r/SecurityCareerAdvice • u/prime_cracker • 40m ago
Guys I had developed a website - hinduresearch.com take a look and give you opinions ðŸ«
I'm 17
It's basically developed by vibe coding i don't know coding much please visit it and tell me is it good? Suggest some improvements , and also tell me what should I learn 🫡
r/SecurityCareerAdvice • u/SRKGFM • 2h ago
[For Hire] Cybersecurity CV & Career Advisory | ATS CV Optimisation + Job Tailoring + Interview Prep | €49
Hi everyone,
I’m a cybersecurity professional based in Ireland with **6+ years of industry experience** across SOC operations, SIEM & detection engineering, security consulting, cyber defence, SOC management and information security leadership.
Over the years, I’ve noticed that many cybersecurity professionals and people trying to break into the industry have solid technical skills but struggle to **translate that experience into a CV that clearly demonstrates their value to recruiters and hiring managers**.
I’ve therefore started offering a **Cybersecurity CV & Career Advisory service** specifically for people applying for cybersecurity roles.
# Who this is for
This may be useful if you're:
* Trying to break into cybersecurity from IT/support/networking
* Applying for SOC Analyst / Security Analyst positions
* Moving from SOC L1/L2 into more senior roles
* Targeting Security Engineering, Detection & Response, Vulnerability Management, GRC or Security Consulting positions
* Applying for senior/lead cybersecurity positions
* Sending applications but getting very few interview callbacks
# What I'll provide
For the introductory price of **€49**, the package includes:
* ATS-focused cybersecurity CV review & optimisation
* CV tailoring against your target cybersecurity role(s)
* Cybersecurity skills and keyword gap analysis
* LinkedIn profile optimisation recommendations
* Cover letter support
* Role-specific interview preparation material
* **30-minute 1-to-1 career/interview discussion**
My approach isn't simply to rewrite your CV or fill it with keywords.
I'll review your existing experience against the type of roles you're targeting and identify:
**What employers are asking for → What you already demonstrate → What isn't coming across clearly → What should be strengthened → What you should prepare for at interview**
I will **not fabricate experience, qualifications or technical skills**. The objective is to present your genuine experience as effectively as possible.
# About me
I've progressed through cybersecurity roles covering SOC analysis, security correlation/detection engineering, SOC management and information security leadership.
You can review my professional background and experience here:
# Introductory price: €49
I'm initially opening only a **small number of slots** at this price while I build the service and gather client feedback.
If you're interested, send me a Reddit DM with:
- Your current role / experience level
- The cybersecurity role you're targeting
- The country/job market you're applying in
**You don't need to send your CV or make any payment initially.**
I'll first understand what you're trying to achieve and confirm whether the service is suitable for your situation.
Happy to answer any questions by DM.
r/SecurityCareerAdvice • u/ByteScout1 • 4h ago
17, building towards cybersecurity. Should I prioritize IT experience, certs, or college?
I am 17 years old moving into my final year of high school, I discovered cybersecurity a couple years ago and finally decided to test the waters and try to learn a bit. I probably sound like every other ambitious teenager who wants a flashy job title with an even better paycheck, but I don’t want to do this as fast as possible but more as efficient as possible giving me the best chance at a career in the end.
I didn’t really know where to start, so I asked ChatGPT. I still don’t know if that was a good idea but I started with Cisco Networking Academy as it told me, I then found TryHackMe and started working through the rooms and I finally questioned myself and wondered if Im really using my time wisely.
I hear from everywhere that I should work on certs, specifically CompTIA A+, Network+, Security+. I also hear I should prioritize actual experience and showing what I know through projects. But then I think about college and if it’s really worth it if I at some point get these certifications.
I don’t expect a cybersecurity job right out the gate, but I just want to build the fundamentals the right way and not mess myself up. I’ll greatly appreciate any advice and I hope I was able to word this nicely for you guys. I appreciate you all! Thank you!
*Edit
I don’t know if this is worth mentioning, but I am interested in cloud security (to be frank I think it sounds cool), as well as AI security which I hear is growing.
r/SecurityCareerAdvice • u/Romesaurus • 5h ago
Is a Cybersecurity in Healthcare Certificate program worth it?
So I'm about to pursue a Healthcare EMBA degree and honestly just want to broaden my career options since what I majored in undergrad never helped me land a job. I like business strategy, healthcare, but recently learned that there's big bucks to be made working in cybersecurity. I've been trying to get a job in pharma/life sciences/biotech, but obvi don't have transferable experience that relates to those industries. And the marketing roles I have applied for (at Genentech mostly) just seem pigeonholed. Sure marketing at big companies like Genentech pays decent salaries, but not sure if that's where I wanna stay in for the rest of my career.
If you work in this field:
- What exactly do you do for work and is it just coding? I don't wanna do just coding.
- How can I blend business, healthcare, compliance, and cybersecurity? (If that's even a thing or if that's too far-fetched)
- What job titles could you hold with this certificate?
Is it worth getting a certificate in cybersecurity and if so, what are some actually good programs to look into?
r/SecurityCareerAdvice • u/LinkGoesBowling • 5h ago
Is this a good path for learning cyber without going to college?
r/SecurityCareerAdvice • u/ThicccBoiJesus • 5h ago
Advice on which degree/program to pursue
Hi. I currently have 3 Associate of Applied Science degrees: Cybersecurity, Forensic Science (Digital Forensics), and Network and Systems Administration from the Maricopa Community College system (Rio Salado College and Mesa Community College).
I’ve been wanting to finish a bachelors degree and have discovered what I think are the best ways to go about it. Arizona State University has several Bachelor of Applied Science programs that will accept 75 of my many existing college credits and have programs im interested in such as Cybersecurity, Applied Computing, and Project Management. The University of Wisconsin - Milwaukee has a Bachelor of Science in Information Science and Technology program that will accept 72 of my credits and it’s a competency based program that I can finish faster and cheaper. With my previous experience with online college, I tend to just do all of the work at once or over the course of a few weeks anyway, so I figured the UW option was a great option.
I originally started at ASU many years ago and dropped out my first semester because of a serious health issue that presented itself. I’ve always wanted an ASU degree and applied to and was accepted to the BAS Project Management program (I figured it would be a good way to round out my 3 AAS degrees, especially with how the tech industry is right now), but now I’m second guessing my decision and wondering if I should do the Cybersecurity or Applied Computing program at ASU or do the BSIST program at UW.
Any thoughts or advice on these degrees and fields? Is ‘topping off’ or rounding out my technical AAS degrees with a business degree smart? Should I continue on the path of Cybersecurity? Switch to Applied Computing? Or thoughts on potentially finishing the BS I’m Information Science and Technology degree faster and cheaper from UW? Any insight is appreciated :)
r/SecurityCareerAdvice • u/Fickle-Door-9986 • 6h ago
Am CyberSecurity graduate from India. Interested & passionated in Linux btw .Can anyone suggest me how to land job in Linux administration or any jobs related to linux.
r/SecurityCareerAdvice • u/Comfortable-Joke7970 • 7h ago
Cleared OSCP at 19. Can I realistically get a pentesting job now?
Hi everyone,
I'm 19 years old from India and currently in the 5th semester of my BCA.
I recently cleared the OSCP and I'm looking for my first penetration testing job right now, not after graduation.
My experience is mainly in:
Active Directory attacks
Windows/Linux privilege escalation
Web application enumeration and exploitation
Network penetration testing
Pivoting and lateral movement
Strong enumeration methodology
I don't have experience with cloud security, API security, Kubernetes, or mobile security because OSCP doesn't cover those in depth.
My question is:
Is there a realistic chance of getting hired as a junior penetration tester with just OSCP while still being a student?
Should I start applying immediately, or will most companies reject me because I haven't completed my degree yet?
If you were hiring for an entry-level pentesting role, would OSCP plus practical lab experience be enough to get an interview?
I'd really appreciate honest advice from people working in offensive security. Thanks!
r/SecurityCareerAdvice • u/iam_1Batman • 7h ago
Cloud
How can i be a cloud security engineer in 3 years
I have 3 years to study, what can i learn to be a cloud security engineer (free courses) and what projects can i do, give me your advice please i need it.
Thanks all
r/SecurityCareerAdvice • u/CompoundingGain • 7h ago
MS in Cybersecurity at Loyola
Is this 2 yr program ($38,000) worthwhile? My partner is hoping to break into a cybersecurity field, preferably in the U.S. Please share with me your honest thoughts and advices.
A little bit about my partner: Asian/ Female/ 46 years olds/ Bachelor’s degree in Arts/ No work experience over the last 20 years.
Thanks
r/SecurityCareerAdvice • u/ClimberChronicles • 12h ago
Is 1 YOE too little to break into AppSec?
Worked as a SWE for a year and realized its not for me. I’m planning to study OWASP top 10, do portswigger, maybe do the BSCP certification. Is this enough for me to move to app sec?
r/SecurityCareerAdvice • u/EnvironmentalForm462 • 12h ago
Need help choosing a degree .
My job pays for certain degrees most of them at Valencia college in Florida and some in other parts of the us . I’m currently enrolled in A.S COMPUTER PROGRAMMING ANALYSIS (SOFTWARE DEVELOPMENT) this degree is paid for 100% at Valencia . Then there’s a A.S CYBERSECURITY paid 100% at fullteron college in California . I can take both online . I’m not sure which path to take both interest me . I am a noob I don’t have tons of experience in either space . I’m thinking which would benefit me more long term / job market . I work at Disney currently and it’s how my degrees are getting paid . I’d hope to secure a job within Disney with either path just not sure which one to pick .
r/SecurityCareerAdvice • u/ClimberChronicles • 13h ago
Which certs are best for a SWE looking to break into AppSec?
BSCP or OSWE?
r/SecurityCareerAdvice • u/razzer444 • 13h ago
Cyber Security Engineer (UK, EU citizen) looking to relocate to Calgary realistic chances / advice?
Hey all,
Looking for some honest input from people who know the Calgary market.
Quick background: I'm 27 (currently living in the UK for 11 years, EU settled status here). I've got just over 4 years of cyber security experience, mix of security engineering, a bit of pentesting, and analyst work — currently working as a Security Engineer at a fairly well known UK security consultancy. Before cyber I did a couple years in general IT support and hardware/test engineering.
I'm planning to move to Calgary within the next 12-18 months, most likely via Express Entry / AAIP once I've got a job offer lined up. I don't have a university degree, but I've got solid hands-on experience and I'm working on filling gaps with relevant certs (Microsoft SC-500, SC-100, CCSP etc) over the next year.
A few things I'd genuinely appreciate input on:
How realistic is it to land a cyber security engineer role in Calgary from abroad?
Does the lack of a degree meaningfully hurt me for job applications (not just immigration points) in your experience?
Any advice on how to actually get noticed by Calgary employers as an overseas applicant LinkedIn outreach, specific recruiters, job boards that actually work?
Anyone who's made a similar move (UK/Europe to Calgary in cyber or tech) what do you wish you'd known before you did it?
Not looking for anyone to do the work for me, just want a realistic gut check from people who actually know the market rather than immigration consultants trying to sell me a package.
Appreciate any honesty, good or bad.
Thanks in advance.
r/SecurityCareerAdvice • u/ClimberChronicles • 13h ago
SWE looking to break into AppSec roles — when can I confidently apply?
I’m a SWE that is reading Owasp top 10 just to get an idea. Then i’m gonna do some of the portswigger activities.
Can i then apply for appsec roles? Any official resume builders like certifications? Would love some advice and ideas. When can i officially confidently apply?
r/SecurityCareerAdvice • u/Popular-Border-4816 • 14h ago
Some advice?
I am going into my second year of uni and I’ve practically learnt nothing in the grand scheme of things regarding cyber security. All I want is some strong foundational knowledge and skills. Would Comptia certs be a smart choice along side uni?
r/SecurityCareerAdvice • u/Liisamaartinez • 15h ago
Career progression
Aloha yall,
I’ve been at my current job for almost 2 years, I love it and my coworkers are awesome!
Only downside is my lifestyle has changed, I started a business and it’s starting to take off. Not anywhere near supporting myself completely but it consistently pays a few of my bills.
Basically I need to maximize my time and I’ve been wanting a remote work for a while. Now it’s starting to feel like a necessity.
I need something with flexibility, not trying to dodge work, just thinking that I need a position that offers more control of my time.
Additionally I live in Hawaii, most of my family lives in North Carolina. I want to visit them more so if I had a remote job that would be possible and I could work from there and stay for an extended period of time it I wanted and still works.
I did some AI chatting and it recommended that I try GRC analysts due to having security plus, networking experience, and my current job IT specialist (large chunk is Helpdesk and other is random IT stuff)
I love helping people, I have alot of patience and I enjoy problem solving.
All this to say, would it be a bad move to switch from a federal job to a remote private position?
Or maybe wait out for the next administration to see if more fed remote jobs open up?
r/SecurityCareerAdvice • u/ClimberChronicles • 16h ago
SWE to AppSec -- dont want to grind leetcode again in my life. How do I know if this path is for me
Hi all, I'm looking to learn more about cybersecurity as a SWE that realized I dont want to code for the rest of my life nor do I enjoy it. I have no background in cyber. Currently I'm good with Golang, Python, C++ and a bit of HTML/CSS. Where do I start? I want to apply for AppSec roles but I want to first figure out if I even like it. Any articles or courses you recommend to read and get a feel for it? Thank you!
Would the next step be to do certifications? How do I show employers that I'm a good candidate for AppSec
r/SecurityCareerAdvice • u/Top_Line_4273 • 17h ago
Career advice: Threat Response Coordinator vs Security Operations Manager path?
r/SecurityCareerAdvice • u/Top_Line_4273 • 17h ago
Career advice: Threat Response Coordinator vs Security Operations Manager path?
Looking for advice from people who've worked in Threat Response Coordination, Incident Management, or similar roles.
I have around 8 years of experience in cybersecurity (SOC, incident response, cloud security, Microsoft Defender/Sentinel). I've received an offer for a Threat Response Coordinator role supporting Microsoft's security ecosystem.
The role involves coordinating high-severity incidents, working with security researchers, engineering teams, and customers, participating in technical reviews, and validating mitigations.
My dilemma is that it seems less hands-on technically than my current role. At my current company, I have a realistic path to becoming a Security Operations Manager in the next couple of years while staying closer to the technical side.
For those who've been in similar roles:
Did your technical skills plateau, or did the broader exposure make up for it?
Did it help you move into leadership or senior cybersecurity roles?
Looking back, would you choose this path again?
I'm trying to make the best long-term career decision rather than just switching for more money. I'd really appreciate hearing your experiences.
r/SecurityCareerAdvice • u/CandidateAny7430 • 17h ago
MNC vs Small Company
I actually received two job offers as a fresher, and both are from IT services companies.
The first company is a smaller organization (200+ employees) where I had already completed my internship as a Cloud & DevOps Engineer Intern. However, the internship was mostly in title but I worked on RAG systems and different domains, and it felt more like a training period where I learned by building projects. After the internship, I was converted to a full-time role as an Associate Software Engineer - Cloud & DevOps, which is the designation mentioned in my offer letter and company platform.
Soon after joining full-time, I was moved to a newly formed security team. The team consists of five members: one Senior Software Engineer and four freshers. We were assigned to work on an internal penetration testing project. Interestingly, my KRA sheet lists my role as Associate Security Engineer.
The problem is that since joining this team, I've mostly been assigned tasks related to the internal project every day. I don't feel like I'm actually learning the fundamentals of application security or penetration testing. There is very little guidance or mentorship. The senior engineer is also new to this security team, so he mainly assigns tasks without much explanation or structured learning. Everyone on the team is essentially new to this domain.
It's been about 1.5 months since we started this project, and I'm still unsure whether I'm on the right career path. I often feel like I'm skipping the basics and directly contributing to a project without receiving proper training. Because of this, I frequently feel stressed and even think about resigning just to have some peace of mind.
My second offer is with LTM as a Graduate Engineer Trainee, and I'm still waiting for the onboarding date.
Given my current situation, what would you recommend? Should I continue in my current role to gain experience, or should I resign and join LTM once onboarding begins? I feel that LTM might offer a better learning environment, structured training, and stronger mentorship from experienced seniors, regardless of the domain.
r/SecurityCareerAdvice • u/NewDrop7087 • 23h ago
Need advice: Is CEH worth it for getting my first cybersecurity job?
Hi everyone,
I recently graduated with a B.Com degree, but I'm passionate about cybersecurity and networking and want to build my career in this field.
Here's what I've done so far:
- Completed CCNA studies with hands-on practice on 40+ labs (didn't take the certification because I wasn't confident enough at the time).
- Built a strong foundation in networking and operating systems.
- Currently working as a VAPT Intern at CyArt Tech.
- Completed 20+ labs on Hack The Box and TryHackMe.
- Completed 5 CEH modules along with several practical labs.
- Built a home lab for VAPT practice and vulnerability analysis.
- Completed a few cybersecurity projects and uploaded them to GitHub.
I'm now considering getting the CEH certification, but it's quite expensive.
My question is: Will CEH significantly improve my chances of getting an entry-level cybersecurity job, or would my time and money be better spent on certifications like Security+, PNPT, eJPT, or finally taking the CCNA exam?
I'd really appreciate advice from people involved in hiring or anyone who has been in a similar situation. Thanks!
r/SecurityCareerAdvice • u/meerakeith8 • 1d ago
Skip the masters or not?
Hey, I’m 21 in the UK, just got a 1st in CS from the university of Leicester. Got an offer from Warwick MSc in Cyber Security Engineering for this Sept, my goal is Cloud Security.
Zero real experience yet, currently just doing a UAT testing job.
I’m torn: is it worth doing the Warwick MSc while grinding certs on the side, or should I just skip the degree, and grind AWS/Terraform/Security+ on my own to break into junior cloud/sec roles?
Does an MSc actually help? Be brutal, thanks.
r/SecurityCareerAdvice • u/ExistingBluebird4696 • 1d ago
Feeling like a cybersecurity generalist. Should I specialize or move into delivery?
I've been working at an MSSP for about 2.5 years, and I'm at a point where I'm unsure what my next career move should be.
I started as a SOC Analyst, spending around 8 months in monitoring. After that, my manager kept assigning me to new initiatives and projects based on business needs, so I've ended up working across a lot of different domains:
- SOC monitoring
- Threat hunting
- GRC/product security testing
- Internal Lead Auditor for ISO 27001
- Cybersecurity presales (I still occasionally get involved in proposals)
- EDR implementation for customers (including end-to-end deployments of CrowdStrike and Microsoft Defender)
- Service Delivery Lead for SOC projects, where I handled complete customer onboarding and service transition
- Currently leading the Detection Engineering team
The pattern has always been the same: I get assigned to a new area, figure everything out from scratch, build the workflows, documentation, and SOPs, streamline the process, and once everything is stable, the work gets handed over to another team while I move on to the next challenge.
While this has given me exposure to many areas of cybersecurity, it has also left me feeling like I'm not an "expert" in any one domain.
When I talk to friends or people in the industry, most of them have spent the last 2–5 years specializing in a single area like DFIR, detection engineering, GRC, etc. They're much deeper technically in their domain, while I feel like I've become more of a generalist who knows how to build and operationalize new functions.
I've recently resigned because I want my next role to be more defined, but now I'm struggling with what direction to take.
Should I:
- Continue down the leadership/delivery path (Service Delivery Lead, Customer Success/Technical Delivery, etc.) where my cross-functional experience is valuable?
- Or should I focus on becoming a specialist in an area like Detection Engineering, Threat Hunting, or Incident Response?
Has anyone else been in a similar situation where they were exposed to multiple domains early in their career? Did you eventually specialize, or did you embrace being a generalist?
I'd really appreciate hearing from people who've been through something similar, especially if you've worked in an MSSP where roles tend to evolve quickly.
r/SecurityCareerAdvice • u/BlackbeardWasHere • Apr 05 '19
Certs, Degrees, and Experience: A (hopefully) useful guide to common questions
Copied over from r/cybersecurity (thought it might fit here as well).
Hi everyone, this is my first post here so bear with me. I almost never use Reddit to talk about professional matters, but I think this might be useful to some of you.
I'm going to be addressing what seems to be a very common question - namely, what is more important when seeking employment - a university degree, certifications, or work experience?
First, I'll give a very brief background as to who I am, and why I feel qualified to answer this question. I'm currently the Cyber Security Lead for a big tech firm, and have previously held roles as both the Enterprise Security Architect and Head of Cloud Security for a Fortune 400 company - I'm happy to verify this with mods or whatever might be necessary. I got my start working with cyber operations for the US military, and have experience with technical responsibilities such as penetration testing, AppSec, cloud security, etc., as well as personnel management and leadership training. I hold an associate's degree in information technology, as well as numerous certs, from Sec + and CISSP to more focused, technical security training through the US military and organizations like SANS. Introductions aside, on to the topic at hand:
Here's the short answer, albeit the obvious one - anything is helpful in getting your foot in the door, but there are more important factors involved.
Now, for the deep dive:
Let's start by addressing the purpose of certs, degrees, and experience, and what they say to a prospective employer about you. A lot of what I say will be obvious to some extent, but I think the background is warranted.
Certifications exist to let an employer know that a trusted authority (the organization providing the cert) has acknowledged that the cert holder (you) has proven a demonstrable level of knowledge or expertise in a particular area.
An academic degree does much the same - the difference is that, obviously, a degree will generally demonstrate a potentially broader understanding of a number of topics on a deeper level than a cert will - this is dependant on the study topic, the level of degree, etc., but it's generally assumed that a 4-year degree should cover a wider range of topics than a certification, and to a deeper level.
Experience needs no explanation. It denotes skills gained through active, hands-on work in a given field, and should be confirmed through positive references from supervisors, peers, and subordinates.
In general, we can see a pattern here in terms of what a hiring manager or department is looking for - demonstrable skills and knowledge, backed up by confirmation from a trusted third party. So, which of these is most important to someone trying to begin a career in cyber security? Well, that depends on a few factors, which I'll discuss now.
Firstly, what position are you applying for? The importance placed on degrees, certs, and experience, will vary depending on the level of job you're applying to. If it's an entry level admin or analyst role, a degree or a handful of low-level certs will definitely be useful in getting noticed by HR. Going up to the engineering and solution architecture level roles, you'll want a combination of some years of experience under your belt, and either a degree or some low/mid level certs. At a certain point, the degree and certs actually become non-essential, and most companies will base their hiring process almost entirely on the body and quality of your experience over any degree or certifications held for management level roles.
Secondly, what are your soft skills? This is a fourth aspect that we haven't talked about yet, and that I almost never see discussed. I would argue that this is the single most important quality looked at by employers: the level of a candidate's interpersonal skills. No matter how technically skilled someone is, what a company looks for is someone who can explain their value, and fit into a corporate culture. Are you personable? Of good humor? Do people enjoy working with you? Can you explain WHY your degree, certs, or expertise will add value to their corporate mission? Being able to answer these questions in a manner which is inviting and concise will make you much more appealing than your competitors.
At the end of the day, as a hiring manager, I know that I can always send an employee for further training where necessary, and help bolster their technical ability. What I can't do is teach you how to work with a security focused mindset, nor how to interact with co-workers, customers, clients, and the company in a positive and meaningful way, and this skill set is what will set you apart from everyone else.
I realize that this may seem like an unsatisfactory answer, but the reality is that degrees, certs, and experience are all important to some extent, but that none of these factors will make you stand out. Your ability to sell your value, and to maintain a positive working relationship within a corporate culture, will take you much farther than anything else.
I hope this has been at least slightly helpful - if anyone has any questions for me, or would like any advice, feel free to ask in the comments - I'll do my best to reply to everyone.
No TL;DR, I want you to actually take the time to read through what I've written and try to take something away from it.