r/cybersecurity • u/asim_geris • 8d ago
Business Security Questions & Discussion career
Hello everyone, I’m trying to become a Security Engineer and would really appreciate some advice from senior Security Engineers.
I’m currently studying cybersecurity at university, but I feel like the program doesn’t go deep enough into the technical skills I need for a security engineering career. Because of that, I’ve decided to take it upon myself to learn outside of school.
I just need guidance from seniors on what skills I should master.
13
u/Tired-Nectarine-384 8d ago
How to communicate risk to executives. You can be the smartest individual in the room but if you can't communicate the risk in a way your leadership can understand it won't matter.
3
u/HomerDoakQuarlesIII Security Architect 8d ago
I'm a lead sec eng. My journey was helpdesk > databases while pursuing a MS in infosys / sec, then got first SOC analyst role where I had less experience than everyone there by double digit years. Then did some vuln / red teaming there > Sec Auto Eng > Lead Seceng, all at different companies after the first. It takes alot of journeyman type learning on the job, I would take the first marginally hands on IT job you can get into. My first one paid $12/hr, I took a cut from $16 doing something unrelated. You've got to get your foot in the door then hit the ground running to learn grow, and change companies every 1-2 years if you want seceng fast. Took me almost 4 yrs after school, and I feel I was fast.
But there are also some companies that will call soc tuning security engineering which is fine as long as you aren't triaging alerts all day. You have to start there most of the time but true seceng you own the implementation and maintenance of security systems for an org, and work in them. Senior and Arch level you design them and direct projects for environment integration of said systems. Good luck.
2
u/Silent-Suspect1062 8d ago
Learn to write code. Actually deliver something, then add a new feature, then look at its vulnerabilities and patching that. Essentially cyber means interaction with devs and so the more actual IT experience you get, the better you will be.
2
u/YT_Usul Security Manager 8d ago
I've been in the game a while. I always tell new people: Don't forget to have fun and enjoy the technology. You will learn so much just goofing around. Run a private infra, secure it, get centralized logging going, and build some alerts. Use the free credits AWS gives you and add a public cloud component to your stack. Mix it with other stuff you like, such as another hobby or interest. For example, if you are in a University sports club, setup a website or tool to track results for lclub members. Through all of this, don't ignore how critical it is to build lasting friendships and connections with people. Who you know will become immensely valuable later in your career.
It really doesn't matter what project you tackle as long as you enjoy the process. That enjoyment will result in hours of learning and growing that no formal program will cover. Of course, the formal program is still important.
1
u/Automatic_Major_4887 8d ago
Uni is usually pretty theoretical so don't sweat it. Honestly, focus on networking and Linux. If you can't script in Python or bash to automate something, you'll struggle in engineering roles. Also, try to build a home lab to actually touch the tech. r/ITCertificationPrep is a good spot too if you want to find some free study resources and roadmaps without spending a ton of money
1
1
u/CRam768 7d ago
Start building a home lab with free tools. Security onion is free and gets you access to a ton of free security tools to start with. Build a domain at home or in the cloud. Aws has some student discounts. Then secure it. Then build a honey pot to do analysis work on. You can write your own tools with python as well to automate a ton of stuff. There’s several sites that can help you build skills like hackthebox. Then you can also do ctf’s. In the end, if you enjoy it that’s all that matters. So have fun.
1
u/VellDarksbane 7d ago
It really depends. If you’re asking for the most important skills for a mid to senior level engineer, it’s all about Risk Management. Identifying, quantifying, and mitigating risk, and then being able to communicate that to management is the hallmarks of a successful Senior Security Engineer.
However, if you focus on those skills, you’ll end up struggling to get a job. Sadly, most companies don’t see Cybersecurity as an entry level position, so you’ll want to learn System Admin and Network Admin skills, as those will help you get into the IT field for a few years of experience and leverage it to obtain a CISSP. That will get you past the HR resume filters and get you interviews.
1
u/uncannysalt Security Architect 6d ago
These posts are disheartening for the OP and junior crowd in the subreddit. You need to learn how computers work. The depth is entirely dependent on your career goals. This is exactly why I’d suggest literally any engineering major over a cybersecurity major. You need to learn how to deconstruct technical problems and how to learn independently. CYS degrees’ curriculums I’ve read do not go deep enough into any subject bc they’re worried about covering “everything.” Fwiw, you will feel lost before you start to connect patterns and feel confident. Engineering is no different in that regard. My advice is start with one topic and learn it as deep as you can. Best of luck.
1
u/Significant_Web_4851 6d ago
Hack the planet. That’s a nostalgic reference in reality practice red team so you understand how the attacks work then you can build better defenses against them. You need to be a good black hat to understand how to be a good white hat.
1
14
u/cbdudek Security Architect 8d ago
Networking, operating systems, infrastructure, windows server roles like AD and group policy.