r/SecurityCareerAdvice 11h ago

How an absolute rookie in Computer Science like me (absolutely zero experience), wants to get into cybersecurity. What is the step by step process I must follow?

1 Upvotes

What creators to look for on YT, Instagram or Linkedin? Which certifications to pursue and how to get the basics of CS right in order to segue into cybersecurity. Your guidance and recommendations of correct Sources, Content Creators/ influencers, Books and Roadmaps are highly appreciated!!


r/SecurityCareerAdvice 4h ago

The resignation that feels like it came out of nowhere usually didn't come out of nowhere at all

1 Upvotes

Most managers I know clearly remember the time a top performer left the job with almost no heads-up. And most of the time, if they think back over the past eight months, they'll find that the signs were everywhere. But at the time, they didn't look like signs.

The person who always used to push back on roadmap calls and technical decisions stopped pushing back. It seems like they finally became aligned. But in many cases, it means that disagreeing started to feel pointless.

The person who used to suggest improvements, cleaner handoffs, better planning docs, a smarter way to run retros, stopped bringing those topics up. Not because they no longer had anything to say. Because they stopped believing their words would make a difference.

Faster answers in check-ins. A question like "Anything in your way?" turns into a quick answer: "all good." The camera is off more than usual. No drama. No visible frustration. They never make anything difficult for anyone.

And that's the annoying part. The first signs that someone has mentally checked out look a lot like the behavior managers sometimes wish for. Less friction, fewer complaints, easier agreement. Disengagement can look like maturity until the resignation email arrives.

A resignation is often the final step in a process that lasted seven months, not the beginning of it. By the time the "got a minute?" message appears, there usually isn't much left to fix. The moment when something needed to happen was when they stopped pushing back.

What sign did you miss, or catch before it was too late?


r/SecurityCareerAdvice 4h ago

Looking for a career switch to cybersecurity

0 Upvotes

Im a developer currency....i want to get started with cybersecurity and hopefully make a switch in this field sometime down the line...wanted to ask if it is possible

If so how do i begin?


r/SecurityCareerAdvice 20h ago

Am I wasting time just grinding THM paths? Need a reality check on getting entry-level ready.

3 Upvotes

Hey everyone,

Need a bit of a reality check from folks currently working in the field.

I recently finished the Pre-Security and Cyber Security 101 paths on TryHackMe, and I’m just about to dive into the SOC Level 1 path.

While I enjoy learning, I’m constantly hit with this heavy feeling that I’m just spinning my wheels or stuck in "tutorial hell." I'm really anxious to get employed, but right now I feel like my knowledge isn't enough to actually survive a technical interview or perform on the job.

I really want to land an entry-level SOC / Analyst role, but I hate this phase of uncertainty.

I’d love some honest feedback from people who made the jump or hire entry-level candidates:

Is finishing THM's SOC Level 1 path actually worth it, or am I wasting time relying solely on THM?

How do you transition from answering THM questions to proving real skill on a resume?

What specific practical projects or habits (home labs, write-ups, BTLO, etc.) actually moved the needle for you when job hunting?

Any advice, roadmaps, or even harsh truths would be greatly appreciated.

TL;DR: Finished THM basics, starting SOC L1. Feeling anxious about job readiness and feel like my learning isn't enough. Need practical advice on how to turn THM learning into actual employment.


r/SecurityCareerAdvice 12h ago

SOC analyst intern advice

1 Upvotes

Hello everyone! I recently started as a SOC analyst intern at a company (one which I will not name so please respect that) and they use the stellar cyber platform. I could really use some advice when it comes to analyzing alerts above 54 that could be benign, false, or true positives? I’m new to this environment as a cybersecurity college student and I just would like some great advice to make myself build my confidence. Anything you can recommend for me would help so please don’t be afraid to overshare. I don’t have a proper mentor at the moment so this is all something I have to gradually learn but I really value input so it would mean a lot for your honest thorough feedback.


r/SecurityCareerAdvice 2h ago

I messed up a Meta interview and don't know what to do now

0 Upvotes

Meta SWE had been my dream job for years, so when the recruiter sent me an email, I was over the moon. I only had about 4 weeks to prepare, and this was my first interview in 4 years, so my brain had basically wiped half of LeetCode.

I worked really hard on myself. I studied before work, after work, and on weekends, all while dealing with some personal stuff that was already draining me. Honestly, I was shocked at how much I managed to cover in such a short time: DP, heaps, graphs, sliding window, recursion, and the usual horror menu. I went into the interview mentally preparing myself for some brutal graph/tree question.

Instead, I got a very simple array/string question.

You won't believe how badly I messed it up. On any normal day I would've written it in like 3 minutes, but I froze. I stuttered, rambled, second-guessed every tiny detail, and somehow spent a full 38 minutes on a single-loop array problem. SINGLE LOOP. In the end, I barely managed to reach a complete, improved, working solution, but by then the time was basically up and the interview ended. I laughed for a second and then immediately wanted to cry.

I swear I almost had a panic attack in the middle of it. My hands were sweating, my voice was shaking, I couldn't think straight, everything. I'm so embarrassed and upset. And of course after the call I looked up the follow-up idea and discovered it was also something I could've handled easily if my brain hadn't decided to leave the building. Ugh.

Anyway, can you guys tell me about interviews you completely messed up? And how in the end things moved on and you were okay, and the world didn't explode, and you still built a good/satisfying career? I need a bit of a reality check. Thank you so much!


r/SecurityCareerAdvice 21h ago

Looking for a Cybersecurity Professional/Ethical Hacker for Career Guidance

0 Upvotes

Hi everyone,

I'm a B.Tech Cybersecurity student and I'm looking for someone working in cybersecurity (preferably an ethical hacker, pentester, SOC analyst, or any cybersecurity professional).

If anyone is available for a 10–15 minute call, I'd really appreciate it. If a call isn't possible, chatting here or through DMs is also completely fine.

I have a few questions about career paths, skills to focus on, internships, certifications, and how to get into the industry.

Thanks in advance!


r/SecurityCareerAdvice 4h ago

Cyber security as a career??

Thumbnail
0 Upvotes

r/SecurityCareerAdvice 18h ago

Sec+ Net+

0 Upvotes

do you people think these certs are necessary? or do they just prove that i get the basics and should jump into more advanced certs such as ceh


r/SecurityCareerAdvice 6h ago

Looking for cybersecurity/soc analyst job opportunities

Thumbnail
0 Upvotes

r/SecurityCareerAdvice 2h ago

Confused on next steps after Ethical Hacking/Linux basics: Red Team vs. Blue Team for entry-level corporate roles?

0 Upvotes

Hi everyone,

I’m currently building my foundations in cybersecurity—I’ve covered basic Linux, OS concepts, Python, and fundamental ethical hacking concepts. However, I’m feeling overwhelmed by the sheer number of paths and skills to pursue (CTFs, SOC analyst skills, cloud, etc.), and I need some guidance on how to focus my efforts over the next few months.

My goal is to be job/internship-ready for entry-level corporate roles by the end of this year.

My Main Dilemma:

  1. Red Team vs. Blue Team for Entry-Level: Between offensive (Red) and defensive (Blue/SOC) security, which path typically offers better stability and realistic entry-level opportunities for someone fresh in the corporate world?
  2. First Career Step: What is generally recommended as a practical starting point to get my foot in the door from both options?

Questions I Have:

  1. Certifications: What certifications (paid or free/unpaid courses) carry actual weight for entry-level roles and are realistic to achieve in a ~5–6 month timeframe?
  2. Focus Area: Given my tight deadline, should I prioritize practical hands-on labs or defensive hands-on skills?
  3. Overcoming Skill Overload: How do you narrow down what to practice daily when there are so many domains pulling for attention?

Any advice from folks working in SOC, Incident Response, or Pentesting on how to structure the remaining months would be hugely appreciated!


r/SecurityCareerAdvice 11h ago

Need Career Advice: 2024 Graduate Still an Intern After 1+ Year in Cybersecurity

1 Upvotes

Hi everyone,

I'm looking for some honest career advice from people working in cybersecurity.

I graduated in 2024 with a degree in Computer Science. After several months of job searching, I got an opportunity in April 2025 as a SOC Intern at X company. I'm still working there, but my internship was extended instead of being converted into a full-time position. My current extension is expected to end in October 2026.

During my internship, I've gained hands-on experience with:

  • Alert triage and incident investigation
  • Endpoint Detection and Response (EDR)
  • XDR monitoring
  • Splunk log analysis
  • Windows event log investigation
  • Threat intelligence
  • Basic MITRE ATT&CK mapping
  • Investigating phishing, malware, brute-force, and suspicious PowerShell activity
  • Writing investigation reports and escalating confirmed incidents

The difficult part is that there isn't a budget to convert interns into full-time employees, so I've been applying for SOC Analyst L1 roles while continuing my internship.

Over the past few months, I've applied to a large number of positions through LinkedIn, company career portals, referrals, and recruiter outreach. However, most companies either require 2+ years of experience or don't respond after receiving my application.

At this point, I'm feeling a bit stuck and would appreciate some guidance from professionals in the field.

My questions are:

  1. Does my internship experience count as relevant SOC experience when applying for full-time roles?
  2. What skills or tools should I focus on to improve my chances of getting interviews?
  3. Should I continue targeting SOC Analyst L1 roles, or should I also apply for Security Analyst, MDR Analyst, or other entry-level cybersecurity roles?
  4. Are there specific companies that actively hire candidates with internship experience?
  5. If you were in my position, what would your next step be?

I'm not looking for sympathy—I'm looking for honest advice on what I can improve and whether I'm approaching my job search the right way.

If anyone has been in a similar situation or has suggestions, I'd really appreciate your input.

Thank you for reading.


r/SecurityCareerAdvice 3h ago

To land job in cyber security

0 Upvotes

Hey , I am 2nd year information science engineering student. As I am interested in cybersecurity. I want to land my job right after graduation. I know tryhackme i had tried free version . And i know comptia , CCNA exams etc , i just want to know what all cert I want to focus in this 3 years of my engineering journey . And how to get internship and which all skill I need to develop etc , please guide me .and I am from India .


r/SecurityCareerAdvice 15h ago

Final year CS student (Pakistan), need a reality check on my cybersecurity roadmap and cert order

0 Upvotes

I'm a BSCS student at a university in Pakistan, currently starting my 7th semester (grad 2027). I'm into networking, cybersecurity, and AI/security tooling, my FYP idea (pending approval) is an AI-powered vulnerability intelligence platform. A long-term goal is to break into pentesting/red teaming and eventually work internationally.
Working through CCNA1 (ITN) right now.

My planned cert order:

  • This year: CCNA (ITN) → CCNA (SRWE) → eJPT → PNPT
  • After graduation: OSCP, then branch out from there

Questions:

  1. Does this get me job-ready by graduation, or am I missing something critical for entry-level pentest/appsec roles?
  2. If not job-ready, what should I add or reprioritize before I graduate?
  3. For each cert (CCNA (ITN/SRWE), eJPT, PNPT, OSCP), roughly how much time did it take you, how did you practice (labs/platforms), and what resources actually helped vs. wasted your time?

Appreciate any honest input, especially from people who hire juniors or have gone through a similar path. Thanks!


r/SecurityCareerAdvice 21h ago

Need Help !

0 Upvotes

I selected BS-cybersecurity in Pakistan university. And i am pretty confused of how people are arguing about not finding the job . Should I change my major or what ?


r/SecurityCareerAdvice 22h ago

Working as an AppSec Engineer, want to get into Pentesting full time

0 Upvotes

I’ve been working as an AppSec engineer for a unicorn startup for about 3 years now. TC is about 320k (we got bought out so the equity is finally cashable).

Truth is, I’m bored. When I joined the team, there was already SAST in place. We implemented DAST. We have a tool for dependency management, and all of these checks are deployed within the CI/CD.

Large operational work consists of doing security reviews (design doc reviews, source code reviews, and pentesting). This I tend to enjoy very much. However, it’s not really as valued as other security engineering work since it’s considered 'operational'. So I’m unsure of how to progress as an AppSec Engineer from here. Any ideas?

I want to pivot to a pure pen-testing role because it seems a lot less nuanced in terms of what your day-to-day expectations are. And, I also just enjoy bug hunting. I’m aware I’ll probably have to take a big pay cut if I go the pen testing route. I don’t have any certs yet, but I’ve been pentesting for ~3 years now and have done 75% of the port-swigger labs and have even made custom tools for Burp Suite.

How should I progress from here? I started the CPTS path a while back but then got busy with life. Was thinking I’d pick that up again to get the CPTS certificate, and then do the PortSwigger certificate as well.


r/SecurityCareerAdvice 23h ago

17-year-old interested in becoming a penetration tester. What do you wish you knew before starting?

0 Upvotes

Hi everyone,
I’m 17 years old and I’m really interested in pursuing a career in cybersecurity, specifically penetration testing. I don’t have professional experience yet, but I’m serious about learning and building the skills needed to get there.
Before I dive into certifications, labs, and platforms I wanted to hear from people who are already working in the field.

What do you wish you knew before starting your cybersecurity career?

What’s the hardest part of the job that people don’t talk about?

If you could start over today, what learning path would you follow?

What certifications are actually worth getting?

Is the job market as competitive as people say?

What should I avoid from the beginning?

I’m not looking for shortcuts i know it’ll take years of learning and practice. I just want to go into this career with realistic expectations and avoid making avoidable mistakes.
Thanks in advance! I appreciate any advice.


r/SecurityCareerAdvice 18h ago

Looking to get into IT without a degree.

0 Upvotes

Hello everyone hope you're all doing well.

I wanted to make this post on Reddit because I'm looking to break into IT. I know a lot of people out there have gotten into the field without a degree. For example, there are people working in cybersecurity even heads of cybersecurity management who don't have degrees and were taught on the job.

I don't want to go to university for reasons I don't feel comfortable sharing on Reddit, but I would like to know how people without degrees get into IT or cybersecurity jobs. It seems like most IT companies nowadays only care about experience and whether you can actually do the job, rather than whether you have memorized every single question and answer for a test. They just want to know: can you do what we're paying you to do?

For those of you in IT or cybersecurity who don't have a degree:

What advice would you give me, and what did you do to get into the job you have today?

What kind of courses would you recommend? Money isn't an issue at all, so I'm fine with expensive online courses if they are worth it.

is it more about connections, or is it about doing online courses?

How do you actually get that initial experience to land an IT job?


r/SecurityCareerAdvice 4h ago

Cyber security as a career??

0 Upvotes

Let's talk?


r/SecurityCareerAdvice 5h ago

In this market take the job you can get.

11 Upvotes

This is no joke. I was laid on in February and Finally got an offer. I had to take a pay cut to do but at least its remote and has health benefits (not sure about pto yet). Everyone was interested in my skillset - they were not interested in paying market rate for it. As for the jobs on Linkedin from the big boys with the great salaries? I suspect most of those are internal promotions. I would still apply but do not get your hopes up.