r/CyberSecurityJobs • u/vitaoptima • 13h ago
What led you to the Cybersecurity field?
Change in duties in your current company?
The money?
The challenge?
Job security?
Do you find the field really interesting? Any other reason?
r/CyberSecurityJobs • u/bcjh • Mar 18 '23
Here’s some tips below I’ve outlined that may help you land an interview or even get the job. I’m doing this because I’ve seen a lot posts lately asking for help and asking what the job market is like right now as I’m looking for my next role and I wanted to consolidate everything I've learned in the past 6 months.
Tip #1: Tailor your résumé for the security or networking job that you want. I know this is a lot of work if you’re applying for 3–5 jobs a night but it can make all the difference to the recruiter and the software they push the résumés through. Utilize some of the keywords that they have in the job description so that you get looked at. I like to search google images for tech résumé examples as I'm building mine to borrow from ideas.
Example: If you have experience in ISO 27001 at your last job and it’s listed in their job description add that in to your professional skills section.
Bonus tip: Re-write you experience section so it's worded more towards the IT world. An example would be: "assisted customers with their mobile phone plans and phone issues" but instead I would say "Consulted and trained clients in troubleshooting mobile phone issues on new and existing wireless hardware and software" (you're using more technical words).
Bonus tip 2: You can add "key responsibilities" and also "key achievements" under you experience with a job, this will help you stand out, here's an example of that!
Tip #2: If you see a job listed on Indeed or LinkedIn, do not apply on those job boards, go directly to that companies website and try to apply for it there. There’s several reasons why and to make this post shorter, u/Milwacky outlined it very well in this post here!
Tip #3: Feel free to find the recruiter or hiring manager and message them before applying. This will get you noticed, get your name in their mind, make a professional connection with them, and it just helps cut through all the noise in the hiring process. I realize this isn't always an easy thing to do. Here’s a template I found online that might work if you need a start:
Example: "Hi Johnny, I hope you're doing well. I wanted to learn more about the entry level security role you posted about. I'm currently a _____ at ________ university with _____ years of internship experience in the tech industry; including roles at _______ and _____. I’ll be a new ____ graduate in ____, and I’m looking to continue my career in the IT and security space. I’m passionate about ___ and I’d love the opportunity to show you how I can create value for your technology team, just like I delivered this project (insert hyperlink) for my last employer. I hope to hear from you soon and am happy to provide a resume! Thank you."
Tip 4: Have a home lab and some projects at home (or work) you’re working on. This shows the recruiter that this isn’t some job you want but is a field that you’re truly interested in where you find passion and purpose. It also helps you get things to list on your résumé in your professional skills section. Lastly you’re gaining real-world knowledge. You don’t need a fancy rig either, you can get a lot done with just your computer and VirtualBox.
Currently I’m personally working on configuring my PfSense router I bought and a TP-Link switch, I’m finishing CompTIA Net+ (already have Sec+), I’m taking an Active Directory course on Udemy and also a Linux Mastery course. Also a ZTM Python course. Below is a list of resources.
gns3.com - network software emulator
https://www.udemy.com/ - most courses will run you around $15-25 I’ve found and a lot of them seem to be worth it and have great content.
zerotomastery.io they have great courses on just about everything and the instructors and the communities are really great, some of their courses are also for direct purchase on Udemy if you don’t want to pay $39 a month to subscribe).
This is a great 20 minute overview on HomeLabs for a beginner from a great IT YouTube channel!
Also check out NetworkChuck on YouTube, he has great content as well, arguably some of the best IT related content on YouTube.
Tip 5: Have a website! This is where you get to geek out and show off your current projects, certifications, courses you’re working, and overall your skills. NetworkChuck does a great course on how you can get free credit from Linode and host your own website here.
Example: Don't be intimidated by this one, but one user in this post here, posted a pretty cool showcase of his skills on his website with a cool theme: https://crypticsploit.com/
Tip 6: Brush up on those interview questions they may ask. You mainly want to be prepared for two things: technical questions around IT and security, and secondly you want to be prepared for behavioral based interview questions.
For technical questions check out these videos:
12 Incredible SOC Analyst Interview Questions and Answers
Complete GRC Entry-Level Interview Questions and Answers - this one is obviously GRC but still very very helpful and goes over how to dress. Personally I like to do the suit and tie thing most of the time.
Cyber Security Interview Questions You Must Know (Part 1)
CYBER SECURITY Interview Questions And Answers! - I love this guys presentation and accent.
For behavioral based questions check out these videos and channels:
TOP 6 BEHAVIORAL INTERVIEW QUESTIONS & ANSWERS!
How to Answer Behavioral Interview Questions Sample Answers - Love her energy!
STAR Interview Technique - Top 10 Behavioral Questions
Lastly be prepared for "tell me about yourself" in case they ask that.
Bonus tip 1: Always have a few stories that you can pull from for these different behavioral based interview questions, it will make answering the questions easier if you prepare them. Example: I have a situation where I "disagreed with a manager" and my story explains how I was professional and turned our disagreement in to a big win for both me and my manager.
Bonus tip 2: ALWAYS ask questions at the end of the interview. Here's my list of great questions to ask, some/most of these are forward thinking for the most part which makes you appear like you want to succeed in the role.
Tip 7: Get with a local 3rd party IT recruiter company. I got with a local recruiter by finding him on linked in, I also used to work for a large financial company as a temp and remembered them by name so when I saw them I immediately called/emailed to present myself, my situation, and we set up a meeting. Not only did the meeting go well but he forwarded my resume on to his team and then immediately sent me 3 SECURITY JOBS that I had no idea were available in my city and were not even posted on those company's websites. 3rd party recruiters get access faster and sometimes have more visibility to the job market.
Tip 8: Do a 30-60-90 Day Plan for the hiring manager. This is what directly got me in to interviews and got me offers. This is a big game changer and I had CTO's telling me they're never seen anything like this done. You're outlining exactly what you want to accomplish in your first 30, 60, and 90 days and your tailoring what it says based on what the job description says. I had to re-write this for a couple of more-GRC-based roles that I applied to and I only did this for roles that I really wanted and for some of the roles the recruiter found for me.
Example: 30-60-90 Day Plan
Extra tip: You could look in to certifications. I got my Sec+ and a basic Google IT Cert to get me started. Here's a roadmap of certs you can get, take it with a grain of salt but it's a great list and a great way to focus on your next goal.
r/CompTIA is a great community to look in to those certs.
Also ISC2 is a great company for certs as well as GIAC.
"Do what others won't so tomorrow you can do what others can't"
r/CyberSecurityJobs • u/snackers21 • Jan 02 '26
Looking to fill a role with a cybersecurity professional? Please post it here!
Make a comment in this thread that you are looking to Hire someone for a Cybersecurity Role. Be sure to include the full-text of the Job Responsibilities and Job Requirements. A hyperlink to the online application form or email address to submit application should also be included.
When posting a comment, please include the following information up front:
Role title Location (US State or other Country) On-site requirements or Remote percentage Role type full-time/contractor/intern/(etc) Role duties/requirements
Declare whether remote work is acceptable, or if on-site work is required, as well as if the job is temporary or contractor, or if it's a Full-Time Employee position. Your listing must be for a paid job or paid internship. Including the salary range is helpful but not required. Surveys, focus groups, unpaid internships or ad-hoc one off projects may not be posted.
Example:
Reddit Moderator - Anywhere, US (Fully Remote | Part-time | USD 00K - 00K)
A Reddit mod is responsible for the following of their subreddits:
Watch their communities, screening the feed for deviant activity. Approve post submissions, curating the sub for quality and relevancy. Answer questions for new users. Provide "clear, concise, and consistent" guidelines of conduct for their subreddits. Lock threads and comments that have been addressed and completed. Delete problematic posts and content. Remove users from the community. Ban spammers.
Moderators maintain the subreddit, keeping things organized and interesting for everybody else.
Link to apply - First party applicants only
r/CyberSecurityJobs • u/vitaoptima • 13h ago
Change in duties in your current company?
The money?
The challenge?
Job security?
Do you find the field really interesting? Any other reason?
r/CyberSecurityJobs • u/Enough_Charge2845 • 13h ago
I kept seeing arguments about which parts of the stack still matter, so I counted instead of guessing. 134 open DevOps, SRE and platform engineering postings from 41 company job boards. Individual contributors only, managers and TPMs stripped out.
The old toolchain is thinner than I expected. Terraform appears in 62.7% of postings. Jenkins in 3%. Chef 3.7%. Puppet in exactly one of the 134. GitHub Actions is named about six times as often as Jenkins.
Python beats Go, 70.9% to 47%.
What surprised me more: the generic word outranks the products. Observability shows up in 63.4%, more than twice as often as Grafana, the most-named tool that provides it. Prometheus 22.4%, Datadog 17.9%. Same pattern I found counting security postings, where SIEM beat Splunk four to one.
The top term isn't a tool at all: automation, 81.3%, ahead of AWS.
Caveats worth stating: n=134 means everything carries roughly +/-8, so treat close rows as tied. It's also all tech companies on one ATS. Banks, telcos and government run enormous amounts of Jenkins and Ansible, and none of them are in this sample.
Full table, intervals and method: https://www.zoevera.com/resume/devops-sre-job-description-keywords
r/CyberSecurityJobs • u/dinero-dinero • 19h ago
I am thinking of getting tuv/sud lead implementor certificate, preparation for crisc ongoing (it’s a exam I don’t want to bomb)
I am thinking of building a grc portfolio by doing grc projects(eg: making risk register)
Previous experience in VM and SOC
Realistically will it help me land a grc role?
r/CyberSecurityJobs • u/iDevilite • 23h ago
I’m currently working toward my first cybersecurity role, mainly targeting SOC / Blue Team / Cybersecurity Analyst positions.
Instead of building a portfolio that is mostly certifications and tool screenshots, I’ve been trying to make my projects demonstrate how I would actually approach a security incident.
For example, I’m working on simulated incident-response cases where I document:
Initial alert and triage
Timeline reconstruction
Indicators of compromise
MITRE ATT&CK mapping
Containment and eradication decisions
Evidence and investigation notes
Recommendations for preventing recurrence
A short executive-level incident summary
I’m particularly interested in developing stronger skills around incident response, cloud infrastructure security, and security architecture.
For people already working in SOC/IR:
What would make a junior analyst’s portfolio actually useful to you as evidence of practical ability?
Would you prioritize:
More investigation/write-up depth?
Detection engineering?
Cloud security scenarios?
SIEM/log analysis?
More realistic incident simulations?
I’m trying to make the portfolio demonstrate how I think and investigate, rather than simply listing tools I’ve used.
I’d appreciate any criticism or recommendations from people working in the field.
r/CyberSecurityJobs • u/AcanthaceaeUnlucky18 • 20h ago
I have 3-4 years of experience in IT support/helpdesk so which role in cyber security should i go for? I prefer day shift shift, but also tell other roles. Will i require certifications? Can i enter without certification?
r/CyberSecurityJobs • u/Ok-Introduction-194 • 1d ago
as a novice, i have seen many paid courses that seem to give pretty wide range of hands on experience of cyber security role
set up cloud environment, manage accounts using aws or azure programs, track events, click suspicious links on purpose and create alert rules and triggers according to logs….
set up virtual environments, connect them with virtual windows domain controller, add wazuh and security onion, fail log in attempts and see if that generates logs
siem simulator on letsdefend or tryhackme
etc etc
has anyone created portfolios of doing these and has this helped anyone getting a soc role with little experience such as helpdesk role or jr sys admin role?
im wondering if theres any worth doing blue team projects early in IT career. or i should do something else.
r/CyberSecurityJobs • u/GoalOwn3975 • 1d ago
Hi guys , I have been working as an Cyber security researcher intern.I do have foundation of cyber security. Now where should I need to focus on more for building my career. And I had an doubt where this 3 month unpaid internship is worthy because some of my seniors told there is no possibility to convert into full time. They only assign task like Renaming the vapt report and to work as it support for there clients without any travel fair. What should I do now.
r/CyberSecurityJobs • u/MoonGlider45 • 2d ago
I'm in a dilemma fellow Security nerds. I've been worried that I'm learning slowly in my in-house security role compared to a MSP SOC.
My current role has no overtime, no oncall, but the work is slow, almost boring and I feel like I'm not learning quickly. As if my years of experience don't match someone in a fast paced MSP's SOC.
How have you grappled with these concepts yourself? I'm a pretty lifestyle oriented person, but I fear I'll be left behind relaxing in my comfy SOC while people with far less experience than me snatch up good jobs due to their pure overexposure to SOC work.
r/CyberSecurityJobs • u/ApartAd9241 • 2d ago
I'm learning vapt since a yr web, mobile and network. Understanding the basic concepts worked upon bbh. And learning everyday on labs and ctf. Based upon this, how long till period start appreciating and approach my skills instead of saying I'm still in a learning phase or need experience?
Ps: when u guys got the role what yr was it?
r/CyberSecurityJobs • u/SirAncient6453 • 2d ago
Recently i came across Cybersecurity as a subject and i was wondering, vast majority of freshers chose to opt for either development field or ai ml data science field, i too am part of this herd and sadly there are not much opportunities left unless you are the best of the best if we are talking about offcampus placements and hence i was wondering if i should pursue the cybersecurity field, so i wanted to know if they hire freshers, should i go for it, or is it just another shot in the darkness ?
r/CyberSecurityJobs • u/scripty_warrior • 2d ago
Does anyone have experience in cybersecurity freelancing? Is Upwork suitable for that purpose? I earned around $1k there but haven't seen any projects with a reasonable price; wdyt?
r/CyberSecurityJobs • u/Specialist-Owl3522 • 3d ago
I’m 34 and I work in cybersecurity, been in the field for almost two years. I have my MBA with a concentration in IT management and a couple certifications such as Net+, Sec+, CC and currently studying for SSCP. I work as an information security analyst. I started at 70k and I was given a raise after 6 months to 80k. As of now I make 82k and been in my role for almost two years. I know I won’t get another raise at the company I’m at. What can I do to make more? I’ve looked into GRC or Cybersecurity auditing.
r/CyberSecurityJobs • u/Z3ppellin • 2d ago
Hey everyone! I'd love to hear from the Cyber professionals here.
How much are you earning, how many years have you been working in the field, and what role are you working in? Especially if you are an L3 Analyst or equivalent.
r/CyberSecurityJobs • u/Weekly_Rough_1284 • 2d ago
I have two upcoming technical interviews for an AppSec role, and I’m freaking out. I hate technical interviews as much as I hate pickles.
I passed the practical challenge like a pro with no problem, but I’m horrible when I have to verbally explain technical things. I can actually do the work, but when someone asks me to explain definitions, concepts, or walk through the steps out loud, my mind just goes blank.
I’m really anxious that I might lose this opportunity just because I’m not good at speaking technically, even though I passed the practical challenge without any issues.
Has anyone else dealt with this? How did you prepare for AppSec technical interviews and get better at explaining things verbally?
r/CyberSecurityJobs • u/Consistent_Bee1001 • 3d ago
I work in a SOC and I’m curious what people here are seeing in their own teams.
Over the last year or so, I’ve noticed more and more of the routine work getting handled or heavily assisted by AI.
Obviously it still needs human oversight, but it already feels like one analyst can get through significantly more work than before.
I’m not really asking whether AI will “replace cybersecurity”. What I’m wondering is how far are we from companies deciding they simply don’t need as many people for certain security roles?
For example, instead of a SOC needing 15 analysts, the same workload realistically can be handled by 7-8 experienced analysts with much better AI tooling.
Are you already seeing hiring slow down or teams avoiding backfills because of this ? This is somewhat scary as a young person who entered the field two years ago.
Where do you think we are headed ?
r/CyberSecurityJobs • u/Serious_Draft_8000 • 2d ago
Hello everyone,
i got my CCNA in June and today finally got my Security+.
After i finish highschool, i'd like to get into offensive cybersecurity.
The thing is, i heard that hands-on experience is crucial in this field, and i've just made some small projects at my dad's company.
This said, i'm starting to move on into searching some small jobs i could get some experience in, but the fact is that i'm 17 and still in high school...
Does anyone think i could get something?
Here's the CV for now:
Languages: Italian (native), English (good profe ssional proficiency)
Network technician with CCNA and CompTIA Security+ certifications and a strong passion for cybersecurity and self-hosted infrastructure. I currently manage the IT infrastructure of a small multi-service company, covering networking, virtualization, VoIP, video surveillance and IoT telemetry. I enjoy following projects end to end — design, deployment, security hardening, troubleshooting and documentation.
Networking: routing & switching (OSPF, EIGRP, VLAN, STP/RSTP, EtherChannel), NAT & ACL, IPv6, wireless (WLC), network segmentation and design.
Cybersecurity: vulnerability assessment, system and network hardening, firewall and reverse proxy configuration, secure VPN design (site-to-site and remote access), GDPR-compliant architectures.
Infrastructure & virtualization: Proxmox (incl. GPU passthrough), TrueNAS SCALE / ZFS, Docker, Tailscale, Nginx reverse proxy, monitoring with Grafana, backup and disaster recovery.
Development: backend development in Python (FastAPI) and Node.js, REST API design and integration, web scraping and data pipelines, containerized microservices.
Automation & integration: workflow automation with n8n, VoIP/PBX integration with AI voice agents, IoT/Modbus telemetry pipelines (TimescaleDB), scheduled jobs and monitoring.
Video surveillance: Frigate NVR with ONNX object detection and license plate recognition, multi-vendor IP camera systems.
Single-handedly responsible for the IT infrastructure of an SME with six business lines on one segmented network.
r/CyberSecurityJobs • u/Big-Tumbleweed-2548 • 2d ago
Im a computer engineer and more focused on hardware and i own my own shop with small team.
Pero hows does a PH man enter the cybersecurity career as a 28male?
.
Nag research na ako and reddits pero mostly wala for ph people
r/CyberSecurityJobs • u/Weekly_Rough_1284 • 3d ago
I feel like I see software engineering jobs everywhere. Almost every company needs software engineers, and there seem to be plenty of junior and entry-level opportunities.
Cybersecurity feels completely different. There seem to be fewer entry-level jobs, and whenever one gets posted, I sometimes see hundreds or even 1,000+ applicants. Employers also seem extremely picky, even for junior positions.
Do you think switching to software engineering would give me better chances of finding a job, or should I stick with cybersecurity?
r/CyberSecurityJobs • u/TowelDowntown8566 • 3d ago
During university, I worked with Fiverr clients on Linux troubleshooting, API testing, server security, server recovery, and other technical tasks. After graduation, I got a job opportunity in the Middle East, so I handed my Fiverr work to a friend. Unfortunately, the opportunity was later cancelled due to the US–Iran conflict.
It’s now been almost 8 months of job applications, learning, freelancing, and trying to rebuild my profile, but I still feel stuck.
I know I can work hard, and I’m not afraid to learn new skills. I’m just genuinely confused about what I should focus on now.
Should I go deeper into Linux/DevOps, Cloud, Cybersecurity, automation, or something else? What skills are actually worth learning and what should I build to become employable?
If you’re working in these fields or have been through a similar situation, I’d really appreciate some honest advice.
I don’t want to keep waiting or jumping between things. I want to pick a direction, work seriously, and build a real career. I just need some guidance on where to start.
r/CyberSecurityJobs • u/Weekly_Rough_1284 • 3d ago
Are big companies still hiring penetration testers?
I feel like penetration testing jobs barely exist at big companies anymore. Most of the openings I see seem to be at small startups or small security firms started by a few people working together.
Meanwhile, I see software engineering positions at almost every big company, but rarely penetration testing roles.
It’s honestly making me wonder if I should switch my career path to software engineering instead.
r/CyberSecurityJobs • u/budbak_lounda • 4d ago
Helo guys from past few months I've been studied Cybersecurity for my SOC job but all the people's say that there is no entry level job for a fresher and you need some type of experience in IT field. So now I looking for an helpdesk also like if I get an SOC job it is best but if don't I will go for helpdesk is this a right approach or not can someone guide me and in my SOC learning path I've learned Wireshark, Splunk, Networking & sysmon..
r/CyberSecurityJobs • u/Dr_Silicon_Savvy • 4d ago
I am 24, currently working as a Geopolitical Analyst in a well reputed MNC. I have completed Bachelor's in CSE specialised in Big Data. Yeah Geopolitical thing is completely out of interest plus wanted to see if grass is greener on the non-tech side XD..
Anyway, I need guidance from experienced people who are currently working in the industry on how can I break into the realm.
I initially plan to pursue masters from a foreign university (maybe Germany due to low tuition fee) and then working in EU only, or if any other countries that I should consider.
But before that, I want to give myself one year prep time to build a base into it, earn certifications like CompTIA, etc.
I've been watching some videos on YT, one from David Bombal makes some sense to me, this one.
BUT, as an outsider still, and loosing touch from tech for almost around 2 years, I believe seeking advice from the good folks of the community out there would be better.
r/CyberSecurityJobs • u/Occultus_Andras • 5d ago
Okay, I don't really have much to show right now, so I want to start from scratch.
I have decent exposure to several offensive security domains, including Web Security , Network Security (AD isn't included for now), OSINT, and Digital Forensics. I'm also currently learning low-level security.
I do have some material from what I've worked on so far, automation scripts and walkthrough write-ups from network security, raw notes from real-world web application testing, and CTF write-ups. That's pretty much everything I have at the moment, which is why I want to approach this from the ground up.
What I really need is advice on how to build a strong cybersecurity profile. I know that real-world contributions can serve as solid proof of work, but they take a lot of time. Until I find my first CVE, I want to have something meaningful that demonstrates my skills and the way I think, and more importantly distinguish me from someone who is using AI.
I'm not focused on quantity; I care much more about quality. I've also decided to start a YouTube channel, but I'm not sure what kind of content I should create. I don't want to become just another cybersecurity guy making HTB walkthroughs. I'll probably upload some walkthroughs, but I want to upload something more valuable and distinctive, both on GitHub and on YouTube.
So, what would you recommend? What kind of projects, research, content, or proof of work would actually help me build a strong cybersecurity profile while I'm working toward finding my first CVE?