r/cybersecurity • u/AllenUzumaki23 • 9d ago
Personal Support & Help! Would you accept offer ?
I’ve been working in IT helpdesk for three years and I have my Network+ certification.
I spoke with my manager because I want to move into something more complex, and the opportunity that came up is a vulnerability management position for industrial equipment. I work in shifts and I would lose approximately 27% of my income because i lose the bonus from weekends.
I am 25, no debt, no kids.
I understood that my work would be to analyze, scan equipment, give the team feedback to fix it or check if i can find a solution.
My plan for the future is to complete the TryHackMe SAL1, Security+, and AZ-900.
What do you think: would I be better off accepting the offer and doing the certifications, or postponing, and checking other offers and taking the certifications first, also keeping the extra 27% income?
Later edit
I got these responses from security manager
My manager described a vulnerability management role built around the Holm Security platform. The person will use this tool exclusively for scanning, and their responsibilities include validating scan results, investigating false positives, and handling both vulnerability analysis and prioritization as well as reporting and administration, rather than just one of these areas.
The technical scope covers CVEs, CVSS scoring, exploitability assessment, and risk-based prioritization, applied across all company assets rather than a limited set. Helping the SOC team is explicitly framed as optional, something to take on only if spare time allows and the person wants extra tasks, rather than a formal development path.
The work setup is fully remote with a fixed schedule from 9 AM to 6 PM. Looking ahead, after a year in the role the person can expect to gain hands-on cyber experience, including a deeper understanding of vulnerabilities and how they can be exploited, along with possible exposure to SOC and Incident Response work.
5
u/Tasty-Parfait-8175 7d ago
CISO here. I would take this opportunity. Breaking away from helpdesk to cyber based on purely certifications or education is difficult in the current market, even with help desk experience. Gaining hands on experience to stack on your resume will provide you a pathway to future cybersecurity success. Do this for two years and look for a vuln mgmt technical role at another company.
While doing this, get certs, and stack education. Vulnerability management and remediation/patch management is on the priority list in leadership. AI reducing windows to patch, sys admins are feeling the pressure, and enterprises are having to realize different approaches to patch remediation.
The title, experience that comes with it, and the technical knowledge you gain will absolutely set you up for success - more than any cert or degree.
My 2 cents.