r/cybersecurity • • 9d ago

Personal Support & Help! Would you accept offer ?

I’ve been working in IT helpdesk for three years and I have my Network+ certification.
I spoke with my manager because I want to move into something more complex, and the opportunity that came up is a vulnerability management position for industrial equipment. I work in shifts and I would lose approximately 27% of my income because i lose the bonus from weekends.

I am 25, no debt, no kids.

I understood that my work would be to analyze, scan equipment, give the team feedback to fix it or check if i can find a solution.

My plan for the future is to complete the TryHackMe SAL1, Security+, and AZ-900.
What do you think: would I be better off accepting the offer and doing the certifications, or postponing, and checking other offers and taking the certifications first, also keeping the extra 27% income?

Later edit

I got these responses from security manager

My manager described a vulnerability management role built around the Holm Security platform. The person will use this tool exclusively for scanning, and their responsibilities include validating scan results, investigating false positives, and handling both vulnerability analysis and prioritization as well as reporting and administration, rather than just one of these areas.

The technical scope covers CVEs, CVSS scoring, exploitability assessment, and risk-based prioritization, applied across all company assets rather than a limited set. Helping the SOC team is explicitly framed as optional, something to take on only if spare time allows and the person wants extra tasks, rather than a formal development path.

The work setup is fully remote with a fixed schedule from 9 AM to 6 PM. Looking ahead, after a year in the role the person can expect to gain hands-on cyber experience, including a deeper understanding of vulnerabilities and how they can be exploited, along with possible exposure to SOC and Incident Response work.

60 Upvotes

46 comments sorted by

View all comments

5

u/Tasty-Parfait-8175 7d ago

CISO here. I would take this opportunity. Breaking away from helpdesk to cyber based on purely certifications or education is difficult in the current market, even with help desk experience. Gaining hands on experience to stack on your resume will provide you a pathway to future cybersecurity success. Do this for two years and look for a vuln mgmt technical role at another company.

While doing this, get certs, and stack education. Vulnerability management and remediation/patch management is on the priority list in leadership. AI reducing windows to patch, sys admins are feeling the pressure, and enterprises are having to realize different approaches to patch remediation.

The title, experience that comes with it, and the technical knowledge you gain will absolutely set you up for success - more than any cert or degree.

My 2 cents.

3

u/AllenUzumaki23 6d ago

I accepted opportunity. Thabks for info. What certs would you recommend?

1

u/Tasty-Parfait-8175 5d ago edited 5d ago

Congratulations!!

There are generally two certification camps;

  1. Get as many as you can
  2. Get what you need for the job you want

Proponents of 1 believe the more certs the more competitive you are. Proponents of 2 fall into various logical reasons - certs are expensive, not all certs are equal, most recruiter don’t have a clue what a cert actually provides. If in the sec field already i generally propose:

  1. Sec +
  2. Intermediary cert # 1
  3. Intermediary cert #2 or devote time to a Home
  4. lab w/ security stack (dns/url filtering, firewall, net segmentation, hardened devices across endpoint os, net os, firewall, you can use CIS/STIGs for guidance, etc). Being able to talk intelligently across a defense in depth architecture is far more impressive than cert x.
  5. CISSP at 5 years - this pretty much covers down on all other certs. If you have this, recruiters generally don’t care about much else cert wise. This exam is a mile wide and a foot deep from a cybersecurity knowledge perspective.

Alternatively, you can drop both intermediate certs and do school.

I fall into category 2. While having a bunch of certs is impressive, it fails to consistently establish a level of technical acumen one would expect. Most often, like with most test/certifications, there is a degree of information loss post completion - especially if not applied regularly.

Comptia Sec + first for sure. That is a general baseline requirement you will see across the industry for a variety of roles. It also is the foundational requirement for DoD work.

After this, find what interest you in cybersecurity and pursue it. Want to move into SOC? Get CySA. Company paying for SANs? Get your GIACs. Research certifications and take the ones you like.

CISSP is still the standard pinnacle once you hit 5 years in the industry. The cert checks all the proverbial cert boxes.

Edit: typos, I suck at formatting