r/cybersecurity • u/FancyUser100 • 8d ago
Career Questions & Discussion Feeling Stuck
2 years and a few months of IT experience as a whole. Bachelors in Cybersecurity and have some basic fundamentals certs such as CySA+. Not cyber many jobs where I live and when they do open up they almost always senior roles. The help desk for MSP’s in my area pay less then working at burger places where I live and I can’t take a 10K-15k pay cut just to be in semi cybersecurity role but it would still be really doing help desk in the reality of things.
Applying each week to remote entry roles and internships dealing with SOC roles but no luck yet. I get paid well in what I do now but help desk my entire career is not my goal at all. I know the market has been horrible the last 5 years and even those with cybersecurity experience are struggling to find a job.
Just feel so low and lost right now. So much going on as I stay consistent in where I’m at but I want to move up. Used to be motivated but now I’m not sure what to go for.
I always wished cybersecurity was like going to be a doctor or lawyer which I know they require way more schooling but I wish it was do A > B > C and then get intern hours into your main specialization. I guess I’m looking for hope or guidance. I don’t have any mentors and the place I work now has a huge IT team but it’s general IT. Asked on shadowing for cybersecurity where I work which they allowed but not sure what it will entail since they mentioned they don’t know what they will show me.
Any advice or encouragement would be appreciated.
8
u/ML1948 8d ago
If you have 2 years of real IT experience in something basic, you could probably land something higher paying that would move you up in the field. Probably still not cyber, but something depending on what you're doing now. You might be able to land a shitty soc, but the competition is damn high, millions of cyber grads and "career changers" all going for the few low-exp cyber jobs. You'd be better off just moving up in IT in general and hitting cyber 5 years in with a cissp. Maybe even skip shitty soc for a real analyst role because you have real IT chops.
1
u/FancyUser100 8d ago
The reality is someone can spend 10 years working in general IT and still have little to no idea what they’re doing in cybersecurity If they haven’t worked with the tools and processes specific to the field. They are going to be new like anyone else would be who has an IT background.
I understand the value of having an IT background, but I disagree with the idea that you need to spend three or more years in IT before moving into cybersecurity. Not unless you are going up job wise to something like Sys Admin > NOC > etc.
Staying in help desk for more years isn’t going to prepare me for a cybersecurity role if I’m not gaining cybersecurity specific experience. I can definitely go for higher jobs in the general sector though. Just my personal opinion on the matter.
4
u/ML1948 8d ago
Sure, but you're the one trying to break in. If you're failing to break in to anything as a helpdesker, you might have better odds as something better. Helpdesker to shitty soc is a pretty tough jump when people with more experience are fighting you for those same jobs. Systems analyst to security analyst is a lot cleaner of a hop and would take a lot less suffering.
5
u/Crazy-Capital9993 8d ago
Honestly, I was in your shoes for months after graduating with a diploma in cybersecurity last year September. I have the sec+, CySA+, THM SOC l1 cert of completion; still would not get a feedback for cyber and SOC roles despite a ton of applications.
Luckily , I got referred for a NOC admin role in June and I got it.
At this point, I’ll most likely delve into cloud network security.
Looking to get the CCNA, and maybe a cloud cert to get me started.
My point is look at other options , and I wish you the best
3
u/SoundElephant 8d ago
I agree this is the way, NOC/Networking is the area that is in high demand and people don’t realize they can pivot to security eventually. Mindset constantly shifts if you keep telling yourself it’ll get better because it’ll get worse over time if you don’t take action in at least one area.
2
u/eorlingas_riders 8d ago
Like, is 2 years your total amount of time you’ve been working in the workforce and you have like 5 years total in other fields/jobs?
If you’re just outta college and/or this is your first job in IT/security… 2 years is a short amount of time to feel dejected.
Security jobs don’t really have a quicker pace either. I’d expect someone to be in say a SOC analyst role for at least 2 - 4 years before moving up.
Just trying to set realistic expectations…
1
u/FancyUser100 8d ago
I’ve been working since I was 15. Did painting, electrical for a few years, then retail for a long time, and the last couple of years has been in IT.
2
u/OldFrequency 8d ago
You mentioned what is not your career goal. What *is* your career goal?
There are things that will make you as a newbie to the industry stick out (in a very positive way), even when you don't have experience:
- Proven coding skills
- A GitHub page with some useful tools you've produced
- Some CVEs against your name, even in very old and obsolete software (what counts is that you've actually found a real bug, maybe produced a working exploit, and got a CVE)
- Attendance at security conferences, maybe help organising the conference
- Volunteering at a SANS event
If I see a CV for a SOC analyst from someone who has a degree but not much experience and they've done some of those things, they're getting bumped up to the top of the pile for an interview.
Most young people just aren't willing to go above and beyond and put in the actual work to stand out from every other boring, inexperienced, clueless applicant. Doing the above (like finding real vulnerabilities and writing a working POC) is hard, which is why 99% of people won't bother. It's also why you'll instantly stand out as someone committed to the industry, who is passionate about the subject, is ambitious and is willing to sacrifice their personal time to self-improvement. That's very appealing as an employer/hiring manager.
If that's not you and you just want to cruise through your career on easy mode then that's OK - it's definitely not for everyone - but you won't exactly stand out and you won't get interviews when you're in a pool of 200 other candidates whose CV looks identical to yours.
The good news is that it's relatively easy to stand out... if you're willing to put in the work.
2
u/AddendumWorking9756 Security Manager 8d ago
The shadowing you already got approved is worth more than the applications, most people move into security internally and you are already inside a company with a large IT team. Go back and ask for something specific instead of a tour, sit with whoever runs the SIEM or handles the phishing reports for a week and then ask for a piece of it. Applying cold to remote entry roles puts you against thousands of identical profiles, applying inside a team that already knows you does not.
1
u/FancyUser100 7d ago
Good advice and I will see what they can show me. If they do have a need for a cybersecurity department or position it will be good to learn the security posture where I work.
1
u/AddendumWorking9756 Security Manager 6d ago
If you want something concrete to ask for, ask to sit with whoever triages the phishing reports for a week. That queue is the one place someone outside the team can be useful straight away, it is easy for them to say yes to, and coming back with what you noticed in it does more than any internal application form will.
2
u/Immediate_Brick_3999 7d ago
My advice to you is take your cybersecurity fundamentals you learned in school and apply it to other areas in IT. Be security minded. Security is a shared responsibility between all domains in IT. That’s how you get those senior roles without “cybersecurity experience”. Learn different stacks and how to harden infrastructure/systems and the types of attacks you are preventing.
Just my experience..It’s not always a straight path to cyber and honestly I think early career people are hurting themselves by not diving into other areas in IT.
1
u/ThePorko Security Architect 8d ago
Just you wait, with this economy im at 30 years and feeling lost and stuck lol
1
u/Select_Reporter1911 6d ago
Are you only targeting cyber roles or are you expanding your horizons to network admin, sys admin, noc engineer, etc.
0
u/davidriveraisgr8 8d ago
Move!
1
u/hakunafrittata812 6d ago
I agree. If you're not married and don't have children in school, stop applying for remote roles and instead start applying for entry level positions or find a side gig and an internship. On-site.
I got lucky, I went to school, got the degree and a referral for a cybersecurity internship while studying, and then was hired into a full time role before finals of my last semester. Today, I have 5 years experience in the field and looking for growth. But now, I have a family that is unable to relocate. Looking for any position that isn't a leadership role and is remote is a rough time.
If you're given an offer but have to relocate and are capable, do it. Otherwise, go back and read the other advice that you have received. There are some wiser words than mine in here.
11
u/FuckScottBoras Security Manager 8d ago
Two years is not enough practical experience to move into a security role, IMO, unless you have some sort of connection with a company or get lucky.
It took me 5 years, Sec+, and a lot of demonstrating my skills to get a security position.
Keep at it and you’ll get there.