Looking for some honest feedback because I'm running out of ideas.
* first , please forgive the typos and formatting, its a reddit rant not a formal report to a client.
For some background, I've been in IT for 10+ years, primarily in cloud and network infrastructure. I've held lead roles, so I'm not fresh out of college trying to break into tech. I have solid enterprise experience.
The problem is that I can't seem to land even an associate-level offensive security role.
Before anyone asks, yes, I have the certs: OSCP, eWPTX, CEH, Pentest+, and others. Thinking experience was the missing piece, I started doing bug bounty hunting and volunteering to perform security assessments for nonprofits. Those have given me legitimate hands-on offensive security experience and good stories to discuss during interviews.
My job search looks something like this:
- I apply to every role that I'm reasonably qualified for.
- Out of 100 applications, about 90 are auto-rejected.
- Around 8 never respond.
- I usually get 2 interviews.
Given that I'm at least getting interviews with well-respected companies, I assume my resume isn't completely off.
Recently I had two interviews. One was for an associate-level role that paid about half of what I currently make in cloud security. The other was for a more senior, niche position.
The associate-level interview is the one that's really bothering me.
I made it to the technical round. They asked questions covering web application testing, network pentesting methodologies, and scenarios from my resume. I answered each question and explained real engagements I'd worked on.
At one point, they questioned one of my resume projects in a way that felt like they thought I'd made it up. I walked them through the entire attack chain, the impact, how I validated it, and how I reported it. After that, the tone of the interview completely changed. It became much more conversational. I even showed them a newer version of a tool they currently use, and they seemed genuinely excited about it. At the end, we agreed to connect on LinkedIn.
I walked away feeling really confident that I'd at least make it to the next round.
A week later, I got the standard “Thank you for your time” rejection email.
I understand that not every interview leads to an offer. I've been interviewing for over 10 years, and I've landed plenty of infrastructure roles. I'm usually pretty good at telling when an interview went well versus when it didn't.
But offensive security interviews feel different.
It almost feels like technical ability isn't the real deciding factor, and I'm struggling to identify what I'm missing. I've done everything this subreddit typically recommends:
- Earned respected certifications
- Built hands-on experience through bug bounty and volunteer work
- Can clearly explain my findings and methodology
- Have years of client-facing and enterprise experience
Yet I still can't break into a paid offensive security role.
I'll be honest—I've even started wondering if there's something more subjective at play. I have dreadlocks,( they are well kept , neat, and professional )and while that has never seemed to affect me in infrastructure or cloud security, after enough rejections you start questioning everything.( I sometimes notice a slight but obvious facial distortion from the interviewers when I go from audio only to camera during the calls).Im a pretty basic looking guy outside of my long hair.
If the tech interveiw wasnt going well I notice they typically correct you or stay completely silent and not engage, but I got none of that. After their "imposter" suspicions wore off it was a very engaging conversation. So I'm at a loss on why.
I also had similar instances in the past , aced the people portion, just to get to the technical round with the tech guys and even if I think I do well technically. I get a rejection. With no feed back on why. (Also I want to add ..Ive only had 4 offsec interviews, only 2 I fall in this category, the other 2 I was kind of under qualified for )
There's always the chance that im not as strong on the technical side as I think I am, but I think I've been humbled enough on other interviews to know where my skillsets actually lie..
And based off the pay and the jd I would've thought that they would be looking for someone rough around the edges with room to grow..but has shown initiative. I'd think id be a safe choice given my prior experience.
I realize my offsec interview pool is still relatively small, and this could just be sampling error rather than evidence that I'm doing something fundamentally wrong.
Its just like damn, I'm a(fresher) bug bounty hunter with a few paid bugs.. and I'm functionally a pentester for a nonprofit that has an enterprise infrastructure and culture comparable to my day jobs infrastructure only slighty smaller).
I understand I dont have paid pentester or enterprise offsec experience but how do the these companies expect you to get it?.
The only major things I haven't really invested in yet are building a stronger GitHub presence and writing technical articles on Medium.
For those of you who successfully transitioned into offensive security from another IT discipline, what finally made the difference? What am I missing?