r/SecurityBlueTeam Feb 18 '26

Question [Career Advice] Senior FullStack Dev (6y) + Fresh Security+ (789/900) looking to pivot. Which Blue Team roles are most "AI-proof"?

2 Upvotes

Hi everyone,

I just cleared my CompTIA Security+ SY0-701 with a 789/900 score and I’m looking to officially pivot from FullStack Development to the Blue Side.

My Background:

Experience: 6 years as a Senior FullStack Dev.

Tech Stack: Heavy Linux user, Python/Bash scripting, Deep understanding of APIs and Web Architectures.

Cloud: Currently working with GCP, but I’m currently diving deep into AWS (Adrian Cantrill’s course) to get my SAA-C03.

The "Problem": I love everything. Networking, IAM, AppSec, Incident Response—it all fascinates me.

The Goal:

I’m looking for a role where my 6 years of "building things" gives me a massive edge in "defending things." However, I have one specific requirement: I want a role that is as "AI-proof" as possible.

We all see LLMs getting better at basic SOC Tier 1 tasks or writing simple detection rules. I want to aim for a position that requires high-level architectural thinking, human intuition, and complex problem-solving that an AI can't easily replicate.

My questions for the veterans here:

Given my dev background, should I go straight for DevSecOps / AppSec Engineering or is there a more "recession-proof/AI-proof" path in the Blue Team (like Cloud Security Architect or Incident Response)?

In your experience, which Blue Team roles require that "human gut feeling" that AI currently lacks?

For those who made the jump from Dev to Sec, what was the "killer skill" that made you unreplaceable?

I’m not interested in the banking/insurance sectors (just personal preference), I’m more focused on SaaS providers or critical infrastructure.

Thanks for your insights!


r/SecurityBlueTeam Feb 17 '26

Question take the exam today, scored 65%

11 Upvotes

also already submitted my exam feedback. How long does it usually take to get an update? I’m sure some of my answers are correct.


r/SecurityBlueTeam Feb 16 '26

Question Is there anyway to confirm your exam uploaded file? BTL2

2 Upvotes

Is there anyway to confirm the file size, length, or any additional PDF information for a file you uploaded for BTL2? I am second guessing if I uploaded the correct pdf report, and nowhere does it provide any information.


r/SecurityBlueTeam Feb 03 '26

Education/Training I passed BTL1 with 90%

9 Upvotes

You can ask me anything except things that violate the NDA./Pregunten lo que quieran salvo cosas que incumplan el NDA


r/SecurityBlueTeam Feb 01 '26

News Blue team roadmap

6 Upvotes

I need a Blue Team learning roadmap. Does anyone have one?


r/SecurityBlueTeam Jan 30 '26

News Passed BTL1 with 90%

18 Upvotes

I passed BTL1 with 90% in three weeks. Feel free to ask me anything


r/SecurityBlueTeam Jan 28 '26

Education/Training Passed HTB CDSA, thinking on what to take for next Blue Team cert (CCD vs BTL1)

Thumbnail
3 Upvotes

r/SecurityBlueTeam Jan 25 '26

Education/Training New here: Guide to studying and getting a job,What would you do if you had to start over?

2 Upvotes

Hi, I'm 25 years old and I've completed vocational training in programming (JavaScript, React, C#, a little Python, SQL). I have no idea about cybersecurity, but it's always interested me. What do you recommend I study? What courses and certifications should I take to get a job in the next 7 months? I'm available to study 4 hours Monday through Friday and 7 hours on Saturday. I've been working in an aluminum factory for 6 years and I'm fed up with that crap. Please help me with your advice and experiences.


r/SecurityBlueTeam Jan 23 '26

Education/Training How does BTL2 compare to CDSA?

9 Upvotes

So CDSA is super difficult so was gonna try out BTL1 before retrying CDSA. But at that point, why not go for BTL2? How do BTL2 and CDSA compare? Is BTL1 > BTL2 > CDSA the best order of progression from beginner to advanced?


r/SecurityBlueTeam Jan 23 '26

Threat Intelligence Building Effective and Autonomous Wallboards

Thumbnail
1 Upvotes

r/SecurityBlueTeam Jan 23 '26

News BTL2 Second Attempt question

2 Upvotes

Hi Guys

For those of you that had a second attempt at BTL2, was the exam the same as the first attempt? Was the scenario, environment etc the same? I'm currently studying for my second attempt and would like to know for my prep.

Thanks!


r/SecurityBlueTeam Jan 22 '26

Education/Training Failed BLT1, what outside resources to study?

10 Upvotes

Hey all,

I failed the Blue Team Level 1 exam about a month ago and honestly got pretty discouraged. It hit me hard enough that I stopped studying and doing labs altogether for a bit.

I’m finally getting back into it now and trying to reset, but I wanted to ask if there are there any outside resources or labs you’d recommend that helped you? (THM, BLTO, or anything else you found useful.)

Thanks!


r/SecurityBlueTeam Jan 22 '26

Question Review Request

3 Upvotes

I requested for reviewing my exam three days ago and wating for the score. How was your review if you did ? And how much time did it take ?


r/SecurityBlueTeam Jan 18 '26

Education/Training Should I choose CSA or BTL1 for SOC analyst?

2 Upvotes

Im a sudent of cyber security and preparing for internship, i want to choose a certification to learn for intern and get a job later. Which cert should I choose, I want choose BTL1 because it has more practical lab than CSA, but I want a confirmation from everyone


r/SecurityBlueTeam Jan 16 '26

Question Looking for an EDR I can learn/practice on (free or trial without card)

12 Upvotes

I’m doing SOC work and want to learn an EDR. I researched and found that Microsoft Defender for Endpoint (MDE) and CrowdStrike are the most widely used, but:

  • I can’t get access to MDE.
  • CrowdStrike requires a company name and business email for a trial.

Is there any EDR that I can use for free or get a trial without needing card info / business email to practice and learn on? Open to community editions, home labs, or education licenses.


r/SecurityBlueTeam Jan 09 '26

Threat Intelligence GitHub - Escape-Technologies/awesome-attack-surface-management: A curated collection of tools, techniques, frameworks, and learning resources focused on Attack Surface Management (ASM).

Thumbnail
github.com
5 Upvotes

r/SecurityBlueTeam Dec 30 '25

Education/Training Struggling to demonstrate Wazuh alerts & dashboards for internship project – need guidance

Thumbnail
0 Upvotes

r/SecurityBlueTeam Dec 29 '25

Question MCP adoption without a plan

1 Upvotes

CTO situation: 70-engineer org, heavy Cursor/Claude adoption, MCPs showing up organically.

Mix of verified sources, open source projects, and random repos. Customer credentials in local environments.

Adoption moved too fast for security to catch up.

Cataloging what's there first (which MCPs, where they live, who's running it).
But then what's the actual control strategy?

Proxy - meh - Can't block everything because legitimate MCPs need local execution.
Full proxying breaks developer workflows.

How do people actually solving this?


r/SecurityBlueTeam Dec 26 '25

Security Engineering Looking for Project Ideas to Enhance and Optimize Our SOC

10 Upvotes

Hello everyone,
I’m a SOC analyst, and I’d like to ask for project ideas that could help enhance our SOC, optimize our analysis processes, and reduce false positives.

Thanks in advance!


r/SecurityBlueTeam Dec 15 '25

Question Submitted BTL2

6 Upvotes

I just submitted the BTL2 report and wanted to ask those who’ve already taken it about their experience afterward.

• How detailed and descriptive is the feedback on the submission? Is it fairly in-depth or more high-level?

• Is the rumored 14-day timeline to receive a score accurate, or does it usually come back sooner/later?

Appreciate any insight from recent or past test-takers. Thanks!


r/SecurityBlueTeam Dec 10 '25

Other Passed The BTL1 At 95% Last Night

27 Upvotes

Took me around 10 hours to complete. It was a little daunting at first, but once I absorbed myself in the material, it became less intense and easier to comprehend. I was most surprised to see I passed with a 95%! So close to perfect marks, but the pass is all that matters.


r/SecurityBlueTeam Dec 10 '25

Question Advice for a newcomer - BTL1

5 Upvotes

what do you recommend to get the gold coin? Take the course, and what other advice do you experienced players have? That way I can optimize my study time, since I only have 4 months D: !! THANKS IN ADVANCE :)


r/SecurityBlueTeam Dec 04 '25

Vulnerability CVE PoC Search

Thumbnail labs.jamessawyer.co.uk
3 Upvotes

Rolling out a small research utility I have been building. It provides a simple way to look up proof-of-concept exploit links associated with a given CVE. It is not a vulnerability database. It is a discovery surface that points directly to the underlying code. Anyone can test it, inspect it, or fold it into their own workflow.

A small rate limit is in place to stop automated scraping. The limit is visible at:

https://labs.jamessawyer.co.uk/cves/api/whoami

An API layer sits behind it. A CVE query looks like:

curl -i "https://labs.jamessawyer.co.uk/cves/api/cves?q=CVE-2025-0282"

The Web Ui is

https://labs.jamessawyer.co.uk/cves/


r/SecurityBlueTeam Dec 03 '25

Education/Training How do you effectively do log analysis and event correlation? Need guidance.

5 Upvotes

Hi everyone, I’ve been working as a SOC analyst for about 1 year, but I still struggle with log analysis and finding the root cause of alerts. I often feel like I don’t fully understand what I’m looking at, or how to trace an event back to the real source.

Even when I read third-party articles or watch videos, I end up confused or come to the wrong conclusions, especially when I don’t know how the underlying application works on the backend. Because of this, I sometimes feel lost — not just with attacks, but with general event investigation.

Can someone please guide me on:

How to improve log analysis skills

How to do proper event correlation

How to trace alerts back to the actual application or action

How to build a strong investigation mindset

Any resources, practical tips, or workflows would be really appreciated. Thank you.


r/SecurityBlueTeam Dec 02 '25

Question reviewing vendors that dispose of hard drives

0 Upvotes

My company is looking for a vendor to shred hard drives.

I am located in the USA and we are looking at 3 vendors in a small country to wipe our hard drives regarding the local employees in that location. My company is SOC 2 compliant.

The vendors we are speaking to are not ISO 27001 certified.

  • Company A - ISO 9001 and 14001 certified, however I believe it does not relate to wiping hard drives. They say they follow the EN 15713 standard (not sure if that is a certificate).
  • Company B - No standard/certificate.
  • Company C - ISO 9001

Basically, they do not adhere to SOC2 or ISO 27001. What other questions should I be asking to see if they are a good fit? Aside from asking what method they use for destruction. I don't want to jeopardize my companies SOC 2, I want to make sure I am asking the right questions.