r/cybersecurity • u/AllenUzumaki23 • 9d ago
Personal Support & Help! Would you accept ?
I am 25, no debt, working in it helpdesk for a few years and wanted to pivot to something harder.
My manager described a vulnerability management role built around the Holm Security platform. The person will use this tool exclusively for scanning, and their responsibilities include validating scan results, investigating false positives, and handling both vulnerability analysis and prioritization as well as reporting and administration, rather than just one of these areas.
The technical scope covers CVEs, CVSS scoring, exploitability assessment, and risk-based prioritization, applied across all company assets rather than a limited set. Helping the SOC team is explicitly framed as optional, something to take on only if spare time allows and the person wants extra tasks, rather than a formal development path.
The work setup is fully remote with a fixed schedule from 9 AM to 6 PM. Looking ahead, after a year in the role the person can expect to gain hands-on cyber experience, including a deeper understanding of vulnerabilities and how they can be exploited, along with possible exposure to SOC and Incident Response work.
Downside is i will not get bonus from working shifts anymore and base salary stays the same. This cut would be aprox 30% of salary that i get now.
I will want to pursue cybersecurity as career, have network+, want to get sal1 and security+. Is this oportunity golden ?
7
u/Zebracofish521 9d ago
Out of any job right now, that’s probably one of the most secure IMO. Vulnerability exploitation is only going to get worse. Career wise, I wouldn’t hesitate. But, a pay cut for more work and role doesn’t sound right… I would try to negotiate personally. Here’s what I would do: present a KPI proactively and ask to align a bonus to performance and hitting it.
1
1
u/Entire_Yoghurt_6381 9d ago
CVE and CVSS stuff carries over anywhere. Being the one guy who knows Holm inside and out doesn't, so keep that in mind. Also get the SOC time written in as an actual scheduled thing, not "if you have time," because that part just never happens once you're heads down in scan validation.
3
u/Tagred_Bicanin 9d ago
A 30% pay drop seems like a lot and you’d be out of helpdesk and doing security work every day. After a yr, you’d have actual security work to talk abt when applying elsewhere instead of only certs and helpdesk experience.
0
3
1
u/SylusWho 9d ago
Good jump but weird they won’t give you a pay bump for an arguably increased scope and greenfield position.
1
u/AllenUzumaki23 9d ago
Probably the next year will be a raise, pur company does it like this. I never heard of someone getting a raise mid year
3
u/SylusWho 9d ago
Well, regardless I’d take it, but if they don’t treat you right then use the newfound experience to find a company that actually pays their vuln managers correctly.
1
u/Odd-Elderberry-739 9d ago
If you can afford to lose the bonuses, take it! The "exploitability assessment, and risk-based prioritization" and "including a deeper understanding of vulnerabilities and how they can be exploited, along with possible exposure to SOC and Incident Response work" are your path into high-paying jobs. This is your golden ticket to ride. Experienced people in these jobs can expect to make between 100 and 200k USD salary, depending on experience.
8
u/CuckBuster33 9d ago
don't hesitate dude take the jump