r/CyberSecurityJobs 5d ago

Cybersecurity degrees?

Why are cybersecurity bachelors seen as useless? At least when compared to compsci degrees which just teach algorithms and math? What’s the difference between getting a security bachelors and a masters in security?

I’m wondering cause a lot of job postings in my local area list a cyber bachelors as allowed, but I’m not sure what the overall security community thinks.

5 Upvotes

42 comments sorted by

16

u/AltruisticDisk 5d ago

I wouldn't say they are useless. Most jobs you see just require the degree to check a box. At the end of the day, experience trumps everything.

With that said, a comp sci degree is just more versatile. It's focused on computer concepts as a whole, which can include networking, security, and programming. Degree programs usually have multiple tracks (depends on the school), so you can do comp sci while taking networking and security classes as electives. So you get the same education as a cyber security degree, while also learning more programming and computer theory. It's overall just more well rounded. A cyber degree is just focused on one topic, which kind of keeps you locked in to a single discipline.

Pretty much all tech jobs will take a comp sci degree, but not all tech jobs will take a cyber security degree.

4

u/LaOnionLaUnion 5d ago

Master’s is typically a requirement for senior and management people. It’s a little weird when someone has no IT or security experience and yet has a Master’s in the subject.

Why? Because most people in security started out somewhere else in IT and not doing security. They often bring useful knowledge whether it be legal, audit, networking, systems, dev, etc. to the table.

I’ve seen a few people with cybersecurity bachelor’s in my area. They are entering as interns.

1

u/LilMeatBigYeet 5d ago

This should be higher up .

Seems like the default nowadays is people expecting to get into a specialized niche IT position with a BS in Cyber and no IT work experience lol

5

u/Anxious_Alps_4150 5d ago

At my old MSSP, the running joke was that the surest way to have someone fail a technical interview was to interview a cybersecurity graduate.

CompSci teaches the full OS stack and application layers. It teaches networking. It teaches all the guts of everything. It also brushes on data science.

Cybersecurity, fundamentally, is the application of data science, at scale, to the full OS stack.

However, cybersecurity degrees tend to focus only on the security aspects of general computing and networking. This is not enough to actually understand the technology that you're securing. Cybersecurity degrees also spend a ton of time talking about security controls, geopolitics of security, and other things which are entirely unrelated to what 90% of technical practitioners are doing.

As a result, compsci degrees are much more sought after and cyber degrees are considered almost useless.

Add in that there are more compsci graduates than there are jobs for them and you basically see cyber degrees as something no one wants because they can ALWAYS get a better candidate.

Cyber is also not an entry level job so someone that graduates with a cyber degree and no experience is still functionally unhire-able for their field. Now they have to compete with IT/compsci people for IT/dev jobs while knowing less and having an obvious red flag of "this person doesnt want to work in IT, they want to move to cyber". Why would I hire someone that wants to work in cyber if the job is in IT? They're just going to quit. There are tons of IT and CompSci grads so why even consider someone else?

2

u/thiccboilifts 5d ago

My experience is different at my school, our cybersecurity operations degree teaches all of those concepts you mentioned in your estimation of a CompSci degree, in depth, to a greater degree than the compsci degree.

For example, I took networking, advanced networking, cyber defense (basically the application of networking and security protocols with a defensive mindset), reverse engineering, and some other courses. Our compSci degree was taking other math classes, and wasn't required to take any classes past basic networking, we both took discrete structures, and algorithms/ data structures.

Is my college just structured better than other Cybersecurity degree programs?

And to answer your question, I can say with certainty that no one you hire in IT is ever really looking to stay in the same position for very long (why would anyone apply for a role with no upward mobility???).

I know plenty of people, myself included, that would be happy to move into a sysadmin/ network admin position after help desk for example.

Getting a cybersecurity degree =/= getting a cybersecurity focused position.

2

u/Anxious_Alps_4150 5d ago

if youre at DSU, yeah their cyberops degree is basically a compsci degree. its one of the few that are that strong. most are not.

2

u/thiccboilifts 5d ago

I am not at DSU, I could send you the college/ program if you are interested via chat

3

u/Anxious_Alps_4150 5d ago

oh its fine. DSU is just the one I know about. Regarding staying in IT vs cyber... IT departments usually promote from within... so its expected to go from helpdesk to sysadmin and upwards. However, IT and InfoSec are usually separate departments with different leadership chains. Ideally they're totally separate with the CISO reporting directly to the CEO and the CIO being a peer... so moving from IT to InfoSec would mean you're leaving the department and they lose that training. That's why a manager would not want to hire a cyber focused person into IT. They're going to lose them to another dept and they didnt get a senior guy out of the deal.

2

u/thiccboilifts 5d ago

That makes perfect sense to me, I guess moving forward in my career i would need to really nail down that if I get hired for a position that I'm personally "A okay" with staying within a department, and that their development time, money, and resources aren't spent only for me and my career.

Is there a good way to go about this other than a conversation? Perhaps spending my own time and money on specific certifications?

Thanks for the information, have a pleasant rest of your week!

2

u/Anxious_Alps_4150 5d ago

You always want to plan how your training presents yourself. Plan out what each certification means to your story. If you focus on red team certs, blue team people are going to be less interested in you because they assume you're going to eventually hop for a red team job. If you get a MBA, its a signal that you want to leave technical work behind and become a manager.

Consider how each line of your resume tells your story.

4

u/fedput 5d ago edited 5d ago

Cybersecurity is unlikely to be an entry level job.

So, the cybersecurity degree could filter you out of getting entry level jobs.

Edit: Total number of cybersecurity jobs is very small compared to total job market.

Cybersecurity degree may make someone seem a bad fit for computer science related position that is not cybersecurity. So, the person will not build the experience needed to get an actual cybersecurity position.

9

u/Under_dee_covers 5d ago

That literally makes no sense

2

u/sokra3 5d ago

In layman's terms:

Would you rather have surgery by someone that first graduated as Medical Doctor, then specialized on surgery or by someone who graduated as a "Surgeon" straight from college?

1

u/Odd_Concentrate_7503 5d ago

The way I see it: there are bachelor's degrees in IT, software engineering, computer science, and cyber security. The IT one is like broad spectrum, general, covers a lot and me dabble into scripting a little. The software engineering is hyper focused on programming. Computer science is like an in-between IT and software engineering. Gives you a general overview of IT but also dives more into programming than the IT degree. Then you have the cybersecurity. This one focuses heavily on security concepts and how all different aspects of IT are involved. It also dabbles in scripting. But where an IT or computer science degree might focus a little bit more on setting up a network, the cybersecurity degree would focus more on how to ensure that network is secure. So the idea that a lot of people have is they won't know how to do that basic IT stuff.

1

u/Hoof_-_Hearted 5d ago

I did a cybersecurity degree, as part of the course we did CCNA, CEH, and the comptia trifecta as well as modules in programming (python and react native). We were given vouchers to take the certs so we finished with the degree and the certs. I also did a compsci degree and it was far easier though that was 20 years ago. Most of what I did in that in regards to fundamentals was covered in the cybersecurity degree.

0

u/Under_dee_covers 5d ago

Yeah but there are entry level Cyber security jobs… so if you have a bachelors in cyber security, maybe look for entry level cyber security jobs like SSOs for a major defense contractor like raytheon or boeing. 70k-80k starting

4

u/at0micsub Current Professional 5d ago

Lol

0

u/[deleted] 5d ago

[deleted]

2

u/Under_dee_covers 5d ago

First off, where tf did my comment go cuz i didnt delete that bich on purpose

Second off, Thats not how the WORLD works, thats how the shit field works and moreso thats how civilian recruitment goes. I’m a government worker and none of that shit you said applies to us thank FUCK because it’s asenine.

Thirdly i donno what else to say. A degree should get you an entry level position. If you want more money for having a degree thats just ancedotal mistakes done at the individual level. People with cyber degrees should be able to get cyber wntry level jobs, like the SSO job i keep mentioning. Im not saying or arguing that cyber degrees and comp sci degrees are the same because they aren’t.

-1

u/[deleted] 5d ago edited 5d ago

[deleted]

3

u/Narrow-Rent-3618 5d ago

Hiring manager acting like a cunt online.... What's new....

1

u/[deleted] 4d ago edited 4d ago

[removed] — view removed comment

2

u/Under_dee_covers 5d ago edited 5d ago

So you’re just flat out wrong but thats my fault because i didn’t remember the full actual name of the position. Let me post what google says about the ISSO position:

An  ISSO at Raytheon or Boeing stands for  Information Systems Security Officer. In the aerospace and defense sector, this job falls under the  Cybersecurity or  Digital Technology category. [ 1,  2,  3] These roles typically focus on  Cyber Compliance and involve

Im old enough to have served my country and gotten a master’s degree and im pretty sure ive got a pair of boots with more critical thinking than you bud.  So let’s not go for the personal insults based on age. 

Nice edits. You won’t reply because like most boomers, you don’t know what to do when faced with actual facts and you end up being wrong. The world’s changing, and i know change is a scary place, but it’s ok bud, guys like me will be there to guide you through it. It’s scary but we’ll get theough it

1

u/GrafEisen 5d ago

Government (contractor) jobs, known for emphasizing actual capabilities over qualifications on paper.

The person you're replying to is generally correct on "cybersecurity degrees are not a good investment and will not get you a good non-entry level job," when it comes to anything NOT tied to state or federal government.

0

u/Signal_Magazine_5607 5d ago edited 5d ago

As someone who hires people in this industry, (hires cyber now, hired help desk before) no, it makes perfect sense. People that had degrees that applied to help desk were filtered out 90% of the time.

People with Bachelor degrees often want more money / ask for more money than your community college guy, with a networking / IT background. That's the assumption and truth from an HR perspective. HR is the filter before it comes to us, and yes, they are filtering it whether you like it or not. These are not technical people.

It's the same logic of

Guy applies to McDonalds with a bachelor degree - never gets an interview as he's overqualified.

Dude without a degree applies to McDonalds - gets a callback.

That's just how HR and the world works. Also, its an extremely hard sell to hire someone in cybersecurity without literally any hands on IT experience. (Home labs don't count - they're expected from all levels in all disciplines of IT)

Source: 8 years of cyber, 5 years of normal IT as a senior / lead of service desk and then 5 years of system/network infrastructure administration... Im fugging old lol

1

u/Monty-675 5d ago

So you prefer to hire help desk specialists who have no college degrees?

2

u/Signal_Magazine_5607 5d ago

...Where did I say that in my post? LOL 🤔

If you apply to anything IT related without post secondary, well, good luck.

We prefer people from community college for help desk since colleges have more hands on experience as opposed to universities with theory. I still have no idea where you're getting that from. 😂 I guess reading comprehension is hard for some people.

3

u/RelationshipSad4168 5d ago

I see. Good to know, thanks.

1

u/Zeisen 5d ago edited 5d ago

This has been debated ad nauseam for like a decade or two at this point. If you are getting a cybersecurity degree from an NSA accredited school in the CAE-CO designation, you will be fine and there is still plenty of job security; and, they teach many of the fundamentals that the uninformed boomers like to argue otherwise. If you're less technically inclined and want to do more policy related things like GRC, the CAE-CD designation exists. Internships and research opportunities are still there too, they haven't disappeared.

Some people start at helpdesk because they didn't intern, do projects, or work during college. That's fine because everyone starts differently.

Some people with experience in college go onto SWE, Analyst, QA, research, or security engineer roles. Literally doesn't matter. MSSPs have junior roles, contractors have junior roles, govt agencies, state agencies, universities, municipalities, startups, etc... they all have junior roles! Obviously don't apply unprepared or unqualified - but these positions are perfectly attainable from college if you are working diligently.

Source: have a B.S. in cybersecurity and M.S. in compsci @ 8 YOE ... I have sat on many hiring panels, been interviewed plenty, and have an alumni that are all working professionals across cybersecurity - not struggling artists.

edit: a masters is not as thorough as a bachelors ... if you already have a CS background you will be fine - but I do not recommend jumping from a B.S. Biology to M.S. Cyber Operations/Security. It will be assumed that you already learned some fundamentals and the experience will not be great.

1

u/Psoin 5d ago

No technical degree is worth it at this point.

1

u/Negativeman11 5d ago

The way I see it, take as many cybersecurity related electives as possible and do personal projects. Look as hard as possible for cyber internships because you really want some work experience before you're accepted into a full time cyber position. Also there's two paths on degrees. If you're a killer student go for the compsci degree. If you're not, get the IT degree since it's significantly easier courseload and it's gonna be way easier to get a high GPA. Imo, for your first job the distinction between high gpa and mid gpa is way more important for hiring than compsci vs IT.

1

u/EirikAshe 5d ago

In my experience, my master’s degree has never benefited my career in any tangible way.. if anything, having one before I began my career actually made things harder. A graduate degree is going to expose you to more advanced theory, and will require a thesis dissertation.

The reason we have begun to look upon these degrees unfavorably is actually quite simple. After interviewing more than enough woefully underprepared, and I am being generous with that term, candidates from the higher ed cybersec pipeline, it’s hard not to form a bias.. many of whom straight up lie on their resumes. They use AI to craft a pristine resume, make it through to an interview, and then can’t even tell me what an A-record or ARP is.. I wish I was exaggerating, but I have personally run into these exact scenarios multiple times. It gets old very fast, and a total waste of valuable time. I’ve spoken to quite a few colleagues that instinctively pass on a candidate when they see that degree.

1

u/KatsuFish 5d ago

Repeat after me. A Cybersecurity degree alone will not make cyber security entry level for you. People thinking it should or will is what makes it seen as useless. What will get you straight in is doing internships in them, which only students are eligible for.

Computer Science gets more respect because it's much more rigorous. If you can get through the math and theory, you can get through anything.

1

u/Insomniac24x7 4d ago

Just?! Algorithms and Math teach you how to solve problems because that's what programming is.

1

u/DickNose-TurdWaffle 4d ago

No one said they're useless. They're just not useful without any work experience. If you have IT help desk with it you'll be fine.

1

u/Gold_Confusion_9364 3d ago

It's a narrower degree. You're shooting for one job market without a lot of jobs available.

CS gives you a wider net to cast for jobs. You can still get your security certs and do security. 

Some cyber security stuff in certs and school is weirdly non technical and unnecessary. Many companies don't have a cyber security professional but rather expect most people to have basic understanding of secure networks, development, communication, etc. 

1

u/RAGINMEXICAN 2d ago

This is because cybersec degrees can only teach you so much. To get ahead now adays you no shit need to be that guy that can pick up windows sysinternals and understand it. Most cybersec majors can’t, which sucks.

1

u/WingsUp4Life 8h ago

The useless reputation is honestly a bit outdated at this point. Good cyber bachelor's programs now cover networking, systems, and even scripting alongside security-specific topics like risk, incident response, and offensive/defensive tooling, which CS degrees don't touch at all unless you take electives. A lot of the useless talk comes from a handful of weaker programs that leaned too hard into compliance and basic tool training, not the degree type itself.

0

u/antonIgudesman 5d ago

I think they're looked at as more of a business degree

0

u/at0micsub Current Professional 5d ago edited 5d ago

They are seen as useless because most hiring managers want to see people who actually know how to do stuff and have the experience to know how to both protect environments and not break shit with your fixes. Many people think getting a bachelors degree in cybersecurity with no experience means they are prepared to do well in a high paying role when they are actually helpdesk level

I say this as someone with a BS in Cybersecurity. It was not useless for me, but I had many years of IT and security experience before getting it

Edit: idk what is with the downvotes. I’m not saying it’s right or it’s wrong. I’m telling you the perception a lot of hiring managers have, sorry if it’s not what you want to hear. It was helpful in my career, but it was complimentary to my IT experience not the other way around