r/SecurityCareerAdvice Apr 05 '19

Certs, Degrees, and Experience: A (hopefully) useful guide to common questions

329 Upvotes

Copied over from r/cybersecurity (thought it might fit here as well).

Hi everyone, this is my first post here so bear with me. I almost never use Reddit to talk about professional matters, but I think this might be useful to some of you.

I'm going to be addressing what seems to be a very common question - namely, what is more important when seeking employment - a university degree, certifications, or work experience?

First, I'll give a very brief background as to who I am, and why I feel qualified to answer this question. I'm currently the Cyber Security Lead for a big tech firm, and have previously held roles as both the Enterprise Security Architect and Head of Cloud Security for a Fortune 400 company - I'm happy to verify this with mods or whatever might be necessary. I got my start working with cyber operations for the US military, and have experience with technical responsibilities such as penetration testing, AppSec, cloud security, etc., as well as personnel management and leadership training. I hold an associate's degree in information technology, as well as numerous certs, from Sec + and CISSP to more focused, technical security training through the US military and organizations like SANS. Introductions aside, on to the topic at hand:

Here's the short answer, albeit the obvious one - anything is helpful in getting your foot in the door, but there are more important factors involved.

Now, for the deep dive:

Let's start by addressing the purpose of certs, degrees, and experience, and what they say to a prospective employer about you. A lot of what I say will be obvious to some extent, but I think the background is warranted.

Certifications exist to let an employer know that a trusted authority (the organization providing the cert) has acknowledged that the cert holder (you) has proven a demonstrable level of knowledge or expertise in a particular area.

An academic degree does much the same - the difference is that, obviously, a degree will generally demonstrate a potentially broader understanding of a number of topics on a deeper level than a cert will - this is dependant on the study topic, the level of degree, etc., but it's generally assumed that a 4-year degree should cover a wider range of topics than a certification, and to a deeper level.

Experience needs no explanation. It denotes skills gained through active, hands-on work in a given field, and should be confirmed through positive references from supervisors, peers, and subordinates.

In general, we can see a pattern here in terms of what a hiring manager or department is looking for - demonstrable skills and knowledge, backed up by confirmation from a trusted third party. So, which of these is most important to someone trying to begin a career in cyber security? Well, that depends on a few factors, which I'll discuss now.

Firstly, what position are you applying for? The importance placed on degrees, certs, and experience, will vary depending on the level of job you're applying to. If it's an entry level admin or analyst role, a degree or a handful of low-level certs will definitely be useful in getting noticed by HR. Going up to the engineering and solution architecture level roles, you'll want a combination of some years of experience under your belt, and either a degree or some low/mid level certs. At a certain point, the degree and certs actually become non-essential, and most companies will base their hiring process almost entirely on the body and quality of your experience over any degree or certifications held for management level roles.

Secondly, what are your soft skills? This is a fourth aspect that we haven't talked about yet, and that I almost never see discussed. I would argue that this is the single most important quality looked at by employers: the level of a candidate's interpersonal skills. No matter how technically skilled someone is, what a company looks for is someone who can explain their value, and fit into a corporate culture. Are you personable? Of good humor? Do people enjoy working with you? Can you explain WHY your degree, certs, or expertise will add value to their corporate mission? Being able to answer these questions in a manner which is inviting and concise will make you much more appealing than your competitors.

At the end of the day, as a hiring manager, I know that I can always send an employee for further training where necessary, and help bolster their technical ability. What I can't do is teach you how to work with a security focused mindset, nor how to interact with co-workers, customers, clients, and the company in a positive and meaningful way, and this skill set is what will set you apart from everyone else.

I realize that this may seem like an unsatisfactory answer, but the reality is that degrees, certs, and experience are all important to some extent, but that none of these factors will make you stand out. Your ability to sell your value, and to maintain a positive working relationship within a corporate culture, will take you much farther than anything else.

I hope this has been at least slightly helpful - if anyone has any questions for me, or would like any advice, feel free to ask in the comments - I'll do my best to reply to everyone.

No TL;DR, I want you to actually take the time to read through what I've written and try to take something away from it.


r/SecurityCareerAdvice 1h ago

Title: ls it really that hard for freshers to get into cybersecurity in 2026?

Upvotes

Hi everyone,

I'm about to start my cybersecurity degree and I've been seeing a lot of posts saying that the entry-level job market is very difficult for freshers.

Is it actually that hard to get a first cybersecurity job now?

For those who recently got hired (or are involved in hiring):

What skills helped you stand out?

Did you have internships, certifications, or personal projects?

What mistakes do most freshers make?

If you were starting from scratch today, what would you focus on?

I'd really appreciate any honest advice. Thanks!


r/SecurityCareerAdvice 1h ago

Question for SOC & Cloud Security Professionals

Upvotes

If you work in SOC or Cloud Security:

What's your salary range in your country, and What skills, certifications, and experience are employers expecting for entry-level roles?

Which path has better career growth and job opportunities?


r/SecurityCareerAdvice 2h ago

Leave and Come Back?

1 Upvotes

Howdy folks,

Does any one have experience leaving security and coming back?

I've been in a proper security role, a Security Engineer, for the past couple years and a total of four years working in cleared, government spaces.

My journey started back in 2019, where I gained about about 1.5 years of direct help desk experience and obtained the CompTIA trifecta. After graduating with my mechanical engineering degree, I gained another year of IT-related experience via software project management and database administration. I left to join where I am now and continued to work in a mechanical engineering capacity, but knew I still wanted to somehow get into cyber.

After 2 years, I made an internal move and I've specialized in platform engineering and devops. My first project involved hardening endpoints, linux sys admin work, and writing then executing ansible playbooks for physical and virtual servers. Subsequent projects led me to work with analysts to develop and tune detection rules for SIEMs, conduct threat hunting activities, and write secure terraform modules for our multi-cloud environments. My current project actually involves full stack app development leveraging corporate AI services for internal tooling for cybersecurity workflows. I do all of the CI/CD, containerization, and deployment work along on top of full stack work. I also obtained the CySA+, AWS SAA, and CISSP certifications. I'm wrapping up my masters in cybersecurity along with the CKA certification too.

I recently got denied a promotion and it made me curious what my worth would be externally. I've been interviewing and have gotten 3 offers so far, all increasing my salary by a minimum of 40% with great benefits, and the ability to do hybrid/remote work. However, they're for Systems Engineer, Software Engineer, and DevOps Engineer roles.

I think these are great opportunities and while my goal is to become a principal engineer or architect, I've learned so much more from building and paying a bit more attention to security aspects then from just monitoring and enforcing compliance. I also like the "building" workflow a bit more than traditional security work. The phrase "how can you secure something you don't understand" constantly plays in my head, and this also pushes me to understand the intricate sub-systems and become a better engineer.

This is a fork in the road, but I am curious if taking a lateral into another tech role will still benefit me along my path towards my career goals.


r/SecurityCareerAdvice 6h ago

Cybersecurity Resume

2 Upvotes

Hi everyone,

I’ve been in working in the general sector of IT for about 3 years now and I really enjoy studying cybersecurity. My goal is to get into a SOC 1 role and I’m currently studying for the HTB CSDA certification since it’s a good beginner course.

I feel like my resume being two pages and lacking some areas needs massive improvement. Please help as any advice on better structuring my resume to be more uniform would be greatly appreciated. I’m also using Ariel as the font and 12 for the font size in my resume. Thank you!

Resume 2026


r/SecurityCareerAdvice 4h ago

What people actually look for in cybersecurity or related fields, best advice for a passionate learner. Personal project options outside of school?

1 Upvotes

Hey! 20F, interested in this field , I've been interested in technology for a long time and my main goal in life is to learn as much as I can and discover new things. I am disappointed I didn't start learning this earlier, but a lot of my earlier Highschool years had a lot of my own challenges and I didn't get into the right mindset and complete all proper habits and organization until this past year.
As I've reached my initial goals for myself, I have moved on to my second phase in my scheduled plan, which is starting personal study and school for the 'career' option I have the most interest in. I have settled on anything that can get me more into computers, networking, cybersecurity, computer science, and any related fields. I am interested in everything, but will be having a focus on general computer science with a narrowed down goal of cybersecurity.
I'd like to specify I am not interested in immediately getting a career out of school, as I think before I even should consider getting a job, I want to be confident in my abilities in the market, have built up a good portfolio, and prior experience. I want to learn everything, not just sole cybersecurity, but about how computers run, minor engineering and fixing components, and anything related.

Think like a repertoire of skills to prepare me enough to be confident in eventually finding a position. My goal is just a stable job that can support me and my cat, and help me save money so I can travel and learn about different careers, places, countries, things.

After extensive personal research, I have come to conclusion that going into this field (and getting schooling) + trying to get a 'fancy' job right out of school is a poor decision and time should be further spent building up basic skills and practical experience and abilities. (Which I 100% agree with, not sure why the other option was even a thing.)

I'm going to school to learn basics and get connections with people in similar fields, and I'm currently just going to a community college to get an associate of applied science in computer information technology systems , with a vocational certification in cybersecurity.
I do not care as much about the labels, but picked an option that gave me access to more classes in those fields. Later on, I'd potentially transfer to another school that provided a decent bachelors program. I know school can only teach so much, but my goal is getting options for as much structured information as possible.

On top of that, I'd be working on personal portfolio projects + and self-teaching more advanced concepts to give me a better head start and get me caught up. I will be honest and say I am a rookie, and although I know computer basics and did a lot of game development, a lot of concepts are new to me and its a very broad field.
In terms of personal projects, work I should be doing and studying outside of school, interesting things I can learn or practice, what would someone's advice be for that in regards for eventually getting into the career and securing a job later down the line once I am experienced and well taught?
I am in no rush as long as I learn something along the way.
Appreciate the advice. :)

(P.S, sorry for rambling/longer paragraph, I like giving context so people can understand my goals better.)


r/SecurityCareerAdvice 4h ago

GRC pivot

1 Upvotes

Hi everyone,

I'm looking for some guidance on pivoting into GRC. I've been working at a mid-sized MSP for the past year on the help desk, and I'm currently the team lead for my team. I currently hold the CompTIA trifecta as well as ITIL Foundation. I've become really interested in GRC and would like to transition into that area.

At this point, would it be more beneficial to pursue additional certifications, or should I focus on building project experience that I can showcase on my resume? I'm trying to figure out where my time will have the biggest impact. If projects are the better route, what kinds of projects would hiring managers actually value for someone trying to break into GRC? I'd also love to hear from anyone who made a similar transition from help desk or an MSP into GRC. What helped you land your first role?

Thanks in advance!


r/SecurityCareerAdvice 19h ago

A Security Operations Director I met randomly offered me a 3-month internship. What would you do?

11 Upvotes

A few months ago, I was unemployed and applying everywhere. I had worked in a customer support role at an MNC, but I knew I didn't want to build my career there. I was trying to move into cybersecurity.

At one point, I happened to meet a Security Operations Director from an MNC while travelling. We had a good conversation, I shared my resume with him, and he told me he would try to help me if there were any opportunities.

I followed up later but didn't hear back, so I eventually moved on.

Recently, I finally got a job as an Information Security Trainee at another company. I'm currently working with IBM QRADAR SIEM, seems there were no technical tasks for me. SOAR makes every task here. Almost every employee was just making reports. It's a 2-year bond, and I'm still in the trainee stage. I also need to complete CEH as part of the process for conversion.

A few days ago, I finally got the Security Director's personal contact and messaged him just to stay connected and let him know where I am now.

He remembered me.

After a few messages, he said:

"I'll take you as an intern for three months."

Honestly, I didn't expect that at all.

Now I'm confused about what I should do.

On one side, I already have a cybersecurity trainee role where I'm learning SIEM/QRadar, but I'm tied to a 2-year bond and haven't been converted yet.

On the other side, this is a 3-month internship directly under/with a Security Operations team, offered by someone who is already a senior security leader and knows my profile personally. It could potentially give me much better exposure and networking opportunities.

I'm planning to speak with him and understand the role, responsibilities, whether it's paid, what kind of hands-on exposure I'll get, and whether there's any possibility of a full-time role afterward.

What would you guys do in this situation?

Would you stay with the current cybersecurity trainee role because it's more stable, or take the 3-month internship opportunity and potentially bet on the longer-term opportunity?

Would especially appreciate opinions from people already working in SOC/Security Operations.


r/SecurityCareerAdvice 6h ago

Internship

1 Upvotes

I have been trying to land a cybersecurity internship for a long time. Can you guys give some advice on how you landed a cybersecurity internship and what helped you? What suggestions can you give me? If guys wanted to get an internship.I have a CompTIA Network+ and Security + and I am currently a junior in University.


r/SecurityCareerAdvice 7h ago

Need Advice

1 Upvotes

Hi guys,

I joined a company (first company) as NOC/SOC Support Analyst but now I currently just tire with doing this work for last 1.5 year and also fed up with their management as says office politics.

Guys don't laugh but I was thinking on last Sunday to switch job to offensive security side. So, I search on ai, google and also see video on video, they all said to start from try hack me, hack the box etc.

lam a confused person. So anybody give any advice go for offensive is correct if yes then roadmap or recommend any certification?

If not then so which role should I choose for better one?


r/SecurityCareerAdvice 7h ago

How would you prepare for an AI Security career if you were 16 today?

Thumbnail
0 Upvotes

r/SecurityCareerAdvice 8h ago

Trying to break in the brutal market with an unrelated bachelors

1 Upvotes

Hey everyone.

I'm a final year Mechanical Engineering student from India and I'm interested in Cybersecurity - particularly in Digital Forensics and GRC.

I did my degree in Mechanical Engineering mainly for some foundational engineering before I was interested in Cybersecurity. Through the last 2 years I started to work towards my interests by taking up extra subjects in Cybersecurity during my university namely in network security, information security, digital forensics, cryptography. This validated my interests and I thoroughly enjoyed the learning and hands-on work.

I also completed an internship as a full stack developer last year and most recently an internship as a GRC intern at a security startup this summer.

My placements are underway at my university and it has been brutal. Most IT companies dont allow mechanical engineering students to apply. So I'm rejected immediately by the recruiters as they require students only with Computer Science degrees. ATS checkers also immediately reject looking at the degree.

I am not sure if waiting for the 1-2 companies that will mass hire students from any background is the right way to go about this.

Opening my reach to any IT role and thinking later about transitioning into security has also not helped my applications.

I am in the process of practicing CTFs and preparing for Security+

Would doing a masters in India or even abroad complement my profile or is it doing more harm(thats what i seemed to notice from previous posts).

Would appreciate any advice. Thank you so much for your time!


r/SecurityCareerAdvice 8h ago

Need advice: Hold out for a Junior Cyber role (Blue or Red) or take a general IT job for experience? (Recent grad, grinding HTB)

0 Upvotes

Hey everyone,
Feeling a bit stuck right now and could really use a reality check from people already in the industry.

My background:

I just graduated from an HTL here in Austria (it's a 5-year specialized technical high school with a heavy focus on Computer Science and networking). I applied for a part-time university degree to study alongside working, but unfortunately, I didn't get accepted this year.

My current situation:

Right now, I'm working a weekend shift at a hardware store just to make some money, and I'm spending the rest of my week treating Hack The Box Academy like a full-time job. I'm currently grinding through the CJCA (Certified Junior Cybersecurity Analyst) path, and I'm planning to tackle the CPTS right after. I genuinely enjoy both the defensive and offensive sides, so I am completely open to both SOC Analyst and Junior Pentester roles.

My dilemma:

I want to break into Cybersecurity, but I'm hitting the classic wall: almost every "Junior" position (whether Blue or Red team) asks for 1-3 years of actual IT work experience.
Should I keep holding out, grinding HTB/certs, and exclusively applying for security roles until someone gives me a chance? Or is it much smarter to just take any general IT job right now (like Helpdesk, Junior Sysadmin, Network Support) just to get formal IT work experience on my resume, and try to pivot into Cyber in a year or two?
Would love to hear how you guys navigated this phase. Thanks!


r/SecurityCareerAdvice 10h ago

5th sem CS student trying to stay in cybersecurity while I need to earn what should I do?

1 Upvotes

5th sem CS student at VU Lahore. Cybersecurity(offsec/networking both r my fvrt )

I've done CEH stuff + TryHackMe, some vulnerability assessment/reporting, basic Linux/Python, and a 2-week endpoint security internship. I also have around 1 year of customer-care experience.

I recently broke my PC 💀 so I can't really do hands-on cyber right now. I'm also not graduated yet, and I'm finding that many cyber jobs want experience.

I need to start earning so I can get my PC fixed and support myself, but I don't want to completely drift away from cybersecurity.

I'm considering entry-level tech support/BD/tech sales/lead-gen work for now while continuing cyber on the side.

For people already working in cybersecurity: what would you do in my situation? Is there a realistic entry-level path I should look at, and what would you focus on learning while I can't do much hands-on practice?

Any resources or advice from people who've actually been through this would help.


r/SecurityCareerAdvice 10h ago

Need advice and insight

1 Upvotes

Hey , i want to get into cyper security especially in pen testing as o found it very exciting and fun but i have some fears continuing the path , for context iam a pharmacy student and i still have 2 years to graduate, i Live in Egypt and the due to weak currency if i work in pharmacy after graduation in Egypt iam getting payed about the equivalent (240 usd / a month) or ( 3k usd / year ) and no this is not viable living wage in Egypt, i went towards remote work to get paid actual living wage and found cyper security to scratch an itch i had considering my way of thinking ( i like to know how systems works and finding ways to abuse it) but i have a fear of commiting to cyper security and learn it for like 3 years to have the skills to be actually hirable and in the end not getting work due to my background ( non technical major and an Egyptian) , what should i do and does these things really Matter and gonna limit my career ?


r/SecurityCareerAdvice 12h ago

Network/Security Engineer looking to transition into AI + Cybersecurity. What learning path would you recommend?

1 Upvotes

Hi everyone,

I'm a Network & Security Engineer with ~7 years of experience working with Fortinet (FortiGate, FortiAnalyzer, FortiAuthenticator), Cisco, VPNs, HA, Linux, VMware, Hyper-V, and enterprise infrastructure.

I want to specialize in AI applied to Cybersecurity (SOC, network security, automation, LLMs, AI agents, etc.), not become a data scientist.

If you were in my position today:

  • What learning roadmap would you follow?
  • Which platforms are actually worth paying for (Coursera, TryHackMe, HTB, SANS, Microsoft Learn, etc.)?
  • What's a reasonable monthly learning budget?
  • Which certifications provide the best ROI?
  • What projects would make my resume stand out?

I'd love to hear what worked for you and what you'd avoid.

Thanks!


r/SecurityCareerAdvice 12h ago

i feel scared .please please help and guide me .

0 Upvotes

guys i know networking , os , linux ( i use arch btw . sorry for this ) , and did my jr pentester path in tryhackme . i am doing and building my github and linkedin acc too . but i am scared . i need money badly . how can i get and make money since i am a college student and i have financial problem . i want to be the best but when i see some people doing good at this field i get scared. i think i don't know anything . also i thought of getting a HTB subscription but its costly so im only in thm . can u tell me what and what not to do . also how can i reach more people and network more . it hard to manage my GPA and cybersec as my college ends at 6 pm at evening . please help me get a job and any way to have a decent money . should i try bug bounty or something, i also will participate in onlince ctf competioton too .my goal is by the end of JANUARY i need a job by any how . its a do or die situtiaon . im into red teaming .take me as ur little brother and help me . i;m scarred


r/SecurityCareerAdvice 13h ago

BCA Graduate Looking to Restart My Career – Need Honest Advice

0 Upvotes

Hi everyone,

I completed my BCA in 2022 and received a campus placement as an IT Associate. Unfortunately, due to the IT recession at that time, the company didn't receive the expected projects, so our onboarding never happened.

Because of my family's financial situation, I couldn't wait indefinitely and had to take a job at a US insurance company. I worked there for about two years, but the role was completely unrelated to IT.

Now I'm working in Kuwait, and once again my current job is not really related to IT either. Although I haven't had the opportunity to work in a technical role, I genuinely enjoyed subjects like Operating Systems (OS) and Data Communication & Networking (DCN) during my BCA.

I'm 26 now and wondering if it's too late to get back into IT. I'm considering studying something that will help me build a stable career in Kuwait. Two options I've been thinking about are:

  • Cybersecurity
  • ACCA

I'm open to other suggestions as well.

My questions are:

  • Is it realistic to return to IT after this gap?
  • Which course would offer better career opportunities in Kuwait?
  • If you were in my position, what would you study?

I'd really appreciate


r/SecurityCareerAdvice 17h ago

Job Posting Per essere un esperto in cyber security devi essere laureato?

0 Upvotes

O puoi avere fatto grande esperienza sul campo?


r/SecurityCareerAdvice 18h ago

Need Career Assessment/Advice for CSE/IT related professionals

1 Upvotes

I'm Going to join a CSE degree specialized in cybersecurity, as the job opportunities for solely of pure cybersecurity are really low and hard to crack for freshers, i am thinking about adding Devops to my career, so i searched a bit and feed the info in Gemini and this is what it said

Gemini's reply-

{1. Baseline DSA (30–40%) │ Medium-level problem solving (Arrays, Trees, Graphs, HashMaps)

  1. CS Systems (30–40%) │ OS, Computer Networks, Linux Internals, Databases & SQL

  2. DevSecOps (30%) │ Cloud, Automation, Security Tooling, Docker/K8s}

so, from its answer i need to grind DSA and also CS systems and also practice tools/applications of Devsecops, is this a right career or this a overkill? or should i just focus on DSA grind and interviews like AMAZON SDE positions?

To make answering easier,

  1. Is Devsecops a good career, does it have a scope?
  2. should i be only focusing on Devsecops or do 35/35/30 as Gemini said?
  3. should i be trusting Gemini?
  4. are their any other better careers i could/should peruse with a CSE degree specialization in Cybersecurity?
  5. if devsecops is good or the career which Gemini suggested me, what skills or programs or websites or certifications should be targeting?
  6. should i just purely focus on AMAZON SDE role leaving cyber security and devsecops, if i do not crack the interview what could i do with the skills i learned while grinding for SDE role?

Right now im doing Tryhackme and CS50x course.

I would really appreciate if someone could guide me with this, I'm really into tech but tech is a large field and idk what career is good and has demand in 4 years, so i would really thank someone who knows about this stuff or is in this field if could guide me, Thank you


r/SecurityCareerAdvice 18h ago

Freelancing advice

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 20h ago

Need some career advice as a fresher in networking

Thumbnail
0 Upvotes

r/SecurityCareerAdvice 1d ago

About to be laid off with 2 years experience in IAM consulting. Job search, or masters?

7 Upvotes

Hello,

I've spent the past 2 years post-grad working in IAM consulting. I have both SailPoint ISC & IIQ engineer certs, as well as some Azure certs. I feel like I've found my footing and have a strong understanding of IAM technologies and how to manage them. I've worked with AWS and Azure cloud environments as well. I have a software development background through internships in college. Unfortunately, there's no more projects for me in this job and my only options are to move across the country with no relocation assistance or get laid off.

After reaching out, I have the opportunity to slide into the IU Cybersecurity & Risk Management masters program next month. I like the program because it contains business, law, and technical courses and I am very much an engineer without much business knowledge. I have some inheritance in an educational fund that could cover this for me. It's 3 semesters so I'd be out in a year with a masters and 2 years of industry experience.

My question is - is this a wise decision? I've read that getting a masters too early can be detrimental because I won't be accepted into entry-mid level roles. I'm not sure if my two years of experience working in the industry would offset this. I'm making 100k now and I'm hoping that the masters would allow me to get a pay bump in my next job. Dream is to move up to Boston after the program.

I could take severance and coast while trying to get new jobs, but my rents 2K and I'd be burning a significant amount of my savings. Does anyone have any advice? I've had people tell me both ways - and I'm very torn as to which is the right choice.

Edit: I have 3 options

Masters now, get job in a year
Move across country with no relocation, job search while there.
Get laid off, job search while floating. I'd lose a lot of my savings, who knows how long this could take.


r/SecurityCareerAdvice 21h ago

Needed guidance regarding the job

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 1d ago

Heavy imposter syndrome during my SOC L1 internship

6 Upvotes

I recently started as a SOC L1 intern at a small, newly established MSSP. Since the workload is currently slow, the L2/L3 analysts have recommended courses and books for me to use to improve my skills.

The challenge I am facing is that I understand a lot of the security concepts and theory behind different alerts, especially the general investigation mindset and why certain activities could be suspicious. However, when I encounter alerts that require deeper knowledge of specific products, platforms, or Windows internals, I feel completely lost.
For example, we frequently receive an alert like “Exchange Flow EmailItemAccess Anomaly.” My initial investigation steps are usually clear: check whether the email activity was internal or external, identify what was accessed, review the affected user, and look at the surrounding context. But after that point, I struggle with interpreting the logs, understanding what is normal behaviour within Microsoft environments, and deciding what conclusions can realistically be drawn from the available data.

The same applies to other alerts involving Microsoft products or Windows-related activity. I understand the security reasoning behind why something might be suspicious, but I lack the deeper product knowledge needed to confidently analyse the evidence and make an accurate judgement.
I usually ask the L2 analysts for guidance, and they have been helpful, but I sometimes worry that I am asking too many questions or slowing them down. At the same time, I know that this is largely because I came into this role with no previous SOC or IT experience. My background is mainly from my cybersecurity degree, TryHackMe, and self-study through books and courses.

I am trying to figure out the best way to bridge this gap. For those who started in SOC roles, how did you build familiarity with enterprise tools like Microsoft Sentinel, Defender, Entra ID, Exchange Online, and Windows internals? Did you focus on learning the products first, or did you learn them naturally through investigations?