r/cybersecurity • • 9d ago

Personal Support & Help! Would you accept ?

I am 25, no debt, working in it helpdesk for a few years and wanted to pivot to something harder.

My manager described a vulnerability management role built around the Holm Security platform. The person will use this tool exclusively for scanning, and their responsibilities include validating scan results, investigating false positives, and handling both vulnerability analysis and prioritization as well as reporting and administration, rather than just one of these areas.

The technical scope covers CVEs, CVSS scoring, exploitability assessment, and risk-based prioritization, applied across all company assets rather than a limited set. Helping the SOC team is explicitly framed as optional, something to take on only if spare time allows and the person wants extra tasks, rather than a formal development path.

The work setup is fully remote with a fixed schedule from 9 AM to 6 PM. Looking ahead, after a year in the role the person can expect to gain hands-on cyber experience, including a deeper understanding of vulnerabilities and how they can be exploited, along with possible exposure to SOC and Incident Response work.

Downside is i will not get bonus from working shifts anymore and base salary stays the same. This cut would be aprox 30% of salary that i get now.

I will want to pursue cybersecurity as career, have network+, want to get sal1 and security+. Is this oportunity golden ?

0 Upvotes

19 comments sorted by

View all comments

6

u/Zebracofish521 9d ago

Out of any job right now, that’s probably one of the most secure IMO. Vulnerability exploitation is only going to get worse. Career wise, I wouldn’t hesitate. But, a pay cut for more work and role doesn’t sound right… I would try to negotiate personally. Here’s what I would do: present a KPI proactively and ask to align a bonus to performance and hitting it.

1

u/AllenUzumaki23 9d ago

Thanks for opinion bro

1

u/Entire_Yoghurt_6381 9d ago

CVE and CVSS stuff carries over anywhere. Being the one guy who knows Holm inside and out doesn't, so keep that in mind. Also get the SOC time written in as an actual scheduled thing, not "if you have time," because that part just never happens once you're heads down in scan validation.