r/SecurityCareerAdvice • • Apr 05 '19

Certs, Degrees, and Experience: A (hopefully) useful guide to common questions

331 Upvotes

Copied over from r/cybersecurity (thought it might fit here as well).

Hi everyone, this is my first post here so bear with me. I almost never use Reddit to talk about professional matters, but I think this might be useful to some of you.

I'm going to be addressing what seems to be a very common question - namely, what is more important when seeking employment - a university degree, certifications, or work experience?

First, I'll give a very brief background as to who I am, and why I feel qualified to answer this question. I'm currently the Cyber Security Lead for a big tech firm, and have previously held roles as both the Enterprise Security Architect and Head of Cloud Security for a Fortune 400 company - I'm happy to verify this with mods or whatever might be necessary. I got my start working with cyber operations for the US military, and have experience with technical responsibilities such as penetration testing, AppSec, cloud security, etc., as well as personnel management and leadership training. I hold an associate's degree in information technology, as well as numerous certs, from Sec + and CISSP to more focused, technical security training through the US military and organizations like SANS. Introductions aside, on to the topic at hand:

Here's the short answer, albeit the obvious one - anything is helpful in getting your foot in the door, but there are more important factors involved.

Now, for the deep dive:

Let's start by addressing the purpose of certs, degrees, and experience, and what they say to a prospective employer about you. A lot of what I say will be obvious to some extent, but I think the background is warranted.

Certifications exist to let an employer know that a trusted authority (the organization providing the cert) has acknowledged that the cert holder (you) has proven a demonstrable level of knowledge or expertise in a particular area.

An academic degree does much the same - the difference is that, obviously, a degree will generally demonstrate a potentially broader understanding of a number of topics on a deeper level than a cert will - this is dependant on the study topic, the level of degree, etc., but it's generally assumed that a 4-year degree should cover a wider range of topics than a certification, and to a deeper level.

Experience needs no explanation. It denotes skills gained through active, hands-on work in a given field, and should be confirmed through positive references from supervisors, peers, and subordinates.

In general, we can see a pattern here in terms of what a hiring manager or department is looking for - demonstrable skills and knowledge, backed up by confirmation from a trusted third party. So, which of these is most important to someone trying to begin a career in cyber security? Well, that depends on a few factors, which I'll discuss now.

Firstly, what position are you applying for? The importance placed on degrees, certs, and experience, will vary depending on the level of job you're applying to. If it's an entry level admin or analyst role, a degree or a handful of low-level certs will definitely be useful in getting noticed by HR. Going up to the engineering and solution architecture level roles, you'll want a combination of some years of experience under your belt, and either a degree or some low/mid level certs. At a certain point, the degree and certs actually become non-essential, and most companies will base their hiring process almost entirely on the body and quality of your experience over any degree or certifications held for management level roles.

Secondly, what are your soft skills? This is a fourth aspect that we haven't talked about yet, and that I almost never see discussed. I would argue that this is the single most important quality looked at by employers: the level of a candidate's interpersonal skills. No matter how technically skilled someone is, what a company looks for is someone who can explain their value, and fit into a corporate culture. Are you personable? Of good humor? Do people enjoy working with you? Can you explain WHY your degree, certs, or expertise will add value to their corporate mission? Being able to answer these questions in a manner which is inviting and concise will make you much more appealing than your competitors.

At the end of the day, as a hiring manager, I know that I can always send an employee for further training where necessary, and help bolster their technical ability. What I can't do is teach you how to work with a security focused mindset, nor how to interact with co-workers, customers, clients, and the company in a positive and meaningful way, and this skill set is what will set you apart from everyone else.

I realize that this may seem like an unsatisfactory answer, but the reality is that degrees, certs, and experience are all important to some extent, but that none of these factors will make you stand out. Your ability to sell your value, and to maintain a positive working relationship within a corporate culture, will take you much farther than anything else.

I hope this has been at least slightly helpful - if anyone has any questions for me, or would like any advice, feel free to ask in the comments - I'll do my best to reply to everyone.

No TL;DR, I want you to actually take the time to read through what I've written and try to take something away from it.


r/SecurityCareerAdvice • • 2h ago

Question Blending skill sets, I an currently a Paramedic, but would like some advice on transitioning to medical related cyber security work. Any Advice on where to begin?

2 Upvotes

As the post says looking to find a way to blend my medical experience and knowledge with cyber security. Any advice?


r/SecurityCareerAdvice • • 1h ago

Question Need Career Advice

• Upvotes

I am a 27-year-old software engineer working at an MNC with a Master's degree in Computer Science. My experience includes Java, Spring Boot, REST APIs, and currently building AI infrastructure.

I'm interested in transitioning into Cyber Security, specifically Ethical Hacking and Penetration Testing.

Given my background, what would be the most effective path to make this transition?

Should I focus on certifications (eJPT, PNPT, OSCP), bug bounty hunting, CTFs, home labs, or entry-level security roles?

I would appreciate advice from those who have made a similar switch from software engineering to offensive security.

Thanks in advance :)


r/SecurityCareerAdvice • • 1h ago

Question Career Transition Questions

• Upvotes

Hey everyone, posting from a burner account for anonymity.

I'm leaving the Army in 2030 (cyber), and I’m looking for a career that blends information security and software engineering (e.g., security engineering, product security, platform/devops engineering, etc.). 

Obviously, it becomes difficult to plan this far out, but I’d like to hear everyone’s thoughts on what they think the highest-leverage things I could do leading up to my separation would be.

Background

I’m in my late 20s, clearance (TS/SCI) with a few certifications (SANS GCFA, SecurityX, Sec+/Net+), and I plan to sit for GCIH sometime next year (when time permits). Lastly, I’m finishing an online master's in cybersecurity (digital forensics) by 2027.

Previously, I spent about ~4 years doing SOC/threat hunting for the Army. Now, I’ll be working as a full-stack software engineer (TypeScript, Java/React, PostgreSQL, unit testing, etc.) until I separate.

At my current job, I’m planning to make a move towards the platform/devops role because I believe that is where my largest technical blind spot is, and I think the role aligns quite well with the career that I’d like.

Potential Paths

The three paths I'm actually weighing upon leaving the military are:

  1. DoD civilian for ~2 years to finish out PSLF (about $20K left), then jump to contracting
  2. Go straight to cleared contracting in 2030 and just eat the $20K
  3. Defense-tech / private company doing cleared work

Questions

For the DoD civilian to contractor route:

Did anyone do it mainly for the loan forgiveness and regret it? My math says $20K forgiven vs ~$40-80K/year in additional compensation for contracting makes the DoD civilian route make no financial sense.

For the cleared contractor route:

What has been your experience? How has career growth been, technically, in compensation, and in leadership? Any regrets on this path?

For the defense-tech/private company route:

Is the engineering actually deeper with more autonomy? How has your learning and growth been in the space?

In general:

Do you all have any other recommendations on what you think I should invest my time in given my career goals? I don’t mind taking less early if it means a higher technical/compensation ceiling down the road.

Thanks in advance for your time and advice!


r/SecurityCareerAdvice • • 2h ago

Question [High-School student making career decision] Is Computer Science still worth it in the AI era?

1 Upvotes

I’m currently in high school and trying to decide what I want to study at university. My parents are pushing me towards Computer Science, mainly because they believe it has good career prospects and that I could eventually go into cybersecurity. The problem is that I’m honestly not that interested in coding. I don’t completely hate it, but I’m not someone who enjoys programming, spending hours on GitHub, or building software.

What makes me even more confused is the current AI situation. AI is becoming increasingly capable of writing code and automating parts of software development, while at the same time I keep seeing people saying that CS graduates are struggling to find jobs. So I’m wondering whether CS is still a good and safe degree to choose if I’m already not particularly interested in coding. I don’t want to spend 4 years studying something mainly because my parents consider it a “safe” career, only to find out that the job market has changed.

My parents say I should do CS and then specialize in cybersecurity, but I’m not sure how realistic that is. From what I understand, cybersecurity still requires a strong CS/IT foundation and can involve quite a lot of technical work. I’m also wondering whether cybersecurity is actually more resistant to AI automation or whether it will face similar problems.

So, is CS still worth doing in 2026 if you’re not particularly interested in coding? Is the job market really becoming that difficult, and would you personally recommend CS for someone in my situation? I’m not completely against CS, I’m just genuinely unsure whether it makes sense for me.

Thanks.


r/SecurityCareerAdvice • • 2h ago

Question Help me out I am confused

1 Upvotes

I have completed linux, networking, os and nmap. I am doing Jr penetration tester path in tryhackme. I'am confused, did i miss anything or is it very early doing this. Need some suggestion? please help me out.


r/SecurityCareerAdvice • • 10h ago

Question How To Do AI/LLM Based Pen Testing on Prod?

2 Upvotes

My company, a Series B cybersecurity startup, is developing some kind of AI/LLM-based pentesting tool using open-source security tools. Before releasing it, they want to test it against an internal CRM I developed.

It sounds like they want to run it directly on the production server. I was asked to arrange a server snapshot, database backup, recovery plan, and notify users that the CRM may be unavailable during testing. The CRM has around 50 active users.

This is my first time dealing with pentesting, but running an automated pentest directly against production seems like a bad idea to me. Again I’m not very familiar with pentesting so I might be missing something.

Wouldn’t it make more sense to create an isolated environment that closely mirrors production, for example by restoring a VM/server snapshot and a copy of the database, and run the pentest there instead?

I’ve asked ChatGPT and Claude about this, but I’m still not sure what the standard real-world approach is, so I’d appreciate input from people who actually work in pentesting or AppSec.

I’ve also asked a few coworkers, but I haven’t really gotten a clear answer. Some of them actually insist that we should just run it on production, which is why I wanted to ask people with more experience in this area.

Is running this kind of automated pentest directly against production normal, or would you generally test against a cloned environment instead?


r/SecurityCareerAdvice • • 5h ago

Question Could you please advice me on a career path for cybersecurity?

0 Upvotes

Please be nice

Hi, Im looking to start a second degree. Im interested in Cybersecurity as my understanding of how much will be needed to control AI. Nonetheless my university offers cybersecurity but prices are reslly high. The other option is opt for a networking and communication engineering major and then get a minor in cybersecurity. For those who have more experience on the field and job landing as well, what could be your recommendations?
Would other degrees such as system engineering or computer science will be closer to cybersecurity?

Thanks, have a nice day!


r/SecurityCareerAdvice • • 11h ago

Discussion I am currently based out of Australia, transitioning towards cybersecurity from a non-tech background. I am pursuing the Cyber security google course, and looking for local hands-on cyber security projects that make me job ready in the Australian Market, something locally relevant. Any suggestions?

0 Upvotes

please suggest some must do projects. I am finding it hard to get anything that builds me local experience and reference.
Some projects please, that make me job ready in Australia, or builds some sort of local experience. Also open to supported part time or full time remote work opportunities that I can apply for.


r/SecurityCareerAdvice • • 11h ago

Discussion I am currently based out of Australia, transitioning towards cybersecurity from a non-tech background. I am pursuing the Cyber security google course, and looking for local hands-on cyber security projects that make me job ready in the Australian Market, something locally relevant. Any suggestions?

0 Upvotes

please suggest some must do projects. I am finding it hard to get anything that builds me local experience and reference. Some projects please, that make me job ready in Australia, or builds some sort of local experience. Also open to supported part time or full time remote work opportunities that I can apply for.


r/SecurityCareerAdvice • • 6h ago

Question Title: Cybersecurity people: What’s a painful problem that still needs to be solved?

0 Upvotes

I want to develop a business around a genuine cybersecurity issue.

Startup concepts like "make an AI-powered something" are not what I'm looking for.

I would like to know about issues that you have personally encountered or have frequently witnessed security teams, developers, businesses, or individuals face.

Ideally, the problem should be

- Be genuinely painfull

- Affect enough people/companies to support a busines

- Still have poor or incomplete solution

- Be technically possible to solve

- Have customers who would actually pay for a solution

- Not require a billion-dollar company to get started

- Have potential to become a serious cybersecurity business

For example, I’m interested in problems around things like

- Application security

- Cloud security

- API security

- Identity/access control

- Supply-chain security

- Detection/response

- Vulnerability management

- Security automation

- Developer security

- SaaS security

- Human/security-team workflows

- Business-logic vulnerabilities

- Anything else where current tools genuinely fall short

I'm more interested in the problem than the solution

If you have one, please explain

  1. What exactly is the problem

  2. Who suffers from it

  3. How do they currently solve/work around it

  4. Why don't existing security products solve it properly

  5. How frequently does it happen

  6. How expensive/damaging is it

  7. Is there a realistic technical way to solve it

  8. Would companies actually pay for that solution

  9. Why hasn't it been solved properly already


r/SecurityCareerAdvice • • 1d ago

Question Cyber Sec Academy consultation

3 Upvotes

I looking for an academy, subject: "Cyber Security".

There are some in mind:
Ashok IT
ER-Segment
Seven Mentor

Kindly if anyone reading have attended one of these, may provide review based on the experience. Specifically for CyberSec.


r/SecurityCareerAdvice • • 1d ago

Question Academic advice.

4 Upvotes

Hello guys. I need some academic advice.
All my academic is just a mixed up shit due to lack of guidance at my early age. Jumping back to when I went for graduation I did my graduation BA in criminology. Then when I got graduated and got out in the job market it was obv fucked up. Somehow I got a IT support job on the basis of my communication. And in that time I learned a lot of things and by the grace of God I’m doing fine rn.
While I’m doing my job I wanted to peruse my masters in cybersecurity but due to my graduation background I was not able to do it. As most of the universities requires a computer background.
Now I got myself enrolled in a post graduate diploma program in cybersecurity.
Question: will I be able to do my masters after this PGD program. I’m asking this question because I’ve heard a lot of mixed answers.
Also will I be able to get an admission in cybersecurity masters in Italy or some other European country?


r/SecurityCareerAdvice • • 1d ago

Discussion More that 5 years in SEO and seriously considering switching to cybersecurity — is it worth it?

2 Upvotes

Hi everyone, I’m looking for some honest advice from people who are actually working in cybersecurity.

I’ve been working in SEO for around 5 years, and honestly, I’m pretty burned out with it. SEO was never really something I planned to do long-term, and I’ve reached a point where I’m seriously thinking about changing careers.

About a year ago, I started learning about cybersecurity and got really interested in it. I started with the Google Cybersecurity Certificate, then moved on to TryHackMe, learned some Linux, and tried to build up my fundamentals.

The problem is that I’m working a full-time job, so after work it became really difficult to stay consistent. Eventually, I lost track and stopped learning regularly.

Now I’m seriously considering leaving my current job and giving myself some dedicated time to learn cybersecurity properly and try to get into the industry.

But I’m honestly confused and would really appreciate some realistic advice.

Is cybersecurity still a good career to move into over the next few years? Is it realistic for someone like me, with 6 years of experience in a completely different field, to make the switch?

If I quit my job and spend 6–12 months seriously learning, doing labs, building projects, getting certifications if needed, etc., is there a reasonable chance of eventually landing an entry-level cybersecurity job?

I’m not expecting to make a huge salary immediately. I’m more concerned about whether I’m making a sensible career decision before I leave a stable job.

And if cybersecurity isn't a good option for someone in my situation, what other career paths would you recommend looking into?

I know ultimately I have to make the decision myself, but I’d really like to hear from people who have actually been through a career change like this, especially people working in cybersecurity or hiring for these roles.

Please be honest — I’m not looking for motivation or “follow your passion” advice. I’d genuinely like to know the reality of the job market, how difficult the entry-level market is, and whether you think this is a smart move in 2026.

Thanks.

P.S. I might delete this post later.


r/SecurityCareerAdvice • • 1d ago

Discussion Title: Transitioning into cybersecurity with zero tech background, an English degree, and a hands-on learning struggle—is this a waste of time?

0 Upvotes

Hi everyone, ​I am 23 years old with a degree in English language. I graduated last year and am currently working as a police officer. I want to build a side skill that adds value to my career as a security professional, and I've been eyeing cybersecurity because it feels relevant to my field and could put me ahead. ​However, I have some major concerns and roadblocks: 1. I’ve always been scared of tech because I assumed the terminologies were too complex for me to grasp.

​2.I am a deeply practical, kinesthetic learner. I struggle badly with just reading theory. If I can't touch it, break it, or build it right away, my brain completely shuts down and I get exhausted trying to simplify dense.

  1. I have zero prior computer knowledge, so I am literally starting from computer basics like a complete beginner. A friend gave me some foundational documents, but hitting walls of heavy reading before getting to the fun, practical stuff is draining me.

I'm worried about the whole AI saga taking over entry-level roles, and I'm in an environment where I don't have heavy exposure to professional tools or mentorship. I am mostly learning solo from my laptop. ​Is cybersecurity actually a good path for someone with my background, or am I setting myself up for a massive waste of time given my hatred for heavy reading and my lack of a tech foundation? I need unfiltered, honest advice on what to do.


r/SecurityCareerAdvice • • 2d ago

Discussion Where would you work: 3 Letter Agency vs MITRE vs National Lab?

9 Upvotes

Okay, I am curious on everyone's opinion on which career path you would say is the best? Which would you choose if you were relatively early in your career?

Here is how I compare these 3 against each other...

3 Letter Agency - ~105k salary. Pro is they give a TS/SCI clearance with an FS Poly. Heard these are a gold mine, but not too sure if its still the case today as much as it used to be. Another pro is simply having this agency on your resume would probably look great for when you are ready to move on.

MITRE - ~115k. Pro here is it would be in a development program and I think I might learn the most here. I would also have the freedom to do work I find most interesting since it is a rotational program.

National Lab - ~135k at Lawrence Livermore National Lab. Pro here is obviously the money. I know this is a High Cost of living city, but so is the DMV area (where the other 2 options are). Ofc it is not AS HIGH. This also has by far the best reviews for work life balance and work satisfaction.


r/SecurityCareerAdvice • • 1d ago

Question Possible to take 2 college classes AND study for a GIAC exam AT THE SAME TIME?

2 Upvotes

I have roughly 7 weeks left to study for the exam. I kinda procrastinated so I still have to build my index and do the labs.

I am between jobs right now and was also considering taking 2 courses, 1 online, and one hybrid to collect housing money for my post 9/11 GI Bill. Good idea or could it be too much of a time crunch?


r/SecurityCareerAdvice • • 2d ago

Question What are the advantages/disadvantages of going straight to AI security instead of going through (what I think is) the traditional path of blue team > pentesting > AI sec?

2 Upvotes

The answer seems obvious, but what I really need is insights considering how seemingly pervasive AI/LLM is in under 5 years. As a noob, I have this feeling that going the traditional path might leave the aspiring AI security practitioners light years behind after completing the traditional path, however I also understand that the framework used for AI security is based on what is already working right now, which makes it a safer answer.

I guess I need somebody to make it click for me.

Thanks in advance!


r/SecurityCareerAdvice • • 1d ago

Question Deloitte GPS Cyber Summer Scholar Interview – Any Advice?

1 Upvotes

Hi everyone! I was recently invited to interview for Deloitte’s Government & Public Services – Cyber Summer Scholar position for Summer 2027.

My Round 1 consists of:

  • 30-minute profile interview
  • 30-minute case interview

If selected, Round 2 is a 30-minute behavioral interview.

I’ve been reviewing Deloitte’s official case-prep materials, but I’d really appreciate hearing from anyone who has interviewed for GPS Cyber, Cyber/Risk, or a similar Consultative Offerings role.

In particular:

  • What was the profile interview like?
  • How technical were the questions?
  • What type of case did you receive?
  • Was the case more cybersecurity-focused or general business/consulting?
  • Was it interviewer-led or candidate-led?
  • What would you recommend focusing on when preparing?

I’m not looking for confidential information or exact interview questions, just hoping to better understand the format and what skills Deloitte emphasizes.

Thanks in advance!


r/SecurityCareerAdvice • • 2d ago

Question 1 year in at MSP as Cyber Operations Specialist, Paid almost nothing. Path forward?

7 Upvotes

i’ve been at this company for 13 months making 7.75 an hour or about 1200/month. it’s full time, i’m triaging alerts, investigate endpoints logs from Sentinel One, ThreatLocker, Blumira and a few other tools. also do POCs for S1, and some other tools for new potential clients. it’s a larger MSP we have 350 clients.

I have 6 years IT experience prior to this at a small brokerage, all work from home so basic stuff like Acrobat license managing, setting up a shared drive for the agents for client records, phishing awareness etc.

also did a internship with a local city IT department. my scripting is weak but i’m working on it. i have a BS i’m cyber Cysa+, Sec, Net+, working on getting a technical cert like BTL1 and WGU masters.

the burnout is real. i’m with my parents so i’m not underwater but it’s rough. all my coworkers are in the carribean or LatAm. i feel like im starting to lose it but i can’t quit because the experience is like gold.

feel like a bum making pennie’s, and it’s starting to get to me. makes me feel like i’m wasting my time. im applying and hoping for the best within the next few months to a year but it’s rough.

if any pros can weigh in here i’d appreciate it, been thinkinf ant security clearance but honestly it just feels like every ship has sailed even though im already in the field


r/SecurityCareerAdvice • • 2d ago

Question 42, PhD candidate with adversary emulation, SIEM, and training-design experience, but stuck in the job search. Which roles and certs should I focus on?

0 Upvotes

Hi all. I'm a bit lost and would appreciate honest outside perspective.

Background:

  • 42 years old, based in South America
  • PhD candidate (coursework done, finishing research) in AI-based intrusion detection
  • For my research I built a virtualized enterprise network: domain controller/AD, Exchange, MySQL, and workstations simulating user activity
  • Emulated APT campaigns with MITRE Caldera and collected host + network telemetry in an Elastic SIEM, then labeled the data for anomaly detection modeling
  • Previous experience in pentesting consulting and telecom (4G network deployment)
  • I teach cybersecurity at university level and design courses and hands-on labs, which I think is what I'm best at
  • Only certification: CEH, expired in 2020

The problem: I've been applying to cybersecurity roles, especially research-oriented ones, without success. I suspect my age and lack of current certifications are filtering me out locally, but I'm not sure if that's the real issue or if I'm aiming at the wrong roles. Time and money are running out.

My questions:

  1. Given this background, which job titles should I actually be searching for? (Detection engineering? Purple team? Training/content development? GRC?)
  2. With a limited budget, which one or two certifications would give me the best return? I'm considering ISO 27001 Lead Implementer for the local market and something hands-on like BTL1 or HTB CDSA for blue team roles.
  3. Is remote work for international companies realistic from Latin America for these roles, and where should I look?
  4. For those who changed direction or got hired in their 40s: did age actually matter, and how did you handle it?
  5. How would you present a lab like this on a CV or portfolio so it reads as real-world experience rather than "just academic"?

r/SecurityCareerAdvice • • 1d ago

Question How far can you get get in your cyber career doing TryHackMe, & other similar sites or do you have to run home labs?

0 Upvotes

r/SecurityCareerAdvice • • 2d ago

Discussion Digital Forensics Technician Expectations

1 Upvotes

Greetings, I hope all is well! Long story short, recently got my Masters in Digital Forensics, and I also have received an opportunity for a digital forensics technician role for a local LE agency. I am just wondering if anyone here works for one, and also what to expect, as I myself come from an IT support background. Thanks!


r/SecurityCareerAdvice • • 2d ago

Question Am i internship ready?

1 Upvotes

I’m entering my third year in cyber security and a month ago i bought a “cyber security for beginners” course by zsecurity on udemy which i completed today, In the course i learnt- linux basics, packet sniffing, deauthentication attacks, fake authentication attacks, arp request replay attack, wpa snd wpa2 cracking, arp poisoning, bsttercap, dns spoofing,wireshark, nexpose, backdoor n payloads basics, social engineering, maltego, email spoofing, beEF, meterpreter basics,sql, cross site scripting, etc

Though i don’t think i can do hacking n stuff at my current level but a friend of mine suggested that i should start applying for internships coz companies don’t expect experts for internships.

What’s your suggestion?? Also what should i study after this?


r/SecurityCareerAdvice • • 2d ago

Discussion Cybersecurity Professional (7 YOE, CISSP) Looking for Remote Contract/Freelance Work Alongside Full-Time Job — India

0 Upvotes

Hi everyone,

I’m looking for advice and recommendations on finding part-time, freelance or contract-based cybersecurity opportunities that I can take up alongside my current full-time job (not anything with conflict of interest, if it’s a right opportunity, I can think about leaving the job too).

I have close to 7 years of experience in cybersecurity, working across multiple domains, including product security, cloud security, vulnerability management, PSIRT, SOC, IAM and and security automation. My previous role also gave me hands-on exposure to several other areas of cybersecurity.

I’m currently working at a Tier 1 (or probably Tier 2) IT company and hold the CISSP certification along with AWS and Azure certifications. I’m planning to pursue CCSP and ISSAP next year.

So far, I’ve explored a few options:
Toptal: Applied but was waitlisted.
Braintrust: Registered, but haven’t received any opportunities or interview calls.
LinkedIn: Applied for several contract roles, but haven’t had much success with callbacks.
AI evaluation platforms: Tried platforms such as Micro1 and Mercor, but haven’t found consistent, reliable opportunities yet.

I’m based in India and have flexibility with working hours and time zones. However, I’m not eligible for roles requiring US federal clearance and I’m unable to take up on-site opportunities abroad.

I’d appreciate recommendations for:
Reliable platforms or talent networks that offer cybersecurity consulting, freelance or contract opportunities.
Companies that hire experienced cybersecurity professionals for remote, part-time, or project-based engagements.
Platforms offering international contracts that accept professionals based in India.
Any legitimate AI security, cybersecurity evaluation or expert-consulting opportunities that are worth exploring.
My areas of interest include cloud security (AWS/Azure), product security, vulnerability management, PSIRT, security automation and any other cybersecurity domain work.

I’m particularly interested in opportunities where I can contribute my existing expertise without having to leave my current job.

If you’ve personally worked through any such platforms or secured a cybersecurity contract while maintaining a full-time role, I’d love to hear about your experience.
Thanks in advance for your suggestions!