**TL;DR:** I am a new cybersecurity analyst with a helpdesk background, the CompTIA trifecta, and a CCNA. My long-term goal is pentesting, and I recently started studying for the eJPT. However, my company appears to have a genuine need for someone who can grow into a security engineering and architecture role alongside its senior infrastructure staff. Should I spend the next year or two building analyst and engineering depth before returning to pentesting, or continue specializing toward offensive security and eventually pursue opportunities elsewhere? If engineering is the better path for now, where should I start?
Hey guys,
Just looking for some career advice.
I moved into a cybersecurity analyst role just under five months ago after spending just shy of three and a half years on the helpdesk. Before the promotion, I earned the CompTIA trifecta and CCNA, which I feel put me somewhere between entry-level and intermediate knowledge, though I still have a lot to learn.
My long-term goal has always been to move into penetration testing or red teaming. After finishing the CCNA, I started studying for the eJPT and planned to follow it with the CPTS, OSCP, and eventually CISSP to build a broader understanding of security.
At least, that was the plan I had in mind while I was still working in Helpdesk. The opportunity to become an analyst seemingly came out of nowhere, and I had to take it. Now that I am actually in the role, however, I am starting to question whether the path I envisioned still makes sense for where I am now.
The offensive material is interesting, and understanding how attacks work definitely has value. The problem is that much of what I am learning has limited direct carryover to my day-to-day responsibilities.
It was different when I was on the helpdesk. I became comfortable in that position, had spare time to study during the day, and more energy left after work which I would spend studying for my next cert as well. Now I am still learning and trying to optimize my skills in my current role, and my time is tight, and mental energy after work have become much more limited. I feel like I am slowly developing skills that do not complement what I currently do while falling behind in the areas that would make me more effective now.
My company operates in a complex hybrid environment with very lean infrastructure and systems teams. Each side has a senior engineer or architect who has essentially helped build everything from the ground up. In many ways, they act as de facto security architects through the decisions they make, but there has always been a need for a dedicated security-focused peer who can complement them.
I appear to have an unusual opportunity to eventually grow into that gap.
I am starting to become regularly included in project and integration calls so I can learn and provide a security perspective. The challenge is that many of these conversations are still above my current level. I might understand the initial goal, but then the conversation quickly shifts into technical limitations, alternative solutions, dependencies, and the tradeoffs those alternatives introduce.
By the time we reach the more nuanced integration issues or vendor-specific questions, I am usually several steps behind. It sometimes feels like my brain is being violently thrashed through my skull, and I struggle to even come up with a meaningful question.
By the time I catch up to what the current plan is, someone has already identified why it may not work, introduced another combination of enterprise technologies that could account for the shortcomings, and then identified an entirely new set of drawbacks with that design. At that point, we are asking the vendor for more information, and I barely even know what we are talking about anymore.
Do not get me wrong, I touch a lot of these systems and understand our environment fairly well in the areas I interact with. I just do not understand how everything is engineered deeply enough to confidently challenge a design, make recommendations, or identify concerns that have not already been raised. There are still plenty of gaps in my knowledge when it comes to specific configurations, system dependencies, and technologies I do not directly manage.
I also try to learn from them directly, but they are working under constant time constraints and have their own team members to support and develop. They answer questions when they can and include me in these discussions, but they realistically do not have the time to mentor and build my foundation for me. I can learn through exposure, but I need to figure out how to close the gap independently.
This leaves me weighing two paths.
I could stick to my original plan, continue specializing toward the offensive role I ultimately want, accept that the skills may have limited immediate value in my current position, and eventually leave for a role where they are more directly applicable.
Alternatively, I could spend the next year or two developing stronger analyst and security engineering skills, with the eventual goal of contributing at an architecture level. That would align much more closely with my current responsibilities and could allow me to become what I believe my company genuinely needs. I could then return to pentesting later with a much stronger understanding of how enterprise environments are actually designed, integrated, secured, and operated.
If I do go down this road, I don't expect to become the expert administrator for every platform. I want enough depth to understand proposed designs, evaluate integrations, identify security weaknesses, implement and govern controls, and defend my recommendations. I want to be able to sit in these calls as a genuine peer rather than someone who is still trying to reconstruct the conversation in his head.
For anyone who has moved from an analyst role into security engineering or architecture:
* Would it make sense to spend the next year or two building engineering depth and return to pentesting later?
* What fundamentals would you prioritize first?
* How can I develop architecture-level thinking without trying to master every platform individually?
* Are there certifications, books, labs, or learning paths that provide a strong progression from analyst to engineer?
* How can I make the most of my exposure to senior engineers when formal mentorship is not realistically available?
I do not want to abandon offensive security permanently, and I would still love to pursue penetration testing or red teaming later. I am mainly trying to determine whether I should stick with the path I originally chose or take advantage of the opportunity in front of me and build toward what my company currently needs.