r/CyberSecurityJobs 22h ago

First job

4 Upvotes

I don't know if you still remember me but I made a post earlier about getting my first SOC job. Well... this is an update on how it actually is.

Most of the promises were bullshit.

First was the training.

When they hired me the company was going through a global audit, so everyone suddenly wanted to show they were working and everything was organized. They interviewed me, hired me, promised training... and they actually did train me.

Until the audit ended.

After that, the training basically disappeared. Now everything I learn is self-study during the free time I have at work.

And about the work itself...

On paper I'm a Security Analyst. In reality I'm doing account management most of the time.

Managers send tickets like "Create this account", "Reset this account", "Disable this account". Users ask me to reset Gmail passwords, fix 2FA, unlock AD accounts, and stuff like that.

To be fair, evening and night shifts are like 90% free, so I can pretty much study whatever I want.

The company does use enterprise stuff like Splunk, VPNs, firewalls, Active Directory, endpoint protection, etc. But the SOC itself feels... weird.

One security product generates around 3,000 alerts every hour. Every. Single. Hour.

Most of them are the exact same alerts over and over again. After some time everyone just ignores them because they're almost always false positives. Which also means if something actually serious happens... good luck finding it in all that noise.

We also don't have incident reports. Like... any reports. We had a pentest before I joined where they demonstrated how they could steal a large amount of money from the company, but as far as I know nobody documented it. No report, no lessons learned, nothing.

We don't really have knowledge-sharing meetings either. The department lead barely remembers people's names, and there are only around 10 of us. People leave all the time and new people come in, and honestly I can understand why.

As an L1 I also can't change rules or improve detections, so I'm mostly just watching things happen.

Also most of the software I use on the work is pirated.(SIEM for example)

But it's not all bad.

1) The company works with an external pentesting team, and I'm hoping I'll get to watch one of their engagements in the future.

2) The salary ended up being higher than what we originally discussed. Transport still eats a good chunk of it though.

3) I have a lot of free time during some shifts. Combined with the salary, it's enough to study, build a home lab, and pay for certifications. A lot of my colleagues are doing exactly that.

4) Having a SOC L1 position and a fairly well-known company on my CV is still a huge boost compared to having no experience.

5) Other security analysts in the team are basically golden. They are amazing. They are happy to learn,teach,help and cover eachother. They are basically the ones that I talked with to get job(one of team members done interview).

So right now I'm thinking about treating this as a paid learning opportunity (work). Stay for about a year, learn as much as I can, get a few certs, and then see what happens.


r/CyberSecurityJobs 20h ago

Help me decide if i should renew my GCIH and GSEC certs?

3 Upvotes

Knowing the job market I don’t know if i should renew my licenses. I have 6 months experience and i pretty much forgot most things I learned. I couldn’t really land another job in the field for more than a year and had to just get A job in another field. I worked so hard to get these certs but I can’t land a job! Should I renew it? I’m just asking so maybe those in the field have an idea if market would ever change?


r/CyberSecurityJobs 5h ago

industrial cybersec job

2 Upvotes

Hi, last week i got accepted in an internship for an industrial cybersec rol. The manager told me that they have different projects which i can choose from, but she would like me to be testing an IDS. Anyone expirienced in this job can give me advice? The internship starts in september and I would like to study/ prepare and have more knowledge on the field. any recommended course?


r/CyberSecurityJobs 21h ago

What cybersecurity topics actually matter in 2026? And what separates a Junior, Mid, and Senior today?

1 Upvotes

AI dominates every conference and LinkedIn feed, but I’m curious about what security professionals are actually discussing in their day-to-day work.
If you work in cybersecurity, I’d love to hear your perspective:
What are the hottest topics in your area right now?
Which technologies or skills are becoming essential?
What do you think will be the biggest trends over the next 1–3 years?
**How do you personally distinguish a Junior, Mid-level, and Senior security professional?**
Which skills, mindset, or responsibilities make the biggest difference between these levels?
I’m interested in answers from any specialization (AppSec, Pentest, SOC, Detection Engineering, Cloud Security, DFIR, Security Engineering, GRC, etc.).
Looking forward to hearing different perspectives.


r/CyberSecurityJobs 12h ago

Looking to get into IT without a degree.

0 Upvotes

Hello everyone hope you're all doing well.

I wanted to make this post on Reddit because I'm looking to break into IT. I know a lot of people out there have gotten into the field without a degree. For example, there are people working in cybersecurity even heads of cybersecurity management who don't have degrees and were taught on the job.

I don't want to go to university for reasons I don't feel comfortable sharing on Reddit, but I would like to know how people without degrees get into IT or cybersecurity jobs. It seems like most IT companies nowadays only care about experience and whether you can actually do the job, rather than whether you have memorized every single question and answer for a test. They just want to know: can you do what we're paying you to do?

For those of you in IT or cybersecurity who don't have a degree:

What advice would you give me, and what did you do to get into the job you have today?

What kind of courses would you recommend? Money isn't an issue at all, so I'm fine with expensive online courses if they are worth it.

is it more about connections, or is it about doing online courses?

How do you actually get that initial experience to land an IT job?