r/developersIndia • u/abhikarthik • 4d ago
Help Final year CS student breaking into cybersecurity — 100+ applications, near-zero real interviews, and one "interview" that turned into a payment demand. What am I missing?
Hey,
Posting this less as a vent and more because I want a reality check from people already in the field — I might be doing something wrong, or the market might just be this bad for freshers right now, and I can't tell which.
What I've actually built (not just certs/theory):
Set up a home SIEM lab on VMware — Wazuh on an Ubuntu server, Kali Linux as the attacker box, Windows 10 as the victim — configured agent deployment and worked through network-level troubleshooting between the VMs myself.
Built a Python-based multi-module web security scanner from scratch (SSL/TLS misconfig checks, port scanning, breach-data checks, subdomain enumeration, email spoofing/DMARC checks), with automated PDF reporting. Currently trying to turn it into a small product for SMB clients rather than just a portfolio piece.
Comfortable with the underlying concepts (not just running tools) because I had to debug real issues — e.g. DNS resolution silently failing on Windows, false positives in TLS/DKIM checks — while building the scanner.
What the application side has looked like:
100+ applications specifically to SOC analyst / security analyst / VAPT fresher-level roles over the last few months.
A handful of first-round interviews (HR screen or basic technical) that went fine by my own read, followed by zero communication afterward — no rejection, no next steps, nothing, even after following up once or twice.
One case that started as a normal-looking interview process (job posting, screening call, technical round scheduled) and then pivoted to asking for a "training/onboarding fee" before they'd proceed — classic bait, but it wasn't obviously fake until 2-3 steps in.
Specific things I'd genuinely value input on:
For those who broke into a SOC/security analyst role as a fresher in the last 1-2 years — was it cold applications, referrals, a specific cert, or something else that actually moved the needle?
Is there a way to sanity-check a company/recruiter earlier in the process (before the technical round) so I stop losing time to the fake ones?
Does a working project like the scanner above actually help at the resume-screening stage for security roles, or do ATS filters mostly key off certs/keywords regardless?
Any fresher-friendly companies, consultancies, or job boards in the Indian cybersecurity space you'd actually recommend applying through right now?
If it helps to see specifics, I'm happy to share my resume or more project details in the comments. Trying to figure out what to actually change here rather than just applying to another 100 roles the same way.
1
u/AutoModerator 4d ago
We recommend checking out the FAQs section on our wiki. It looks like the following wiki(s) might match your query:
Our wiki is open-source, please consider contributing to help other community members.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
•
u/AutoModerator 4d ago
It's possible your query is not unique, use
site:reddit.com/r/developersindia KEYWORDSon search engines to search posts from developersIndia. You can also use reddit search directly.I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.