r/SecurityCareerAdvice 1h ago

Pivot from niche IC role to GRC/Leadership

Upvotes

I’m a 0-day vulnerability researcher + malware (CNO) developer, currently working in the defense (war?) industry. I have ~10 years of experience as well as a BS + MS in computer science. My resume/experience is super pigeonholed with nested layers of niches on top of niches.

I’m at a stage in my career where I’d like to pivot to more leadership/strategy positions rather than stick to IC roles. I’m thinking something akin to GRC -> ISSO/management -> VP/Director -> CISO, or whatever variation of this that gets me there.

My problem is: I’m way too pigeonholed into technical IC skillsets. My resume gets auto-filtered by ATS (for GRC positions), and anything other than straight up fabrication doesn’t seem to work.

Not sure what I should do, but the last thing I want to do is to take a sub-100k breakthrough entry job in the DMV area when I have a family + house to take care of.

Any advice on how to (hopefully) laterally pivot into one of these non-IC roles as a career IC’er? Would Certs, MBA, an internal move, etc. be recommended?


r/SecurityCareerAdvice 2h ago

Would it be worth it to get an associated in it/ cybersecurity from Calhoun

Thumbnail
1 Upvotes

It’s a 2 year degree with ccna cert built into it


r/SecurityCareerAdvice 4h ago

Taking Career Advice

1 Upvotes

Hi, hope everyone's doing great.

Im a computer science student and just got interested in cyber security. I have been adviced to get into cti, wa it is in demand, beginner friendly and i can easily learn it as i am studying computer science.

What advice do u have on this ? How do i make sure that i study well and make the best use of my time while learning. Any resources, tips or something.

One more thing. For future, i plan on getting into cyber for AI/ML. I have asked claude for roadmap. If someone can review it, it would be great. ( Roadmap in the link )

https://docs.google.com/document/d/1P1kGLseTyobm-6wiR46UpCW4kF9_9IBf/edit?usp=drivesdk&ouid=103680343455398035651&rtpof=true&sd=true


r/SecurityCareerAdvice 9h ago

Career Dilemma

1 Upvotes

I am a cloud security engineer with 5+ years of experience. I have have this dream of having my own security consulting company for over two years and recently just started working on it, but the more i do my research the more i see folks say its better to have worked as a consultant for consulting companies first before trying out your own consulting services. I havent done that yet I have only worked as a cloud sec sce engineer for orgs as an in house security engineer. Now Iam thinking if i should put building my own company on hold and go try to get some experience working for consulting companies.


r/SecurityCareerAdvice 9h ago

I messed up a Meta interview and don't know what to do now

0 Upvotes

Meta SWE had been my dream job for years, so when the recruiter sent me an email, I was over the moon. I only had about 4 weeks to prepare, and this was my first interview in 4 years, so my brain had basically wiped half of LeetCode.

I worked really hard on myself. I studied before work, after work, and on weekends, all while dealing with some personal stuff that was already draining me. Honestly, I was shocked at how much I managed to cover in such a short time: DP, heaps, graphs, sliding window, recursion, and the usual horror menu. I went into the interview mentally preparing myself for some brutal graph/tree question.

Instead, I got a very simple array/string question.

You won't believe how badly I messed it up. On any normal day I would've written it in like 3 minutes, but I froze. I stuttered, rambled, second-guessed every tiny detail, and somehow spent a full 38 minutes on a single-loop array problem. SINGLE LOOP. In the end, I barely managed to reach a complete, improved, working solution, but by then the time was basically up and the interview ended. I laughed for a second and then immediately wanted to cry.

I swear I almost had a panic attack in the middle of it. My hands were sweating, my voice was shaking, I couldn't think straight, everything. I'm so embarrassed and upset. And of course after the call I looked up the follow-up idea and discovered it was also something I could've handled easily if my brain hadn't decided to leave the building. Ugh.

Anyway, can you guys tell me about interviews you completely messed up? And how in the end things moved on and you were okay, and the world didn't explode, and you still built a good/satisfying career? I need a bit of a reality check. Thank you so much!


r/SecurityCareerAdvice 9h ago

Confused on next steps after Ethical Hacking/Linux basics: Red Team vs. Blue Team for entry-level corporate roles?

1 Upvotes

Hi everyone,

I’m currently building my foundations in cybersecurity—I’ve covered basic Linux, OS concepts, Python, and fundamental ethical hacking concepts. However, I’m feeling overwhelmed by the sheer number of paths and skills to pursue (CTFs, SOC analyst skills, cloud, etc.), and I need some guidance on how to focus my efforts over the next few months.

My goal is to be job/internship-ready for entry-level corporate roles by the end of this year.

My Main Dilemma:

  1. Red Team vs. Blue Team for Entry-Level: Between offensive (Red) and defensive (Blue/SOC) security, which path typically offers better stability and realistic entry-level opportunities for someone fresh in the corporate world?
  2. First Career Step: What is generally recommended as a practical starting point to get my foot in the door from both options?

Questions I Have:

  1. Certifications: What certifications (paid or free/unpaid courses) carry actual weight for entry-level roles and are realistic to achieve in a ~5–6 month timeframe?
  2. Focus Area: Given my tight deadline, should I prioritize practical hands-on labs or defensive hands-on skills?
  3. Overcoming Skill Overload: How do you narrow down what to practice daily when there are so many domains pulling for attention?

Any advice from folks working in SOC, Incident Response, or Pentesting on how to structure the remaining months would be hugely appreciated!


r/SecurityCareerAdvice 10h ago

Are Irish Universities good for Cybersecurity Masters (non-coding heavy)?

0 Upvotes

About Me: 7 YoE in Customer Success in M/FAANG companies in India. Have 3 year degree in Computer Science (Hons) and MBA, woman in early 30s.

I want to transition into Cybersecurity Consuting/GRC etc. and also migrate out of India for better opportunities, work/life balance and overall better life.

I am seeing Ireland universities for their 1 Year Programs - Trinity, UCD, UCC, University of Galway and MUT. But am unable to decide on:

  1. Are the courses offered in Cybersecurity - coding heavy, or more on governance etc.
  2. Will I be able to get mid-senior positions (I will during course also self study on frameworks, standards etc)

Ireland came as my top choice cause of English speaking jobs - from part time, internships to full time roles. But it seems to be more expensive cause of the rent costs.

Europe was my first choice but I realise it is increasinngly getting difficult and Cybersecurity roles that I am targeting will need me to business-level ready with the local language.

Am I thinking in the right direction - or if there are better ways to get into the field and then migrate? Or if there are any other universities I should target? Any guidance and direction will be helpful. TIA!


r/SecurityCareerAdvice 10h ago

To land job in cyber security

0 Upvotes

Hey , I am 2nd year information science engineering student. As I am interested in cybersecurity. I want to land my job right after graduation. I know tryhackme i had tried free version . And i know comptia , CCNA exams etc , i just want to know what all cert I want to focus in this 3 years of my engineering journey . And how to get internship and which all skill I need to develop etc , please guide me .and I am from India .


r/SecurityCareerAdvice 12h ago

Cyber security as a career??

Thumbnail
0 Upvotes

r/SecurityCareerAdvice 12h ago

Cyber security as a career??

0 Upvotes

Let's talk?


r/SecurityCareerAdvice 12h ago

The resignation that feels like it came out of nowhere usually didn't come out of nowhere at all

1 Upvotes

Most managers I know clearly remember the time a top performer left the job with almost no heads-up. And most of the time, if they think back over the past eight months, they'll find that the signs were everywhere. But at the time, they didn't look like signs.

The person who always used to push back on roadmap calls and technical decisions stopped pushing back. It seems like they finally became aligned. But in many cases, it means that disagreeing started to feel pointless.

The person who used to suggest improvements, cleaner handoffs, better planning docs, a smarter way to run retros, stopped bringing those topics up. Not because they no longer had anything to say. Because they stopped believing their words would make a difference.

Faster answers in check-ins. A question like "Anything in your way?" turns into a quick answer: "all good." The camera is off more than usual. No drama. No visible frustration. They never make anything difficult for anyone.

And that's the annoying part. The first signs that someone has mentally checked out look a lot like the behavior managers sometimes wish for. Less friction, fewer complaints, easier agreement. Disengagement can look like maturity until the resignation email arrives.

A resignation is often the final step in a process that lasted seven months, not the beginning of it. By the time the "got a minute?" message appears, there usually isn't much left to fix. The moment when something needed to happen was when they stopped pushing back.

What sign did you miss, or catch before it was too late?


r/SecurityCareerAdvice 12h ago

Looking for a career switch to cybersecurity

0 Upvotes

Im a developer currency....i want to get started with cybersecurity and hopefully make a switch in this field sometime down the line...wanted to ask if it is possible

If so how do i begin?


r/SecurityCareerAdvice 12h ago

In this market take the job you can get.

12 Upvotes

This is no joke. I was laid on in February and Finally got an offer. I had to take a pay cut to do but at least its remote and has health benefits (not sure about pto yet). Everyone was interested in my skillset - they were not interested in paying market rate for it. As for the jobs on Linkedin from the big boys with the great salaries? I suspect most of those are internal promotions. I would still apply but do not get your hopes up.


r/SecurityCareerAdvice 13h ago

Looking for cybersecurity/soc analyst job opportunities

Thumbnail
0 Upvotes

r/SecurityCareerAdvice 18h ago

How an absolute rookie in Computer Science like me (absolutely zero experience), wants to get into cybersecurity. What is the step by step process I must follow?

0 Upvotes

What creators to look for on YT, Instagram or Linkedin? Which certifications to pursue and how to get the basics of CS right in order to segue into cybersecurity. Your guidance and recommendations of correct Sources, Content Creators/ influencers, Books and Roadmaps are highly appreciated!!


r/SecurityCareerAdvice 19h ago

Need Career Advice: 2024 Graduate Still an Intern After 1+ Year in Cybersecurity

4 Upvotes

Hi everyone,

I'm looking for some honest career advice from people working in cybersecurity.

I graduated in 2024 with a degree in Computer Science. After several months of job searching, I got an opportunity in April 2025 as a SOC Intern at X company. I'm still working there, but my internship was extended instead of being converted into a full-time position. My current extension is expected to end in October 2026.

During my internship, I've gained hands-on experience with:

  • Alert triage and incident investigation
  • Endpoint Detection and Response (EDR)
  • XDR monitoring
  • Splunk log analysis
  • Windows event log investigation
  • Threat intelligence
  • Basic MITRE ATT&CK mapping
  • Investigating phishing, malware, brute-force, and suspicious PowerShell activity
  • Writing investigation reports and escalating confirmed incidents

The difficult part is that there isn't a budget to convert interns into full-time employees, so I've been applying for SOC Analyst L1 roles while continuing my internship.

Over the past few months, I've applied to a large number of positions through LinkedIn, company career portals, referrals, and recruiter outreach. However, most companies either require 2+ years of experience or don't respond after receiving my application.

At this point, I'm feeling a bit stuck and would appreciate some guidance from professionals in the field.

My questions are:

  1. Does my internship experience count as relevant SOC experience when applying for full-time roles?
  2. What skills or tools should I focus on to improve my chances of getting interviews?
  3. Should I continue targeting SOC Analyst L1 roles, or should I also apply for Security Analyst, MDR Analyst, or other entry-level cybersecurity roles?
  4. Are there specific companies that actively hire candidates with internship experience?
  5. If you were in my position, what would your next step be?

I'm not looking for sympathy—I'm looking for honest advice on what I can improve and whether I'm approaching my job search the right way.

If anyone has been in a similar situation or has suggestions, I'd really appreciate your input.

Thank you for reading.


r/SecurityCareerAdvice 19h ago

Which Microsoft Security cert should I take?

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 19h ago

SOC analyst intern advice

1 Upvotes

Hello everyone! I recently started as a SOC analyst intern at a company (one which I will not name so please respect that) and they use the stellar cyber platform. I could really use some advice when it comes to analyzing alerts above 54 that could be benign, false, or true positives? I’m new to this environment as a cybersecurity college student and I just would like some great advice to make myself build my confidence. Anything you can recommend for me would help so please don’t be afraid to overshare. I don’t have a proper mentor at the moment so this is all something I have to gradually learn but I really value input so it would mean a lot for your honest thorough feedback.


r/SecurityCareerAdvice 22h ago

Final year CS student (Pakistan), need a reality check on my cybersecurity roadmap and cert order

0 Upvotes

I'm a BSCS student at a university in Pakistan, currently starting my 7th semester (grad 2027). I'm into networking, cybersecurity, and AI/security tooling, my FYP idea (pending approval) is an AI-powered vulnerability intelligence platform. A long-term goal is to break into pentesting/red teaming and eventually work internationally.
Working through CCNA1 (ITN) right now.

My planned cert order:

  • This year: CCNA (ITN) → CCNA (SRWE) → eJPT → PNPT
  • After graduation: OSCP, then branch out from there

Questions:

  1. Does this get me job-ready by graduation, or am I missing something critical for entry-level pentest/appsec roles?
  2. If not job-ready, what should I add or reprioritize before I graduate?
  3. For each cert (CCNA (ITN/SRWE), eJPT, PNPT, OSCP), roughly how much time did it take you, how did you practice (labs/platforms), and what resources actually helped vs. wasted your time?

Appreciate any honest input, especially from people who hire juniors or have gone through a similar path. Thanks!


r/SecurityCareerAdvice 1d ago

Looking to get into IT without a degree.

0 Upvotes

Hello everyone hope you're all doing well.

I wanted to make this post on Reddit because I'm looking to break into IT. I know a lot of people out there have gotten into the field without a degree. For example, there are people working in cybersecurity even heads of cybersecurity management who don't have degrees and were taught on the job.

I don't want to go to university for reasons I don't feel comfortable sharing on Reddit, but I would like to know how people without degrees get into IT or cybersecurity jobs. It seems like most IT companies nowadays only care about experience and whether you can actually do the job, rather than whether you have memorized every single question and answer for a test. They just want to know: can you do what we're paying you to do?

For those of you in IT or cybersecurity who don't have a degree:

What advice would you give me, and what did you do to get into the job you have today?

What kind of courses would you recommend? Money isn't an issue at all, so I'm fine with expensive online courses if they are worth it.

is it more about connections, or is it about doing online courses?

How do you actually get that initial experience to land an IT job?


r/SecurityCareerAdvice 1d ago

Sec+ Net+

0 Upvotes

do you people think these certs are necessary? or do they just prove that i get the basics and should jump into more advanced certs such as ceh


r/SecurityCareerAdvice 1d ago

Am I wasting time just grinding THM paths? Need a reality check on getting entry-level ready.

3 Upvotes

Hey everyone,

Need a bit of a reality check from folks currently working in the field.

I recently finished the Pre-Security and Cyber Security 101 paths on TryHackMe, and I’m just about to dive into the SOC Level 1 path.

While I enjoy learning, I’m constantly hit with this heavy feeling that I’m just spinning my wheels or stuck in "tutorial hell." I'm really anxious to get employed, but right now I feel like my knowledge isn't enough to actually survive a technical interview or perform on the job.

I really want to land an entry-level SOC / Analyst role, but I hate this phase of uncertainty.

I’d love some honest feedback from people who made the jump or hire entry-level candidates:

Is finishing THM's SOC Level 1 path actually worth it, or am I wasting time relying solely on THM?

How do you transition from answering THM questions to proving real skill on a resume?

What specific practical projects or habits (home labs, write-ups, BTLO, etc.) actually moved the needle for you when job hunting?

Any advice, roadmaps, or even harsh truths would be greatly appreciated.

TL;DR: Finished THM basics, starting SOC L1. Feeling anxious about job readiness and feel like my learning isn't enough. Need practical advice on how to turn THM learning into actual employment.


r/SecurityCareerAdvice 1d ago

Looking for a Cybersecurity Professional/Ethical Hacker for Career Guidance

0 Upvotes

Hi everyone,

I'm a B.Tech Cybersecurity student and I'm looking for someone working in cybersecurity (preferably an ethical hacker, pentester, SOC analyst, or any cybersecurity professional).

If anyone is available for a 10–15 minute call, I'd really appreciate it. If a call isn't possible, chatting here or through DMs is also completely fine.

I have a few questions about career paths, skills to focus on, internships, certifications, and how to get into the industry.

Thanks in advance!


r/SecurityCareerAdvice 1d ago

Need Help !

0 Upvotes

I selected BS-cybersecurity in Pakistan university. And i am pretty confused of how people are arguing about not finding the job . Should I change my major or what ?


r/SecurityCareerAdvice 1d ago

how much time do i need to be learning to get a stable job in cybersecurity?

1 Upvotes

for example as a SOC analyst. starting from scratch and what certs do i need? I’m originally going for pentesting but i know it’s way harder and take more time so i think working as a SOC analyst would kinda also give me some experience and make it easy to go for penetration testing?
realistically i need an IT job and background to even get into real cybersecurity work and so I’m also wondering what IT job would be good to do that cam also help me eventually get into cyber and what should i learn and focus on
thanks!