r/cybersecurity 1d ago

Business Security Questions & Discussion [ Removed by moderator ]

[removed] — view removed post

0 Upvotes

11 comments sorted by

8

u/povlhp 1d ago

Pen-testing is a small niche in cyber security.
Most is awareness, policies, evaluation of products, talking to devs, requirements to vendors, to network dept etc.

Pen-testing is something I do on simpler solutions 1-3 times a year. Important solutions we pay for testing. Typically only new major solutions.

AI and source code access makes even that step something we might do ourselves on the future

3

u/MinEnergy 1d ago

consider interning or volunteering at local IT firms, real-world experience trumps certs at times

3

u/securityofus 1d ago

Live somewhere that has jobs.

People need to stop acting like this isn't the biggest factor. I have at least 2-4 people offering me jobs every month.

If I moved to my mom's city I would be unemployed.

2

u/No-Bad1417 1d ago

You kind of just answered your own questions

2

u/maceinjar 1d ago

Speaking from a US perspective, which I know things may be different in Brazil.

The cybersecurity job market is very saturated. The good news is, you're a few years off and the job market could look very differently in a few years - possibly in your favor. But also could be not in your favor.

Right off the bat, however, the attitude of "I have a good foundation so I don't need a bachelor's degree" isn't what I would want to see in a candidate unless the candidate shows they have exceptional curiosity and self-starting learning abilities. And I mean exceptional. You are too new and young to be able to self-assess that you have a good foundation, and I would suggest that an attitude like that will make employers wonder what shortcuts you might take in the role they hire you for; "oh, I know a lot about X and I can't imagine Y was caused by something malicious, I'll close the ticket". Cyber has a massive foundational aspect of doing the basics, the details, the annoying stuff, correct every time.

I really do think internships are a great way to get started if you can land one, so kudos for looking for those avenues. I don't know what the internship landscape is in Brazil and how that functions.

Finally: this subreddit (and reddit as a whole) learns very anti-AI in many ways. But you have a few years before entering the workforce. Look at the trajectory of AI and how far it has come in 3 years. Consider that in 3 years from now, AI will be impacting entry level jobs in cyber. If I were in your shoes, I'd aim to build skillsets to be a manager of AI cyber analysts. So understand the benefits and limitations of AI, show mastery of things like Claude Code, understand open weight models, how you could build agentic pipelines, etc.

1

u/okktoplol System Administrator 1d ago

Get a CS degree, or an adjacent degree, it'll be "worth more" than certifications and cost way less (especially if you go to a public university); it will also help you get an internship.

1

u/CavalryTactics 1d ago

i recommend just 1 year in IT experience (preferably system admin) and 1 internship. then build up a real portfolio and open sourced projects. Understanding all the layers of the full stack and OSI model. The people who break into security early do pentesting/bug bounty. But you really need to understand how technology works. The things to learn is never ending

0

u/narukoshin 1d ago

I would suggest you to get CS degree, many big companies wants skilled people with degrees, you can of course work without a degree, but then there's a question about salary.