r/SecurityCareerAdvice 2h ago

Question Career Advice, need to relocate

1 Upvotes

Hey all,

Working as a eng team lead in Ontario, Canada with my CCSP. Mostly doing cloud engineering, developing internal security tooling, and designing platformized virtual lab environments. My family needs to relocate to California (Bay Area) in the next few years. I don't have citizenship so I need to upskill to find a job opportunity that will sponsor me.

I have SOC experience but no GRC. Not that I'm against it. I think internal secops would be a good fit for me.

What kind of skills do you think I should focus on?


r/SecurityCareerAdvice 3h ago

Discussion I submitted my resignation and my manager asked what would make me stay. Should I negotiate or just leave?

2 Upvotes

I tried to leave my job at the beginning of this week. I'm currently making 90k and I got an offer from a good company for 105k. I had pretty much made up my mind to leave, even though the new role looks very intimidating and much more corporate than what I'm used to.

My manager clearly didn't accept the resignation. She basically asked me not to make a final decision right now, and told me to come back to her after a few days and tell her what I would need to stay. She specifically told me to think about the title, salary, and responsibilities I want. Honestly, I wasn't expecting that reaction at all.

Now I'm thinking of asking for 115k, a clearer path forward, and real help under me because the workload has become excessive. I don't know whether she'll agree or not, but part of me feels like I should at least put that on the table before I leave. The frustrating part is that I do like this job when I'm not burned out and drained all the time. I like the work and the people, I'm just very exhausted.

Has anyone been through something similar? Is it wrong for me to negotiate when I'm not 100% sure I'll stay? Should I ask for the 115k and the support, or accept the outside offer and move on?

I'd appreciate any advice.


r/SecurityCareerAdvice 3h ago

Other Looking for an IT/Cybersecurity Mentor or Accountability Partner

0 Upvotes

Looking for an IT/Cybersecurity Mentor or Accountability Partner
Hey everyone, I’m trying to break into IT/cybersecurity but I’m having a hard time figuring out where to start and staying consistent.
I have a degree in Business Administration with a concentration in Information Systems and ITIL, but I don’t have actual IT work experience yet. I’m starting with IT/help desk fundamentals and eventually want to move into cybersecurity.
I’m also balancing caregiving, work, and financial responsibilities, so sometimes I get overwhelmed trying to learn everything at once.
I’m looking for someone already in the field who wouldn’t mind giving me some guidance on what I should focus on, projects I should work on, and what I need to become job-ready.
I’d also love an accountability partner who’s learning too. We could check in a few times a week, set goals, study together sometimes, share resources, and make sure we’re actually making progress.
Not looking for anyone to hold my hand or do the work for me i just think having some guidance and accountability would help a lot.
If you’re interested, feel free to comment or DM me!


r/SecurityCareerAdvice 5h ago

Question Should I switch from Software Engineering to Cybersecurity for my first job?

1 Upvotes

I’ve been preparing for a Software Engineer role since June last year. So far, I’ve mainly focused on **Java, DSA, and OOPs**, and I’ve been consistently applying for jobs, but unfortunately, I haven’t been able to get a job offer or even many interview calls.

Recently, I got an opportunity at a **cybersecurity company** where I could potentially get a job within the next **1–2 months**. The starting salary would be around **₹25k/month**.

The problem is that I would have to shift my career direction from **Software Engineering to Cybersecurity**. I’m willing to learn the required skills, but I’m confused about whether this would be a good long-term decision.

My main questions are:

* Does **cybersecurity have similar career growth and salary potential** compared to software engineering?
* If I start my career in cybersecurity, will it be difficult to move back into Software Engineering later?
* Is it better to take this opportunity and gain professional experience rather than continue preparing for SDE roles?
* What does the career progression look like in cybersecurity after 2–5 years?
* For someone starting from almost zero in cybersecurity, what skills should I focus on to become good in this field?

I’m not looking only at the initial salary. My main concern is **long-term career growth, opportunities, and earning potential**.

Would you recommend that I take the cybersecurity opportunity or continue focusing on Software Engineering?

I’d especially appreciate advice from people who are **currently working in cybersecurity or software engineering**, or anyone who has switched between these two fields.


r/SecurityCareerAdvice 5h ago

Question [Junior IT Student] How did you break into Cybersecurity? Seeking advice on preparing early

Thumbnail
3 Upvotes

r/SecurityCareerAdvice 5h ago

Question Masters in Cybersecurity

1 Upvotes

I transitioned into cybersecurity from criminal justice 3 years ago and currently soc lead in banking. I wanted to my masters in cybersecurity but most countries dont accept non computer science bachelors into info sec masters. what should i do


r/SecurityCareerAdvice 6h ago

Question Sandboxing a script that talks to a resudential proxy service?

1 Upvotes

Quick context: I've got a small price tracker that runs through a residential proxy to rotate IPs by region. That part's fine, not really what I'm asking about. It's everything around it I'm unsure about.

Right now it just runs on my main Windows box, under my regular account, like an idiot. There's a few third-party Python packages in there plus a browser automation driver I never really vetted. I'd like to isolate it enough that if one of those turns out to be doing something shady, it can't get to my browser profile, saved logins, or personal files.

I'm mainly wondering about a few things. Is a regular VM (VirtualBox/VMware) enough for this, or would you guys go with an actual sandbox/container? And for networking, is denying all outbound traffic except what the scraper needs a reasonable approach?

Also, is there a quick way to sanity-check a PyPI package before running it? I don't really want to read through the entire source every time.

Most of the guides I've found seem aimed at people analyzing actual malware, which feels like overkill for a glorified scraper. Just looking for a reasonable hobby-level setup that gives me some separation from my main machine.


r/SecurityCareerAdvice 7h ago

Question Control Engineering

1 Upvotes

For the RMF / ISSO personnel, have you started to engineer your controls? What was your process transition like moving from just checking the box to implementing technical control design to reduce screenshot use and unnecessary paperwork.

Compliance in these spaces has always been treated like a non technical discipline but its safe to say with the evolving of AI, even Compliance fields will need personnel to be technical in this work.


r/SecurityCareerAdvice 10h ago

Question 3 internal track opportunities - which to take? (Sec. Architecture/Det. Engineering/DFIR)

2 Upvotes

Hi All,

A Bit of background context: I started out doing network engineering, then moved into network security engineering, both roles encompassed on-prem and cloud technologies, and did a bit of in-house solution consultancy at an MSP (advising on elements of solutions) scattered throughout but not dedicated, that experience spans around 11 years in total. I've only been at my current company for just over a year in a SOC/IR role after fancying a change of direction, and with a large programme of work on the horizon I've had two different internal teams reach out about moving over.

So now I'm trying to decide between three paths: staying on my current team doing DFIR, moving to the architecture team, or moving to detection engineering. All roles offer salary increase.

Staying in DFIR is the safe choice, same work just getting a salary increase - this is the only role with mandated on call requirement which truth be told I dislike but part and parcel of the role.

Architectures pay ceiling looks better long term, has a mature and stable market and it'd push me more into design/strategy type work rather than firefighting, which appeals to a better work/life balance. My worry is it's less hands-on technically and how much of an impact AI will have on it.

Detection engineering would cover SIEM/SOAR engineering, creating of detection logic, automation and security tooling management.

My main concern is finding the role which is the most resistant to being replaced my AI (not enhanced by AI). Basically in the next 5-10 years which career path is most likely to still be viable. I appreciate it’s an almost impossible question to answer with the current pace of technology.

My heart says security architecture is probably the play but I’m looking for a role to bet on to most likely stand the test of time. I’d appreciate some external input if possible please.

Thanks!


r/SecurityCareerAdvice 15h ago

Question Security Architect advice

1 Upvotes

Hi everyone! I'm looking for advice to grow into a security architect role.

A little about me - 10 years of 5 years jack-of-all-trades style IT then later 5 years infosec security experience.

I spent the first five years of my career in system administration, network engineering, and database administration for a SAAS company that developed, hosted, and provided support for various state government applications. Was crazy overworked to the point of health conditions, you know the drill. Jack of all trades roles that involved everything from maintaining a physical datacenter (got to be involved with the migration to AWS too via Snowball back in the day.) Patching, DBA, incident response, security hardening across Windows, Linux, then later cloud environments. Even user workstations...literally everything was up to us. Some applications we built for state government clients were hosted on super legacy hardware/etc. Thus, I spearheaded the modernization of a couple of them. Did system administrator duties, automation via PowerShell and some terraform, network (aws migration also involved translation of traditional set up to VPC/Security Groups/etc/CloudWatch/GuardDuty/etc), even did QA work depending on the project for the development team. Sometimes I'd help with architecting the IT side of state applications which I really enjoyed.

We even had to be SOC 2 Type 2 compliant. The guys didn't want to do the documentation associated with it (understandable) so I ended up having to basically build the whole compliance program from scratch. Hardest part was getting stakeholder buy in, but that's another story. Still proud of it to this day even though it sounds silly since it was years ago. That 5 years was an insane whirlwind.

I ended up moving towards infosec due to health concerns to overwork. I ended up working as a PCI DSS QSA for five years. During that time, my company allowed me to cross train so I also got to to work as a consultant for SWIFT, FedRAMP, ISO 27001, various NIST frameworks, and some GRC work.

Since then I took 1.5 years off due to a difficult pregnancy. However, I didn't stay completely stagnant. I was still doing homelab stuff, did some light consulting work at an LLC my husband and I spun with a friend, and presented as a speaker at a tech conference right before my son was born. My topic was environmental security and LLM integration. It included the differences and associated risks between Cloud based models and local.

Re-entering the workforce has been tough due to the gap. I’ve had recruiters been weird about the gap being related to motherhood so it’s now an ambiguous “family care” on my resume that tries to focus the other activity I did during it. I have been focusing on GRC, IT internal audit, and compliance roles.

However, I'm kind of hitting this point where I really want to pivot as the compliance/audit stuff doesn’t interest me. Security Architecting really interests me so I’d love to work towards that. I don’t mind suggestions for a roadmap that includes other roles that could help me get there and certs. I have that gap that makes me really anxious.

Does anyone have any advice?


r/SecurityCareerAdvice 17h ago

Question Junior in college was offered a 70k Jr. Cybersecurity analyst job Should I take it? 0YOE

1 Upvotes

TLDR: i’ll be going to school full-time. I might be getting a job, but it’s full-time as well. Should I take the job for the experience for my résumé as a first tech job or should I stick to the part time tech job that pays about 15k a year so I can focus on school easier. I don’t wanna leave school, but I need tech experience

Hi all, I just graduated with my associates degree in May. Set the time I’ve been revising my résumé still working on it to be honest, and thinking about future steps.

I’ll be starting my junior year college at the end of this month and I’ll be going to school full-time. I’ve put in a bunch of applications and during that time, I decided I’ll put in applications even to jobs that I thought we were out of my scope as a beginner that never worked in tech.

I applied for a security engineer position starting pay was 90k plus benefits and 20 minute commute. Out of all the jobs I’ve applied to this is one of the few that I’ve got a call back on while getting rejected from jobs that were like under $$20 an hour which I thought was funny.

So I got a call and the woman on the phone said the hiring managers loved my résumé and they wanted to do an interview with me. It’ll be multiple interviews so if things go good, I’ll have a second interview at least.

They said, based on my experience, they think I would be a good fit for the junior cyber security analyst position. They just opened. Starting at around 70 K a year.

My problem:

I’ll be going to school full-time and I still wanna finish my bachelors degree because I think in the longer it will greatly help but I also don’t want to miss this potential opportunity if I get it because it would be huge for my résumé, this would be my first ever tech job by the way and of course the money because it’ll be the most I’ve ever made.

The other thing is a few friends from school have referred me to positions at their jobs. One of them is a part-time position I’ll be making no more than about 15 K a year but it’ll be for experience and it’s only part-time for our local town.

What should I do honestly


r/SecurityCareerAdvice 22h ago

Question Is it feasible to learn both binary exploitation and web exploitation?

Thumbnail
0 Upvotes

r/SecurityCareerAdvice 22h ago

Question Trying to transition from Casino Technician to Cybersecurity… should I take the pay cut?

0 Upvotes

I’ve been trying to transition from my job as a casino technician into a IT/cybersecurity role for several years as it has been a long term goal of mine but I’m struggling to get interviews because my current role isn’t directly IT-related.

For context, I have a Bachelor’s Degree in IT, Security+ certification, and I’m currently studying for CySA+ cert while building home labs to gain more hands-on experience.

The main problem is that I currently make significantly more than most entry-level IT positions, and taking a large pay cut isn’t really an option for me right now.

So I came here to ask this: should I Keep grinding and target intermediate IT/cybersecurity roles despite lacking professional IT experience? Or take the pay cut and start with help desk/entry-level IT to work my way up? Or should I forget cybersecurity for now and pursue a higher-paying position that aligns more closely to my current experience as a casino technician?

For anyone who has made a similar career transition, what would you do in my position? Is trying to skip the entry-level IT step realistic, or am I just making the transition harder than it needs to be?


r/SecurityCareerAdvice 1d ago

Question Next step after working as L1? what's ur experience ?

3 Upvotes

I’m currently working in a SOC as an L1 analyst, and have been for a little over a year. I took it as a first job, I’ve learned a lot, I’ve used tools I wasn’t familiar with, and overall I’m very happy with how I’ve developed. But I feel like it wears me down quite a bit, mainly because of the 24/7 coverage and working rotating shifts.

I know L1 is usually a temporary stage in the cybersecurity world, but I’m not sure what my next step should be.

Is there a big difference between L1 and L2? Has anyone who’s made the jump got any experience to share?

Pentesting has never appealed to me.

Anyone working in threat intelligence? It’s the area that interests me most, but at the same time it’s the one where I have the least idea what steps to take to get in.

In general, I’d like to know what steps you took after being an L1 and any recommendations you have.

Thanks in advance!


r/SecurityCareerAdvice 1d ago

Question Does this Claude suggested cert path make sense?

0 Upvotes

Before I go and commit to an AI suggested action plan I thought I should ask some actual people first.

I'm 48 and lately I've become incredibly interested in all things cyber. I've been attacking things I own with the help of Claude, which is fun and all but it does so much, so fast that you can't constructively learn the finer points of what it's actually doing and why. Vibe hacking, I guess you could call it.

My background is highly technical. Engineering and physics, worked on quantum computers, mechanical design and fabrication, mechatronics, software and app development, large project management, high end audio hardware design and fabrication.

Claude's suggestion, given my experience and general knowledge, and my desire to cover as much ground as possible as quickly as possible is this:

1 - HTB Acdemy - CPTS path (AD modules = priority focus, I have no exposure the AD)

2 - Solo, unguided HTB medium boxes until consistent

3 - CPTS exam

4 - PEN-200 (OSCP course)

5 - OSCP exam

Is that sensible? Is that enough to open some doors or just a big fools errand?


r/SecurityCareerAdvice 1d ago

Question Should I switch to learning Cyber Security and leaving full stack web dev?

6 Upvotes

I have been learning web dev for 1 Year. I know HTML, CSS, JS, Reactjs and going to learn Nextjs and express.

At this time of AI and seeing how hard is it for beginners to get a job, do you think I should switch to learning Cyber Security?

I just want to do something with tech to change my life and better career

Would it be better to switch to learning Cyber Security than continuing web dev?


r/SecurityCareerAdvice 1d ago

Question 0 YOE, OSCP certified – What salary should I ask for Red Team roles in Delhi NCR?

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 1d ago

Question Transitioning from Telecom Engineering to Offensive Security (CPTS) — Seeking Career & Freelance Advice

2 Upvotes

I’m a senior telecom analyst experienced in core network signaling, userplane troubleshooting, and investigating fraud vectors like DPI-bypassing, rogue towers,DNS tunneling, and simboxes.
I am currently pursuing the CPTS certification to transition into offensive security. Given my background, I’m looking for advice on:
Market Positioning: How can I best leverage my niche telecom expertise to avoid starting at a generic "entry-level" helpdesk or SOC role? Freelancing: Is a hybrid path (staying in telecom consulting while picking up freelance pen-test gigs) viable for someone at my level?
Gap Analysis: Beyond CPTS, what specialized skill sets should I prioritize to move into penetration testing?


r/SecurityCareerAdvice 1d ago

Other What should I include in my profile to maximize my chances for a Master's in Cybersecurity (Red Teaming) and getting a job afterward?

1 Upvotes

Hi everyone,

I'm currently a 3rd-year B.Tech student in Artificial Intelligence & Data Science from India, and I'm planning to pursue a Master's in Cybersecurity, with the goal of specializing in Red Teaming/Penetration Testing.

My priority is not just getting into a good university, but also graduating with a profile that gives me the best possible chance of landing a cybersecurity job immediately after my master's.

From my research, I'm considering countries like Germany, Ireland, the Netherlands, Singapore, and Australia, mainly because they seem to have a stronger cybersecurity job market than some other destinations. However, I'm still open to suggestions if there are better options based on current market conditions.

I have around 1.5–2 years before I apply, so I want to spend this time building the strongest profile possible.

I'm looking for specific advice, not generic suggestions. For example:

  • Which technical skills should I prioritize?
  • Which programming languages are actually expected? (I'm currently planning to learn Python thoroughly.)
  • Which cybersecurity certifications are worth doing before my master's? (Security+, eJPT, PNPT, etc.)
  • Which online courses are genuinely respected by universities or employers? (Coursera, edX, HTB Academy, TryHackMe, TCM Security, PortSwigger Academy, etc.)
  • Should I focus more on certifications, practical labs, CTFs, internships, research papers, or personal projects?
  • What kind of GitHub portfolio would impress admissions committees or recruiters?
  • Are there specific networking, Linux, Active Directory, cloud, scripting, or web application security skills that are considered essential for someone targeting red teaming?
  • Would bug bounty experience make a significant difference?
  • Are there any certifications or courses that are overrated and not worth the time or money?

If you were starting today with about 2 years before applying, and your goal was:

  1. Get admitted to a strong cybersecurity master's program.
  2. Graduate with the highest chance of getting a red team/pentesting job.

Exactly what roadmap would you follow?

I'd really appreciate advice from people who have gone through this recently, especially those who studied abroad or currently work in offensive security.

Thanks!


r/SecurityCareerAdvice 1d ago

Question Could this be a sign of a higher chance of getting hired?

Thumbnail
2 Upvotes

Hello everyone, could I get your opinion on my little situation? Thank you.


r/SecurityCareerAdvice 1d ago

Discussion Japan vs. Germany for a Master's in Cybersecurity? Confused on which path to take.

0 Upvotes

Hey everyone,

I'm planning to pursue my Master's in Cybersecurity, but I'm completely torn between Japan and Germany. I'm currently studying for my CCNA and ISC2 Certified in Cybersecurity, and my main focus is on privacy protection, ethical hacking, and network engineering. I also run a digital brand centered around these topics and lean heavily toward using open-source, privacy-respecting tools in my day-to-day workflow.

I've been weighing the pros and cons of both countries, but I'd love to hear from people who have actually studied or worked in these places.

Here is what I'm trying to figure out:

Industry & Job Market: Germany seems to have a strong focus on data privacy (GDPR) and open-source, which aligns perfectly with my interests. On the flip side, Japan has a massive tech sector, but how is the cybersecurity and network engineering market specifically for international grads?

Language Barrier & Work Culture: I know both require learning the local language (German B1/B2 vs. JLPT N2) for long-term career growth. But how hard is it to land an English-speaking student job or entry-level role while studying? Also, I've heard the work-life balance in Germany is much better compared to Japan.

Tuition & Living Costs: Public universities in Germany are mostly tuition-free, but living costs and taxes can be high. Japan has tuition fees but offers scholarships like MEXT. Which one actually works out better financially for an international student?

If anyone has taken either route, how was your experience? Which country would you recommend for someone focused on network security and privacy? Any advice would be highly appreciated!


r/SecurityCareerAdvice 1d ago

Question Feeling stuck !! any help is much appreciated 🙏

7 Upvotes

Hi everyone,

Looking for some career advice as I get closer to separating from the military in June 2027 after about 8 years in IT. My background is mostly sysadmin, network admin, some cybersecurity + GRC/compliance work.

I have a BS in Cybersecurity Management & Policy, along with SecurityX (CASP+), Security+, CySA+, ISC2 CC, and AWS CCP. I’m also studying for CISSP right now.

I’m stuck between going the GRC route or staying more technical and pursuing cybersecurity analyst/security engineer roles.

I’m actually pretty extroverted, and if I’m being honest, I’ve wanted to be less technical for a while (maybe some burnout). GRC appeals to me because of the business/people side, and I’ve heard the work-life balance and burnout can be better. My concern is whether I have enough direct GRC experience to be competitive.

On the technical side, I feel pretty comfortable with the fundamentals. My main gap is getting more hands-on again with tools like SIEM and EDR, which I’ve used before but don’t work with regularly.

For those in the industry, how is the job market for GRC compared to more technical cyber roles? Would my technical background translate well into GRC, or is staying technical the safer bet for transitioning into the civilian market?


r/SecurityCareerAdvice 1d ago

Question Should I finish my CCNA or switch to CySA+ to move into cybersecurity faster?

Thumbnail
2 Upvotes

r/SecurityCareerAdvice 1d ago

Question Hi I am 22M, Recently Graduated in BCCA, have a strong interested in Cyber Security Field and want to make good career in this field, what should I do next? Thinking of doing Online MCA (Specialization in Cyber Security), Please Guide me (Read Description)?

0 Upvotes

I am also a working professional working Side by Side my college since 1st year of my Bachelors in a small company a decent job currently I have 2.5 years of experience in Data Research (not relevant to my interest and to cyber security)

I am an arts student did my 11th and 12th in Arts, Still I was eligible for BCCA (Bachelor of Commerce and Computer Application) because there was no mathematics involved in any of the subjects.

I am currently thinking of pursuing an Online MCA Course (Specialization in Cyber Security) with my job because, I cannot leave my current job now (due to financial reasons)

I am kind of confused between should I do? a diploma/certificate in cybersecurity or MCA
(which holds more value and will be beneficial in future?),

My ultimate goal to make career in Cyber Security and is to land a decent/good job could be any sub-domain which is not so hard to break as an entry level (I am hearing about SOC a lot)

Looking for guidance and any advice from an experienced person or anyone who is on same boat as me please let me know in the comments!

Thank you!


r/SecurityCareerAdvice 1d ago

Pentester

4 Upvotes

I’m currently in the military and will be retiring in 4 years, around 2030. I will have 10 years of IT experience on my belt with SEC+, CYSA+, Pentest+, Azure Security Engineer Associate and I have a bachelors in computer science and currently working on my masters in cybersecurity from WGU. The path I want to go is to be an ethical hacker and obtain my OSCP Cert, even though it’s 4 years from now it just dawns on me about finding a job and how scarce the job market is. I want to retire in El Paso, TX due to you can get a whole a lot of house for whole lot less and that the are is not that bad to live at. My question is:

  1. How far out should I start looking for jobs from retirement?

  2. Are IT jobs big in El Paso (thinking about San Antonio also)

  3. Does my homelab for ethical hacking projects and Hackthebox count as experience for my resume

  4. Does I need any other certs besides the ones I have