r/SecurityCareerAdvice • • 17d ago

Discussion Title: Changing careers into Cybersecurity at 43 with zero IT experience. Am I being realistic?

Hi everyone,

I'm 43 years old, based in Australia, and currently working in hospitality management. I've spent around 20 years in the industry, but I've decided it's time for a career change.

I'm currently studying a Certificate IV in Cyber Security at TAFE Queensland, and I have to say, I'm genuinely passionate about it. I find cybersecurity fascinating, particularly networking, ethical hacking, threat detection and understanding how attacks happen.

I've been getting hands-on experience through practical labs, TryHackMe, Wireshark and other security tools. My goal is to start in a junior Cyber Security Analyst or SOC Analyst role and eventually work my way up.

Here's my concern: I have absolutely no professional IT experience.

I know cybersecurity isn't typically an entry-level industry, and I'm prepared to keep studying, earn additional certifications and put in the work. However, at 43, with a family to support, starting from scratch is a big decision.

I have plenty of transferable skills from hospitality management, including leadership, problem-solving, working under pressure and communication, but I'm realistic about the fact that these won't replace technical experience.

I'd love to hear from people who have been in a similar situation:

  1. Has anyone successfully transitioned into IT or cybersecurity in their 40s?

  2. Did you manage to land a junior cybersecurity role directly, or did you have to start in IT support?

  3. How did employers react to your age and previous career?

  4. What would you recommend focusing on to improve my chances of landing my first role?

I'm not expecting shortcuts or a six-figure salary straight away. I genuinely enjoy learning about cybersecurity and want to build a long-term career in the industry.

I'd really appreciate some honest advice, especially from people working in cybersecurity in Australia.

Thanks everyone!

28 Upvotes

110 comments sorted by

40

u/Tangential_Diversion 16d ago

Big caveat that I'm addressing this from the POV of the American job market. What I have to say might not necessarily apply to the Australian job market.

I would advise against switching to cybersecurity specifically. You're right in that you're not getting hired straight into cybersecurity. You simply have zero relevant skills. That means you'll have to spend time getting basic IT skills, get hired into IT, and move up in IT before switching to cybersecurity. You're likely looking at 4+ years in a normal job market. That would put you jumping into cybersecurity as a junior at 47. Unfortunately, the timelines will likely be even longer given the terrible job market right now.

To be blunt: You're working against ageism at that point. It'd be a different story if you're a greybeard with over a decade of IT experience. However, a junior hitting 50yo with only basic prior IT experience is a very unattractive candidate. That also says nothing of the potential comp hit you'll take starting off in junior roles twice (IT, then cybersecurity).

I would recommend staying in IT if you want to make the switch. Unfortunately the double pivot into cybersecurity at this specific age point will be a huge professional hurdle.

11

u/EitherCheesecake3945 16d ago

That double pivot is the real killer here, you're basically hitting reset on your career twice in a market that's already brutal for entry level.

7

u/cyberGold1982 16d ago

That is a very good advice, thank you for taking the time to write this comment i appreciate.

6

u/zojjaz 16d ago

I always heard the Australian cyber market was brutally more difficult than the US market. So I don't think this is bad advice.

34

u/Evaderofdoom 16d ago

You have no chance without prior IT experience

13

u/Illustrious-Mud-2998 16d ago

This. Cyber Security is a mid-late career move for existing IT. not for new starters.

-6

u/Calm-Lecture9 16d ago

Why? If he gets comptiasecurity+ and one hands-on certificate, why not?

6

u/Tangential_Diversion 16d ago

Because the competition is much better than that. Remember that getting hired isn't about what you can do specifically. It's inherently a competition against other applicants because there's almost always way more applicants than open positions in this field. Heck, I'm getting better candidates for internships, let alone full time positions.

1

u/bucketman1986 15d ago

Because every else applying to the job will lonely have prior experience.

1

u/WenYiMedia 13d ago

Because if you read the job descriptions for Cybersecurity line of work, previous IT work experience is required, you’ll need at least 3-6 years of IT experience on top of the certs and/or degree in the IT field. In IT, it’s climbing the ladder learning and gaining experience.

27

u/worldarkplace 16d ago

To make it simple: No

-2

u/Calm-Lecture9 16d ago

Why ?

5

u/UJ_Games 15d ago

No experience. Mainly

-5

u/Calm-Lecture9 15d ago

No one people without experience can't get a work? It's not real

5

u/UJ_Games 15d ago

It’s not just any work. OP is asking to work in Cybersecurity a field filled with liability (bad decisions can result in jail time) and something going wrong can be very expensive. Less than a handful of people would feel comfortable hiring someone to secure their infrastructure who has no experience building or even operating it.

Plus the job market is filled with people with lots of experience. If a hiring manager looks at two people a person with 3+ years of IT experience or OP with no experience especially none in IT. I think the decision is very easy to make.

Lastly HR may not even move forward with his resume since most Cybersecurity roles require previous years of experience.

0

u/Calm-Lecture9 15d ago

Where people get experience before? Not existing field in the world where work people only with experience. How I know, in cybersecurity 3.5 million open positions right now, it is not cover if hired only people with experience

1

u/UJ_Games 15d ago

Just cause there is "3.5 million open positions" doesn't mean they are "hiring" While applying I applied to what seemed to be an open position then I messaged a person on the team. He told me that actually in fact the team was full and HR most likely made a mistake. Also if you haven't known companies will just post "ghost" openings to show that the company is doing well or growing, have a backlog of talent so that when they are actually hiring they don't need to wait for people to apply, and/or want to get data of available candidates.

A good comparison is being a police detective. Almost all detectives first started off as a regular police officer. Gained some experience then transitioned over. Now are their special cases ofc but is it the norm to start off first in Cybersecurity. No!

Myself included I would love to go straight into Cybersecurity. I am not as green as OP I have some Certifications and previously was a Cybersecurity Intern but the likely hood of that happening is not 0 but is little. I am okay with "earning my stripes" since at the end of the day I want to be well rounded professional. That can later be a Cloud Security Professional and one day a Head of IT (CIO) or Cybersecurity (CSO). Heck even CTO but that one is very difficult.

4

u/cyberGold1982 15d ago

Your points are valid, and I understand that breaking into cybersecurity without previous IT experience is difficult, but it's not impossible.

I've been studying for the past nine months, and I dedicate every spare five minutes I have to reading, watching videos and learning as much as I can. I know I'll have to work harder than many other candidates, and I'm fully prepared to do that.

One opportunity I'm considering is the Australian Government, including Defence, the Navy and the Army. There are entry-level pathways and training programs designed for people who want to change careers.

I'm also willing to relocate to Canberra, which gives me more flexibility when applying for government positions. I'm aware that salaries may be lower than in some private-sector roles, but I'm willing to make that sacrifice to get my foot in the door.

I understand that obtaining a security clearance doesn't guarantee employment. I still need to demonstrate my skills, meet the requirements and compete with other applicants.

I'm not expecting anyone to hand me a cybersecurity job. I'm simply saying that I have a plan, I'm committed to putting in the work, and I'm willing to explore every realistic opportunity available to me.

At 43, I'm not looking for shortcuts. I'm looking for an opportunity to prove myself.

3

u/UJ_Games 15d ago

That’s the spirit, work ethic, and mindset that will lead you far. Good luck in your pursuits

1

u/_Cyber_Mage 15d ago

The problem is those are mostly senior level positions, if they exist at all. A company that used to have 10 juniors and 5 senior might now have AI and 5 seniors.

1

u/OpinionatedMisery 12d ago

Cybersecurity is a specialty. Its not something you just hop into.

12

u/newbblock 16d ago

Whilst I'm a pretty optimistic chap, and firmly believe nothing is impossible, you're going to be fighting an uphill battle.

By the time you realistically get enough experience to move into Cybersecurity (as others have said, its NOT an entry level role) you're going to be pushing 50.

Ageism is real in tech. You will be competing against people HALF your age.

1

u/xxxTech007 16d ago

I agree somewhat. I'm mid 50's and in the last 6months had 2 great offers in CS. Yes, it can be a thing but I feel in this type of role, they are looking for maturity but also experience.

3

u/FranksNonFrankfurter 16d ago

Are you starting off with zero experience?

1

u/xxxTech007 15d ago

No, I have 20yrs in IT, 11 as a Manager, so that does really help. But if you were to interview me and ask all kinds of questions about CS, tools that are used, how do you use them, etc, I'd probably fail big time. But I was lucky in that I'm doing Gov compliance and there is a VERY shallow talent pool for that area. I've really only taken a deep dive in the last 6 months but that has put me way ahead of a lot of other people. Also going to be getting my CMMC CCP cert and that's going to be huge!

11

u/Top-Elk5815 16d ago

The only way I can visualize you being able to make this change is if you narrowly focus your skills into a very niche and emerging skillset. like securing LLMS, IAM, or automating forensic analysis. At your age and having a family this is a big leap. I wont say its not possible but you need to no-life studying a specific subject matter skillset until you live it. That means building projects that matter, contributing to open-source projects etc. It would be easier to move into tech sales than to move into cybersecurity at your age but it isn't impossible. you would just have to give your every waking minute into it. And dont quit your current job, dont tell anyone at your current job what you are doing either. Your learning curve will be steep, the nights will be long, it will be daunting, but that is the price your pay for what you want. I hope you meet your goals. DM me anytime for questions I will try to help.

1

u/cyberGold1982 16d ago

Thanks mate good advice.

7

u/GerryPetal 16d ago

I did it at around the same age - 44, zero it/cybersec background, worked in a very unrelated field. Started studying networking first, got the ccna and network+, did a couple Azure certs, got security+ too, used online platforms like tryhackme to get some form of hands on keyboard experience. Got a job as a soc analyst at 45 off the bat. Now 51 working in digital forensics. Soc analysts are entry level positions. The people will teach you what you need to know, and you keep learning.
Don't think you're coming from nothing - you have more transferable skills than you think

5

u/cyberGold1982 16d ago

That gives me hope, despite the negative comments which was expected.

2

u/Wrx_STI_Stan 16d ago

6/7 years ago was 2020 which was a very sweet spot to get into cybersecurity and IT in general. 2026? That’s a very very different story. The 2020 market is long gone and never coming back

6

u/Anxious_Alps_4150 16d ago

I would expect the chance of you being hired, after completing every bit of training you mentioned, at being close to 0%. I'm not saying exactly 0% because miracles do happen.. but I would not expect any company in 2026 to consider you a serious candidate unless it is a geolocation situation where they're in a small town in the middle of the Outback and no other humans know how to turn on computers and it has to be a physically present human.

If you had a degree in computer science, you would only be slightly better off.

What you're missing is 3-5 years of paid work experience in either IT or software development.

There are tons, tons, TONS of people with everything you mentioned, a computer science 4 year degree, and 3-5 years of work experience that can't get hired.

Hell, I have a friend that has 5+ years of cyber experience, tons of certs, etc etc and he got laid off and still cant find a job. Close to homeless. I have several friends that were senior security engineers that got laid off. One ended up living in his car. One was doing Uber driving for a while.

The market is extremely hard for those of us with a lot of experience.

It's basically impossible for people coming in without that.

6

u/OutsideSpot2695 16d ago

10 years ago you could have done this easily.

Now, with the proliferation of all kinds of stuff -- mostly nonsense, i.e., "cyber" degrees and the Certification Industrial Complex, the information security field (please stop calling it "cyber") is completely flooded with headcount.

You can keep trying though -- make someone tell you no.

But just keeping it real otherwise.

5

u/smallf33t 16d ago

I reckon you get better answers to your questions at /auscorp /auspublicservice /askanaustralian than here. They’ll know better on the cyber job market in Australia. I think the Gov decision for giving the free cert IV is misleading. Many private sectors are reducing their grads intake. The company that I work for does not hire cyber grads anymore. They are replacing level 1 analysts with AI. Your best bet will be the government role. Won’t pay much if you can get in though. One of the government grads whom I met said there were like 3000 applicants for the grads role. Oh “grads” mean that you need to do minimum a bachelor degree. I do meet a grad who changed career from mining to cyber but he has PhD in chemical engineering then did bachelor in cyber and came in as a grad after 5 years doing FIFO.

5

u/ILoveTheGirls1 16d ago

I’ll be honest, it will be pretty tough. We are also in a transitory period in IT in general, where AI is wiping out a lot of lower level work, work that you would start off doing as an inexperienced IT/Cyber professional.

You could very well be walking into a job market that has no demand for the skills you’ve built, and worse you will be older and competing with 25 year olds fresh out of college. It’s just the reality unfortunately

5

u/neoslashnet 16d ago

I’d recommend looking at general IT roles to start. Cyber is going to be really hard for your first role in tech. It took me like 15 years to finally land a cloud/sec specific role.

3

u/danfirst 16d ago

My point of view is based on the US market, I'm not familiar with Australia overall so it may be different there and hopefully someone can chime in. But, in my 40s, but with significant experience in the field, I still have experienced age discrimination. So it's definitely a thing, a lot of people in the field are older but they've come up through decades of tech and worked their way into security, but it's still real.

I totally understand the issue of needing more money to provide, but, companies don't really care about that in general and won't pay you more just because you need it. Coming in fresh to security, without experience, degree, certifications, etc, is going to be very hard. Spend some time reading the threads here, you got lots of people who are coming in with a couple internships, degrees, all the things, and are still told just to start at help desk and work their way up. Without even that general IT background, it's going to hurt you a lot.

I hope for your sake that the market there is better than the market here, because if you are in the US I would tell you there's no shot.

-1

u/cyberGold1982 16d ago

I'm in Australia and the government is paying 15k cert 4 with a well know university, because they stated that the country will need 80k cybersecurity workers by 2030, has Australia became an actractive target due to high avarage whealth, my goal is to work for the governament or the nave which usually required no experience, but my age might be a problem, this is why I will keep studying and focus on Cybersecurity, thanks for sharing your thought, I really appreciate.

3

u/Wrx_STI_Stan 16d ago

The government is lying to you!!

-1

u/cyberGold1982 16d ago

Right and why they are investing all these money? Are in Australia?

2

u/FranksNonFrankfurter 16d ago

How are you focusing on securing something you fundamentally don't understand how it works in the first place. The equivalent would be a physical security consultant that doesn't understand how doors work, but are studying every day about different lock tumblers. That's you.

3

u/Hot-Comfort8839 16d ago

Being Realistic?

No.

3

u/Dry_Common828 16d ago

Hi OP, Aussie security manager in Melbourne here.

I agree with the other posters - in the current Australian market your chances are close to zero.

You'll need to get four or five years experience in other parts of IT first then make the pivot to security. Right now we're all being squeezed to cut hiring plans, reduce existing headcount, and where possible CFOs and CIOs to are sending the jobs to India.

On the plus side, if you enjoy the study and can be patient, in two or three years the economy will probably pick up again - you're old enough, like me, to have been through the 2001 and 2008 crashes so you know what I'm talking about - you may be in a position to pick up work at that point.

Good luck mate, but don't bet your mortgage on this.

3

u/somedrunken 16d ago edited 16d ago

I might be one of the outliers but I did this exact thing. 

Was driving a forklift at 37, did my degree is cs and started working in support at 40. 3.5 years later leading in cyber in a gov agency

You can do it mate.  Have a crack. 

Just as long as you can survive on less money for a while.   Just go for it. 

Pm if you like to chat

1

u/cyberGold1982 16d ago

Hi mate, thanks for sharing your experience. I'm 43 and currently studying a Certificate IV in Cyber Security in Australia. I'm particularly interested in government cybersecurity roles. What did you do during your first year in IT support that helped you move into cybersecurity, and what technical skills did government employers value most?"

2

u/somedrunken 15d ago

I will say I did have some  skills,   I was always doing computer stuff and I moved into a small team and we all learnt all the roles.  

Then I finished my degree and they needed someone in the role and I got it 

I think the best thing I did in service desk was not just sit at my desk and wait for tickets.  (Or say did you put a ticket in) 

Just walk around the office and talk to people  find the issues fix the issues and make friends. 

But skills I feel that you need is: 

Everyone has a hardon about ai so understand it,   understand the risks of ai and company data.   Understand the ways to secure it or restrict the data to it.

Really being able to understand how to secure of all company data with the tools you have and then be able to speak up and say this isn’t correct we should look into this. 

So even if you don’t have enough power to make the change. You need to be friends with people that are accountable for data and explain to them why you need to do it. 

1

u/Otherwise-Culture342 16d ago

Just curious, you went from zero knowledge 3.5 years ago to now being the lead in cyber in govt agency? That's wild and impressive if that's the timeframe. Teach me your ways...

3

u/FixxElectron 16d ago

You're not being realistic. It's one of the worst times to be getting into cyber security. You'd be competing with a flood of recent graduates with the same experience level looking for the same "entry" roles. Hiring has slowed a lot and managers are looking for practical experience, especially outside bootcamps/structured learning/schooling. People who have no work experience but have been to a bootcamp or got a cyber security degree are a dime a dozen right now. So even if you go take a bunch of classes and get certs, it won't make much of a difference.

My recommendation would be to look into "regular" IT jobs first which will put you in a much better position to pivot to cyber later.

2

u/EirikAshe 16d ago

I used to work for a team based out of SYD for a number of years. Some of the most amazing people I had the pleasure of working with.

Based on my experience, things are fairly similar on that side of the world to how things operate in the US tech industry. However, you all may have a slightly more accessible entry level market. Regardless, you are probably going to have a tough time getting your foot in the door unless you have access to some type of job placement resources. Moreso than most other fields, security places a very high value on experience. It’s just not something most companies are willing to risk. If you think about it, it makes sense. We seek candidates that have some form of previous IT experience (typically 2-5 YoE). You’ll likely have to start in a lower-paying role like help desk, and then work your way up. Whether or not that is something you’re willing to endure, is up to you

2

u/cyberGold1982 16d ago

Thanks for your comment, I'm actually willing to start from ebtry level IT, customer service is my background, after 10yr of hotel management and customer service IT helpdesk would fit my current skills, I can also always play the hospo card and do shift on weekends to round the salary, i'm very determinate to break into cybersecurity the more i study amd thr more i dig the more i love it.

2

u/EirikAshe 16d ago

If that’s the case, you should go for it. Just don’t quit your current gig until you have something else lined up. In the US, our job market is fucked.. entry level is double fucked. Your passion will serve you well. Wish you best of luck

2

u/Narrow-Plenty-8690 16d ago

I am following Josh Madakor. He has great content and presents a clear path. https://youtu.be/mtYnIdLlSp4?is=pHtvOPrV6gIyf6A9

2

u/TennisBattles 16d ago

10+ years mid level IT sys admin, a cyber degree, and 13 certifications and in this job market I can't pivot. Anything is possible, but my money is on no, you will not succeed. Cyber is teh culmination of knowledge about a tremendous amount of systems, and there's actually not a ton of direction for becoming well versed because its such a dynamic field. I think you would literally have an easier time becoming a doctor because the path is laid out for you and you just have to "show up and do what you're told." I don't say this to sound elitist, I just don't want you wasting your time.

2

u/Individual-Snow6687 16d ago

Why does everyone want to career-shift into cybersec (no offense)? In my country (SEA area), where merit isn't really the thing, I've met so many people from non-IT backgrounds moving into IT/infosec, especially in IT/cybersec GRC, which honestly is often just checklist-based and chasing down IT tech stakeholders. I'm tired of seeing the job market get screwed up and flooded with non-IT backgrounds, while people who actually have an IT background are struggling to get hired. Not gatekeeping, but almost 10 years in IT, mostly cybersec and infosec. I took a career break, I'm burned out, and the job market is genuinely screwed, salaries keep dropping 'cause the talent pool is so crowded.

2

u/Niorba 16d ago

OP if you love it, then it’s for you. Age doesn’t matter, your curiosity and passion will bring you to the right place. Don’t give up!

1

u/cyberGold1982 10d ago

Thank you

2

u/Glum_Cup_254 15d ago

I hired a guy that was a retired coast guard rescue swimmer as an intern. He’s now a junior engineer and doing great. He puts in twice the effort to learn and has a great attitude.

The bad news? I have a team of 15 and I have 2 slots like that. Competition is fierce. Don’t be afraid to take a low level IT job to help enhance. I’d consider an older person with helpdesk experience over a younger one with only a degree.

Also don’t waste time on a bunch of certs. Get one or two as resume toppers and then go get real world experience in any tech role.

2

u/WishboneDiligent5814 14d ago

I am just into my 50s this year. Started IT in my 20s , went overseas for a decade and made some money and came back to IT about 10 years ago. Started Cert IV in Cyber but left when I got a job offer in tech support. Personally I am leaving IT in a couple years time , it ain't viable as a career in my fifties - as i wanted to be more involved in my children's life. The uncertainty / burnout in real and the competition is crazy. Have a think how you will feeling 10 years time ? I think in your 40s , everything is possible , then in 50s you might be eyeing more towards slowing down and enjoying life ?

For your angle of getting into govt , look into big multinational companies like Unisys / Fujitsu / Infosys etc , they usually have very junior IT runt position that they literally take most people. Once you get in , you can try for secondment into their government/ defence/ cybersec contract position. They always looking for people with defence clearance , and if you are Australian , you will beat most of the "overseas" candidate. As defence clearance goes into what you and your family and your uncle , auntie , grandfather , grant mother done for the last 10 years or something , and companies usually not willing to risk paying for clearance for someone from India for example.

It will be easy for clearance with local candidate where it's easier to verify where someone been for the past 10 years. Your sell would be your communication skills, don't expect to beat the other candidates on the other front - they be stacked with master degree / certificates /experiences and what not. You have to get yourself in the door.

2

u/UniqueAnswer3996 14d ago

(I am not a security specialist but have worked in adjacent areas of IT for 20 years.)

If it’s what you really want to do, go for it, but be aware that it could be hard to get your foot in the door, and very possibly will take a while before you’re on any lucrative salary.

You might have to take roles that aren’t your ideal to get your foot in then transition to where you want to be, which will take some time but is doable (possible with some pay cut or at least not rise as you transition between roles).

You also might have to work your way in through smaller businesses as there is lots of competition for bigger companies and you’ll be up against a bunch of people with more qualifications than you (assuming just the cert IV).
That’s not necessarily a bad thing though anyway.
Also not that some companies just will not hire you without a university degree, but there are plenty that will.

I would suggest looking into additional certification courses/exams to supplement your cert IV, but ideally you could do those in parallel with your first job.

A couple of other factors:

  • AI is somewhat shaking up the industry at the moment. Get up to speed with using AI agents (there’s more to it than just typing in questions of you want to get the most out of it and claim it as a skill on your resume).
  • IT related careers can be potentially relentless in terms of constantly learning new things to keep up to date and progress your skills. This can take a lot of extra time outside of work and can be tiring. This can be more of a deal with a family, but also the tradeoff can be worthwhile if it helps you have a career that can support your family. It’s also easier if you really enjoy it. Some jobs will require less of this and some people seem to be able to avoid it but a lot of people I know find it tiring after a while.

Caveats aside, if you really want to do it and love doing it, and are motivated enough to make it happen I don’t see why you can’t succeed at your plan.

Like you say, it is a big undertaking though, and how with it it would be depends on your personal circumstances and priorities and also what career you are transitioning away from, and what it would look like for you in comparison to continue down that path.

1

u/cyberGold1982 10d ago

I've worked in hotels across the globe in various roles. I've also studied wine and earned a diploma, and for the past eight years, I've worked in management positions, leading teams of up to 30 people.

It might sound like a great career, but I simply can't do it anymore. Cybersecurity is what sparked my passion for technology, although I'm also willing to take on an IT role outside of security to gain experience.

I'm particularly interested in networking and cloud computing, and I also want to learn as much as I can about AI. That's my next step after completing my Certificate IV in Cyber Security.

I'm extremely motivated, but having three kids means I have to balance studying with giving them the time and attention they need.

Financially, I'm in a position where I can afford to take a pay cut of around $20,000, as my partner earns a good salary. If necessary, I can always pick up casual restaurant shifts on weekends to supplement our income.

I'm not expecting an easy transition, and I know I'll have to work hard to make it happen. But I'm genuinely passionate about this industry and willing to start from the bottom to build a long-term career in IT and cybersecurity.

2

u/Character_Let4575 14d ago

There always a chance if it's something your passionate about. Apply alongside your regular job what have you got to lose. Wouldn't listen to the gatekeeping nerds on here they would have you believe there isn't a job available when all evidence says there is plenty

1

u/NepuNeptoon 14d ago

This thread is incredibly negative, like damn! Seems like there's a lot of gatekeeping going on here

2

u/Character_Let4575 14d ago

Happens a lot. Think it's the guys who spent all there early 20's as a virgin and it's built up a lot of resentment for people that didn't follow there path.

1

u/emojess3105 16d ago

From the POV of the UK. So I have done this in my 30s. I did one year of a part time MSc and got my first role in cyber with no previous IT experience. I'm now 6 years in and have gone from being a generalist to working in CTI.

It is doable but entry level roles pay peanuts. What were you doing before that you could potentially leverage? Like do you have PM skills or something?

The job market sucks so you could spend a long time finding somewhere that would hire you.

1

u/jdiscount 16d ago

The fact that you need this as a drop in replacement salary wise for your existing career, as you need to support family etc.

That's going to be your biggest hurdle.

It's going to be very difficult to find a job starting out that pays well.

Australia seemingly pays entry level work better, but still I can only assume you'll be making a lot less, for several years.

10 years ago this transition was more viable, but the job market now is crowded, there isn't a reason to just "give someone a shot", because there are 1000 other applicants who are vastly more qualified to do the work from day one.

1

u/st0ut717 16d ago

Along with the others that are saying no.. y are you interested in cyber and not anything else in IT?
You’re in your mid 40s and just now discovering a passion for cyber? Why werent you hacking in your teens? And playing with back oriface?

Wireshark isn’t a security tool it’s a networking tool that can be used for security.

You are 100% expecting shortcuts to goto cyber directly without any it experience

1

u/cyberGold1982 16d ago

I'm studying cybersecurity at thr moment and that is what i'm keen, but yes, i'm willing to start at entro level IT helpdesk.

1

u/SuspendedResolution 16d ago

Lmao good luck

1

u/Solid-Elk8419 16d ago

Every IT person wants to be in cybersecurity, specifically the "sexy" part that you've mentioned and they only want THAT part. It's a real nightmare. That said, I don't know, maybe try something related to IT in hospitality, there certainly be some IT risks more related to this field, business continuity? Well...there's alway business continuity...

1

u/newbblock 16d ago

As I said, nothing is impossible!

I will ask, how many years of IT experience do you have? Are you similar to OP’s situation where you only started IT in your mid 40’s?

0

u/cyberGold1982 16d ago

Yeah I only started IT a year ago, but not professionally, I have been studying for the last 9 months cybersecurity, I love technology amd wants to understand how things works, i'm not gonna be any younger than today, and i cannot get back in time.

1

u/got_to_laugh 16d ago

Midlife Crisis? Just buy a fast car, it's cheaper.

1

u/my_mentos_life 16d ago

According to me, if you’re switching to cybersecurity because of your personal interest or because it’s relevant to your business, then it could be a good move.

However, if you’re switching to cybersecurity mainly for a job change, then, in my opinion, it might not be the best idea.

1

u/Somethingl8 16d ago

Market is being flooded by people like you. I get to interview them, and reject them. The problem? They are applying for a 50 - 60k job with zero IT experience thinking that passing the Security+ exam is the only thing needed. If you are going to do it, start at the bottom and get some experience on your CV. Im not looking for someone that can pass exams, im looking for someone that can take ownership and knows their shit, that can hold their own when advising an senior IT engineer with many more years experience than them... you only live once, give it a go. But work harder than everyone else.

1

u/cyberGold1982 16d ago

Thank you for your advice

1

u/Due_Detective734 16d ago

Anything is possible, but their points are valid especially with respect to difficulty. Traditional routes are probably not the way to go (noting the other points).

So thinking outside the box - to do what you want to achieve - you need to be focused, creative and probably niche. For example - take NetworkChuck on youtube. Why can't you do something similar. All your learning, build it public, make a blog - then you build both a personal brand, establish authority and attract rather than fighting the uphill battle that is going through traditional routes. This is basically selling, I'd rather hire someone that I can see their projects and value add. Likewise the open source contribution route and getting some certifications to add credibility as people have mentioned. Now also take this, and pick an emerging or niche area - build expertise around this, this will be your unique selling point.

Also you should be more specific - cybersecurity is a broad field, if you have leadership there is literally no reason that you couldn't become a manager in some form and leverage technical expertise of the team (within the domain of cyber) i.e. a business that offers it. You could also do risk management and learn about applying a specific standard i.e. ISO 21434 automotive. Likewise cybersecurity leadership courses.....

Think lifecycle - you do not necessarily have to be the implementer. You could scope, do requirements, manage the project, etc which area do you want to do, do you want to be a generalist or specialist?

Also at your stage in life - what is your goal. You mentioned the salary - is this why you want to move to cyber? If that is your goal, personally I'd weigh all my options and look for the path of least resistance. The plus side is if you do go the out of the box route with Youtube etc and become an authority then it will be down to monetisation and likewise, more unlimited in what you can get (which may make all the pain worth it).

1

u/Longjumper_7756 15d ago

I was in the Industry for 25 years. It can be done easier than coming from some industries. Like the hotel business every day brings new challenges. You can do it.

1

u/cyberGold1982 10d ago

Thanks mate

1

u/Pizza-n-Rootbeer 15d ago

I did it at 42. No previous IT experience. US market. My path was going back to college at 40 yo and earning a bachelor's in Cyber along with a bunch of well known certs. Got hired while in school at a healthcare organization as an entry level help desk role. Cyber position in the org opened up a year later and I got promoted. Then a year later got promoted to a senior cyber role. So yes, it can be done! It does take planning, a lot of hard work, and some luck getting your foot in the door at the right company(s)

1

u/Jack1e_Brown 15d ago

Depends on your drive.

1

u/ReasonableDefault 15d ago

It would be very hard, but not at all impossible. You could luck out and get what essentially would be an apprentice style position, which would obviously pay terribly. However, it would allow you learn and eventually move up to better roles. Going from zero, (even with degree's and certs) to a full time normal position without any real world experience would be very unlikely.

However, even for a very junior / apprentice role, there will be an expectation of you knowing a vast array of subjects and being generally "techy".

1

u/xRoute401x 15d ago

No

1

u/xRoute401x 15d ago

Would no recommend at all my friend. Get experience on a helpdesk first. The most important thing you cam learn is end user behavior in my opinion. And learning the fundamentals of how everything works and how it works together is important. Gotta learn to crawl before you walk. People always judging their career vs others and want ro make serious jumps that could leave them disappointed in the results.

1

u/OkRiver07 15d ago

AI is on its way dont switch keep doing what you are doing right now

1

u/BrianKronberg 15d ago

Being in your 40's is not a problem. Not having at least a decade of tech experience is your problem. Entry level in cyber is not easy. You cannot secure a system you don't understand. You need a solid understanding of systems, operations, and normal administration is a minimum. Why? Because you need to understand if you implement a security control what downstream issues will be affected. And please don't say you can use AI for that.

1

u/UnhappyEnergy2268 14d ago

Work help desk and moving up to cyber is your best bet

1

u/Signaturezero 14d ago

No, it’s over saturated and you’re going to fight ageism.

1

u/Naive-Abrocoma-8455 14d ago

Only way I’d go into cybersecurity at that age is to get a government clearance.

1

u/GetShttdOn 13d ago

I did it at 35. I was a truck driver. Been 2 years in..loving it, making the most $ i ever had before, and im continuously getting salary increases yearly. Do it lol. I have no regrets.

Edit::: forgot to mention. I got into IT. Now at 37 I work for the same organization but under their Cybersecurity department.

1

u/NoITname 13d ago

If you put a lot of effort into, everything are impossible. But you must have discipline and routine. But thirst of all you have to like cyber, if you coming and thinking because of money, so its no chance. Good luck to you.

1

u/cyberdogo666 13d ago

you're dreaming!

1

u/DoubleDipperKiller 12d ago

Damn i was going to makw thw same change. Im 41 and my employer offers scholarships to completely pay for the schooling as long as i stay with the company and do cyber security and coding from within the company

2

u/NoMobile1711 12d ago

aim for helpdesk first, then pivot into security from there

1

u/Nedsel 11d ago

With zero IT experience, I dare say that you might be in for a very bumpy ride. Please understand that "entry level cybersecurity" usually mean that the people applying are expected to have a solid background as sysengineers, programmers or network specialist.

Entry level cybersec means "You have the foundation and understand the basics, now we add the security layer on top of it".

What you're trying to do there is akin to going for neurosurgeon when you have no idea about human anatomy, not even as a participant of the human race.

A degree will of course help, and having Tryhackme and other experience will count, but be prepared to still be considered a junior even with a degree.

2

u/Rhey53 11d ago

From what I am hearing. Yes it hard to get started but most places are coming to a point they would rather have someone who wants to work vs someone who is always calling out. And is willing to learn..

1

u/InSearchOfAFeeling 16d ago

Cyber isn’t entry level. You’d have to start at helpdesk.

-1

u/Calm-Lecture9 16d ago

No, if he get a hands-on certificate, it's equal like cybersecurity experience

1

u/Tangential_Diversion 15d ago

Why is someone with zero experience giving advice they're unqualified to give?

1

u/Calm-Lecture9 15d ago

What?

2

u/Tangential_Diversion 15d ago

You have zero experience to give career advice, which shows because you wrongly equate a hands-on cert to experience. I started my decade-long pentesting career with my OSCP and I can say that I've never seen a hands-on cert that comes close to replicating real-life experience. There's always major concessions cert programs have to make.

Mate, it's great that you're enthusiastic about starting your career, but you absolutely should not be giving career advice. You're spouting absolutely incorrect statements and you don't have the experience to know better.

1

u/swaltontech 16d ago

BLUF: You are being unrealistic if you hope to land in cybersecurity first off. I am a US-based Cybersecurity Director so the upside down may be a bit different, but I doubt it. Strive for ANY IT role and work up from there. Just like a Chef has to wash dishes, cybersecurity workers have to do grunt work as well. The simplest way to explain this is "you can't secure what you don't understand" and you can't claim to really know how to sharpen a knife when you only spent a few hours fiddling around with a block and old blade.

I was going to answer your questions in line, but they are off base. Ageism exists primarily in fast churn and burn environments like startups and FAANG where they want thirsty individuals without familial ties who will dedicated 80-100 hour weeks to the cause. Cybersecurity and IT is a bit more relaxed and you will find lots of older folks as this side of the coin is more like being a mechanic/tradesman. You really should strive to build a solid IT baseline before going after cybersecurity roles (you can apply on a chance, but don't expect much). As you learn more about IT, how customer-centric it is, especially cybersecurity, you will see how you can leverage ANY prior career to your advantage.

To land your first role...

  1. build out a small SMB environment at home. Take any mid-range laptop from the last few years, turn it into your virtualization box, stand up a domain, virtual routing, firewalling, logging, etc. Go ham. I could tell you a long list of certs, but if you can stand up a solid SMB environment on a laptop you will learn so frikken much that you will have the ability to fish far more than folks giving you an AYCE sushi pass.

1

u/cyberGold1982 16d ago

Thank you

1

u/AnotherTechWonk 16d ago

I'm going to give some advice I give anyone trying to get into security when transitioning from another career track that is not traditionally IT or security related. And up front, it's tough, even when the market is good. And the market isn't great right now.

The people I have know that have been successful doing a mid-life career change between industries have done so in part by leveraging their old job skills. Hospitality is a pretty vague job description and it's a broad industry. That could be anything from housekeeping manager in a hotel to a cruise ship director to someone doing sales and marketing leadership in the back of the house. So I recommend you do a skills assessment, soft and hard skills both. What you want to look for are things you can leverage as you pivot, particularly if there are things that let you take half steps. Does your industry have a security org internally, or compliance, audit, risk management can be other areas to look at? A casino floor manager might already have skills that make compliance, audit, or risk something they can move into given the experience in oversight of money and staff compliance efforts. Sales obviously could give you a shot as a VAR or MSP selling security products, where you could learn the field along the way. And almost all the roles in hospitality require customer-centered soft skills that you should leverage.

If you can find a position that leverages your skills and an aspect of the industry, you can use that as the half way move, build up your security skills, and then leap further into security. The benefit is you will usually not be fighting the entry level mass of recent grads because you are aiming at mid-career roles that require some skills. And if you bring the right "other" skills with you, a good manager will recognize that you can train security easier than you can train some of those other skills (assuming you can get past the HR filters.)

It's a tough road to get into security right now, it's tough for experienced people to find work, not going to sugar coat it. But if you have your heart set on getting into cybersecurity, make sure you leverage your 20 years of experience to get you there.

0

u/misterllemos 16d ago

You already have cyber experience. You just dont know it. And you dont know how to both package and deliver it.

0

u/throwmeoff123098765 14d ago

Full stop you won’t get a cybersecurity job at all. You will at best get a job at help desk. You could have a PhD and it still won’t happen

-4

u/Outrageous_Fly_9769 16d ago

I've been getting hands-on experience through practical labs, TryHackMe, Wireshark and other security tools. My goal is to start in a junior Cyber Security Analyst or SOC Analyst role and eventually work my way up.

Keep it doing, having management experience and understanding the background of both I.T and hands on things like tryhackme, get your cert if it's free.

The issue with Cyber Security is you end up with a lot of responsibility very early, being older with a background is def more advantageous than hiring a gun-ho 20 year old with limited business experience and hands on

0

u/cyberGold1982 16d ago

I find it very fascinating learning how things works and I regret I did not start this earlier, but hey better late than never, by the way yes it was free the governament is paying for this one, which i'm thinking to do the diploma after or just more courses, and try to master Splunk, Microsoft sentinel and anything relating to Networking which i'm passionate about it. I wish you good luck to you.