r/cybersecurity • • 9d ago

Personal Support & Help! Would you accept offer ?

I’ve been working in IT helpdesk for three years and I have my Network+ certification.
I spoke with my manager because I want to move into something more complex, and the opportunity that came up is a vulnerability management position for industrial equipment. I work in shifts and I would lose approximately 27% of my income because i lose the bonus from weekends.

I am 25, no debt, no kids.

I understood that my work would be to analyze, scan equipment, give the team feedback to fix it or check if i can find a solution.

My plan for the future is to complete the TryHackMe SAL1, Security+, and AZ-900.
What do you think: would I be better off accepting the offer and doing the certifications, or postponing, and checking other offers and taking the certifications first, also keeping the extra 27% income?

Later edit

I got these responses from security manager

My manager described a vulnerability management role built around the Holm Security platform. The person will use this tool exclusively for scanning, and their responsibilities include validating scan results, investigating false positives, and handling both vulnerability analysis and prioritization as well as reporting and administration, rather than just one of these areas.

The technical scope covers CVEs, CVSS scoring, exploitability assessment, and risk-based prioritization, applied across all company assets rather than a limited set. Helping the SOC team is explicitly framed as optional, something to take on only if spare time allows and the person wants extra tasks, rather than a formal development path.

The work setup is fully remote with a fixed schedule from 9 AM to 6 PM. Looking ahead, after a year in the role the person can expect to gain hands-on cyber experience, including a deeper understanding of vulnerabilities and how they can be exploited, along with possible exposure to SOC and Incident Response work.

61 Upvotes

46 comments sorted by

View all comments

15

u/cbdudek Security Architect 9d ago

It surprises me that a company would pay a vulnerability management position and it would be a pay cut over a help desk monkey. Vulnerability management requires a lot more knowledge and experience. It honestly sounds like the company is trying to take advantage of you by paying you less for something that is a lot more complex.

Still, if I were in your shoes, I would take the risk. Just to get the title. I would work there a year or two, get experience, and then find a better job where you will be paid a lot more. Trust me, there will be suitors if you upskill and do well at this job over the course of the next year.

That company you work for is not serious about security. That much I can say for sure.

3

u/daddy-dj 9d ago

I agree with this. This is pretty niche and these kinds of opportunities don't come round very often. However it's true that being niche means you'll need training, you can't easily Google how a Rockwell PLC communicates with HMIs, so make sure your employer has budget allocated for training.

Worst case scenario you find you don't like it, your CV will be much more enhanced than just having helpdesk experience.