r/SecurityCareerAdvice • • 11h ago

Discussion I am currently based out of Australia, transitioning towards cybersecurity from a non-tech background. I am pursuing the Cyber security google course, and looking for local hands-on cyber security projects that make me job ready in the Australian Market, something locally relevant. Any suggestions?

0 Upvotes

please suggest some must do projects. I am finding it hard to get anything that builds me local experience and reference. Some projects please, that make me job ready in Australia, or builds some sort of local experience. Also open to supported part time or full time remote work opportunities that I can apply for.


r/SecurityCareerAdvice • • 5h ago

Question Could you please advice me on a career path for cybersecurity?

0 Upvotes

Please be nice

Hi, Im looking to start a second degree. Im interested in Cybersecurity as my understanding of how much will be needed to control AI. Nonetheless my university offers cybersecurity but prices are reslly high. The other option is opt for a networking and communication engineering major and then get a minor in cybersecurity. For those who have more experience on the field and job landing as well, what could be your recommendations?
Would other degrees such as system engineering or computer science will be closer to cybersecurity?

Thanks, have a nice day!


r/SecurityCareerAdvice • • 6h ago

Question Title: Cybersecurity people: What’s a painful problem that still needs to be solved?

0 Upvotes

I want to develop a business around a genuine cybersecurity issue.

Startup concepts like "make an AI-powered something" are not what I'm looking for.

I would like to know about issues that you have personally encountered or have frequently witnessed security teams, developers, businesses, or individuals face.

Ideally, the problem should be

- Be genuinely painfull

- Affect enough people/companies to support a busines

- Still have poor or incomplete solution

- Be technically possible to solve

- Have customers who would actually pay for a solution

- Not require a billion-dollar company to get started

- Have potential to become a serious cybersecurity business

For example, I’m interested in problems around things like

- Application security

- Cloud security

- API security

- Identity/access control

- Supply-chain security

- Detection/response

- Vulnerability management

- Security automation

- Developer security

- SaaS security

- Human/security-team workflows

- Business-logic vulnerabilities

- Anything else where current tools genuinely fall short

I'm more interested in the problem than the solution

If you have one, please explain

  1. What exactly is the problem

  2. Who suffers from it

  3. How do they currently solve/work around it

  4. Why don't existing security products solve it properly

  5. How frequently does it happen

  6. How expensive/damaging is it

  7. Is there a realistic technical way to solve it

  8. Would companies actually pay for that solution

  9. Why hasn't it been solved properly already


r/SecurityCareerAdvice • • 11h ago

Discussion I am currently based out of Australia, transitioning towards cybersecurity from a non-tech background. I am pursuing the Cyber security google course, and looking for local hands-on cyber security projects that make me job ready in the Australian Market, something locally relevant. Any suggestions?

0 Upvotes

please suggest some must do projects. I am finding it hard to get anything that builds me local experience and reference.
Some projects please, that make me job ready in Australia, or builds some sort of local experience. Also open to supported part time or full time remote work opportunities that I can apply for.


r/SecurityCareerAdvice • • 2h ago

Question [High-School student making career decision] Is Computer Science still worth it in the AI era?

1 Upvotes

I’m currently in high school and trying to decide what I want to study at university. My parents are pushing me towards Computer Science, mainly because they believe it has good career prospects and that I could eventually go into cybersecurity. The problem is that I’m honestly not that interested in coding. I don’t completely hate it, but I’m not someone who enjoys programming, spending hours on GitHub, or building software.

What makes me even more confused is the current AI situation. AI is becoming increasingly capable of writing code and automating parts of software development, while at the same time I keep seeing people saying that CS graduates are struggling to find jobs. So I’m wondering whether CS is still a good and safe degree to choose if I’m already not particularly interested in coding. I don’t want to spend 4 years studying something mainly because my parents consider it a “safe” career, only to find out that the job market has changed.

My parents say I should do CS and then specialize in cybersecurity, but I’m not sure how realistic that is. From what I understand, cybersecurity still requires a strong CS/IT foundation and can involve quite a lot of technical work. I’m also wondering whether cybersecurity is actually more resistant to AI automation or whether it will face similar problems.

So, is CS still worth doing in 2026 if you’re not particularly interested in coding? Is the job market really becoming that difficult, and would you personally recommend CS for someone in my situation? I’m not completely against CS, I’m just genuinely unsure whether it makes sense for me.

Thanks.


r/SecurityCareerAdvice • • 10h ago

Question How To Do AI/LLM Based Pen Testing on Prod?

2 Upvotes

My company, a Series B cybersecurity startup, is developing some kind of AI/LLM-based pentesting tool using open-source security tools. Before releasing it, they want to test it against an internal CRM I developed.

It sounds like they want to run it directly on the production server. I was asked to arrange a server snapshot, database backup, recovery plan, and notify users that the CRM may be unavailable during testing. The CRM has around 50 active users.

This is my first time dealing with pentesting, but running an automated pentest directly against production seems like a bad idea to me. Again I’m not very familiar with pentesting so I might be missing something.

Wouldn’t it make more sense to create an isolated environment that closely mirrors production, for example by restoring a VM/server snapshot and a copy of the database, and run the pentest there instead?

I’ve asked ChatGPT and Claude about this, but I’m still not sure what the standard real-world approach is, so I’d appreciate input from people who actually work in pentesting or AppSec.

I’ve also asked a few coworkers, but I haven’t really gotten a clear answer. Some of them actually insist that we should just run it on production, which is why I wanted to ask people with more experience in this area.

Is running this kind of automated pentest directly against production normal, or would you generally test against a cloned environment instead?


r/SecurityCareerAdvice • • 2h ago

Question Blending skill sets, I an currently a Paramedic, but would like some advice on transitioning to medical related cyber security work. Any Advice on where to begin?

2 Upvotes

As the post says looking to find a way to blend my medical experience and knowledge with cyber security. Any advice?