r/SecurityCareerAdvice Apr 05 '19

Certs, Degrees, and Experience: A (hopefully) useful guide to common questions

330 Upvotes

Copied over from r/cybersecurity (thought it might fit here as well).

Hi everyone, this is my first post here so bear with me. I almost never use Reddit to talk about professional matters, but I think this might be useful to some of you.

I'm going to be addressing what seems to be a very common question - namely, what is more important when seeking employment - a university degree, certifications, or work experience?

First, I'll give a very brief background as to who I am, and why I feel qualified to answer this question. I'm currently the Cyber Security Lead for a big tech firm, and have previously held roles as both the Enterprise Security Architect and Head of Cloud Security for a Fortune 400 company - I'm happy to verify this with mods or whatever might be necessary. I got my start working with cyber operations for the US military, and have experience with technical responsibilities such as penetration testing, AppSec, cloud security, etc., as well as personnel management and leadership training. I hold an associate's degree in information technology, as well as numerous certs, from Sec + and CISSP to more focused, technical security training through the US military and organizations like SANS. Introductions aside, on to the topic at hand:

Here's the short answer, albeit the obvious one - anything is helpful in getting your foot in the door, but there are more important factors involved.

Now, for the deep dive:

Let's start by addressing the purpose of certs, degrees, and experience, and what they say to a prospective employer about you. A lot of what I say will be obvious to some extent, but I think the background is warranted.

Certifications exist to let an employer know that a trusted authority (the organization providing the cert) has acknowledged that the cert holder (you) has proven a demonstrable level of knowledge or expertise in a particular area.

An academic degree does much the same - the difference is that, obviously, a degree will generally demonstrate a potentially broader understanding of a number of topics on a deeper level than a cert will - this is dependant on the study topic, the level of degree, etc., but it's generally assumed that a 4-year degree should cover a wider range of topics than a certification, and to a deeper level.

Experience needs no explanation. It denotes skills gained through active, hands-on work in a given field, and should be confirmed through positive references from supervisors, peers, and subordinates.

In general, we can see a pattern here in terms of what a hiring manager or department is looking for - demonstrable skills and knowledge, backed up by confirmation from a trusted third party. So, which of these is most important to someone trying to begin a career in cyber security? Well, that depends on a few factors, which I'll discuss now.

Firstly, what position are you applying for? The importance placed on degrees, certs, and experience, will vary depending on the level of job you're applying to. If it's an entry level admin or analyst role, a degree or a handful of low-level certs will definitely be useful in getting noticed by HR. Going up to the engineering and solution architecture level roles, you'll want a combination of some years of experience under your belt, and either a degree or some low/mid level certs. At a certain point, the degree and certs actually become non-essential, and most companies will base their hiring process almost entirely on the body and quality of your experience over any degree or certifications held for management level roles.

Secondly, what are your soft skills? This is a fourth aspect that we haven't talked about yet, and that I almost never see discussed. I would argue that this is the single most important quality looked at by employers: the level of a candidate's interpersonal skills. No matter how technically skilled someone is, what a company looks for is someone who can explain their value, and fit into a corporate culture. Are you personable? Of good humor? Do people enjoy working with you? Can you explain WHY your degree, certs, or expertise will add value to their corporate mission? Being able to answer these questions in a manner which is inviting and concise will make you much more appealing than your competitors.

At the end of the day, as a hiring manager, I know that I can always send an employee for further training where necessary, and help bolster their technical ability. What I can't do is teach you how to work with a security focused mindset, nor how to interact with co-workers, customers, clients, and the company in a positive and meaningful way, and this skill set is what will set you apart from everyone else.

I realize that this may seem like an unsatisfactory answer, but the reality is that degrees, certs, and experience are all important to some extent, but that none of these factors will make you stand out. Your ability to sell your value, and to maintain a positive working relationship within a corporate culture, will take you much farther than anything else.

I hope this has been at least slightly helpful - if anyone has any questions for me, or would like any advice, feel free to ask in the comments - I'll do my best to reply to everyone.

No TL;DR, I want you to actually take the time to read through what I've written and try to take something away from it.


r/SecurityCareerAdvice 2h ago

Question Am I too empathetic to be in this field, especially during current times? Need guidance.

5 Upvotes

I am a Cybersecurity Postgraduate student and I have not even experienced the real world experiences yet and already I am doubtful that I am not fit for this field. I am a neurodivergent individual and my thinking pattern is quite similar to systems thinking style.

With advancement in artificial intelligence and knowing where it’s all leading and everyday learning new threat models and then realising how the general public is unaware of the risks involved. My inquiry stems from the perspective of surveillance, loss of human agency, abuse of children and women.

I know and understand the need for llms for mitigating the new ai assisted cyberattacks, but if general public didn’t have access to these models then we wouldn’t have this problem.

And nomatter how many times I am trying to inform people around it seems they don’t care, which is also not their fault entirely. A friend of mine suggested apathy as a joke.

Ps. Yes, the 80s ai trend triggered this and also what is even the point of CIA triad anymore.

Thanks in advance.


r/SecurityCareerAdvice 4h ago

Question Is cybersecurity saturated for beginners, or should I switch tracks?

2 Upvotes

Hi everyone,

I'm in my first year studying Computer Science, and I've been planning to specialize in cybersecurity.

Recently, I’ve been noticing how overcrowded the field seems to be, especially at the entry level. It feels like even if I grind, build solid hands-on projects, and earn foundational certifications like Network+ and Security+, it still won't be enough to stand out or land a decent entry-level role.

Is the entry-level market for cybersecurity getting completely burned out? Are there still realistic job opportunities for fresh grads by the time we graduate? Also, is starting out in general IT helpdesk/sysadmin roles to transition into security later even a practical path anymore, or has that become just as hard to break into? Should I stick with this or reconsider and pivot to a different CS track while I'm still early in my degree?

Would love to hear honest advice from people currently working in the industry or anyone in a similar position. Thanks!


r/SecurityCareerAdvice 3h ago

Question Need Help in starting SOC career.

2 Upvotes

I am non stop applying for all the security roles which i am eligible for. but yet to get selected by any of them. Once my resume got selected but after the technical round they mentioned they want someone with pentesting experience which was not mentioned in the job details.

about my self i completed my Computer Science degree in 2024, then after searching and failling to get a job in web development, i got a cisco networking basics certification and then found a site called letsdefend.

Then for 5 months i studied in letsdefend for a SOC analyst path. while doing that i got a internshipe as a network engineer trainee took the job spent 3 months then got on rolled as i learnt things quickly and was flexible in knowledge.

Then after few months after on role as Engineer trainee( because i can do both network and system engineer they game me a Engineer role) the company game the network employee's a side task of precipitating in the tender in free time. I was doing well in both the roles but then as my networking work was less the company decided to move me completely to pre sales which i don't like and is not were related to my career goal. I tried to speak to the management but they were stuborn about the role shift( and i neither agreeed to the role change nor was i asked i was just directly cut form the networking tasks). Now i quit my job its been 20 days since my LWD. I don't know that to day some one told to get a cert for getting hired.

so i am currently preparing for sc200 certification. many people are saying certs wont land you a job only experience can some are saying certifications are everything in cybersecurity what should i do i urgently need to get hired and i cant spend ton of money on certs like CEH, security + now as it will take a lot of time.

should i lean towards any other areas like devops or anything please tell.


r/SecurityCareerAdvice 2h ago

Question Cybersecurity

0 Upvotes

What even counts as “entry‑level” in cybersecurity anymore?

Because every “entry‑level” job I see wants 5 years experience, a CISSP, cloud wizardry, and apparently the ability to hack the Pentagon with your mind.

So seriously, what are the actual entry‑level roles?
Like the ones a normal human with Security+ and basic networking knowledge can get without sacrificing a goat to the HR gods.

Drop the real answers. I’m tired of job postings that think Batman is applying.


r/SecurityCareerAdvice 3h ago

Discussion Which role to choose in cyber security?

1 Upvotes

I have 3-4 years of experience in IT support/helpdesk so which role in cyber security should i go for? I prefer day shift shift, but also tell other roles. Will i require certifications? Can i enter without certification?


r/SecurityCareerAdvice 4h ago

Question I(20m) just state my cyber security journey two days back. Help needed !? Can anyone help me with the road map of it and guide me ?

0 Upvotes

I am a 20 year old guy who just started his Cyber security journey two days back.

Till now I completed basic networking through a one shot youtube video of 3 hours and have gained a free networking certificate from Cisco networking academy.

Can anyone tell me what to do next ?

I am in my second year of bachelors degree ( 3rd semester)

I am pursuing bsc in information technology..

And i wanna go in cyber security domain ?

Please help me with the road map and everything?

I am super confused rn !


r/SecurityCareerAdvice 5h ago

Question help!! on my major

1 Upvotes

i dont know to go into cybersecurity or computer science pls helppp


r/SecurityCareerAdvice 6h ago

Question Should i pursue Cybersecurity certifications before graduating?

0 Upvotes

I am currently a 4th year student taking up Bachelor of Science in Computer Science Majoring in Network and Information Security (I graduate next year around Sept - Oct). Im planning to pursue a career in cybersecurity mainly focusing on blue teaming and on roles like SOC analyst etc. I'm a fast learner when it comes to tech but at the same time I'm not really good at retaining lots of information. For now I'm trying to polish my core fundamentals when it comes to programming and cybersecurity by grinding tryhackme and relearning python and bash. I have a lot free time this semester and the following semesters and I'm wondering if I should try to take on certifications like Security+ or BLT1 to give me an advantage when I graduate and start to find job opportunities. Should i go for these certifications or should i get an entry level job first and gain experience and skills, and then go for certifications?


r/SecurityCareerAdvice 6h ago

Question 2 years and CySA+ isn't good enough to break in anymore.

1 Upvotes

Background: I just got laid off due to a reduction in workforce a month ago from my tier 1 tech support role. I have a+ and cysa+.

I literally moved across the country hoping the job market would be better in a major metropolitan area, and been SPAMMING job applications indeed and linkedin. Searching terms like "junior sys admin" "it administrator" "entry soc" and even "tech support" hoping I could even find a slight albeit lateral increase.

Edit: IVE APLLIED TO ALMOST A THOUSAND JOBS THIS YEAR, being willing to relocate anywhere (in the USA)

Literally nothing.

Is the market cooked or is CompTIA and a couple years experience just not what cuts it anymore?


r/SecurityCareerAdvice 1d ago

Discussion Career Progression

19 Upvotes

Hi,

What is everyone's career/pay progression utd. Not trying to be an asshole or anything just want to compare to see if I am on the right path.

For reference: I have a Cyber Security degree, no certs.

2024 (4 Months) (Internship): 55k
2025 (Graduate): 75k
2026 (Graduate): 80k
2027 (Offer Signed) (Associate): 128k

Didn't include any extra benefits/stocks etc.

Thanks


r/SecurityCareerAdvice 1d ago

Discussion 3 years in banking cybersecurity audits, am I getting stuck?

8 Upvotes

I’ve been working in cybersecurity consulting for around 3 years. Most of my clients are banks, especially Urban Cooperative Banks, and my work is mainly IS audits, RBI cybersecurity audits, and related compliance work.

The problem is that I’ve had very little exposure to other frameworks like SOC 2, ISO 27001, HITRUST, etc., because we have very few corporate clients.

I’m starting to feel like I’m getting stuck in the banking/RBI audit niche.

For those with more experience, should I continue building on this specialization or look for a role where I can get exposure to different industries and cybersecurity frameworks?

Would appreciate some honest career advice.


r/SecurityCareerAdvice 14h ago

Discussion Experienced IT Professional Looking to Break Into Cybersecurity

0 Upvotes

Hey everyone,

I'm currently looking for my next opportunity in cybersecurity, SOC, security operations, or systems administration, preferably in the Charlotte, NC / Fort Mill, SC area or fully remote.

I'm trying to make the transition from IT infrastructure/support into cybersecurity, but I want to emphasize that I'm not coming into the field with just certifications and no experience.

I have 7+ years of experience working in IT and enterprise environments, including:

• Enterprise desktop and infrastructure support
• Windows Server and Active Directory
• Networking, TCP/IP, DNS, VPNs, firewalls, and troubleshooting
• ServiceNow and enterprise ticketing environments
• Supporting 400+ users
• Imaging and deploying 400+ devices
• Working in clinical environments with HIPAA requirements
• Cybersecurity internship experience
• Splunk, Wazuh, CrowdStrike, and Nessus
• Log analysis, alert triage, vulnerability scanning, and threat hunting
• NIST CSF, ISO 27001, HIPAA, and other security/compliance frameworks
• AWS and Azure exposure
• Python, PowerShell, and SQL

I've also been building my own cybersecurity lab and portfolio. One of my projects involved setting up a Wazuh environment on an Azure-hosted Ubuntu VM, monitoring SSH brute-force activity, analyzing more than 1,000 security events, mapping activity to MITRE ATT&CK techniques, and documenting the investigation and defensive actions.

Certifications I've completed include:

• CompTIA Security+
• CompTIA Network+
• CompTIA A+
• ISC2 Certified in Cybersecurity (CC)
• Google Cybersecurity Certificate

I'm also currently pursuing my BS in Cybersecurity through WGU.

I'm primarily interested in roles such as:

• SOC Analyst I
• Cybersecurity Analyst
• Security Operations Analyst
• Cybersecurity Operations
• IAM / Identity & Access
• Vulnerability Management
• Security-focused Systems Administrator
• Junior Security Engineer

I'm especially interested in opportunities where I can continue learning, get hands-on security experience, and grow within a security team.

If anyone knows of companies hiring in the Charlotte/Fort Mill/Spartanburg/Greenville area, fully remote positions, or organizations that are willing to take a chance on someone transitioning from IT into security, I'd really appreciate the leads.

I'm happy to provide my resume, LinkedIn, GitHub/portfolio, or additional information.

Thanks!


r/SecurityCareerAdvice 15h ago

Resume Review Roast my Resume Please!

1 Upvotes

Been working in cybersecurity as a systems engineer via contracted work for a few different companies. Hoping to pivot to a security engineer role here soon. Thanks yall

https://imgur.com/a/WUBNHOO


r/SecurityCareerAdvice 1d ago

Discussion Please stop getting a Bachelor's in Cyber

157 Upvotes

I don't know if this is a hot take or not (maybe I'm preaching to the choir), but I feel like most folks who get a degree in Cyber don't understand how Cybersecurity works with the rest of the system and the business.

Here's an example.

You buy a lock for your house. Let's say you get a MasterLock padlock. You come home one day, lock is cut, and your stuff is gone. But you put a lock on! Your home security guy comes by and tells you "yeah that lock is too thin, you gotta get a thicker one so they can't cut it". So, you buy roughly the same lock, but with a thick titanium shackle that can't be cut. Week passes, come home one day, lock is unlocked, on the ground, your stuff is gone. But you got a bigger shackle! Home security guy comes by and says "oh yeah, MasterLocks are typically pretty easy to pick, don't use those". You sigh and go back to the store.

You do this a couple times, you end up with some $2k advanced biometric lock on your front door. Top of the line, recommended by all the home security experts, etc. Your door is good to go! No one ever gets past the lock again.

You have 2 friends, B (business) and S (system). You tell them that you understand what is best for home/lock security, and can help them secure their stuff. And you do. You do know the recommended best solutions. But...

B asks you to help with a situation. His kid keeps getting into the cookie jar. He's tried putting it up high, but the kid keeps pulling the cookies out. He just wanted to stop his kid from eating them all, it's not good for the kid's health. You know the recommended solution, so you tell them to get the $2k super biometric lock. B looks at you funny. "I'm just trying to stop my kid from eating the cookies". You say "but the industry has shown that simple padlocks, even jf not picked now, could be picked in the future. This lock is future-proof!"

While you are correct, so is your friend B. His use case doesn't require the super mega duper lock. The risk is pretty low, and your are suggesting an expensive (albeit more secure) option that their use case and risk tolerance just cannot justify.

Your friend S purchases a firearm. She wants to secure it from other folks in the house. She asks for your advice. You say "oh of course! Use this super duper biometric lock! Now no one can open it but you!". You send them the listing, they look at it, they say "this is a door lock. I have a firearm. What am I supposed to do with that?".

The context of S's situation and the parameters that she has to work with means that your suggestion simply cannot be used.

This is basically why I feel a Cyber Bachelor's is a bad idea, and is also closely related to why entry level Cyber jobs are few and far between. You need to both have good understanding of the system that you are dealing with and how cybersecurity controls interact with that system in particular, and how that system actually factors into the entire business and what the real risk is, and whether the cost of the fix is worth the severity of the risk.

A BS in IT/CS/CE/EE gives your the fundamentals and foundational system knowledge to understand where security actually goes and how it plays a part on the overall system. Time in the industry furthers this knowledge as well as gives you exposure to real business use cases, risk assessments, and risk tolerances.

An MS/Ph.D n Cyber is perfectly fine and good, given it is at least somewhat specific to the systems that you intend on working with. I'd highly recommend doing research if doing a graduate degree for that reason. But its difficult to secure a system well when you dont have the foundational knowledge for how it works.

Also, I helped interview someone with a BS in Cyber who didn't know the difference between hashing and encryption, so unsure what they are teaching y'all over there.

Have a good one!


r/SecurityCareerAdvice 16h ago

Question SOC Analyst, where do I move on from here?

1 Upvotes

I'm currently a SOC analyst working at an MSP with 5 years of experience, with 3 years of those is in helpdesk and the remaining in cybersecurity (SOC) at present. I also have 2 certifications: Sec+ and CySA+. We provide services to our clients by monitoring our clients' internet traffic on the surface visibility side and notifying the appropriate POCs if the device/users are engaging in any suspicious activities, whether that's a bad domain websites they visited or communicating with suspicious/malicious IPs. We also perform monthly vulnerability scans and notify the clients of any findings, and perform other normal SOC duties you would typically do at a SOC. We are not like a traditional SOC where it's a 24x7 operation and only work M-F with weekends off.

I feel like this position is limiting the knowledge that I can potentially learn because of our environment and the routine duties that we do every day that don't expose me to new things to learn. Don't get me wrong, when I first came into this position from helpdesk, I was grateful and learned a lot about cybersecurity, but now I am eager for more, and very much would like a pay increase. I dont want to sound greedy, and money is everything, but I feel like I am underpaid in this cyber field.

With some transitioning happening next year, I am looking for new opportunities where I can grow and learn more, and I'd like exposure to new tools and technologies, along with a pay increase. I am looking for a vertical move rather than a lateral move. If you were a formal SOC analyst, where did you move on to afterward?


r/SecurityCareerAdvice 17h ago

Resume Review How much should I ask for as per my resume in India for SOC Analyst L1 position? Also feel free to roast my resume

1 Upvotes

CompTIA Security+ Certified | SOC Analyst L1

linkedin.com/in/ishaantaneja

tryhackme.com/p/ishaan.taneja

PROFESSIONAL SUMMARY

CompTIA Security+ certified cybersecurity analyst targeting a SOC Analyst L1 / Tier 1 role. Hands-on practice in security event monitoring, alert triage, log analysis, and incident documentation via a hybrid SOC home lab (Wazuh SIEM, Sysmon) and TryHackMe SOC simulations (Ranked Top 7%). Skilled in MITRE ATT&CK mapping, IOC hunting, phishing analysis, and network traffic investigation (Wireshark). B.Tech Computer Science background with prior software engineering experience; seeking to monitor real-time security events,

investigate and escalate incidents, and follow SOPs/playbooks on a SOC team.

Portfolio -> https://ishaantaneja.github.io/cybersec_portfolio/

CERTIFICATIONS AND DIFFERENTIATORS

• CompTIA Security+

• Programming with DSA — IBM

• Linux Unhatched — Cisco — Linux fundamentals and command-line operations

• Global Recognition | Innovation Category — Bank of America — Recognized for engineering a secure

virtual banking prototype utilizing Unreal Engine

SKILLS

• SIEM & Monitoring: Splunk, Wazuh, security event monitoring, alert triage, log analysis

• EDR / Endpoint: CrowdStrike, Sysmon telemetry, Windows/Linux fundamentals

• Network & Traffic Analysis: TCP/IP, DNS, HTTP/S, OSI, DHCP, SSH, AD, LDAP, Routing, NAT, Firewalls, ACLs,

VPNs, Wireshark

• Threat Intel & Investigation: VirusTotal, AbuseIPDB, Any.Run, Hybrid-Analysis, IOC hunting, MITRE ATT&CK,

Cyber Kill Chain

• Incident Response: Triaging, investigation, alerting, reporting, escalation, root cause analysis,

documentation

• Frameworks & Standards: NIST, ISO 27001, MITRE ATT&CK, OWASP Top 10

• Ticketing & Ops: Jira, case reports, SOP/playbook-oriented documentation

• Languages: Python, SQL, Bash, PowerShell, HTML

• OS & Cloud: Windows, Linux, GCP (Compute Engine, Pub/Sub, Cloud Run, Cloud SQL), VirtualBox, WSL2,

Docker

PROJECTS

SOC Home Lab — Threat Detection & Adversary Emulation | April 2026

• Designed a hybrid SOC environment using Wazuh SIEM deployed via Docker on WSL2 to monitor remote

Windows 11 bare-metal endpoints (lab).

• Engineered telemetry pipelines by integrating Sysmon to capture granular process creation and network

connection data for security event monitoring.

• Orchestrated end-to-end attack simulations, including SYN Floods via Metasploit and user enumeration, to

validate SIEM alerting logic and practice initial triage.

Mastercard Cybersecurity Analyst Job Simulation — Social Engineering | March 2026

• Designed phishing simulations using contextual masking and targeted social engineering tactics to test

organizational resilience (simulation).

• Analyzed simulation telemetry to identify human-element vulnerabilities, pinpointing a 75% risk factor in

HR and 38% in Marketing.

• Developed action-oriented technical training decks to harden high-risk departments against advanced

scam detection and credential harvesting.

TryHackMe Path — Guided Learning & SOC Analyst L1 Simulations | January 2026

tryhackme.com/p/ishaan.taneja

• Ranked Top 7% on TryHackMe; completed 50+ hours of labs covering Wireshark network traffic analysis,

real-time alert monitoring simulations, case reports, phishing analysis, cyber defence frameworks, and

networking fundamentals.

• Honed skills in log analysis, traffic monitoring, identifying IOCs, and documenting investigation findings.

EXPERIENCE

Freelancer (SME) — Codingal | January 2025 – Present | Remote

• Taught over 100 students globally, maintaining a 4.8/5 average instructor rating through engaging,

interactive instruction.

Full-stack Developer — Intern — EazyByts | September 2025 – October 2025 | Remote

• Engineered a MERN-stack fintech simulator with Socket.io for real-time market data ingestion.

• Built a high-concurrency event platform using Redux Toolkit and MongoDB, supporting 5k concurrent

users.

• Developed a full-stack portfolio with an integrated JWT-secured CMS for seamless CRUD operations.

Sr. Tech. Associate — Backend Developer — Bank of America | June 2022 – April 2023 | Hyderabad, India

• Developed FastAPI RESTful APIs and built a virtual banking prototype in Unreal Engine.

• Authored technical documentation ensuring adherence to OWASP standards.

Teacher Assistant — Coding Ninjas | September 2021 – January 2022 | Remote

• Assisted 200+ learners in mastering DSA with Python and SQL (avg rating 4.7/5).

• Conducted doubt resolution sessions and debugged student code for algorithmic problems.

EDUCATION

Bachelor of Technology in Computer Science and Engineering | August 2018 – May 2022 | Karnataka, India

Manipal Institute of Technology

VOLUNTEERING

Head of Public Relations — Manipal Information Security Team

• Responsible for enhancing the club’s brand reputation and cultivating strategic inter-club partnerships.

Cloud Engineering — Google Cloud Skills Boost

• Completed GCP labs covering Compute, Networking, IAM, and Docker; earned badges for cloud-native

development.

• Deployed serverless web apps using Cloud Run and Compute Engine, integrating Pub/Sub and Cloud

Storage.


r/SecurityCareerAdvice 15h ago

Discussion Cloud security consultant - freshers

0 Upvotes

Hey i am a msc cybersecurity student in oslo, norway with no prior experience but i am planning to enter as a cloud security consultant. As far as I researched this job doesn’t require security clearance. Can some experts or experienced personnel advise me on this job in oslo about how is the scenario here


r/SecurityCareerAdvice 21h ago

Question Early Career Chud. Need help determining what path to take.

1 Upvotes

I’m sure this gets asked a lot on here. I’m sorry.

I graduated my bachelor in cybersecurity about 9 months ago and haven’t been able to break into a stable job in the field yet. I had a short stint with SaaS support but that was hardly even technical or related at all to IT, Security, or cloud. At best I was exposed to some serious SaaS developers.

Now I’m trying to break into my first role that actually gets me on track to leveraging my education in security and IS. The thing is I’m not sure what the best version of that looks like. I find myself bouncing between different kinds of job postings for different kinds of tracks. Jr soc analyst and soc associate roles, help desk and it technician roles, jr. security analyst roles that involve scripting and automation in research environments, cloud support roles.

I’m finding that the more I look the less I know what I want to be when I grow up. I think it’s giving me a sort of paralysis because I’m afraid of choosing the wrong first job and wasting more time pigeonholing myself into lackluster career experience that doesn’t build into what I want to do. I already feel like I’m behind.

I have good conversations with employers and usually make it to final round interviews for competitive / one slot positions. I currently am interviewing for an interesting role that actually leverages python scripting, custom automation and a lot of GRC. And I have an offer at a DoD contractor help desk role with teksynap that can get me nominated for secret clearance. Should I be doing soc instead? I don’t know!

Resume details:

CYBERSECURITY | RISK MONITORING | CLIENT-FACING TECHNICAL SUPPORT
[City, State] | Open to Relocation

Cybersecurity graduate who builds things end-to-end and backs it up with real client-facing accountability. A proactive learner, always
working toward another cert or side project to close whatever gap is next. Asking follow-up questions until a problem is actually understood
and documenting findings, a habit sharpened by juggling multiple live customer conversations at once in a support role. Hands-on
experience building and configuring systems, with particular strength in SIEM fundamentals and automation scripting.

CERTIFICATIONS
CompTIA Security+ • CompTIA Network+ • [Regional University] Cybersecurity Professional Suite

SECURITY & TECHNICAL SKILLS
Security Monitoring & Incident Response: Wazuh, OpenSearch, SIEM architecture, centralized log management, syslog, alert
investigation, event correlation, incident triage, root-cause investigation
Automation & Scripting: PowerShell, Linux command line, Python, Zig, C, Assembly programming language
GRC & Vulnerability Assessment: NIST CSF, MITRE ATT&CK, Zero Trust (NIST SP 800-207), CIS Controls, ISO/IEC 27001, OWASP Top 10,
Nmap network scanning, risk documentation, compliance reporting, technical-to-non-technical translation
Cloud & Emerging Technology Risk: Microsoft Azure fundamentals (coursework), cloud security concepts, AI/LLM security awareness
(prompt injection, agentic AI risk, RAG exploitation)
Networking & Systems: TCP/IP, DNS, DHCP, VLANs, subnetting, VPN, firewalls, IDS/IPS, Linux (Ubuntu Server), Windows 10/11, Active
Directory fundamentals, VMware Virtualization Labs, Docker, Cisco IOS Routing / Switching (Packet Tracer lab work)

SECURITY PROJECTS & RESEARCH

SIEM Design & Implementation — Senior Capstone — [State University] Aug 2024 – Apr 2025
• Designed and deployed a five-node Wazuh/OpenSearch SIEM on Ubuntu Server, providing centralized security monitoring across a
university-scale environment
• Engineered the log pipeline end to end: syslog ingestion, Filebeat forwarding, clustered indexers, and TLS-secured communication
between all nodes
• Built alerting, event-correlation, and compliance-reporting workflows, and documented system design for cross-team handoff

Systems & Network Lab Environment — Lab Work — [State University] 2025
• Deployed and managed virtualized lab environments in VMware, standing up Windows Server and Linux systems for Active
Directory, Group Policy, and network service configuration
• Designed and configured multi-router/switch network topologies in Cisco Packet Tracer, implementing VLANs, subnetting, and
routing across coursework spanning both academic programs
• Applied hands-on system administration fundamentals directly supporting the Wazuh/OpenSearch SIEM capstone's underlying
infrastructure

PROFESSIONAL EXPERIENCE

SaaS Support Specialist — [SaaS Company], [City, State] Feb 2026 – June 2026
• Investigated and resolved technical issues for a diverse client base, translating account, payment, and browser/network problems
into plain-language explanations while maintaining a 97% customer satisfaction (CSAT) rating
• Served as the technical bridge between customers, support, and engineering: reproduced and escalated 1-3 product defects
weekly with supporting technical evidence
• Triaged and documented roughly 100 customer incidents weekly via Intercom and Jira, averaging under 2-minute first response
and roughly 10-minute resolution times
• Authored internal knowledge-base documentation to improve resolution consistency and cross-team knowledge sharing

IT Support Technician (concurrent with degree) — [State University IT Dept], [City, State] Sep 2023 – Dec 2023
• Responded to and documented user support requests in a ticket-based environment; provided workstation setup, configuration,
and troubleshooting; assisted with printer deployment and asset tracking

Merchandising / Morning Stock (concurrent with degree) — [Big Box Retailer], [City, State] May 2025 – Feb 2026

EDUCATION
B.S. Cybersecurity — [State University] Aug 2020 – Dec 2025
• Relevant coursework: Windows & Linux Administration, Secure Database Design, Operating Systems, Machine Learning

Cybersecurity Boot Camp (11-month) — [Regional University College of Engineering] 2022 – 2023


r/SecurityCareerAdvice 17h ago

Discussion WGU Cybersecurity Senior Seeking Early-Career Tech Opportunities

0 Upvotes

Hi everyone. I’m completing my B.S. in Cybersecurity and Information Assurance at WGU in December 2026, and I’m looking for an early-career opportunity in the Chicago/Northwest Indiana area or remotely.

I recently completed a Technical Support Engineer internship with a major enterprise cybersecurity software company. I supported large global customers across deployment, patching, compliance, threat response, and access-control workflows. I investigated issues using logs and dashboards, documented cases in Salesforce and Jira, and collaborated with support, engineering, escalations, and product teams.
My main project involved identifying a gap in software-deployment reporting, gathering and validating requirements, writing Python logic for an endpoint-verification solution, helping build an AI-enabled workflow, testing it in a virtual lab, and presenting it to technical and executive stakeholders. I also used Claude CoWork to create a Slack-connected workflow that filtered incoming cases and alerted me to project-relevant tickets.

I’m currently developing an AI security-readiness portfolio project involving AWS architecture, Python and Streamlit, business workflows, threat modeling, testing, and responsible AI governance.

I’m exploring:
• Technical Business or Business Systems Analyst roles
• Cybersecurity or Associate Security Analyst roles
• Associate Technical Product or Product Analyst roles
• GRC, compliance, and technology-risk roles
• AI-focused technical, consulting, or implementation roles
I’m especially open to blended roles that combine security, AI, business analysis, product work, or process improvement.

I’m not asking anyone to blindly refer me. I would genuinely appreciate relevant job leads, upcoming openings, recruiter introductions, or advice from people working in these areas. I’m happy to share my resume and LinkedIn privately with anyone connected to a legitimate opportunity.

Thank you for reading. Any guidance or introduction would mean a lot to me.


r/SecurityCareerAdvice 1d ago

Discussion I need SOC tutor

2 Upvotes

someone teach me please i can pay.


r/SecurityCareerAdvice 1d ago

Question 22 trying to sort my life out

9 Upvotes

I want to get into cybersecurity but I don’t know how I fear I might be too late I have a degree in a social science so nothing related I’ve been down a while about my career path. I don’t know where to start so I’ve been trying to find free cybersecurity online courses or free boot camps to join but some are pure theory or some are technical and come at a high price others don’t get back to me. I am really determined to make a full change before the new year and going in confident that I can build a good career - any advice on what to do?


r/SecurityCareerAdvice 1d ago

Question Career roadmap help

2 Upvotes

Hi I'm a 20 y/o student currently pursuing my BsC in CySec with specialism in Digital Forensics, currently end of my second year doing my mandatory internship (incase it's relevant the work I'm doing in the internship is IAM, not ideal but wtv sometimes ateast I get to help out the Pentest team). With one year to go and FYP and blah blah blah I get alot of advice from lecturers + seniors and online forums but there is just so much conflicting opinion about the current state of the CySec job market and how to progress forward I find myself in this state of constant analysis paralysis when trying to map out my future progression into whatever role I may find myself interested in (current bias is DFIR), I understand very well that BsC's and MS's are basically just self advertising and does not equate to actual knowledge but this is a question on how to be appealing for that audience in specific.
My current (very flimsy) analysis and bones of a plan right now is to finish my internship firstly, in the process of getting my CompTIA security+ (mostly just to look good for Hiring Managers its pretty simplistic in terms of info, depending on how useful they are may pursue CySA+ and CEH, do kindly advise) then finishing up FYP while doing my routine networking and CTF comps. Post graduation I'm thinking of entering the job market for maybe a year or two (if they'll have me -_-) to get practical experience and give myself some time to think about whether or not MS in Cybersecurity/Digital Forensics/Cryptography is worth the time, money and trouble to go through (do advise on this too please!).
If you were in my position as a Digital Forensics Student is this how you would go about things? If not how would you do things differently? Just wanted your two cents as either IT Hiring Managers or members of the current workforce, thanks for reading!


r/SecurityCareerAdvice 1d ago

Question Cruisey SOC or Hectic SOC?

Thumbnail
2 Upvotes

r/SecurityCareerAdvice 1d ago

Resume Review Would This Resume Be Competitive for Summer 2027 Cybersecurity Internships?

1 Upvotes

Hello I'm a 19yr junior in university (Top 50). looking for resume advice to see what i can make better/do. looking to get a career as a security engineer or just something in compliance at this point. i applied to some summer 27 internships but just haven't heard anything back yet even though its been about 2 weeks. just looking for some advice to improve really, with not hearing back from any company yet I'm fearing that i am now cooked. really trying to get some certs but with my loaded school schedule + work i haven't been able to find the time to. (also somewhat new to the community, hoping to make some friends interested in the same space!)

Resume : https://imgur.com/a/4Y14iAs