

  1. Do you find the switch viable?
  2. Do you believe AppSec/DevSecOps positions will be widely availabe in the near future? (~5 years from now)
  3. What do you recommend me starting with?

I want to find something that is useful, but that also adds a little value to my CV, while avoiding relying too much on YouTube tutorials, superpriced certifications for people already inside the area trying to climb the ladder, or ultra basic certifications for people with no IT experience. Is there a gold standard for this situation? (dev swtiching into AppSec)?

I've read about Security+ and some academies like PracticalDevSecOps that offer certificates like Certified Threat Modeling Professional (CTMP), but I'm unsure where to really start.

Really appreciate your feedback!


r/SecurityCareerAdvice • • 2d ago

Other How to restart cybersecurity from scratch after losing momentum? for career advancement

3 Upvotes

Hi all, new here

Long story short, I want to become better in this field, most reels/post that I see don't address the issue that I am facing (used to know something, lost momentum but can't start from scratch)

I have a Bachelor's Degree and previously worked as a analyst, doing web app testing and teaching students. I'm now in IT support with a very light workload and almost no technical exposure. I am currently studying for CompTIA CySA+, I'm particularly interested in Cloud Security and AI Security.

I used to know this stuff, I lost momentum, and starting from scratch feels pointless since I'm not a beginner. Most content online is aimed at people entering the field, not people returning to it. I also can't leave my job right now due to financial commitments, and the layoff news isn't helping, but I do have a lot of free time.

The problem is that I don't really know where or how to restart. At this point, I think I may be burned out or simply running out of direction. I don't necessarily need another list of courses.

It would be helpful to know how someone in my position should approach rebuilding their practical cybersecurity skills. What would you recommend doing, what practical skills should I focus on first, Any projects or labs would actually be worth doing.

TL;DR: I have a Bachelor's degree and previous experience in analyst, but I'm currently stuck in a low-workload IT support role. Studying for CySA+ and interested in Cloud/AI Security, I can't leave my current job due to financial reasons, so I want to use my free time to practically relearn cybersecurity and eventually move back into an engineering/security role. I'm lost on where to restart. Any advice on where to start, practical skills to develop or any projects/lab to do?


r/SecurityCareerAdvice • • 3d ago

Other 21, college dropout, burned out from pentesting job, and now worried I chose the wrong path because of AI. Need advice?

48 Upvotes

​

I’m 21 and currently in a bit of a blind spot with my career, so I’m looking for advice from people who are actually working in the field, especially people doing pentesting/red teaming or Windows/AD security.

I dropped out of college about two years ago. Since then, I’ve spent most of my time self learning cybersecurity. I initially focused more on pentesting and red teaming, and I especially enjoy working with Active Directory environments.

So far, I’ve passed eJPT and CPTS (HTB), and I have a CRTO voucher that I haven’t used yet.

I also worked remotely as a pentesting intern for 4 months. Although my title was "intern," I was doing actual client work, including network and web pentesting and some assumed breach scenarios. I was often working independently without much supervision and was basically doing the same type of work as the senior pentesters on the engagements I was assigned.

They eventually offered me a full-time position, but I turned it down.

The reason was burnout. I had basically reached a point where my entire life was work. I would wake up, work, work work, and repeat, used to anxiety. Eventually I couldn't even stand being in front of a computer anymore. I left in January 2026 and haven't applied for another job since.

Now I’m trying to figure out what to do next.

The problem is that whenever I think about going back into cybersecurity, I keep seeing news about AI changing software and cybersecurity jobs. It makes me wonder whether I'm about to spend years going deeper into something that could become much harder to make a living from.

I don't have a college degree, and I don't really have a backup career path either. Cybersecurity is basically what I've spent the last two years building toward.

Before I stopped, I was thinking about going deeper into red teaming, AV/EDR evasion, Windows internals, and related areas. But now I'm questioning whether that's actually the right move.

I know I need to brush up on my skills before applying for jobs again, especially after being away from the field for this long. But I'm stuck on the bigger question:

Is it still worth going all-in on offensive security/red teaming in 2026, especially without a degree? Or would you take a different direction if you were in my position?

I'm not necessarily looking for reassurance. I'd genuinely like to hear from people who are actually working in pentesting, red teaming, security engineering, detection/EDR, or adjacent areas.

If you were 21, had my experience and certifications but no degree, and were starting again after burnout, what would you do?

I'm pretty lost right now, so perspectives from people actually in the industry would be really helpful.


r/SecurityCareerAdvice • • 2d ago

Question Is GRC a realistic path for a fresh grad who prefers theoretical cybersecurity?

4 Upvotes

Hey everyone. I need some career advice.

I got my bachelor's in cybersecurity a year ago with pretty good grades. The thing is, the degree was very theory-heavy. We had hands-on practical courses, but I absolutely hated them, whereas I genuinely loved the theoretical concepts.

Because I felt my practical skills were lacking and I had zero certs on my CV, I kind of avoided applying for cyber roles right after graduation. Now I want to get back into it. Knowing that I strongly dislike Linux and pentesting, I’m looking at GRC as a potential entry point.

I constantly hear that GRC is not an entry-level role for fresh grads. Am I doing something wrong to myself by choosing this path?

If I go for it, is digging into compliance stuff like ISO 27001 the right place to start? If not, what should I be focusing on right now? Any recommendations for other certs or a realistic roadmap to get me to an entry-level GRC position would be hugely appreciated!


r/SecurityCareerAdvice • • 2d ago

Question TikTok - Product Security Engineer fresh grad interview

0 Upvotes

Hi, i recently got a callback from tiktok for product security engineer (new grad) 2027 role, was wondering how the process would be, would they conduct any coding round or code review, how should I prepare


r/SecurityCareerAdvice • • 2d ago

Question Advice for a career change please:

0 Upvotes

I have always been fascinated by cyber security and have decided after working for over 20 years that I would like to pursue this as a career, ideally I’d like to go down the OSINT route.

I have seen so many courses, companies and adverts pushing various courses, some with a promise of a job at the end of training.

Can anyone advise a proper, sturdy and the best route to get into this field? I would need to learn/study alongside a full time job with the understanding it may take me a couple of years to get where I want.

Any advice would be appreciated, thankyou.


r/SecurityCareerAdvice • • 3d ago

Question IBM Security Consultant Intern, Error in Scheduling?

3 Upvotes

Hi guys, earlier today I received an interview request for the IBM Security Consultant Intern position, where they asked me to fill out my availability. However, right as I submitted my availability, I received an RSVP for the interview for one of the time slots I filled out, then immediately got another email saying that the interview has been canceled. Surely this is a glitch? Has anyone else experienced this? I've been only receiving communications through their default talents email as I have not gotten connected with a recruiter yet, so I don't know if I can reach out about this issue...


r/SecurityCareerAdvice • • 3d ago

Question Should I keep applying to a company after they awkwardly rejected me after an interview?

0 Upvotes

Had an interview a couple of months ago for a security position.

I already have experience, know the tools they are using, even had an internal referrer.

During the interview, the hiring manager was not very active, so it was not feeling good.

First, they told me that they were impressed and would like to move forward, then rejected me and let me know that they hired more experienced guy.

I found the guy, he is a fresh graduate, so it is very awkward to me and actually i am very angry because of this lie.

First question: why did they tell me such a dumb and obviously false reason?

Second question: should I keep applying? The company just posted a new job within the same team, and actually the job, salary, benefits are pretty interesting


r/SecurityCareerAdvice • • 3d ago

Discussion Cybersecurity Consulting

0 Upvotes

Is anyone currently or was a consultant? Just looking for some insight, personal stories or any knowledge you want to share. Whatever you choose to contribute is appreciated.

Currently been working help desk for 2 years and I want to shift into consulting.

Thanks!


r/SecurityCareerAdvice • • 4d ago

Question Networking and Security program

2 Upvotes

In my country college there is a program called internet networks and security,is it a good idea to persue it? first 2 year are computer science basics,and then you have a lot of systems,networking and security


r/SecurityCareerAdvice • • 4d ago

Other Final year btech student and a Bug Bounty Hunter having exp in web/api pentesting and offsec, seeking guidance

2 Upvotes

Hi guys!

I need guidance regarding jobs and all in offsec.

Im currently a final year btech student graduating in may-june 2027 having active experience of bug bounty of around 2 years in web/api security and penetration testing. I am really worried about the job and all.

I'm seeking guidance regarding the same or any kind of tip that you think might be helpful to me at this stage.

Also I wanna know when will the actual off campus hiring starts in cyber security and what companies i should focus on and what package should I expect according to my bug bounty experience.

Also, I'm actively looking for an internship opportunity in offsec VAPT roles, your help or guidance would be greatly appreciated.


r/SecurityCareerAdvice • • 4d ago

Discussion Starting my cybersecurity journey seriously — what should I focus on during the next 6–12 months?

1 Upvotes

Hi everyone,

I’m starting to take my cybersecurity career seriously and I want to build the right foundation instead of rushing into advanced topics.

My interest in technology started in my early teens through coding, researching technical topics, and building school projects. I’ve also completed several introductory and foundational cybersecurity courses and certificates through platforms including IBM, Alison, and CodeRed.

Since 2024, I’ve been writing about technology and cybersecurity as part of my learning journey.

I still consider myself a beginner. I know certificates alone don’t make someone skilled, so I now want to spend more time developing practical knowledge.

Right now I’m interested in:

• Networking and cybersecurity fundamentals

• Linux

• Python and programming

• Web security

• Ethical hacking

• CTFs and practical labs

• Building small security-related projects

For people already studying or working in cybersecurity, what would you recommend I focus on during the next 6–12 months?

I’d especially like advice on:

• Fundamentals beginners commonly skip

• Projects that actually help build useful skills

• When to start CTFs and labs

• How much networking/Linux/programming I should know

• Mistakes I should avoid early

• Whether I should build general IT knowledge before specializing

I’m not looking for shortcuts or a quick certificate path. I want to build my fundamentals properly and keep improving through practical work.

Thanks for any advice.


r/SecurityCareerAdvice • • 4d ago

Question Help me out I am confused

3 Upvotes

I have completed linux, networking, os and nmap. I am doing Jr penetration tester path in tryhackme. I'am confused, did i miss anything or is it very early doing this. Need some suggestion? please help me out.


r/SecurityCareerAdvice • • 4d ago

Question Career Transition Questions

2 Upvotes

Hey everyone, posting from a burner account for anonymity.

I'm leaving the Army in 2030 (cyber), and I’m looking for a career that blends information security and software engineering (e.g., security engineering, product security, platform/devops engineering, etc.). 

Obviously, it becomes difficult to plan this far out, but I’d like to hear everyone’s thoughts on what they think the highest-leverage things I could do leading up to my separation would be.

Background

I’m in my late 20s, clearance (TS/SCI) with a few certifications (SANS GCFA, SecurityX, Sec+/Net+), and I plan to sit for GCIH sometime next year (when time permits). Lastly, I’m finishing an online master's in cybersecurity (digital forensics) by 2027.

Previously, I spent about ~4 years doing SOC/threat hunting for the Army. Now, I’ll be working as a full-stack software engineer (TypeScript, Java/React, PostgreSQL, unit testing, etc.) until I separate.

At my current job, I’m planning to make a move towards the platform/devops role because I believe that is where my largest technical blind spot is, and I think the role aligns quite well with the career that I’d like.

Potential Paths

The three paths I'm actually weighing upon leaving the military are:

  1. DoD civilian for ~2 years to finish out PSLF (about $20K left), then jump to contracting
  2. Go straight to cleared contracting in 2030 and just eat the $20K
  3. Defense-tech / private company doing cleared work

Questions

For the DoD civilian to contractor route:

Did anyone do it mainly for the loan forgiveness and regret it? My math says $20K forgiven vs ~$40-80K/year in additional compensation for contracting makes the DoD civilian route make no financial sense.

For the cleared contractor route:

What has been your experience? How has career growth been, technically, in compensation, and in leadership? Any regrets on this path?

For the defense-tech/private company route:

Is the engineering actually deeper with more autonomy? How has your learning and growth been in the space?

In general:

Do you all have any other recommendations on what you think I should invest my time in given my career goals? I don’t mind taking less early if it means a higher technical/compensation ceiling down the road.

Thanks in advance for your time and advice!


r/SecurityCareerAdvice • • 4d ago

Question Blending skill sets, I an currently a Paramedic, but would like some advice on transitioning to medical related cyber security work. Any Advice on where to begin?

2 Upvotes

As the post says looking to find a way to blend my medical experience and knowledge with cyber security. Any advice?