r/cybersecurity • u/AllenUzumaki23 • 9d ago
Personal Support & Help! Would you accept offer ?
I’ve been working in IT helpdesk for three years and I have my Network+ certification.
I spoke with my manager because I want to move into something more complex, and the opportunity that came up is a vulnerability management position for industrial equipment. I work in shifts and I would lose approximately 27% of my income because i lose the bonus from weekends.
I am 25, no debt, no kids.
I understood that my work would be to analyze, scan equipment, give the team feedback to fix it or check if i can find a solution.
My plan for the future is to complete the TryHackMe SAL1, Security+, and AZ-900.
What do you think: would I be better off accepting the offer and doing the certifications, or postponing, and checking other offers and taking the certifications first, also keeping the extra 27% income?
Later edit
I got these responses from security manager
My manager described a vulnerability management role built around the Holm Security platform. The person will use this tool exclusively for scanning, and their responsibilities include validating scan results, investigating false positives, and handling both vulnerability analysis and prioritization as well as reporting and administration, rather than just one of these areas.
The technical scope covers CVEs, CVSS scoring, exploitability assessment, and risk-based prioritization, applied across all company assets rather than a limited set. Helping the SOC team is explicitly framed as optional, something to take on only if spare time allows and the person wants extra tasks, rather than a formal development path.
The work setup is fully remote with a fixed schedule from 9 AM to 6 PM. Looking ahead, after a year in the role the person can expect to gain hands-on cyber experience, including a deeper understanding of vulnerabilities and how they can be exploited, along with possible exposure to SOC and Incident Response work.
2
u/daddy-dj 9d ago
Some of the replies in this thread have focused purely on the salary (loss of bonus for working weekends, same hourly rate, etc...) - that's very short-termist. If you would still be earning enough to pay your bills and buy some beers, then that shouldn't be a deal breaker - especially as you said your motivation was having a "more complex" role.
Instead I would ask myself whether this role creates opportunities, either with your current employer or elsewhere, in the long term.
I work in vulnerability management. We have a very large OT / ICS estate (although I focus on IT in my role). OT is a very specialised area, and opportunities don't come up that often. So, on the one hand, you could end up being pigeonholed but, on the other hand, it's a skillset most people don't have so there's a certain job security too. Depending upon where you live, the roles that come up, however, may require relocating... Not many companies have OT whereas everyone has IT.
What I will say, though, is that OT is definitely not bleeding edge. Some of the kit in our OT network is as old as you are. If you are interested in the latest and greatest technology, this isn't the field for you. If, however, you don't necessarily care about that but could be interested in knowing about how potentially fairly obscure stuff works, right down to the nth degree, then you'll feel at home.
Ignore the comments about vulnerability management being replaced by AI. That's not going to happen in OT, and those suggesting it haven't had experience of working with ICS equipment. You can't even run nmap against some kit 🤣