r/SecurityCareerAdvice Apr 05 '19

Certs, Degrees, and Experience: A (hopefully) useful guide to common questions

331 Upvotes

Copied over from r/cybersecurity (thought it might fit here as well).

Hi everyone, this is my first post here so bear with me. I almost never use Reddit to talk about professional matters, but I think this might be useful to some of you.

I'm going to be addressing what seems to be a very common question - namely, what is more important when seeking employment - a university degree, certifications, or work experience?

First, I'll give a very brief background as to who I am, and why I feel qualified to answer this question. I'm currently the Cyber Security Lead for a big tech firm, and have previously held roles as both the Enterprise Security Architect and Head of Cloud Security for a Fortune 400 company - I'm happy to verify this with mods or whatever might be necessary. I got my start working with cyber operations for the US military, and have experience with technical responsibilities such as penetration testing, AppSec, cloud security, etc., as well as personnel management and leadership training. I hold an associate's degree in information technology, as well as numerous certs, from Sec + and CISSP to more focused, technical security training through the US military and organizations like SANS. Introductions aside, on to the topic at hand:

Here's the short answer, albeit the obvious one - anything is helpful in getting your foot in the door, but there are more important factors involved.

Now, for the deep dive:

Let's start by addressing the purpose of certs, degrees, and experience, and what they say to a prospective employer about you. A lot of what I say will be obvious to some extent, but I think the background is warranted.

Certifications exist to let an employer know that a trusted authority (the organization providing the cert) has acknowledged that the cert holder (you) has proven a demonstrable level of knowledge or expertise in a particular area.

An academic degree does much the same - the difference is that, obviously, a degree will generally demonstrate a potentially broader understanding of a number of topics on a deeper level than a cert will - this is dependant on the study topic, the level of degree, etc., but it's generally assumed that a 4-year degree should cover a wider range of topics than a certification, and to a deeper level.

Experience needs no explanation. It denotes skills gained through active, hands-on work in a given field, and should be confirmed through positive references from supervisors, peers, and subordinates.

In general, we can see a pattern here in terms of what a hiring manager or department is looking for - demonstrable skills and knowledge, backed up by confirmation from a trusted third party. So, which of these is most important to someone trying to begin a career in cyber security? Well, that depends on a few factors, which I'll discuss now.

Firstly, what position are you applying for? The importance placed on degrees, certs, and experience, will vary depending on the level of job you're applying to. If it's an entry level admin or analyst role, a degree or a handful of low-level certs will definitely be useful in getting noticed by HR. Going up to the engineering and solution architecture level roles, you'll want a combination of some years of experience under your belt, and either a degree or some low/mid level certs. At a certain point, the degree and certs actually become non-essential, and most companies will base their hiring process almost entirely on the body and quality of your experience over any degree or certifications held for management level roles.

Secondly, what are your soft skills? This is a fourth aspect that we haven't talked about yet, and that I almost never see discussed. I would argue that this is the single most important quality looked at by employers: the level of a candidate's interpersonal skills. No matter how technically skilled someone is, what a company looks for is someone who can explain their value, and fit into a corporate culture. Are you personable? Of good humor? Do people enjoy working with you? Can you explain WHY your degree, certs, or expertise will add value to their corporate mission? Being able to answer these questions in a manner which is inviting and concise will make you much more appealing than your competitors.

At the end of the day, as a hiring manager, I know that I can always send an employee for further training where necessary, and help bolster their technical ability. What I can't do is teach you how to work with a security focused mindset, nor how to interact with co-workers, customers, clients, and the company in a positive and meaningful way, and this skill set is what will set you apart from everyone else.

I realize that this may seem like an unsatisfactory answer, but the reality is that degrees, certs, and experience are all important to some extent, but that none of these factors will make you stand out. Your ability to sell your value, and to maintain a positive working relationship within a corporate culture, will take you much farther than anything else.

I hope this has been at least slightly helpful - if anyone has any questions for me, or would like any advice, feel free to ask in the comments - I'll do my best to reply to everyone.

No TL;DR, I want you to actually take the time to read through what I've written and try to take something away from it.


r/SecurityCareerAdvice 5h ago

Discussion Starting a solo consultancy gig, seeking advice on the fundamentals

6 Upvotes

15 years in cybersecurity (contract and direct), working across assessments, engagements, and various tools/vendors. I’ve also done a few 3-6 month stints leading projects end-to-end: coordination, implementation, documentation, direct communication with CISOs/CEOs. Not glamorous: weekends, on call, tribal knowledge, high stakes.

I have an LLC already registered for a few years, just never pulled the trigger. Reasons to go now: capped out on W2 salary while taking on more responsibility, and burnt out. I want to go solo, setting my own engagement parameters based on what I’ve seen work (and not work) from the inside.

I know to set aside for taxes and I need to figure out insurance (E&O/cyber liability, I assume). Beyond those two, what am I missing? Things like:

Contracts/MSA templates specific to security work.

Scoping and liability boundaries for pentest/assessment engagements.

Pricing models (hourly vs retainer vs project-based).

Client acquisition without an existing referral network.

Certifications/compliance credentials that actually matter for landing clients.

General small business seminars feel too generic for this field. Looking for advice from people who’ve actually done the solo cybersecurity consulting jump.


r/SecurityCareerAdvice 2h ago

Question Should I do it

2 Upvotes

Iam doing Googles cyber security certificate now and it's going well Iam currently in course 4 almost finished I've heard good things and bad things too slow it teaches the basics, but I've also heard that it teaches you how to start and if you finish it you get 40% sec+ I think what do yall think I should do next or whether it was a good choice or bad (Iam a beginner in cyber security)


r/SecurityCareerAdvice 6h ago

Question Work as employee or be self-employed?

2 Upvotes

Hello everyone,

I've been thinking a lot about what I wanna do in the future career wise; I've been conflicted on whether I should pursue being an employee or growing my own business I've been doing for about a year (not entirely cyber-related though).

Some background regarding my current experience:

  • bachelors in cybersecurity
  • pursuing masters in cybersecurity, expecting to graduate next year
  • 1 year contract work at a smaller security firm as pentester and working on backend cloud infrastructure (currently working here)
  • 1.5 years managing school network/security lab (currently working here)
  • certs: CCNA, Sec+, CRTO (taking exam next week)
  • interned at a bigger consulting firm doing pentesting and red/purple teaming. recently accepted a return offer for after I graduate.

I love security. I never really knew whether I wanted to be more red team or blue team-oriented, but the pieces just fell into place and here I am entering offensive security.

I'm extremely grateful for getting a position in offensive security, as I know the job market is rather brutal at the moment. However, the pay isn't all that great and I instantly got shut down when making a very slight counter offer. I thought that my masters degree, certs, and experience would help me earn a little more, but I'm starting off with the same base salary as fresh undergrads.

Given that it's quite unlikely to land another position before then in offensive security, I'm deciding whether I should try to grow my business while I'm in my last year of school. And if I do decide on this, I'd pivot to have my business focus more on security than general IT. Naturally, I pretty much took on any client at the start so long as their problem was technology-related.

For my business, I've done work similar to MSP/IT shops and a few basic security audits: setting up new infrastructure for small businesses, fixing issues with computers, printers, servers, server/workstation/firewall configuration reviews, etc. Also did a small pentest for an e-commerce web app.

If I do decide to focus on the business, I'd most likely aim to be more security-focused. I know I don't have an insane amount of experience but I've been tinkering with technology my entire life. What I listed above are just some main points. I'm confident I can solve most problems which is why I started this side business in the first place.

Why not do both? In addition to overworking myself (my main job will already be consulting, so it won't be uncommon to work over 40 hours a week), if I do pivot to being more security-focused I'll have a conflict with my current employer since I am basically doing the same thing there.


r/SecurityCareerAdvice 11h ago

Question SOC L1 analyst to WHERE?

5 Upvotes

Hey everyone,

​Currently working as a SOC L1 analyst at a product-based company with roughly 2 years of experience.

​The standard career path here seems to be stepping up to SOC L2/L3 which, from what I see, usually means handling escalation tickets plus taking on people management, scheduling, and standard operational overhead. To be completely honest, I want to double down on deep technical rather than managing shift rosters or babysitting alert queues.

​I’m looking to transition into roles that focus heavily on technical depth, continuous learning, and solid growth think Detection Engineering, Incident Response (IR), Threat Hunting, or similar tracks.

​Realistically, I’m also aiming for a significant compensation jump on my next move (not expecting crazy outliers like 50 LPA at 2 YOE, but looking to maximize the bracket for my experience level).

Would love to hear your experiences, reality checks, or recommendations on where to focus my prep over the next few months!


r/SecurityCareerAdvice 3h ago

Question X

0 Upvotes

People say Twitter/X is important in cybersecurity for networking, threat intelligence, security news, and learning from experts. If I don’t use it, will I miss out or be at a career disadvantage? I want to keep my digital footprint minimal, so is X actually necessary for a SOC/Blue Team career?


r/SecurityCareerAdvice 3h ago

Question X

0 Upvotes

Should I use Twitter/X as a cybersecurity student?

I’m studying cybersecurity and planning to build a career in Blue Team/SOC. I already use LinkedIn and GitHub, but I’m considering not using Twitter/X because I want to keep my digital footprint minimal and avoid social-media distractions.

My question is: Will not having a Twitter/X account put me at any disadvantage in cybersecurity, especially for SOC Analyst career growth?

Do cybersecurity professionals actually benefit significantly from using X, or can I get the same information and networking through LinkedIn, GitHub, security blogs, threat-intelligence reports, etc.?

I’d especially appreciate answers from people working in cybersecurity/SOC.


r/SecurityCareerAdvice 4h ago

Discussion should I take a 2-year HPE commitment or move toward Cloud/DevOps?

1 Upvotes

I’ve completed around 6 months in my first job at a System Integrator, and I’m currently getting ₹25k/month. My work has been mainly infrastructure — HPE servers, VMware ESXi/vCenter, Hyper-V, Veeam, Windows Server, networking, Palo Alto, storage, etc. Since it’s an SI, I get exposure to different clients and technologies, but most of my work is implementation and technical support.

Now my company is considering spending around ₹3–4 lakh on HPE training and professional certifications for me, but they want a 1–2 year commitment in return. If I take it, I would probably become more specialized in HPE/VMware/infrastructure.

At the same time, I’ve started getting very interested in Linux, cloud, automation, Terraform, CI/CD and DevOps. I haven’t worked professionally on these yet, but these are the areas that genuinely make me curious. My current company being an SI also means I probably won’t get much DevOps exposure here.

So I’m confused about which direction is better for me:

1. Stay here for 2 years, take the HPE certification and build a career in enterprise infrastructure/virtualization/storage/networking.

2. Stay another 6–12 months, keep building cloud/automation skills on my own, and then move toward Cloud/DevOps/Platform roles.

I’m also seeing some of my friends working as SWEs at companies like Microsoft/Google and earning very well, which has made me question whether I should also consider SWE, although I’m not sure yet whether I actually enjoy software development enough to make that my career.

So what I really want to understand is: with my current background, what kind of engineer should I try to become, and would you recommend that I specialize in infrastructure through this HPE opportunity or keep my options open and move toward Cloud/DevOps?

I don't want to make the decision just based on immediate salary. I want to choose the path that gives me the strongest technical growth and career opportunities over the next 5–10 years. What would you do in my position?


r/SecurityCareerAdvice 13h ago

Question Cert/ career advice

4 Upvotes

Hi all,

I have been working in IT for 6 years. I started on the Helpdesk in a non technical role, moved to level one, then level two and now I have moved to a security specialist role. I’m 3 weeks into this role and so far I’m liking it, it’s a lot of reviewing clients to see what security measures they have in place then aligning them to our sec framework (or looking how to mitigate risk if the specific measure can’t be implemented)

What certification would you recommend for someone new in cyber security? I’ve started with SC900.

I’m honestly not sure what part of cybersecurity I want to specialising in yet.

Ive worked a lot with M365 and I really enjoy working with Azure/365.

I plan on starting a family in the next few years. Before then, I want to hustle, establish a good career and make money.


r/SecurityCareerAdvice 6h ago

Question Should I get a master’s in cybersecurity for foreign policy?

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 6h ago

Question Cybersecurity job in norway

1 Upvotes

I am currently doing my masters in cybersecurity but the problem is for the role like soc we(international students) require security clearance and whomever i ask they say it’s nearly impossible to get it. So like what job can i do with these degree which job profile should i target like cloud security, VAPT or what else. I am fresher with no it experience before


r/SecurityCareerAdvice 6h ago

Question Tier 1 to Detection

1 Upvotes

Been doing SOC Tier 1 for almost two years now, and honestly, I'm done with it. Triaging the same alerts, closing tickets, copy-pasting the same notes. It doesn't challenge me anymore, and I don't enjoy it.

What actually interests me is detection engineering: writing and tuning the rules instead of just working with the output of them.

My current stack is Sentinel (KQL daily), Defender XDR, CrowdStrike, Proofpoint, Zscaler, and LogRhythm.

A few questions for anyone who's made the move:

Did you go straight from Tier 1 to detection engineering, or did you have to do Tier 2 first?

What actually got you the interview: a home lab, public detection repo, GitHub contributions?

Any courses or resources that were genuinely worth it?

Appreciate any advice.


r/SecurityCareerAdvice 7h ago

Question Working in reverse engineering

1 Upvotes

Hello everyone,

I am currently in the final year of my Master's degree in cybersecurity (in France). I have a strong interest in low-level concepts, specifically reverse engineering. I've recently started learning NASM assembly and I would absolutely love to find an internship or a full-time job in this area.

My questions are: Are there roles that are 100% dedicated to reverse engineering? What kind of companies hire for this? Also, what are the career growth and advancement opportunities like in such a specific field?

Any feedback, advice or personal experiences would be greatly appreciated! Thanks in advance.

(I also asked this in r/AskReverseEngineering, but thought it would fit here too.)


r/SecurityCareerAdvice 7h ago

Discussion The newest cybersecurity specialisation isn't securing networks from people, it's securing AI systems from themselves

1 Upvotes

Follow-up to the broader cybersecurity demand numbers going around, roughly a million roles needed against 80,000 qualified professionals in India currently.

One of the fastest-growing sub-specialisations within that is AI security specifically, securing the models and agent systems themselves, not just the infrastructure around them.

Makes sense given how much of this year's AI safety news has been about agents behaving unpredictably or getting exploited in eval environments.

If you're picking a security specialisation right now, knowing how to red-team an LLM or an agent pipeline is turning into its own distinct skill set from traditional network or app security, and it's early enough that there isn't a big established talent pool yet.

Anyone here actively working in AI red-teaming or model security, what does that work actually look like day to day?


r/SecurityCareerAdvice 8h ago

Question What job offer to choose

1 Upvotes

\*\*Two junior security offers which one pays off more long-term?\*\*

Quick background: finishing my CS-adjacent bachelor's in Germany at the end of this year. Currently a working student on a cloud security team at a large financial institution (Microsoft Defender/XDR, SOC-adjacent work, plus identity governance — role concepts for privileged access, PIM, an IGA tool). Web dev before that (Python, Node, TypeScript).

I have two offers, both starting December/January. Compensation is comparable between them, so it isn't really the deciding factor once cost of living is accounted for.

\*\*Option A — Junior SOC / Detection Engineer\*\*

\- Small managed detection provider, \~5 years old

\- SIEM use case + parser development, EDR, vulnerability management, threat intel; IR/forensics/malware analysis later depending on how it goes

\- 100% remote, I could stay where I currently live

\- Shift work (early/late, on-call, weekends possible), no night shifts per the team

\- Generous leave, 10 training days/year, possible SANS course if I perform well

\*\*Option B — Junior IAM & AI Security Engineer\*\*

\- Large listed consultancy, consultant track

\- IAM engineering across client projects: authorization concepts, OAuth/SAML/OIDC, cloud (AWS/Azure/GCP), Terraform/Ansible, CI/CD, some AI security angle. Roughly 70% technical / 30% advisory

\- Hybrid, 2 days on site — means relocating to a much more expensive city

\- No shifts, no on-call

\- Certifications paid for

My worry with A: tier-1 triage feels like exactly what every vendor is currently automating, and I'd be fully remote as a junior with no one in the room to learn from.

My worry with B: IAM has no equivalent of LetsDefend/CyberDefenders to grind on, so skill-building feels less measurable, and consulting could mean getting stuck on one rollout for two years.

Which path ages better over 3–5 years? Has anyone gone either route and regretted it?


r/SecurityCareerAdvice 14h ago

Question Which topics should I prepare as a fresher

3 Upvotes

I am a student now and want to get a internship or job in cybersecurity field. As a junior I want to ask the seniors what are the topics should I prepare or cover for get a job or internship right now? Already I have watched many YouTube videos, roadmaps etc. but confused a bit. If you allow seniors help me a suggest the topics mainly which should prepare, it's very grateful to me and others who will see the post.


r/SecurityCareerAdvice 13h ago

Question Career Pivot in Cybersecurity

3 Upvotes

Hello everyone,

You might be thinking: "Oh God, another person who wants to switch to cybersecurity!"

Before you comment that, here’s a bit of my background, which I hope will provide some useful context (sorry for the long post!)

I’m Italian, although I have been living in the UK since 2018. I have an Italian diploma in IT and Information Technology, but I went on to pursue a BA (Hons) in Graphic Design in the UK.

I started my career as a UX Designer and IT Tester. During my final year of university, I was already learning UX Design alongside my Graphic Design degree, which helped me move into UX and testing roles.

For around a year and a half, I supported my agency with UX-related activities as well as testing IT features.

My key responsibilities as an IT Tester included:

  • Testing software for bugs, errors, and performance issues
  • Creating and executing test cases based on requirements
  • Reporting and documenting bugs for developers to fix
  • Retesting fixes to ensure issues had been resolved
  • Checking user experience and functionality across different devices and browsers

I also have some knowledge of HTML and CSS, a very basic understanding of C++ (I have forgotten almost everything since my diploma due to not practising), as well as some experience with Project Management.

After around a year and a half, I moved into an Account Executive role and am now working in Account Management. I am also currently pursuing a Part Time Master's degree in International Business, which is due to finish in January 2028.

Overall, I have roughly four years of professional experience across these different areas.

Since graduating in IT and Information Technology, I have always wanted to pursue a career in cybersecurity. However, due to some family crap, I ended up moving to the UK and starting my career in the creative industry instead.

Now that I am 28, I am seriously considering making the transition into cybersecurity (which should have happened a long time ago but hey life can be unpredictable). There is genuinely nothing else I would want to pursue more than a career as a SOC Analyst.

With my background, do you think it is realistic and worth transitioning into cybersecurity?

If the answer is yes, how would you recommend I approach it? Would a bootcamp (TripleTen etc) be worthwhile, or would going back to university for another bachelor's degree be overkill?

I am quite confused about how to get my foot in the door, so I would really appreciate any advice from people who have made a similar transition or currently work in cybersecurity.

Thanks to everyone who takes the time to read this and share their advice!


r/SecurityCareerAdvice 15h ago

Question Is Meetup.com worth using for tech/cybersecurity networking in Auckland?

2 Upvotes

Hey everyone, I recently finished my Master’s in Cybersecurity and Digital Forensics and I’m currently trying to get into the IT/cybersecurity industry in Auckland.

I’ve started looking at Meetup.com and found events around Microsoft, Dynamics 365, Power Platform, AI, GitHub Copilot, and other tech topics. I’m thinking of attending some of these in person mainly to learn, meet people in the industry, and understand what technologies companies are currently using.

For people working in tech in Auckland, is Meetup actually useful for networking and finding opportunities? Are there any particular Meetup groups or other communities/events you’d recommend for someone trying to break into IT or cybersecurity?

Thanks!


r/SecurityCareerAdvice 4h ago

Discussion Bug Bounties are EASIER than certs. Full stop.

0 Upvotes

I had posted before about how easy it is to get bug bounties. How its the most underrated way to get your foot in the door. And again and again people told me no its not easy. Yes it is.

To prove it I set out to find some volunteers to have their repo scanned (applause to them for being brave in letting me publicly roast their security posture).

I ran the process in a very open way so that people could see. You can audit every single one of these findings (albeit some may be fixed): https://www.reddit.com/r/vibecoding/comments/1w04gny/comment/p72mszw/?context=1&screen_view_count=2&ext-referrer=DIRECT

And here are the results:

Leaderboard

repo total findings Critical High Medium Low Info
enve book (reddit is not letting me paste in the link. idk why) 499 3 26 23 0 447
https://github.com/rrhoopes3/Grok-Party-Pack 154 1 37 14 23 79
https://github.com/ubermuda/loupe 77 0 14 10 13 40
https://github.com/VIDGuide/dogwatch 76 0 0 19 12 45
https://github.com/homeassistant-extras/pi-hole-card 71 0 0 3 5 63
https://github.com/GChavez0210/NetPulse 60 0 1 3 1 55
https://github.com/shaqkao/screenshotify 36 0 0 2 6 28
ps://github.com/mencelot/DK2-Remix-Predetermined-Hashing 28 0 0 1 0 27
https://github.com/thecyborgcoder/2026-world-cup-simulation 18 0 1 5 0 12
https://github.com/ghreprimand/odytty 13 0 2 3 1 7
https://github.com/gtited-jpg/DaemonCore-Linux-Distro 10 0 1 6 3 0
ttps://github.com/KrystalUnity/krystal-loop-protocol 8 8 8 1 0 7
https://github.com/8exgh/meeting-alert 6 0 0 0 5 1

What should I do next? See if I can get someone to beat the Leaderboard's high score? Give up?


r/SecurityCareerAdvice 19h ago

Question Cyber role to network administrator for 13k raise?

3 Upvotes

I’ve been with the same company for almost a year. I started on Help Desk, spent about five months there, then moved internally into an IT Security Risk Analyst role.
I’m almost finished with my associate degree in Cybersecurity and have close to two years of total IT experience, plus A+ and Network+.

There’s now a Network Administrator position open internally that I think I have a good shot at. It would be about a $13k raise and put me just over $70k.

The problem is I enjoy cybersecurity more than networking and ultimately want my career to stay in security. On the other hand, the networking experience would probably help my security career, and $13k is hard to ignore. LCOL area

Would you take the Network Admin role for the pay and experience and move back into security later, or stay in security and keep building experience?

Also, would Help Desk to Security Risk Analyst then to Network Admin this quickly look bad, or does it just look like internal career progression?

Thank you


r/SecurityCareerAdvice 1d ago

Question Should I go for an IR degree?

1 Upvotes

I'm part of a program that's paying for both my A+ and Security+ certs. I'm a complete beginner but I have a real interest in cybersecurity and everything that goes into it. Call me idealistic but I feel like with things going the way they're going in world there's gonna come a time where every nation is going to start coming up with stricter laws to try and cover themselves. I'm interested in still keeping up with my cybersecurity certifications and renewing them and still doing bootcamps but I also want to try and get an International Relations degree. I want to make sure that hopefully in some way I'll be able to use my knowledge someday to make sure people don't get totally screwed cause some person in charge had no idea what they were doing. I'm only 23 and kinda scared to do it and not even know if it would be worth it or benefit my cybersecurity career in the future. I could really use some advice.


r/SecurityCareerAdvice 1d ago

Question Networking with fellow Cybersecurity professionals

2 Upvotes

Is there a good website where Cybersecurity professionals can meet for discussion and to help each other with job leads ?
I checked meetup.com for a group, but didn't find anything really promising.
I have worked for 3 years on a government contract which will be ending in about 6 months so I would like to network with others to find my next gig.
My experience is in DLP, but I want to branch out into other areas. I have 25+ years in IT.
Thanks much for any helpful input.


r/SecurityCareerAdvice 1d ago

Discussion Am I burned out or just lost? 20yo cybersecurity student feeling like I have no value

3 Upvotes

Hey, I’m 20 and I’ve been into cybersecurity since I was around 15. I spent years doing TryHackMe, messing around with Linux, watching way too much cybersec content, etc. Cybersec was basically the dream I decided on when I was a kid.

I’m currently going into my final year in a cybersecurity degree, and honestly I feel kinda worthless career wise.

A lot of what we learned in university was stuff I had already seen before, so I never really felt like I was progressing much. Meanwhile, people I started university with who knew basically nothing about cyber are now getting eJPT, ICCA, etc. and actually improving consistently. I know comparison is stupid, but it’s hard not to feel like I’ve somehow fallen behind.

I also have around a year of IT experience now. My internship was a mix of IT support, networking, ERP/Oracle stuff, WiFi/VLAN troubleshooting, deploying laptops, printers, etc. It was unpaid, but I stuck with it because I wanted the experience. I’m also working on an FYP where I’m building an SOC dashboard that monitors a company with remote functionality, AD/GPO stuff and other features.

On paper, I feel like I should have something to show for all of this. I have a bunch of smaller/free certs, but nothing I consider particularly valuable. I also recently failed the CC exam pretty badly, which honestly messed with my confidence. I have SC-200 coming up in October, and even though I’m trying to study for it, I struggle badly with sitting down and going through study material. I’m much more of a hands-on person.

I’ve also been applying for junior/remote cybersecurity roles while studying and getting rejected constantly, which obviously doesn’t help.

My current plan is SC-200 then Security+ and then CCNA around next year, but I keep wondering if I’m wasting my time or focusing on the wrong things. Part of me thinks if I had eJPT/CEH/OSCP or something actually respected, I’d finally feel like I had value, but I also know collecting certs probably isn’t the answer.

I don’t even know if I’m burned out, lost, or just comparing myself too much to everyone else.

For people already working in cybersecurity:
what would you do if you were in my position? Would you focus on certs, projects, getting any IT/cyber job possible, or something completely different? And how do you get that motivation/passion back when you feel like you’re putting in effort but getting nowhere?

P.S: This ain’t AI btw, I just used it to check my grammar since English isn’t my first language lol.


r/SecurityCareerAdvice 1d ago

Other Is cisco networking accademy good , Imma absolute begineer

Thumbnail
4 Upvotes

r/SecurityCareerAdvice 1d ago

Question SecOps generalist, 7 YOE (3 in security) at a 4,000-endpoint healthcare company — am I underpaid, and what should I be building toward?

3 Upvotes

Background: 7 years total in IT, last 3 as a Security Analyst. I'm the sole "analyst-level" generalist on a 4-person SecOps team (2 engineers, 2 analysts) at a healthcare staffing company with 4,000+ employees/endpoints. Reporting chain is me → SecOps Manager → VP of Security → CIO. Trying to get a read from people actually in the field on whether my comp lines up with my scope, and what I should prioritize (certs, skills, lateral move) to level up from here.

Day-to-day responsibilities:

  • Alert and ticket triage — ranges from email security and application access reviews all the way through full incident response lifecycle, varies heavily day to day
  • Platform ownership for Tanium and SentinelOne (admin + reporting)
  • SOC monitoring
  • Vulnerability management and reporting
  • EDR administration
  • SOC audit support
  • Own the security awareness program end-to-end

Tools/stack: SentinelOne, Tanium, Lacework, Mimecast, Microsoft Defender/XDR, among others.

Notable wins:

  • Built our security awareness program from scratch to where it is today
  • Own all Tanium and SentinelOne reporting for the org
  • Helped the company pass a full SOC 2 audit two years running
  • Currently leading remediation efforts from our most recent pentest (this has turned into more of a program-management role than pure IC work)

Certs: Security+, Network+, HDI, JAMF 100, Tanium TCO. Currently pursuing CCSP.

Education: Associate's in General Studies — no security-specific degree, picked up some security-adjacent coursework after I was already in the field. I have access to ACI Learning through work if that changes the training-recommendation calculus.

Comp: $91k base + 10% annual bonus target. US-based, MCOL market (keeping exact location vague).

What I'm actually trying to figure out:

  1. Does $91k+10% sound right for this scope of responsibility, or am I leaving money on the table?
  2. Given I'm eyeing a move toward cloud security (CCSP now, CISSP eventually), does my current experience translate well, or am I missing hands-on cloud exposure that certs alone won't fix?
  3. Is the breadth here (SOC + EDR admin + vuln mgmt + audit + awareness) a selling point for my next role, or does it read as unfocused / not enough depth in any one lane?
  4. Any training, certs, or experience you'd prioritize before I start applying elsewhere?

Appreciate any honest feedback — trying to figure out if I should be negotiating harder where I am or start looking.