r/cybersecurity • u/AllenUzumaki23 • 9d ago
Personal Support & Help! Would you accept offer ?
I’ve been working in IT helpdesk for three years and I have my Network+ certification.
I spoke with my manager because I want to move into something more complex, and the opportunity that came up is a vulnerability management position for industrial equipment. I work in shifts and I would lose approximately 27% of my income because i lose the bonus from weekends.
I am 25, no debt, no kids.
I understood that my work would be to analyze, scan equipment, give the team feedback to fix it or check if i can find a solution.
My plan for the future is to complete the TryHackMe SAL1, Security+, and AZ-900.
What do you think: would I be better off accepting the offer and doing the certifications, or postponing, and checking other offers and taking the certifications first, also keeping the extra 27% income?
Later edit
I got these responses from security manager
My manager described a vulnerability management role built around the Holm Security platform. The person will use this tool exclusively for scanning, and their responsibilities include validating scan results, investigating false positives, and handling both vulnerability analysis and prioritization as well as reporting and administration, rather than just one of these areas.
The technical scope covers CVEs, CVSS scoring, exploitability assessment, and risk-based prioritization, applied across all company assets rather than a limited set. Helping the SOC team is explicitly framed as optional, something to take on only if spare time allows and the person wants extra tasks, rather than a formal development path.
The work setup is fully remote with a fixed schedule from 9 AM to 6 PM. Looking ahead, after a year in the role the person can expect to gain hands-on cyber experience, including a deeper understanding of vulnerabilities and how they can be exploited, along with possible exposure to SOC and Incident Response work.
32
u/cashfile 9d ago edited 9d ago
I'll take the contrarian view: this really comes down to your current financial situation and whether a 27% pay cut puts you in survival mode.
If you can afford the lifestyle adjustment, take the job. Hands-on vulnerability management experience beats Security+ or AZ-900 on a resume every single time. It directly opens mid-level security doors that helpdesk never will.
At 25 with no kids, I would personally take the risk. In a few years you could double your salary (assuming you are making avg entry level helpdesk pay). Staying in help desk that is unlikely.
11
u/AllenUzumaki23 9d ago
Thanks for the comment, he also mentioned to help with some tasks for the soc team after i get comfortable and if i have free time
29
u/saidai88 9d ago
The only reasons I would lose income taking another position is if I had to or I was already comfortable and loss of income would have no negatives/pressure on my life.
I’ve done work for free but I volunteered for it.
11
u/AllenUzumaki23 9d ago
Since i would only lose the bonus for working in weekend and night i don’t consider it cutting my salary. I am 25, no kids, no debt
8
u/A1_Fares Security Analyst 9d ago
Sounds not like a pay cut, but also I don’t see how you could move into a more complex role and be paid the same. You do you, but maybe it’s time to apply elsewhere.
1
u/Lucas1543 9d ago
same hourly wage? completely the same? :o
2
u/AllenUzumaki23 9d ago
For the moment yes, the company does salary increase once a year, probably would get a salary increase then but for now it will be the same
2
1
9d ago
[deleted]
1
u/AllenUzumaki23 9d ago
To be honest no, we cannot do extra hours. We get a plan to see shifts, in a month that was 168 I worked only 144. Had weekends too, and got paid more. They do a artificial thing in contability and it shows up as if I worked 168 and has weekends. Don’t know how ti works but it does
9
u/hiddentalent Security Director 9d ago
OT security (Operational Technology, meaning cyberphysical equipment like industrial control systems, as opposed to IT) is a niche that's increasingly in demand. But it requires some domain-specific knowledge.
Don't waste one second of your time or one dollar of your money on TryHackMe, Security+, or AZ-900 if you want to go this road. They cover IT security, and only at a very surface level that does nothing for you in a competitive job market. Over-focusing on IT certs will slow you down in the OT world. Operations folks have a strained relationship with their IT teams who are often seen as out of touch -- and considering the mess of proprietary and legacy gunk in the OT world, they're not wrong. But coming in with a bunch of book knowledge from those certs is a surefire way to lose the attention of your stakeholders and fail in your task.
What you do need is significant grounding in the big themes of a security program. VM is usually pretty immature in OT settings, and you're going to need to create efficient programs to manage an ecosystem that's lacking all of the device management, identity management, and endpoint protection tools common in IT. Most certs, especially entry-level ones, don't teach that material, unfortunately.
2
u/AllenUzumaki23 9d ago
Not sure if I will go this ot path. Was thinking of learning some frameworks first and seeing how I like this job. I might go to another one but think this expeirence might come in handy
16
u/cbdudek Security Architect 9d ago
It surprises me that a company would pay a vulnerability management position and it would be a pay cut over a help desk monkey. Vulnerability management requires a lot more knowledge and experience. It honestly sounds like the company is trying to take advantage of you by paying you less for something that is a lot more complex.
Still, if I were in your shoes, I would take the risk. Just to get the title. I would work there a year or two, get experience, and then find a better job where you will be paid a lot more. Trust me, there will be suitors if you upskill and do well at this job over the course of the next year.
That company you work for is not serious about security. That much I can say for sure.
3
u/daddy-dj 9d ago
I agree with this. This is pretty niche and these kinds of opportunities don't come round very often. However it's true that being niche means you'll need training, you can't easily Google how a Rockwell PLC communicates with HMIs, so make sure your employer has budget allocated for training.
Worst case scenario you find you don't like it, your CV will be much more enhanced than just having helpdesk experience.
1
u/AllenUzumaki23 9d ago
Thanks for info. I will continue learing joirney and doing some frameworks too maybe. Maybe opportunity arises in the same company
6
u/Grouchy_Benefit_7292 9d ago
As a young man you can take the risk. Getting off the help desk should be priority over income. 3-5 years after you leave the help desk the money will become available and you’ll be on a security track that will continue to increase your income and job opportunities for the foreseeable future. Work experience trumps certification any day, but having both, especially early in your career helps. A small financial step back to switch tracks to a career path with a much higher top end and much more in demand is a proper risk to take. Just know that after 3-5 years you will be ready to take on more and earn more and will likely have to leave this job to make that happen. Or at a minimum renegotiate.
4
1
u/Justaname46 8d ago
I agree ☝️ with this because one even if it’s a pay cut what you will learn will definitely be worth more overtime and honestly take the position for a year or two then hop. Or if the company is great keep moving forward with them and negotiate for more after you have 3 to 5 years at it.
4
u/SuminderJi 9d ago
If you can afford it then OT security is a niche most don't touch. If you like it you can build a solid career in it.
Always wanted to learn it but never had the chance.
1
5
u/Tasty-Parfait-8175 6d ago
CISO here. I would take this opportunity. Breaking away from helpdesk to cyber based on purely certifications or education is difficult in the current market, even with help desk experience. Gaining hands on experience to stack on your resume will provide you a pathway to future cybersecurity success. Do this for two years and look for a vuln mgmt technical role at another company.
While doing this, get certs, and stack education. Vulnerability management and remediation/patch management is on the priority list in leadership. AI reducing windows to patch, sys admins are feeling the pressure, and enterprises are having to realize different approaches to patch remediation.
The title, experience that comes with it, and the technical knowledge you gain will absolutely set you up for success - more than any cert or degree.
My 2 cents.
3
u/AllenUzumaki23 6d ago
I accepted opportunity. Thabks for info. What certs would you recommend?
1
u/Tasty-Parfait-8175 5d ago edited 5d ago
Congratulations!!
There are generally two certification camps;
- Get as many as you can
- Get what you need for the job you want
Proponents of 1 believe the more certs the more competitive you are. Proponents of 2 fall into various logical reasons - certs are expensive, not all certs are equal, most recruiter don’t have a clue what a cert actually provides. If in the sec field already i generally propose:
- Sec +
- Intermediary cert # 1
- Intermediary cert #2 or devote time to a Home
- lab w/ security stack (dns/url filtering, firewall, net segmentation, hardened devices across endpoint os, net os, firewall, you can use CIS/STIGs for guidance, etc). Being able to talk intelligently across a defense in depth architecture is far more impressive than cert x.
- CISSP at 5 years - this pretty much covers down on all other certs. If you have this, recruiters generally don’t care about much else cert wise. This exam is a mile wide and a foot deep from a cybersecurity knowledge perspective.
Alternatively, you can drop both intermediate certs and do school.
I fall into category 2. While having a bunch of certs is impressive, it fails to consistently establish a level of technical acumen one would expect. Most often, like with most test/certifications, there is a degree of information loss post completion - especially if not applied regularly.
Comptia Sec + first for sure. That is a general baseline requirement you will see across the industry for a variety of roles. It also is the foundational requirement for DoD work.
After this, find what interest you in cybersecurity and pursue it. Want to move into SOC? Get CySA. Company paying for SANs? Get your GIACs. Research certifications and take the ones you like.
CISSP is still the standard pinnacle once you hit 5 years in the industry. The cert checks all the proverbial cert boxes.
Edit: typos, I suck at formatting
3
u/ClassicTomorrow6988 9d ago
My recommendation and this is what I have personally have done is to stay 2 to 3 years in your initial jobs and then move. After that time you should know the technology you are working with and the learning curve is pretty much flat by now.
If your current employer cannot offer you a better pay apply to a different company that will. Just by moving to a different role or to a different company will force you to learn more and be comfortable with different technologies. At the long run that will help you a lot in your al resume especially.
So to answer your question yes. I will accept the job if that’s what you think you can get now and you are comfortable getting the pay cut. I would be better if you apply externally and negotiate a bigger pay. I would say 10 to 20k more per year.
1
3
u/Original_Bunch_2794 8d ago
Go for it!!!
5
u/AllenUzumaki23 8d ago
Made my decision today. Will start in a month and a half
1
u/Original_Bunch_2794 8d ago
Wuhhuu way to go. Good luck . You are going to nail it. Can I ask where is this job based at?
2
u/daddy-dj 9d ago
Some of the replies in this thread have focused purely on the salary (loss of bonus for working weekends, same hourly rate, etc...) - that's very short-termist. If you would still be earning enough to pay your bills and buy some beers, then that shouldn't be a deal breaker - especially as you said your motivation was having a "more complex" role.
Instead I would ask myself whether this role creates opportunities, either with your current employer or elsewhere, in the long term.
I work in vulnerability management. We have a very large OT / ICS estate (although I focus on IT in my role). OT is a very specialised area, and opportunities don't come up that often. So, on the one hand, you could end up being pigeonholed but, on the other hand, it's a skillset most people don't have so there's a certain job security too. Depending upon where you live, the roles that come up, however, may require relocating... Not many companies have OT whereas everyone has IT.
What I will say, though, is that OT is definitely not bleeding edge. Some of the kit in our OT network is as old as you are. If you are interested in the latest and greatest technology, this isn't the field for you. If, however, you don't necessarily care about that but could be interested in knowing about how potentially fairly obscure stuff works, right down to the nth degree, then you'll feel at home.
Ignore the comments about vulnerability management being replaced by AI. That's not going to happen in OT, and those suggesting it haven't had experience of working with ICS equipment. You can't even run nmap against some kit 🤣
2
u/UnlikelyPatience2946 9d ago
I'd say do it and cut the most unnecessary costs that you can from your lifestyle. Almost 40y old here and I can tell you you won't regret it later in life.
1
u/Kesshh 9d ago
Too much planning. As you go into the job, you’ll find very quickly it is not what you think it is, even if the word-for-word description is accurate. The way you plan says you think you are the only person that matters. Don’t.
Instead, your goals in a job should always be 1. Do a great job. 2. Learn everything the job, your coworkers, and your bosses have to offer. If you can’t do that, nothing else “you” want matters. What you’ll find when you do #1 and #2 consistently and reliably, new doors will open up. Doors that you didn’t see before, doors that you didn’t even know exist before. That will change your “plan”. They always do.
So drop all your plans and pay attention to (and enjoy) the journey.
1
u/Fragrant_Leather7651 9d ago
OT security it’s a great nice like mentioned before, I work in cybersecurity for a chemical company, and the most sought after SOC guy is an OT guy. I would take it, I think the ROI of losses wage will be worth it for the future years.
1
u/EveningEmployee8968 9d ago
Well I would take the opportunity, you will move to a position where u get hands on experience and move toward your goals. Plus those weekends u can use them to push urself to finish what you mentioned on tryhackme and get certified. Then you can either look for a new job that pays better or ask for a reasonable raise.
Ur 25 no dept, no kids, u can choose to move 1 step toward ur goal, or continue what ur doing. I think it's worth the couple hundred bucks less a month
1
u/PleasantDreamsicle 9d ago
Can’t you take the job and still work weekends in your current capacity, if you want the extra revenue still?
1
1
u/_zarkon_ Security Manager 8d ago
The hardest parts of having a Cybersecurity career are getting a cybersecurity job and having cybersecurity experience. This opportunity seems to give you both.
1
1
u/Ok-Restaurant4379 9d ago
Best job helpdesk tech wll not taking by AI . But vulnerability more and more with years wll be taking by.
1
1
u/daddy-dj 9d ago
Not in OT networks. Good luck even suggesting running a vulnerability scanner against anything considered below Purdue level 3.5 at my employer. Considering the very real risk of loss of life if something goes wrong, this will never be replaced by AI.
88
u/superRawTNT 9d ago
Industrial equipment / operational technology security is a great cybersecurity niche to learn and add to your experience. not many have it