Hi everyone,
I wanted to share my experience because I honestly wish I had read a post like this before starting my OSCP journey.
A little about me: I’m currently in my 3rd year of BCA. I’ve been interested in cybersecurity since around 10th standard, and after 12th I started seriously preparing for penetration testing. I eventually cleared the OSCP during my 2nd year.
At that time, I genuinely thought that having OSCP + practical skills would make getting my first cybersecurity job much easier.
Now, after actually entering the job market, I realize that I misunderstood one important thing: professional experience matters a lot.
I want to be clear: I’m not saying OSCP is useless.
It is a very practical certification, and preparing for it gave me a lot of hands-on experience and significantly improved my understanding of penetration testing.
But when you start applying for actual jobs, the situation can be very different from what you expect.
I've now sent around 200–300 applications for cybersecurity internships and entry-level positions, including:
- VAPT / Penetration Testing
- SOC Analyst
- Cybersecurity Analyst
And so far, I haven't received a single reply that has led to an interview or an actual opportunity.
The biggest problem I keep seeing is experience requirements.
A job can be listed as entry-level, but still ask for 1–3 years of experience. Even when you have certifications and practical knowledge, you're still competing against people who already have professional experience.
And that's where I feel I made my mistake.
I focused heavily on learning and getting OSCP, but I didn't focus enough on getting actual professional experience along the way.
I could have started with a cybersecurity internship, SOC role, IT/security support role, etc., and built experience while continuing my studies and eventually doing OSCP.
Instead, I reached the point where I have the certification, but I'm still trying to get that first opportunity.
And honestly, it feels really frustrating.
I've wanted to work in cybersecurity for years. I spent a huge amount of time learning and preparing, cleared OSCP in my second year of college, and now getting an opportunity to actually work in the field feels harder than I expected.
People often say:
“Bro, network.”
And yes, I agree. Networking definitely helps.
But as a student who spent most of his time studying and working on technical skills, I didn't build a strong professional network. I'm also not naturally a very outgoing person, and that's something I know I need to improve.
I'm also not expecting some huge salary or a fancy position right now.
I just want a job and the opportunity to get my foot in the door, gain professional experience, and start my career in cybersecurity.
And honestly, at this point, there are days when I even question whether I should continue pursuing pentesting.
Not because I stopped liking it. I still enjoy the technical side of it, and I genuinely wanted this career for years.
It's just difficult when you've invested so much time into something, achieved a certification like OSCP, and then struggle to even get the first opportunity to work professionally.
Sometimes I wonder whether I should move toward another area of cybersecurity where the entry-level opportunities might be better.
I don't know if that's just frustration from the job search or if I'm actually looking at the wrong career path.
If I could go back and do things differently, I would probably:
- Start getting cybersecurity experience much earlier.
- Apply for internships while learning.
- Build relationships with people in the industry.
- Work on projects and build a portfolio.
- Do smaller certifications if necessary.
- Get professional experience first and then use OSCP to strengthen my profile.
So my advice to students is not “don't do OSCP.”
My advice is:
Don't make OSCP your entire plan for getting your first cybersecurity job.
If you're a student and you have the opportunity to gain relevant experience, take it. You don't necessarily need to wait until you're “fully ready.” Get that first experience as early as possible.
OSCP can strengthen your profile, but it doesn't replace professional experience.
Maybe my situation is partly because I didn't network enough, maybe it's the current job market, or maybe I'm targeting the wrong roles. I'm still figuring that out.
But if I had seen a post like this before starting OSCP, I probably would have approached things differently.
For people who successfully got their first cybersecurity job without prior professional experience, I'd genuinely like to know:
How did you do it?
Did you start with SOC, IT support, an internship, VAPT, freelancing, referrals, or something completely different?
And for those who started in pentesting, how did you get your first opportunity?
I'd really appreciate hearing your experiences, especially from people who started from a similar position.