r/SecurityCareerAdvice Apr 05 '19

Certs, Degrees, and Experience: A (hopefully) useful guide to common questions

331 Upvotes

Copied over from r/cybersecurity (thought it might fit here as well).

Hi everyone, this is my first post here so bear with me. I almost never use Reddit to talk about professional matters, but I think this might be useful to some of you.

I'm going to be addressing what seems to be a very common question - namely, what is more important when seeking employment - a university degree, certifications, or work experience?

First, I'll give a very brief background as to who I am, and why I feel qualified to answer this question. I'm currently the Cyber Security Lead for a big tech firm, and have previously held roles as both the Enterprise Security Architect and Head of Cloud Security for a Fortune 400 company - I'm happy to verify this with mods or whatever might be necessary. I got my start working with cyber operations for the US military, and have experience with technical responsibilities such as penetration testing, AppSec, cloud security, etc., as well as personnel management and leadership training. I hold an associate's degree in information technology, as well as numerous certs, from Sec + and CISSP to more focused, technical security training through the US military and organizations like SANS. Introductions aside, on to the topic at hand:

Here's the short answer, albeit the obvious one - anything is helpful in getting your foot in the door, but there are more important factors involved.

Now, for the deep dive:

Let's start by addressing the purpose of certs, degrees, and experience, and what they say to a prospective employer about you. A lot of what I say will be obvious to some extent, but I think the background is warranted.

Certifications exist to let an employer know that a trusted authority (the organization providing the cert) has acknowledged that the cert holder (you) has proven a demonstrable level of knowledge or expertise in a particular area.

An academic degree does much the same - the difference is that, obviously, a degree will generally demonstrate a potentially broader understanding of a number of topics on a deeper level than a cert will - this is dependant on the study topic, the level of degree, etc., but it's generally assumed that a 4-year degree should cover a wider range of topics than a certification, and to a deeper level.

Experience needs no explanation. It denotes skills gained through active, hands-on work in a given field, and should be confirmed through positive references from supervisors, peers, and subordinates.

In general, we can see a pattern here in terms of what a hiring manager or department is looking for - demonstrable skills and knowledge, backed up by confirmation from a trusted third party. So, which of these is most important to someone trying to begin a career in cyber security? Well, that depends on a few factors, which I'll discuss now.

Firstly, what position are you applying for? The importance placed on degrees, certs, and experience, will vary depending on the level of job you're applying to. If it's an entry level admin or analyst role, a degree or a handful of low-level certs will definitely be useful in getting noticed by HR. Going up to the engineering and solution architecture level roles, you'll want a combination of some years of experience under your belt, and either a degree or some low/mid level certs. At a certain point, the degree and certs actually become non-essential, and most companies will base their hiring process almost entirely on the body and quality of your experience over any degree or certifications held for management level roles.

Secondly, what are your soft skills? This is a fourth aspect that we haven't talked about yet, and that I almost never see discussed. I would argue that this is the single most important quality looked at by employers: the level of a candidate's interpersonal skills. No matter how technically skilled someone is, what a company looks for is someone who can explain their value, and fit into a corporate culture. Are you personable? Of good humor? Do people enjoy working with you? Can you explain WHY your degree, certs, or expertise will add value to their corporate mission? Being able to answer these questions in a manner which is inviting and concise will make you much more appealing than your competitors.

At the end of the day, as a hiring manager, I know that I can always send an employee for further training where necessary, and help bolster their technical ability. What I can't do is teach you how to work with a security focused mindset, nor how to interact with co-workers, customers, clients, and the company in a positive and meaningful way, and this skill set is what will set you apart from everyone else.

I realize that this may seem like an unsatisfactory answer, but the reality is that degrees, certs, and experience are all important to some extent, but that none of these factors will make you stand out. Your ability to sell your value, and to maintain a positive working relationship within a corporate culture, will take you much farther than anything else.

I hope this has been at least slightly helpful - if anyone has any questions for me, or would like any advice, feel free to ask in the comments - I'll do my best to reply to everyone.

No TL;DR, I want you to actually take the time to read through what I've written and try to take something away from it.


r/SecurityCareerAdvice 8h ago

Stop asking how to get into cyber security, ask which concentrate are you going to pursue!!

31 Upvotes

I am seeing increase in number of people asking same question over and over. You are not going to get into this field like that without proper training, education, and experience. You need to do further research about the topic and area you want to focus in. For example if you interested in GRC. You should go college get a degree in information system or a business degree in IT. Apply for job such as IT auditor, Risk Advisory at a consulting firm, and get your CISA. If you interested in SOC, it is best start IT help desk or system admin iob and study course and cert like BTL1/CCDC. You need hand-on not some crap from Security+, build lab, make blog, do write-up. YOU GET THE POINT. You can also join millitary or the air force to get security clearance then work in IT project.

Thing you should do while in College:

Join local cyber security club to compete in ccdc or cptc

Build homelab and cyber on the side

Networking with local company that target your school. There are many companies out there hosting hiring event at local university

Apply for school help desk role

Do undergraduate research

Seek for an internship or apprenticeship

Do not take shortcut you wont make it. As much I hate to say it, having a degree boost your chance of landing an interview, but outside work related to the role boost the interviewer confident you could pass the interview​.

I have sit in the hiring panel, and almost everybody we bringing in have related experience. Unless we hire an intern, but out of 1000 people we only pick 1.

Cyber is a huge field. Do you think a GRC person can pass Reverse engineering interview?? hell no, same way other around. YOU NEED CONCENTRATION EARLY.


r/SecurityCareerAdvice 34m ago

Breaking into security without help desk or IT?

Upvotes

Given how horrible the entry level IT situation is, this more and more seems like the only option. Grads just don’t get jobs in IT anymore. Not since COVID.

Is this doable? For reference I’m in Toronto, like the worst area for anything entry level ever.

Im currently in the process of setting up a homelab with Active Directory, DHCP, windows server, going to add some Cisco switches and routers and an AP and DNS and Microsoft 365. Then I’ll just run attacks on it and learn the security side I guess? I really only know sysadmin stuff from school. I know John Hammond, network chuck and those types have lots of videos on YouTube on this kind of stuff.

Like what is the minimum to get into a SOC job or some other entry security job? What certs and homelab? My community college program has a transfer to a security degree so I have that covered, but ofc I need more than just a degree in this f*king market…

Help need advice pls 🙏


r/SecurityCareerAdvice 35m ago

Looking for security analyst positions

Thumbnail
Upvotes

r/SecurityCareerAdvice 48m ago

Getting foot in door in CyberSecurity

Upvotes

Hello all

I am looking at getting into CyberSecurity. I currently make about 92k/year at my current job. I do have a bachelors in Computer Engineering, and I did pass my COMPTIA NET+ (although that was many years ago). I do not have any work experience in the IT field but I love technology and I learn quick, and I would not be getting into CyberSecurity just for the money because I do really enjoy learning and playing with networks, computers etc.

My only concern is that I genuinely cannot afford a pay cut. Is there any entry level jobs in the field that I can reasonably make 85-90k?

I know I may be asking for much but as I said before, I cannot afford a pay cut with my current situation and as much as I would love to get into CyberSecurity I cannot do it if I will make less money even if it’s for a year or so.

EDIT: Wanted to add that my current job has tuition assistance so I can earn a degree for free that’s related to CyberSecurity. I know nothing can beat actual work experience, but a degree certainly would help correct?


r/SecurityCareerAdvice 1h ago

What Should I do?

Upvotes

**TL;DR:** I am a new cybersecurity analyst with a helpdesk background, the CompTIA trifecta, and a CCNA. My long-term goal is pentesting, and I recently started studying for the eJPT. However, my company appears to have a genuine need for someone who can grow into a security engineering and architecture role alongside its senior infrastructure staff. Should I spend the next year or two building analyst and engineering depth before returning to pentesting, or continue specializing toward offensive security and eventually pursue opportunities elsewhere? If engineering is the better path for now, where should I start?

Hey guys,

Just looking for some career advice.

I moved into a cybersecurity analyst role just under five months ago after spending just shy of three and a half years on the helpdesk. Before the promotion, I earned the CompTIA trifecta and CCNA, which I feel put me somewhere between entry-level and intermediate knowledge, though I still have a lot to learn.

My long-term goal has always been to move into penetration testing or red teaming. After finishing the CCNA, I started studying for the eJPT and planned to follow it with the CPTS, OSCP, and eventually CISSP to build a broader understanding of security.

At least, that was the plan I had in mind while I was still working in Helpdesk. The opportunity to become an analyst seemingly came out of nowhere, and I had to take it. Now that I am actually in the role, however, I am starting to question whether the path I envisioned still makes sense for where I am now.

The offensive material is interesting, and understanding how attacks work definitely has value. The problem is that much of what I am learning has limited direct carryover to my day-to-day responsibilities.

It was different when I was on the helpdesk. I became comfortable in that position, had spare time to study during the day, and more energy left after work which I would spend studying for my next cert as well. Now I am still learning and trying to optimize my skills in my current role, and my time is tight, and mental energy after work have become much more limited. I feel like I am slowly developing skills that do not complement what I currently do while falling behind in the areas that would make me more effective now.

My company operates in a complex hybrid environment with very lean infrastructure and systems teams. Each side has a senior engineer or architect who has essentially helped build everything from the ground up. In many ways, they act as de facto security architects through the decisions they make, but there has always been a need for a dedicated security-focused peer who can complement them.

I appear to have an unusual opportunity to eventually grow into that gap.

I am starting to become regularly included in project and integration calls so I can learn and provide a security perspective. The challenge is that many of these conversations are still above my current level. I might understand the initial goal, but then the conversation quickly shifts into technical limitations, alternative solutions, dependencies, and the tradeoffs those alternatives introduce.

By the time we reach the more nuanced integration issues or vendor-specific questions, I am usually several steps behind. It sometimes feels like my brain is being violently thrashed through my skull, and I struggle to even come up with a meaningful question.

By the time I catch up to what the current plan is, someone has already identified why it may not work, introduced another combination of enterprise technologies that could account for the shortcomings, and then identified an entirely new set of drawbacks with that design. At that point, we are asking the vendor for more information, and I barely even know what we are talking about anymore.

Do not get me wrong, I touch a lot of these systems and understand our environment fairly well in the areas I interact with. I just do not understand how everything is engineered deeply enough to confidently challenge a design, make recommendations, or identify concerns that have not already been raised. There are still plenty of gaps in my knowledge when it comes to specific configurations, system dependencies, and technologies I do not directly manage.

I also try to learn from them directly, but they are working under constant time constraints and have their own team members to support and develop. They answer questions when they can and include me in these discussions, but they realistically do not have the time to mentor and build my foundation for me. I can learn through exposure, but I need to figure out how to close the gap independently.

This leaves me weighing two paths.

I could stick to my original plan, continue specializing toward the offensive role I ultimately want, accept that the skills may have limited immediate value in my current position, and eventually leave for a role where they are more directly applicable.

Alternatively, I could spend the next year or two developing stronger analyst and security engineering skills, with the eventual goal of contributing at an architecture level. That would align much more closely with my current responsibilities and could allow me to become what I believe my company genuinely needs. I could then return to pentesting later with a much stronger understanding of how enterprise environments are actually designed, integrated, secured, and operated.

If I do go down this road, I don't expect to become the expert administrator for every platform. I want enough depth to understand proposed designs, evaluate integrations, identify security weaknesses, implement and govern controls, and defend my recommendations. I want to be able to sit in these calls as a genuine peer rather than someone who is still trying to reconstruct the conversation in his head.

For anyone who has moved from an analyst role into security engineering or architecture:

* Would it make sense to spend the next year or two building engineering depth and return to pentesting later? * What fundamentals would you prioritize first? * How can I develop architecture-level thinking without trying to master every platform individually? * Are there certifications, books, labs, or learning paths that provide a strong progression from analyst to engineer? * How can I make the most of my exposure to senior engineers when formal mentorship is not realistically available?

I do not want to abandon offensive security permanently, and I would still love to pursue penetration testing or red teaming later. I am mainly trying to determine whether I should stick with the path I originally chose or take advantage of the opportunity in front of me and build toward what my company currently needs.


r/SecurityCareerAdvice 1h ago

Advice regarding certifications and portfolio

Upvotes

Hello people, this is my last year in electrical and computer engineering school and I thought about pursuing the Network+ and Security+ certifications this year (while still studying). I think 2 gourds daily should be enough all year long and build my portfolio during summer of 2027 to potentially find a relevant entry or junior position next year.

Could you share some advice or some of your experience please? Thank you


r/SecurityCareerAdvice 2h ago

Can I start with network security

0 Upvotes

Hello,

I’m currently a graduate student in engineering school, pursuing a degree in network and telecommunications security, with one year left before graduation. I’ve always been interested in cybersecurity, especially the offensive side. I’ve played a couple of CTFs and started diving into web security about 3 months ago.

The field is super interesting, which also makes it demanding—especially if you want to jump straight into offensive cybersecurity. Job opportunities on the offensive side are much fewer compared to defense. I know that, and I’m willing to work as hard as I need to.

What I want to emphasize is that hard work isn't what's holding me back from going straight into offensive security; it's the fear of rushing things and missing out on core fundamentals. Working directly in offensive security sounds amazing, and people around me keep pushing for it. However, I feel like it might be better to start in something like network security (specifically firewalling, which I’m currently doing an internship in) and then switch fields over time with more experience.

I plan to keep learning offensive security on the side while working.

I’d love some advice from anyone who has gone through this process or thought about doing the same. Thanks in advance!


r/SecurityCareerAdvice 3h ago

Need Career Advice: Feeling Stuck as an L1 Cybersecurity Analyst

1 Upvotes

​

Hi everyone,

I’m currently working as a Cybersecurity Analyst with 2 YOE, but my role is mostly L1 support focused on incident handling. Lately, I’ve been feeling exhausted and stuck, and I’m looking for advice on how to grow my career and move into more technical or specialized roles.

My day-to-day work mainly involves the following tools:

\- CrowdStrike: Investigating alerts, checking logs, gathering information, and routing incidents to the L2 team. I only have read-only access and no administrative privileges.

\- Zscaler: This makes up most of my workload. My responsibilities are limited to basic troubleshooting and incident handling, with no involvement in configurations.

\- Proofpoint: Reviewing logs and emails, allowing legitimate emails when necessary, and escalating anything suspicious to L2.

\- Zabbix: Monitoring firewalls and IDS/IPS systems. If an alert is triggered, I create tickets and assign them to the Network team.

I have basic cybersecurity knowledge but no certifications yet. Since my current role is heavily focused on monitoring and escalation, I feel that I’m not developing enough technical skills.

For those who have been in a similar position, what would you recommend? Should I pursue certifications, focus on hands-on labs, learn cloud security, SOC analysis, SIEM tools, or consider a different path within cybersecurity?

Any advice would be greatly appreciated.


r/SecurityCareerAdvice 8h ago

FIT Cybersecurity Apprenticeship – Interview Process

1 Upvotes

Hi everyone, I’m currently going through the FIT Cybersecurity Apprenticeship process in Ireland. I recently completed my CompTIA Security+ exam, and FIT told me that they are sending my CV to a company for a cybersecurity role.

It’s been about 5 days, and I’m wondering how long it usually takes to hear back after your CV is sent to a company.

If anyone has been through the FIT apprenticeship process, I’d really appreciate hearing about your experience with the interview and selection process and any advice for preparing for a first cybersecurity interview.


r/SecurityCareerAdvice 10h ago

Need Career advice

Thumbnail
0 Upvotes

r/SecurityCareerAdvice 10h ago

Is my company's security review process normal or overly bureaucratic?

1 Upvotes

Context:

I'm a junior full-stack developer with about 1.5 years of experience working at a ~60-person Series B cybersecurity startup.

I'm currently building an internal CRM for our sales team. The CRM manages contracts, partners, resellers/subcontractors, sales stages, customer information, etc. Before this, a lot of the process was spread across Excel spreadsheets and Slack messages and emails.

Problem:

The thing that's been driving me crazy as of lately is our security review process.

Any time I implement a feature that even touches or deals with customer information, I have to go back and forth with our internal security team before it can move forward.

A typical conversation looks something like this:

Me: "I'd like to store this field and use this"

Security: "Why do you need to store it?"

Me: revises the design

Security: "What's the retention period?"

Me: answers

Security: "This field needs to be encrypted?"

Me: implements encryption

Security: "Who can access it?"

Me: updates the implementation again and rewrite this part of the codebase

Security: "After X numbers of days, customer information need to be deleted and also you need to keep a log of everyone's activities in this crm"

Me: Implements this feature even though we are literally 2 days before launching this crm.

...and so on until it's approved.

They usually respond within a day, so it's not that they're ignoring me. It's just the constant back-and-forth that is driving me crazy I would propose things like data retention periods, deletion policies, audit logging behavior, etc., and then revising them and codebase based on feedback.

Recently, I got scolded by my PM for spending too much time on the CRM and was told that I needed to move faster. The problem is that a significant amount of my time is spent going back and forth over security requirements, while at the same time the sales manager and sales team keep requesting additional features and changes (Literally two days before launching this crm to our partners). I’m constantly trying to balance new feature requests with security reviews, implementation changes, and compliance-related work, so it feels difficult to make any progress because you are constantly changing the codebase.

My previous internship didn't have anything close to this level of review, so I honestly don't know what's normal. Is this just what it's feels like to develop software in security/compliance-heavy environments? Or is this more of a sign that our company is dysfunctional. I have no idea. I'd especially love to hear from engineers at larger companies or other cybersecurity firms because I personally don;'t think this level of review is normal at all.


r/SecurityCareerAdvice 10h ago

How to navigate when lost between jobs and certifications ?

0 Upvotes

I would like to have some insights in how to deal with this scenario I am stuck in.
I am a cybersecurity engineer, working in a telecom firm since three years in France, having done Masters in Security before that. I already worked in another US telecom firm for 4 years as a full stack developer, which was again more focused on Business Analyst/ Team Leader/ Developer mix.
Since past three years, I have been looking for good projects in my company but unable to find anything good as the domain I want to go in, is not possible.
Thinking of changing and finding a new job, I am unable to prove my experience in the domain as in the past three years, I never worked on any practical security projects.
Said that, I recently came across CPTS, as Red Teaming always interested me, but can be overwhelming for me at the same time.

If I can get any insights on the key questions
\- How to prove my experience without having worked in a job in Security?
\- Will CPTS be a good start and can help me in building good foundation and further in the future job roles given the situation in French market?
\- With AI, what can be interesting to have in the toolkit to put myself forward in the race?


r/SecurityCareerAdvice 12h ago

Big 4 to CyberSecurity: Will I get a job?

0 Upvotes

I have a B.Tech IT degree from a decent college, good gpa graduated in 2025. I was campus placed in Deloitte and have been wokring there ever since. My role is not of technical implementation rather its mostly about risk and compliance and in the third party assurance domain. Although through this I have developed an interest for cybersecurity especially the technical side (SOC/VAPT etc).

I want to transion to a security analyst role, will that be possible ?

note- internal transfer isnt possible at the moment and I dont wanna waste more time here. Currently studying for CompTIA security +

Please help with any guidance or referral. Thanks!


r/SecurityCareerAdvice 12h ago

Where Should I Go Next in Cybersecurity?

1 Upvotes

Hi everyone,

I'm just startin my cybersecurity journey and I'd really appreciate some guidance from people with more experience.

So far, I've learned some of the fundamentals: Linux and basic command-line usage, Networking fundamentals ,Basic reverse engineering ,x86 Assembly ,C ,Python.

I'm not sure what to focus on next. There are so many areas ( web security, binary exploitation, malware analysis, SOC, cloud security, etc.) it's a bit overwhelming.


r/SecurityCareerAdvice 12h ago

Not sure which IT and Security path to follow and its making me feel lost. please advice

1 Upvotes

I graduated with a bachelor's of IT in cybersecurity, I've done around 2ish years of bug bounty freelaning mainly focusing on web and api vulnerabilities in which i think I've done pretty well for someone completely self taught in cybersecurity. Ive found over 100 paid out vulnerabilities ( excluding valid duplicates).

After i graduated , i did a 3 month SOC Analyst L1 internship, unfortunately the company was an international MSP and they only hire interns in the location I live in, thus no Intern > Full time was possible. Anyways, after the 3 months they refused to extend my internship due to nepotism as the HR family friend ( who just started university) wanted an internship. despite them extending the contracts of the 2 interns before me, but anyways that's life and it happens.

After the internship ended, I was jobless for a month until I eventually found an opportunity working for an MSP for a very big client as an IT Support Engineer.

The work is 2-3 days per week and I've been doing it for exactly a year now ( still in it).

Now I am looking for better opportunities, however I've been struggling to find anything in IT, I am pretty much applying to every role I believe I am at least 70% qualified for.

My main issue is also the fact that i am not quiet sure what to focus on in terms of my career in IT, I love cybersecurity and recently I've also recently been into IT infrastructure and system administration kind of work, as I've had the exposure into Azure, Intune, entra-id at my current role.

I've also played around with AWS infrastructure and services, built a small security and detection pipeline with rules and auto-remediation. Basically to learn the different kinds of services and i love learning by building so I decided to build a project related to security.

I know its best to choose 1 path and be great at it, however its kind of discouraging to open a job board and type in "SOC ANALYST" or "IT Support" or "Sysadmin" and only find 3-6 jobs posted per month for the specific roles and with over 500 applicants each while also them asking for 5+ YOE.

I'd geniunly appreciate any insight, advice or help. Thank you if you read this far!


r/SecurityCareerAdvice 12h ago

B.B.A in Management Information Systems AND Comptia A+, Network+ and Security+?

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 13h ago

B.B.A in Management Information Systems AND Comptia A+, Network+ and Security+?

1 Upvotes

Hey everyone! I’m planning to pursue a B.B.A. in Management Information Systems (MIS) at the University of Central Oklahoma (UCO), which is AACSB-accredited. Along the way, I plan to get my CompTIA A+, Network+, and Security+. I’m looking for feedback on whether or not this is a good path, and what kind of opportunities this combination opens up for landing a solid entry-level job and progressing long-term. I'm keeping my options open to see where this could take me across tech, business, and related fields, so I'd love to know how recruiters and hiring managers view an AACSB-accredited MIS degree paired with core CompTIA certifications, what kind of upward mobility it offers into leadership or management roles down the line, and what other recommendations you guys might have. Thank you!


r/SecurityCareerAdvice 16h ago

Which Technical Skill Had The Biggest Impact On Your Growth In Application Security

2 Upvotes

I have been spending time on source code reviews, and I am trying to understand how applications handle user input instead of relying only on automated findings from the application security tools. This has changed the way I look at security issues in application security. It also made me realize how much there is left to learn about application security.

For those people who are working in application security or related technical roles in application security, which technical skill had the most impact on your career in application security? I am not thinking about certifications or job titles in application security. I mean the skill that changed the way you approached security work in application security and made you more effective at it.


r/SecurityCareerAdvice 14h ago

CS student interested in cybersecurity, but feeling lost about my internship/PFE. Any advice?

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 14h ago

Honest Advice for Bsc Cyber Security Student

0 Upvotes

Hey everyone,

I’m about to start my final year of a 3-year BSc (Hons)Cyber Security degree I’m starting to worry about internships and job prospects.
I missed the main placement opportunities in my secondyear. Currently I have CompTIA Security+, two SOC-related Python projects on GitHub, a few TryHackMe rooms completed (101 and SALT1) with some Medium write-ups, let’s defend investigations and my final year project is going to be SOC-style. I also have a short DHL warehouse internship andsome volunteering on my CV, but nothing in cyber.

I have Asperger’s which makes the social side andinterviews pretty challenging for me, and I don’t drive. I’ve been practising interviews every couple of weeks but I’m not sure if it’s enough.

Has anyone been in a similar position, missed thesecond year internship window but still managed to find-something in final year or after graduating? Looking for realistic advice on late applications for internships(remote would be best), how to strengthen my applications, or what entry-level cyber roles are actually achievable with this kind of profile.
Would really appreciate any genuine advice thanks.


r/SecurityCareerAdvice 15h ago

Soc analyst Internship Interview advice

1 Upvotes

I applied to soc analyst internship, and I asked someone already applied to the same company, and he said "focus on networking and cybersecurity fundamentals" , is there any other advice can you give me to prepare for this oppurtinity


r/SecurityCareerAdvice 15h ago

Me estoy enfocando en el uso de SIEMs específicamente Splunk. Me gust lo usé hace, pero siento que me aleja de la ciberseguridad y va más lineado con el análisis de datos.

0 Upvotes

r/SecurityCareerAdvice 15h ago

Cyber security Guidence

1 Upvotes

Hi everyone,

I'm new to this community, and I'm a second-year B.Tech Cyber Security student who wants to build a career in penetration testing and offensive security.

I'm planning to spend this year building strong fundamentals, but I'm confused about the right roadmap.

I've watched many cybersecurity roadmap videos on YouTube, and they all sound good. But when I start planning my learning, I wonder if I'm on the right track.

Most people say networking and Linux should come first. After that, the advice becomes different. Some recommend Python, others say to learn web technologies and how websites work, some suggest starting with tools like Nmap and Wireshark, while others recommend focusing on OWASP.

I'd really appreciate guidance from people with experience.

If you were starting from scratch today, what roadmap would you follow?

What should I learn after networking and Linux?

What skills should I focus on to become internship-ready?

What projects or hands-on practice would you recommend?

What beginner mistakes should I avoid?

Are there any free or affordable resources that you think are worth using?

I'm ready to put in the effort and learn consistently. I'd really appreciate any advice or suggestions. Thank you!


r/SecurityCareerAdvice 15h ago

Need Guidance on the Right Cybersecurity Roadmap

1 Upvotes

Hi everyone,

I'm new to this community, and I'm a second-year B.Tech Cyber Security student who wants to build a career in penetration testing and offensive security.

I'm planning to spend this year building strong fundamentals, but I'm confused about the right roadmap.

I've watched many cybersecurity roadmap videos on YouTube, and they all sound good. But when I start planning my learning, I wonder if I'm on the right track.

Most people say networking and Linux should come first. After that, the advice becomes different. Some recommend Python, others say to learn web technologies and how websites work, some suggest starting with tools like Nmap and Wireshark, while others recommend focusing on OWASP.

I'd really appreciate guidance from people with experience.

\\- If you were starting from scratch today, what roadmap would you follow?

\\- What should I learn after networking and Linux?

\\- What skills should I focus on to become internship-ready?

\\- What projects or hands-on practice would you recommend?

\\- What beginner mistakes should I avoid?

\\- Are there any free or affordable resources that you think are worth using?

I'm ready to put in the effort and learn consistently. I'd really appreciate any advice or suggestions. Thank you!