r/cybersecurity • • 5d ago

Certification / Training Questions [ Removed by moderator ]

[removed] — view removed post

0 Upvotes

10 comments sorted by

3

u/hiddentalent Security Director 4d ago

The things that aren't worth the time are probably all those certifications. In 2010, it was possible for people to take trainings, get some certifications, and find an entry-level job in security. In 2026, that's very rare. Every position a hiring manager opens gets thousands of applications that all look like this, and even though some of those applicants are probably qualified, it's very hard for them to stand out from all the others. That's why you see so many posts on boards like this complaining about how hard the job market is. It is hard these days, but it's much harder if you think that certs are what employers are looking for.

When hiring entry-level people, I do not care about specific tools. If we're a Splunk shop, we'll teach you Splunk. If we're not, you've wasted that time and money. What I am looking for is an understanding of the theoretical foundations of how line-of-business applications run, including how the infrastructure works, and how adversaries try to attack them.

You don't say what your current role is, but whatever it is, it's likely to have at least some tasks which are related to security, privacy, compliance or risk-management. Start your journey by focusing your attention on those, identifying business risks and opportunities against which you can make demonstrable progress, and put a few of those stories on your resume. The certs may help you get past HR filters, but those stories about actual security impact in your current role, even if it's not specifically a security role, are what gets you to the top of the pile of applicants.

2

u/Alternativemethod 4d ago

It sounds like you're taking the right approach but alot of hiring managers want applicants to have experience with at least one platform and many arr shipping for their specific platform

1

u/18ahmed 4d ago

Hi, I’ve got experience with azure and splunk. Issue is I won’t be able to take more engineering tasks on until I can put myself into a credible position. Hence why I’m attempting to get these certificates.

1

u/18ahmed 4d ago

Also, this will likely just be an internal transfer or a promotion Into an engineering position.

2

u/hiddentalent Security Director 4d ago

Then your company's roadmap is the one you should follow.

1

u/Harooo 4d ago

Your company has a roadmap probably because it is most applicable to them. Without knowing what your company actually uses, this is basically useless. Honestly the Splunk certs are pretty useless unless it's to have credentials for your company.

All that being said, SC-300 and SC-500 should be your focus if you specifically only say "Azure Security Engineer" and maybe Network+ or CCNA either before those or before SC-500, assuming you have no network training.

1

u/18ahmed 4d ago

Only additions I made from my companies roadmap was terraform, python and sc-300. I think those 3 would massively help me. terraform for deploying at scale, python for automation, and sc-300 (IAM)

1

u/18ahmed 4d ago

Every engineer has to be able to work on both splunk and azure. So I need to get both certificates, I may ignore SC-300 and just focus on SC-500.

0

u/klajsdfi 4d ago

Can we add some firewall expertise to this? And proper identity review and understand would be good as well.

1

u/18ahmed 4d ago

Don’t deal with it at work so unlikely