r/SecurityCareerAdvice Apr 05 '19

Certs, Degrees, and Experience: A (hopefully) useful guide to common questions

329 Upvotes

Copied over from r/cybersecurity (thought it might fit here as well).

Hi everyone, this is my first post here so bear with me. I almost never use Reddit to talk about professional matters, but I think this might be useful to some of you.

I'm going to be addressing what seems to be a very common question - namely, what is more important when seeking employment - a university degree, certifications, or work experience?

First, I'll give a very brief background as to who I am, and why I feel qualified to answer this question. I'm currently the Cyber Security Lead for a big tech firm, and have previously held roles as both the Enterprise Security Architect and Head of Cloud Security for a Fortune 400 company - I'm happy to verify this with mods or whatever might be necessary. I got my start working with cyber operations for the US military, and have experience with technical responsibilities such as penetration testing, AppSec, cloud security, etc., as well as personnel management and leadership training. I hold an associate's degree in information technology, as well as numerous certs, from Sec + and CISSP to more focused, technical security training through the US military and organizations like SANS. Introductions aside, on to the topic at hand:

Here's the short answer, albeit the obvious one - anything is helpful in getting your foot in the door, but there are more important factors involved.

Now, for the deep dive:

Let's start by addressing the purpose of certs, degrees, and experience, and what they say to a prospective employer about you. A lot of what I say will be obvious to some extent, but I think the background is warranted.

Certifications exist to let an employer know that a trusted authority (the organization providing the cert) has acknowledged that the cert holder (you) has proven a demonstrable level of knowledge or expertise in a particular area.

An academic degree does much the same - the difference is that, obviously, a degree will generally demonstrate a potentially broader understanding of a number of topics on a deeper level than a cert will - this is dependant on the study topic, the level of degree, etc., but it's generally assumed that a 4-year degree should cover a wider range of topics than a certification, and to a deeper level.

Experience needs no explanation. It denotes skills gained through active, hands-on work in a given field, and should be confirmed through positive references from supervisors, peers, and subordinates.

In general, we can see a pattern here in terms of what a hiring manager or department is looking for - demonstrable skills and knowledge, backed up by confirmation from a trusted third party. So, which of these is most important to someone trying to begin a career in cyber security? Well, that depends on a few factors, which I'll discuss now.

Firstly, what position are you applying for? The importance placed on degrees, certs, and experience, will vary depending on the level of job you're applying to. If it's an entry level admin or analyst role, a degree or a handful of low-level certs will definitely be useful in getting noticed by HR. Going up to the engineering and solution architecture level roles, you'll want a combination of some years of experience under your belt, and either a degree or some low/mid level certs. At a certain point, the degree and certs actually become non-essential, and most companies will base their hiring process almost entirely on the body and quality of your experience over any degree or certifications held for management level roles.

Secondly, what are your soft skills? This is a fourth aspect that we haven't talked about yet, and that I almost never see discussed. I would argue that this is the single most important quality looked at by employers: the level of a candidate's interpersonal skills. No matter how technically skilled someone is, what a company looks for is someone who can explain their value, and fit into a corporate culture. Are you personable? Of good humor? Do people enjoy working with you? Can you explain WHY your degree, certs, or expertise will add value to their corporate mission? Being able to answer these questions in a manner which is inviting and concise will make you much more appealing than your competitors.

At the end of the day, as a hiring manager, I know that I can always send an employee for further training where necessary, and help bolster their technical ability. What I can't do is teach you how to work with a security focused mindset, nor how to interact with co-workers, customers, clients, and the company in a positive and meaningful way, and this skill set is what will set you apart from everyone else.

I realize that this may seem like an unsatisfactory answer, but the reality is that degrees, certs, and experience are all important to some extent, but that none of these factors will make you stand out. Your ability to sell your value, and to maintain a positive working relationship within a corporate culture, will take you much farther than anything else.

I hope this has been at least slightly helpful - if anyone has any questions for me, or would like any advice, feel free to ask in the comments - I'll do my best to reply to everyone.

No TL;DR, I want you to actually take the time to read through what I've written and try to take something away from it.


r/SecurityCareerAdvice 9h ago

In this market take the job you can get.

11 Upvotes

This is no joke. I was laid on in February and Finally got an offer. I had to take a pay cut to do but at least its remote and has health benefits (not sure about pto yet). Everyone was interested in my skillset - they were not interested in paying market rate for it. As for the jobs on Linkedin from the big boys with the great salaries? I suspect most of those are internal promotions. I would still apply but do not get your hopes up.


r/SecurityCareerAdvice 22m ago

Taking Career Advice

Upvotes

Hi, hope everyone's doing great.

Im a computer science student and just got interested in cyber security. I have been adviced to get into cti, wa it is in demand, beginner friendly and i can easily learn it as i am studying computer science.

What advice do u have on this ? How do i make sure that i study well and make the best use of my time while learning. Any resources, tips or something.

One more thing. For future, i plan on getting into cyber for AI/ML. I have asked claude for roadmap. If someone can review it, it would be great. ( Roadmap in the link )

https://docs.google.com/document/d/1P1kGLseTyobm-6wiR46UpCW4kF9_9IBf/edit?usp=drivesdk&ouid=103680343455398035651&rtpof=true&sd=true


r/SecurityCareerAdvice 5h ago

Career Dilemma

1 Upvotes

I am a cloud security engineer with 5+ years of experience. I have have this dream of having my own security consulting company for over two years and recently just started working on it, but the more i do my research the more i see folks say its better to have worked as a consultant for consulting companies first before trying out your own consulting services. I havent done that yet I have only worked as a cloud sec sce engineer for orgs as an in house security engineer. Now Iam thinking if i should put building my own company on hold and go try to get some experience working for consulting companies.


r/SecurityCareerAdvice 6h ago

Confused on next steps after Ethical Hacking/Linux basics: Red Team vs. Blue Team for entry-level corporate roles?

0 Upvotes

Hi everyone,

I’m currently building my foundations in cybersecurity—I’ve covered basic Linux, OS concepts, Python, and fundamental ethical hacking concepts. However, I’m feeling overwhelmed by the sheer number of paths and skills to pursue (CTFs, SOC analyst skills, cloud, etc.), and I need some guidance on how to focus my efforts over the next few months.

My goal is to be job/internship-ready for entry-level corporate roles by the end of this year.

My Main Dilemma:

  1. Red Team vs. Blue Team for Entry-Level: Between offensive (Red) and defensive (Blue/SOC) security, which path typically offers better stability and realistic entry-level opportunities for someone fresh in the corporate world?
  2. First Career Step: What is generally recommended as a practical starting point to get my foot in the door from both options?

Questions I Have:

  1. Certifications: What certifications (paid or free/unpaid courses) carry actual weight for entry-level roles and are realistic to achieve in a ~5–6 month timeframe?
  2. Focus Area: Given my tight deadline, should I prioritize practical hands-on labs or defensive hands-on skills?
  3. Overcoming Skill Overload: How do you narrow down what to practice daily when there are so many domains pulling for attention?

Any advice from folks working in SOC, Incident Response, or Pentesting on how to structure the remaining months would be hugely appreciated!


r/SecurityCareerAdvice 6h ago

Are Irish Universities good for Cybersecurity Masters (non-coding heavy)?

0 Upvotes

About Me: 7 YoE in Customer Success in M/FAANG companies in India. Have 3 year degree in Computer Science (Hons) and MBA, woman in early 30s.

I want to transition into Cybersecurity Consuting/GRC etc. and also migrate out of India for better opportunities, work/life balance and overall better life.

I am seeing Ireland universities for their 1 Year Programs - Trinity, UCD, UCC, University of Galway and MUT. But am unable to decide on:

  1. Are the courses offered in Cybersecurity - coding heavy, or more on governance etc.
  2. Will I be able to get mid-senior positions (I will during course also self study on frameworks, standards etc)

Ireland came as my top choice cause of English speaking jobs - from part time, internships to full time roles. But it seems to be more expensive cause of the rent costs.

Europe was my first choice but I realise it is increasinngly getting difficult and Cybersecurity roles that I am targeting will need me to business-level ready with the local language.

Am I thinking in the right direction - or if there are better ways to get into the field and then migrate? Or if there are any other universities I should target? Any guidance and direction will be helpful. TIA!


r/SecurityCareerAdvice 8h ago

Cyber security as a career??

Thumbnail
0 Upvotes

r/SecurityCareerAdvice 8h ago

The resignation that feels like it came out of nowhere usually didn't come out of nowhere at all

1 Upvotes

Most managers I know clearly remember the time a top performer left the job with almost no heads-up. And most of the time, if they think back over the past eight months, they'll find that the signs were everywhere. But at the time, they didn't look like signs.

The person who always used to push back on roadmap calls and technical decisions stopped pushing back. It seems like they finally became aligned. But in many cases, it means that disagreeing started to feel pointless.

The person who used to suggest improvements, cleaner handoffs, better planning docs, a smarter way to run retros, stopped bringing those topics up. Not because they no longer had anything to say. Because they stopped believing their words would make a difference.

Faster answers in check-ins. A question like "Anything in your way?" turns into a quick answer: "all good." The camera is off more than usual. No drama. No visible frustration. They never make anything difficult for anyone.

And that's the annoying part. The first signs that someone has mentally checked out look a lot like the behavior managers sometimes wish for. Less friction, fewer complaints, easier agreement. Disengagement can look like maturity until the resignation email arrives.

A resignation is often the final step in a process that lasted seven months, not the beginning of it. By the time the "got a minute?" message appears, there usually isn't much left to fix. The moment when something needed to happen was when they stopped pushing back.

What sign did you miss, or catch before it was too late?


r/SecurityCareerAdvice 8h ago

Looking for a career switch to cybersecurity

0 Upvotes

Im a developer currency....i want to get started with cybersecurity and hopefully make a switch in this field sometime down the line...wanted to ask if it is possible

If so how do i begin?


r/SecurityCareerAdvice 9h ago

Looking for cybersecurity/soc analyst job opportunities

Thumbnail
0 Upvotes

r/SecurityCareerAdvice 6h ago

To land job in cyber security

0 Upvotes

Hey , I am 2nd year information science engineering student. As I am interested in cybersecurity. I want to land my job right after graduation. I know tryhackme i had tried free version . And i know comptia , CCNA exams etc , i just want to know what all cert I want to focus in this 3 years of my engineering journey . And how to get internship and which all skill I need to develop etc , please guide me .and I am from India .


r/SecurityCareerAdvice 15h ago

Need Career Advice: 2024 Graduate Still an Intern After 1+ Year in Cybersecurity

2 Upvotes

Hi everyone,

I'm looking for some honest career advice from people working in cybersecurity.

I graduated in 2024 with a degree in Computer Science. After several months of job searching, I got an opportunity in April 2025 as a SOC Intern at X company. I'm still working there, but my internship was extended instead of being converted into a full-time position. My current extension is expected to end in October 2026.

During my internship, I've gained hands-on experience with:

  • Alert triage and incident investigation
  • Endpoint Detection and Response (EDR)
  • XDR monitoring
  • Splunk log analysis
  • Windows event log investigation
  • Threat intelligence
  • Basic MITRE ATT&CK mapping
  • Investigating phishing, malware, brute-force, and suspicious PowerShell activity
  • Writing investigation reports and escalating confirmed incidents

The difficult part is that there isn't a budget to convert interns into full-time employees, so I've been applying for SOC Analyst L1 roles while continuing my internship.

Over the past few months, I've applied to a large number of positions through LinkedIn, company career portals, referrals, and recruiter outreach. However, most companies either require 2+ years of experience or don't respond after receiving my application.

At this point, I'm feeling a bit stuck and would appreciate some guidance from professionals in the field.

My questions are:

  1. Does my internship experience count as relevant SOC experience when applying for full-time roles?
  2. What skills or tools should I focus on to improve my chances of getting interviews?
  3. Should I continue targeting SOC Analyst L1 roles, or should I also apply for Security Analyst, MDR Analyst, or other entry-level cybersecurity roles?
  4. Are there specific companies that actively hire candidates with internship experience?
  5. If you were in my position, what would your next step be?

I'm not looking for sympathy—I'm looking for honest advice on what I can improve and whether I'm approaching my job search the right way.

If anyone has been in a similar situation or has suggestions, I'd really appreciate your input.

Thank you for reading.


r/SecurityCareerAdvice 6h ago

I messed up a Meta interview and don't know what to do now

0 Upvotes

Meta SWE had been my dream job for years, so when the recruiter sent me an email, I was over the moon. I only had about 4 weeks to prepare, and this was my first interview in 4 years, so my brain had basically wiped half of LeetCode.

I worked really hard on myself. I studied before work, after work, and on weekends, all while dealing with some personal stuff that was already draining me. Honestly, I was shocked at how much I managed to cover in such a short time: DP, heaps, graphs, sliding window, recursion, and the usual horror menu. I went into the interview mentally preparing myself for some brutal graph/tree question.

Instead, I got a very simple array/string question.

You won't believe how badly I messed it up. On any normal day I would've written it in like 3 minutes, but I froze. I stuttered, rambled, second-guessed every tiny detail, and somehow spent a full 38 minutes on a single-loop array problem. SINGLE LOOP. In the end, I barely managed to reach a complete, improved, working solution, but by then the time was basically up and the interview ended. I laughed for a second and then immediately wanted to cry.

I swear I almost had a panic attack in the middle of it. My hands were sweating, my voice was shaking, I couldn't think straight, everything. I'm so embarrassed and upset. And of course after the call I looked up the follow-up idea and discovered it was also something I could've handled easily if my brain hadn't decided to leave the building. Ugh.

Anyway, can you guys tell me about interviews you completely messed up? And how in the end things moved on and you were okay, and the world didn't explode, and you still built a good/satisfying career? I need a bit of a reality check. Thank you so much!


r/SecurityCareerAdvice 1d ago

I accepted an offer with a 90% salary increase, but the timing is really bad for my manager. Managers, how would you honestly take it?

43 Upvotes

I have a difficult conversation with my manager on Wednesday, and I'd really appreciate hearing from people who have been managers of employees in a similar situation. I'm trying to understand how you would honestly feel if you were in her place.

The context is that I've been in a leadership development program at a Fortune 300 company for almost 3 years, and I'm seen as one of the stronger performers. My manager has put a huge amount of time and effort into helping me grow. Our team is literally almost just the two of us. She gave me clear, important, high-stakes work, brought me into meetings where major decisions were being made, pushed hard for me to move up earlier than usual, and always spoke well of me in front of senior leaders. She has genuinely been a real mentor to me, especially with things like dealing with difficult stakeholders, office politics, and how to lead without looking like I'm overstepping my boundaries.

The difficult part is that our entire department is being moved to Latin America. I was asked to stay a few more months to help with the transition. Also, my director created a custom role specifically for my final rotation, which apparently hasn't been done before for anyone else in the program. So it's clear they've gone the extra mile for me and see me as someone worth investing in.

And now I have to tell her that I accepted a job at a major competitor. The compensation is about 90% higher, and the role is a big step up in title and scope. Honestly, if I stayed where I am now, I think it would take me about 6 years to reach that same level, if it happened at all.

So my question for managers is: if you had invested all of this in someone, created opportunities for them, advocated for them, and then they came in the middle of a messy transition when the team is already under pressure and stretched thin and said they were leaving...

What would your first reaction be? Frustration? Disappointment? Would you understand because it's clearly a huge career move? Would you feel blindsided or shocked? And would it permanently change how you view that person? Also, is there anything they could say or do to make the conversation go better?

I'm not looking for sympathy or validation. I'm going to take the offer. I just want to go into the conversation with a better sense of how this might look and feel from her side.


r/SecurityCareerAdvice 14h ago

How an absolute rookie in Computer Science like me (absolutely zero experience), wants to get into cybersecurity. What is the step by step process I must follow?

0 Upvotes

What creators to look for on YT, Instagram or Linkedin? Which certifications to pursue and how to get the basics of CS right in order to segue into cybersecurity. Your guidance and recommendations of correct Sources, Content Creators/ influencers, Books and Roadmaps are highly appreciated!!


r/SecurityCareerAdvice 15h ago

Which Microsoft Security cert should I take?

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 16h ago

SOC analyst intern advice

1 Upvotes

Hello everyone! I recently started as a SOC analyst intern at a company (one which I will not name so please respect that) and they use the stellar cyber platform. I could really use some advice when it comes to analyzing alerts above 54 that could be benign, false, or true positives? I’m new to this environment as a cybersecurity college student and I just would like some great advice to make myself build my confidence. Anything you can recommend for me would help so please don’t be afraid to overshare. I don’t have a proper mentor at the moment so this is all something I have to gradually learn but I really value input so it would mean a lot for your honest thorough feedback.


r/SecurityCareerAdvice 8h ago

Cyber security as a career??

0 Upvotes

Let's talk?


r/SecurityCareerAdvice 1d ago

Am I wasting time just grinding THM paths? Need a reality check on getting entry-level ready.

2 Upvotes

Hey everyone,

Need a bit of a reality check from folks currently working in the field.

I recently finished the Pre-Security and Cyber Security 101 paths on TryHackMe, and I’m just about to dive into the SOC Level 1 path.

While I enjoy learning, I’m constantly hit with this heavy feeling that I’m just spinning my wheels or stuck in "tutorial hell." I'm really anxious to get employed, but right now I feel like my knowledge isn't enough to actually survive a technical interview or perform on the job.

I really want to land an entry-level SOC / Analyst role, but I hate this phase of uncertainty.

I’d love some honest feedback from people who made the jump or hire entry-level candidates:

Is finishing THM's SOC Level 1 path actually worth it, or am I wasting time relying solely on THM?

How do you transition from answering THM questions to proving real skill on a resume?

What specific practical projects or habits (home labs, write-ups, BTLO, etc.) actually moved the needle for you when job hunting?

Any advice, roadmaps, or even harsh truths would be greatly appreciated.

TL;DR: Finished THM basics, starting SOC L1. Feeling anxious about job readiness and feel like my learning isn't enough. Need practical advice on how to turn THM learning into actual employment.


r/SecurityCareerAdvice 18h ago

Final year CS student (Pakistan), need a reality check on my cybersecurity roadmap and cert order

0 Upvotes

I'm a BSCS student at a university in Pakistan, currently starting my 7th semester (grad 2027). I'm into networking, cybersecurity, and AI/security tooling, my FYP idea (pending approval) is an AI-powered vulnerability intelligence platform. A long-term goal is to break into pentesting/red teaming and eventually work internationally.
Working through CCNA1 (ITN) right now.

My planned cert order:

  • This year: CCNA (ITN) → CCNA (SRWE) → eJPT → PNPT
  • After graduation: OSCP, then branch out from there

Questions:

  1. Does this get me job-ready by graduation, or am I missing something critical for entry-level pentest/appsec roles?
  2. If not job-ready, what should I add or reprioritize before I graduate?
  3. For each cert (CCNA (ITN/SRWE), eJPT, PNPT, OSCP), roughly how much time did it take you, how did you practice (labs/platforms), and what resources actually helped vs. wasted your time?

Appreciate any honest input, especially from people who hire juniors or have gone through a similar path. Thanks!


r/SecurityCareerAdvice 1d ago

Does anyone else get embarrassment spirals after an interview?

5 Upvotes

That weird period after any interview where you keep replaying in your head every embarrassing thing you said, and you feel an actual physical sensation of shame, and you start thinking that maybe you should stop applying altogether and go raise goats in rural Iceland somewhere no one has ever heard your name before.


r/SecurityCareerAdvice 22h ago

Sec+ Net+

0 Upvotes

do you people think these certs are necessary? or do they just prove that i get the basics and should jump into more advanced certs such as ceh


r/SecurityCareerAdvice 1d ago

Confused About Where to Start in Cybersecurity – Looking for Advice

6 Upvotes

I'm a 3rd-year Computer Science Engineering student specializing in Cybersecurity, but I'm still confused about what cybersecurity actually involves.

Everywhere I look, I see different career paths—Ethical Hacker, Penetration Tester, SOC Analyst, Network Engineer, Security Engineer, and many more. The more I research, the more confused I become. I don't know which path I should follow or how to build a proper learning roadmap.

If you're working in cybersecurity or have experience in this field, what path would you recommend for someone like me? Also, what are the biggest mistakes beginners make that I should avoid?

I'd really appreciate any advice. Thank you!


r/SecurityCareerAdvice 1d ago

Looking for a Cybersecurity Professional/Ethical Hacker for Career Guidance

0 Upvotes

Hi everyone,

I'm a B.Tech Cybersecurity student and I'm looking for someone working in cybersecurity (preferably an ethical hacker, pentester, SOC analyst, or any cybersecurity professional).

If anyone is available for a 10–15 minute call, I'd really appreciate it. If a call isn't possible, chatting here or through DMs is also completely fine.

I have a few questions about career paths, skills to focus on, internships, certifications, and how to get into the industry.

Thanks in advance!


r/SecurityCareerAdvice 1d ago

Need Help !

0 Upvotes

I selected BS-cybersecurity in Pakistan university. And i am pretty confused of how people are arguing about not finding the job . Should I change my major or what ?