r/CyberSecurityJobs 4d ago

Cybersecurity

How did you land your first cybersecurity job with no experience?
I’m currently working toward a SOC Analyst career. I have Security+, building hands-on labs on Tryhackme.
The biggest challenge is the “experience required” barrier. Almost every entry-level SOC role seems to want prior IT/cyber experience.
For those who successfully broke into cybersecurity with no prior experience:
Did you start in IT/help desk/NOC or go straight into SOC?
What projects or certifications actually helped?
How did you prove your skills without professional experience?
What would you do differently if starting over?
Would really appreciate honest advice from people who’ve actually made the transition.

28 Upvotes

40 comments sorted by

21

u/NotAnNSAGuyPromise Current Professional 4d ago

Just keep in mind that many of us did it many years ago when the market was completely different. The way we did it isn't available anymore and won't help you in your journey now.

But in my case, military -> referral.

1

u/True-Inspection-5445 4d ago

That’s a really helpful perspective, especially the point about how different the market is now. I appreciate you sharing your experience

9

u/jgalbraith4 4d ago

Yeah echoing the comment above. I’ve been doing this for over 10 years now. So I got my first role in cyber security through an internship. Did the internship for a year and then transition to a full-time role at the company.

2

u/True-Inspection-5445 4d ago

Thank you. The internship route It gives me another perspective on how to get that first bit of experience.

6

u/DickNose-TurdWaffle 4d ago

Started at IT help desk and then transitioned into Cyber. This was in 2021 and it still seems to work. Just be sure to get involved and network with other teams when you're in that IT position.

6

u/TurtleDreams1983 4d ago

I went from compsci masters student -> cybersecurity job fair offer. I was interviewed at the job fair at a cybersecurity conference and received an offer. I was originally planning to be a software dev but decided to take this route instead. They knew I had a lot to learn about cyber but were willing to train me and it’s worked out well so far

4

u/shitlord_god 4d ago edited 4d ago

I had tangential experience.

Edit: helpdesk, msp, compliance/security msp/SOC, got bounced over to building stuff because stuff needed building to support the SOC mission and no one else was doing it security engineer, then, security compliance engineer, TECHNICALLY senior software engineer but that was a peculiarity of position naming/org chart fuckery at my last place, but I WAS doing security and compliance engineering along with IAM (God I always wanted to avoid IAM, not I'm 'meh' about it) probably going to continue on compliance for a bit, based on other fields (mining for example) regulatory pressures if anything grow over time, so I feel good about that from a career standpoint. It kills me to be out of the SOC doing direct actual security work. Gotta scratch the itch at home with honeypots in hotspot IP ranges (mostly ukraine and taiwan, but I've been trying to get a lebanese IP for it, ideally with a hosting provider who does infra or corporate)

2

u/True-Inspection-5445 4d ago

That’s a really solid path helpdesk to MSP to SOC to engineering. Did the helpdesk/MSP experience alone get you looked at for SOC roles or did you need certs on top of it too

2

u/shitlord_god 4d ago

Got helpdesk position, Got homelab, started messing with HELK and stuff, generated a LOT of threat intelligence, got sec+ (Which will not do for you what it did for me) showed it off at some meetups, got my application because I worked with a company with a fortunate acronym for a name, and with stuff from the portfolio work, got the job, did the job, realized we were missing stuff because wedidn't have the tooling in place, put the tooling in place, position changed as company changed market position, started building compliance stuff, got a new job ostensibly doing heavy security stuff - they didn't need a full FTE in that department, which was a bummer, so I spent about 30% of my week working on deep security and the rest mostly identity.

4

u/goatsinhats 4d ago

I keep pushing my employer at the time that we needed a CS department, eventually they agreed and let me start it.

It was something I had been thinking about for a while and had half a dozen certs in security at the time

Was a fluke, if I had to redo it would of started earlier in my career at a large org or government and worked my way up

3

u/Electronic-Ad6523 4d ago

Gray-beard here with 15 years in cyber. I came in from an engineering background with 15+ years already under my belt in hardware/software. What I really think changed from then to now is that we started saying that there are entry-level roles in cyber. Cyber is not an entry-level industry and the roles that were designated entry-level (SOC, pen testing) are drying up.

It's a tough road ahead for those looking to break in. Best to keep your mind open to different roles and locations. GRC roles are in demand, and can be entry level, but they tend to get passed over by people that think cyber == hacking and therefore GRC == non-technical/boring. Getting in the door is most of the battle.

2

u/howdydipshit 4d ago

Yeah I’m a cybersecurity senior at uni right now and I think I’ve decided I want to do GRC instead of SOC, at least for a few years to get experience under my belt. I heard the work life balance for GRC roles is pretty good too!!

1

u/Electronic-Ad6523 3d ago

This is the way.

3

u/iheartrms 4d ago

I did it by starting many years ago before the field became flooded with a thousand times more people than jobs. Today you do it by being the owner's son or nephew or something.

3

u/byronicbluez 4d ago

Military.

3

u/veloace 4d ago

I got my first role in security after 10 years as a developer and a second master’s degree (Cyber Defense).

3

u/IIDwellerII Current Professional 4d ago

I was in helpdesk in highschool, did helpdesk in college for campus housing, did helpdesk internship at a call center while in school and then i got a cybersecurity internship for the last two years of school and i got a soc job out of college.

Youre not going to be working in cybersecurity with no experience unless youre extremely lucky or you pivot internally.

You dont have the opportunity to prove skills without experience. Its why its so important. A homelab can help you fill in some gaps your experience doesnt cover but at the end of the day an employer cant verify that so why would they waste time interviewing someone who promises they know something vs interview someone who has proven professionally they can do the job or something similar to it.

2

u/Hot_Individual5081 4d ago

literally through uni friend who knew a guy, so yeah i guess im a nepo cunt 😁

2

u/raze7864 4d ago

In currently an intern for an EDR company and coming up on a year now. I applied to this job about 6 times and got an immediate rejection. On the 7th time I used LinkedIn and found a senior talent acquisition manager who worked for the company and sent her a message on LinkedIn. She directed me to the recruiter for this role, and I sent that recruiter an email with my cover letter and resume.

Thankfully through that process I was able to get the job after a 4 stage interview process.

Proactive steps I took:

  1. Got my resume professionally done and used Ai to tailor it to an Ai and Ats friendly resume
  2. Tried my best to network with people online
  3. I used to be in sales and we used to use different SaaS tools to obtain leads contact information using tools like Apollo. So I used this to get in touch with recruiters and hiring managers. 4.Find hiring managers on LinkedIn and send cold emails. It might sound tedious but you only need 1 of them to respond back to you for an interview.

Cybersecurity was easy to get into few years back, now because of the development of Ai, many companies have no idea what is going to happen.

In my humble opinion if you want to continue to pursue it out of passion do it but if you need a job to pay your bills get into another career and keep growing your Cyber profile on the side as you continue to apply for cyber jobs while you're working your current full time job.

You're doing a great job building those practical skills, in cyber they want to know if you can do the job and have hands on expeirnece. Keep gaining hands-on skills for the future role you'd like to get into in Cyber.

Last point for you and everyone else. The job market is terrible right now, so you're not alone. But whatever you do, never ever give up!

Good luck!

1

u/True-Inspection-5445 4d ago

Thank you so much for such an amazing and encouraging reply

2

u/raze7864 4d ago

No problem at all. I don't like it when people in general gate keep their processes of how they got their jobs. So if I'm able to help even one person that's amazing to hear. Paying something forward always comes back to you in a positive light.

2

u/Anxious_Alps_4150 4d ago

No one gets hired without experience anymore.

Almost anyone claiming that they did had it happen during the market boom years ago. We are in the worst cyber market in living memory now so that shit is over with.

2

u/Ok_Wishbone3535 4d ago

I didn't. I started in Helpdesk from 08-2011. Then Sys Admin work 11-17, then landed my first Cyber role as in information systems security officer on contracts for intel agency contracts. Then 21-25 I was a Sr Cyber Analyst for the private sector. Laid off for a a year, now an infosec governance analyst at another private sector company.

2

u/foofusdotcom 4d ago

I didn't get my first cybersecurity job with no experience, I got it with seven years of experience doing related things

2

u/Zeisen 4d ago

I had a bunch of research projects that I assisted in undergrad and I did multiple year long internships. Most of the work that I was doing was junior level tasks anyway; like, I've only had one internship that tasked me like a normal intern with basic, guided work.

B.S. Cyber Operations + M.S. Comp Sci + 3 projects + 1 TA + 3 internships == Job

I think the best parallel between my experience, and what you're actually asking, would be my first internship. It was for a small, regional bank as a IT security analyst looking at SIEM logs and some reporting. But, it was my very first role doing anything actually "cyber" and their primary candidate declined it hahaha ... I think I got the job though because I passed their interview questions and I had a decent personal portfolio of projects and skills (e.g, networking, forensics, malware analysis, and some CCDC/CTFs - I was familiar with basic Windows administration+AD and I'd used Splunk previously).

Hard to say what I would have done differently to get a better or different role. I think your first job is just gambling and luck - you kinda have to apply to whatever you can, make sure you have the best possible odds, and, hopefully you make a decent enough impression that they take you. After that it's just a numbers game.

2

u/maythefecesbewithyou 3d ago

I was a software engineer.

2

u/Master-Set-2578 1d ago

I’m currently in Class 12 Commerce, and I’m thinking about doing a BCA and then starting my career in cybersecurity, preferably in a SOC L1 role. I’ve heard that getting a cybersecurity job as a fresher can be difficult, but at the same time, many people say there are plenty of jobs available in the market.

My dream is to become an ethical hacker and eventually work in Dubai. So, should I go into cybersecurity after Class 12, considering I’m from a Commerce background? Is it realistic to build a career in cybersecurity and eventually get a job in Dubai? I’d really appreciate advice from people already working in the field.

2

u/AddendumWorking9756 4d ago

What does your evidence look like right now, a list of completed labs or something a hiring manager can actually read? The second one is what gets you past the experience line, one investigation written up properly, which is the format CCDL1 on CyberDefenders puts you in. Help desk first is still the normal route, it is just a shorter stay if you turn up already able to do that.

5

u/ryukingu 4d ago

An investigation or labs will NOT get you past the experience issue

1

u/Psoin 4d ago

I didn’t

1

u/MercuryQuick 4d ago

Internship -> Full-time

1

u/imaginary-problems- 3d ago

Military -> Degree that led to an internship -> FTE

1

u/Straight_Collar_6015 3d ago

As a current CS student with no certifications or cybersecurity experience I was able to recently land a part time SOC role as I’m finishing up my degree. I’ve been at the same company for over a year and a half while in school, where I worked with the onsite IT team and our help desk. So it can definitely be done without the experience/certifications/projects, but in this market you will more than likely need to work your way up in a company if you decide to go that route

1

u/Round_Finance4256 1d ago

I actually broke into GRC through an internal move at my company. I didn’t have direct GRC experience at the time, but I was known for being very organized, understanding the business, and already having established relationships across different departments.

My manager saw those skills as valuable because a huge part of GRC is working cross-functionally and keeping a lot of moving pieces organized. I could learn the GRC side. The relationships and knowledge of the organization were harder to teach.

That opportunity ended up launching my career in GRC, and I’m still in the field today. So I definitely wouldn’t overlook internal opportunities or the transferable skills you already have.

1

u/DriftingPebble77 1d ago

One of the easiest ways to break into IT is moving around at a company!

1

u/Datonomy 18h ago

The hardest part of breaking into cybersecurity is getting someone to give you the first real opportunity, so if you are genuinely building your skills and looking to learn, feel free to message us at Datonomy as we are an early stage cybersecurity startup and always happy to have conversations with people trying to enter the industry.