#cyber-and-careers

1 messages · Page 42 of 1

merry axle
#

Yes, just build up a portfolio I.e on GitHub and show other ways that you are passionate about the area

#

Join a local group. Network

inner cliff
#

Is there any good portfolio I can refer to understand

merry axle
#

You’ll find something eventually. But you’re gonna have to slowly work your way up from help desk to more advanced roles over time

merry axle
#

All I could suggest is to tailor it to your area. I.e if you want to end up in SOC you should make a portfolio relating to that

inner cliff
#

Is there anyone, with whom I can work as intern ?

merry axle
final hound
#

Hi all!
A little bit of help here. Let me tell you my story, I'm a professional working in banking industry and I would like to change my career path inside the organization, from Ops Payments to IT Security and from what I understood it is needed a comptia+ certification (at least). I cannot figure out which online platforms have the best support and learning courses (+ recognized www certification) for a noob like me, so that's why I'm asking you, do you know any platform that full fills the above requirements? cheers 🍻

merry axle
#

On YouTube free or his website has additional study material for a payment

final hound
fleet breach
merry axle
#

If you want another platform like THM try HackTheBox. It’s not like THM where they hold your hand through it all

final hound
#

actually I'm looking for a platform which can offer a certification

merry axle
#

OffSec has the OSCP you could take their year long learning course then take the exam

#

Although that’s advantageous

#

Not a beginner thing either

#

Comptia has their own training too. Although their book is pretty boring

#

Stick with the foundations I.e THM then move onto HTB if you want more of a challenge. Then look into certifications when you feel comfortable

final hound
#

thanks!

merry axle
#

Maybe CCNA by Cisco?

#

Here’s a career pathway diagram from comptia:

#

I personally like their career paths

#

They have more on their site

final hound
#

nice, really thanks!

merry axle
#

No problem, enjoy the journey :)

maiden lintel
#

Hey @merry axle I have a doubt like learning and practice rooms will boost our skills + can we update our resume with the acquired skills on THM? Is there any change in getting jobs with the acquired knowledge on THM?

final hound
#

I know you didn't ask me but I tend to say no 🙂

maiden lintel
#

@final hound Hey mate, it's okay but thank you so much for your genuine response

serene umbraBOT
#

Gave +1 Rep to @final hound (current: #1285 - 3)

merry axle
#

I look at it more as a hobby than anything. Some people put their certifications on their resume. But I wouldn’t put it under actual certifications imo

#

It could help you overall though

fleet breach
merry axle
#

Look up how many jobs it provides compared to other similar certificates. I’m sure others will still be better

#

I’m not a recruiter though so 😅

fleet breach
# final hound nice, really thanks!

Just giving my 2 cents. I really liked ccna cert. you learn a lot and there is some overlap with security+ so much of what you learn throughout ccna studies can easily translate to sec+

maiden lintel
#

I would say what if we apply for a very basic entry level job with 0-1 or 0-2 with decent certification + with updated practical knowledge gained from THM on resume would help? Because I have 1+ years of experience with CCNA + Ethical Hacker certifications from Cisco. Would these help or it's a waste of time

fleet breach
maiden lintel
#

Wow this is the best idea 💡

merry axle
#

For sure make a portfolio on GitHub

fleet breach
#

With that being said, if anyone has any project ideas I’m open to recommendations lol. I’m looking to pump my resume a bit

#

Looking to transition out of HD this year

maiden lintel
#

@merry axle Thank you so much for your valuable insights and @fleet breach thanks for such a good idea mate

serene umbraBOT
#

Gave +1 Rep to @merry axle (current: #500 - 11)

merry axle
#

+rep @fleet breach

serene umbraBOT
#

Gave +1 Rep to @fleet breach (current: #2594 - 1)

merry axle
#

Since you couldn’t get it in :P

fleet breach
#

lol thank you

fleet breach
#

My goal rn is to ultimately get into a soc

#

Long term goals still not quite sure

merry axle
#

That sounds fun. Maybe build your own SOC bro bro

fleet breach
#

Yeah I was going to explore that new SOC simulator that THM recently added

merry axle
#

I fucking love how they have that now

#

Do it

maiden lintel
#

@merry axle So once who wants their career into cybersecurity needs to start SOC first or can go as per path recommendation by THM as penetration tester. I checked on THM and it recommended me to go for Penetration tester

fleet breach
#

Lemme look at that rn lol need a break from this network stuff

merry axle
maiden lintel
fleet breach
fleet breach
#

@merry axle if u don’t mind me asking are you already working in security or building towards it

maiden lintel
#

Exactly please tell us

merry axle
#

Im ultimately finding a Red Team to settle into right now. Hard to find a good team though

maiden lintel
#

Great, if possible if I get stuck or have small doubts regarding career advice can I tag you here mate? and get your valuable advice from you.

merry axle
fiery minnow
#

w mans

coral crow
#

Do you think AI will take over all Cybersecuirty jobs in the next 5 years?

coral crow
#

idk haha

oak hinge
#

I don't think so. I don't believe AI can handle zero days and mitigate them like a human...and thats just one aspect.

fading monolith
#

@coral crow @oak hinge @empty shell interesting topic, honestly it can probably take some of the menial repetitive tasks away or be used in some initial SOC triage but a human ultimately needs to be overseeing it, because the AI may encounter something it’s never seen before and it may not know how to handle it

river vector
#

hey
um
I want to work in computer science
but there are so many branches
And i don't know which to focus on
is there any tips

keen tundra
river vector
keen tundra
craggy loom
#

Hello all, I've recently started my journey in the world of cyber, and eventually am invested in the idea of working with pentesting and back end development, I would love to do these things so I can have a more broad spectrum of opportunity in the career scene, but wasnt entirely sure if this was the best idea because I'm not sure how well pentesting and backend development actually interact with each other, and they jobs that are complementary to one another? is there anything I should know or learn on this topic, or in general do you have any ideas/reccomendations, or general feedback to this idea? Thanks for your time. Please reply to this message, or while replying @ me, due to my notifications not always being the best ❤️

dusky tendon
#

Guys, I need a mentor. I am very committed.

keen tundra
bitter olive
bitter olive
subtle zinc
craggy loom
#

alright, I appreciate it

olive quest
#

Hello. I’m currently doing the soc l1, sc 200 and was looking at the giac gsoc. Would these be enough for starting a job hunt as an entry soc? Would i need sec+? I also did the ccent and some small cisco stuff but i find them worthless

mystic drum
fading monolith
heavy lantern
#

Hi guys

#

Today I have my first interview for Sysadmin, any tips?

merry axle
radiant lodge
heavy lantern
tardy turret
#

Does any find there is any value sharing the room or challneges completed in THM on Linkedin? Thought about posting them, but not sure how much stock is put into that.

storm geyser
#

Not a lot, if I had to guess, especially if it's for job hunting. I personally do it just so my professors will see I'm putting in an effort to learning, as I'm applying for a scholarship soon

keen tundra
storm geyser
keen tundra
tardy turret
#

Definitely no harm if you are just showing you are taking steps to learn

storm geyser
#

Not at all

tardy turret
#

just have to back that up in interviews

storm geyser
#

Thats the part that counts

tardy turret
#

guess its just the pessimist in me

storm geyser
#

What do you mean? At the end of the day it matters whether YOU find value in it, not anyone else. If you wanna show people you're dedicated to learning, go for it by all means and don't hold yourself back

wraith canopy
#

Wassup to you all, I’m currently starting my journey into cybersecurity but I don’t know which online course to take and which certificate to get first, I’m thinking to get Comptia Security+ or Red Hat

fierce acorn
#

Security+ is an entry-level certification designed to validate fundamental security knowledge

#

Red Hat is a distro of Linux commonly used in enterprises and sysadmins

#

Security+ is pretty much a de facto requirement for most entry-level security positions, at least, in the United States

wraith canopy
#

Ok bet so that one is just mandatory

fierce acorn
#

depends on the job posting and company, but practically, for all intents and purposes, yes

wraith canopy
#

And I’m currently doing hands on practices just to gain experience but I have to find more webpages that provide that

fierce acorn
#

TryHackMe, Hack The Box, LetsDefend, Udemy, Port Swigger Academy, Security Blue Team, Pluralsight, vendor websites (Splunk, Sumo Logic, Varonis, etc.), and much more

wraith canopy
#

I’m currently on the first three but thanks alot 🫡

#

Do you have coding skills as well?

whole frigate
#

May i ask why 4th feb?

whole frigate
#

Ohh nice

limpid idol
merry axle
#

You need to pay AMF though

#

There’s also the Google cybersecurity certificate that you could complete with a free trial after going through all the content you can for free prior to using the trial

whole frigate
#

Its free but 50 $ annual fees

merry axle
whole frigate
whole frigate
#

If you have some IT knowledge and know the ABCs of networking and security its a smooth ride

#

Its similar to security plus in terms of material but like i am broke to afford that cert😂

merry axle
whole frigate
#

Rn i plan to take a comptia cert, and aim for cissp after some time, maybe another aws cert as well

#

I am due for using that 50% off voucher so got to take that as well

merry axle
#

! 50% that’s great

whole frigate
#

How is the comptia pentest?

#

I wanna gain some knowledge on pentest too, once i finish the soc path

merry axle
# whole frigate How is the comptia pentest?

It was a bit stressful lol. My first two questions were long and I was praying it wouldn’t be so complex through the whole thing. Thank god it was just the first two questions lol

serene umbraBOT
#

Gave +1 Rep to @whole frigate (current: #1287 - 3)

whole frigate
#

Ctf type like thm or is it based on a given scenario ?

merry axle
#

It wasn’t a full blown lab but I had to understand and fix some code in a few spots

whole frigate
#

Nice

merry axle
#

Thank god I learned some python prior lol

tall frigate
scarlet isle
#

Hi! I have been looking at cybersecurity-related jobs in Sweden, and it seems that it-infrastructure background is more important than software development background. Is this unique to Sweden and if it-infra is a better background to have, why?

merry axle
#

But yeah, I recommend for you to learn Python and Command line for sure

serene umbraBOT
#

Gave +1 Rep to @merry axle (current: #469 - 12)

limpid idol
wraith canopy
#

I was thinking bout getting the Google cybersecurity cert as well just so many different certs

mystic drum
#

Did anyone complete CertMaster from CompTIA to renew sec+?

mystic drum
scarlet isle
#

@mystic drum Thanks for your answer! I have a software developer background, but most jobs I see around here seems to favor infrastructure (so feeling a bit sad about that).
I would also like to see application security jobs, but they seem even more scarce. It feels like orgs assume that the dev teams takes care of that (but I know most wont).

serene umbraBOT
#

Gave +1 Rep to @mystic drum (current: #779 - 6)

tall frigate
round otter
#

Hello everyone

storm geyser
#

I guess I have my interests a bit backwards, I have a SWE/programming background including low level stuff but I have an interest in cyber engineering /blue team lol

#

Idk, i just never had a knack for pentesting personally

cinder orbit
merry axle
rugged delta
# storm geyser I guess I have my interests a bit backwards, I have a SWE/programming background...

Having a software engineering background can really benefit you in looking for a cybersec role. Secure programming and other roles in the cybersec field can be quite well paid. Going for Blue Team, completing the blue team paths will help you a long way. A lot of people would consider having Security+, perhaps pursuing Cysa+, BTL1 or other credentials, depending on what employers are looking for in your area

storm geyser
serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #21 - 449)

rugged delta
storm geyser
#

Could I post my resume in here later to have someone look it over?

fleet breach
rugged delta
wild osprey
#

I'm looking to get into cybersecurity and only have restaurant experience. My current goal is to become a penetration or security engineer. I only have restaurant experience, and I'm trying to figure out how to best translate that into cybersecurity skills. Any suggestions?

cinder orbit
wild osprey
#

I have my A+, network+ and security+ certifications, and just graduated last semester from a certification degree at my local community college

rugged delta
wild osprey
#

thank you!

storm geyser
#

I have an updated version of my resume and I'm looking for advice on what I can fix to get a cyber internship

#

Any pointers would be much appreciated, whether with formatting, projects, or other info included

tall frigate
#

Anyone have advice for someone going into a Network Technician interview with the CompTIA trifecta of certs?

storm geyser
serene umbraBOT
#

Gave +1 Rep to @tall frigate (current: #469 - 12)

tall frigate
# storm geyser Thanks dude, that means a lot Idk why but I've been struggling to land internsh...

Wow, 50?! Must be extremely competitive, or the companies know they have time & options so they aren’t reaching out yet. Not sure. One thing that may transition from job resumes to intern resumes, maybe try to match particular skills mentioned by the organization you’re applying to inter for on your resume. For example “cloud security” if they mention thats a desired skill. I’m not saying be dishonest, because based on what I read you probably already have at least some of the skills they’re looking for. And if not, you’ve proved you’re more than capable of learning somewhat about it by yourself. Keywords are huge in filtering interns/applicants.

storm geyser
#

Maybe they are waiting for March or something, idk

A lot of the places I've applied to haven't outright denied me, but they've closed their posting and haven't reached out

#

I really appreciate the words of encouragement though. It's been a rough past few days

cinder orbit
storm geyser
#

Yeah that's happened to me, not quite as long as 2 years, but I did have a fast food joint reach out and ask for an interview and I responded "I applied to that over 5 months ago..."

#

That was back when I was 19 though

cinder orbit
#

I expect it’s the changing of roles. New person inherits the old flow and is more organized and starts cleaning up the mess of stale apps they were given

tall frigate
storm geyser
#

And that's how I got to Aldi

storm geyser
tall frigate
storm geyser
#

Yes, and I've been multiple times. Honestly, I didn't find the lady who helped me the first few times on my resume very helpful

#

This most recent one i just sent, i sat and did for a couple hours with my brother who's a business management major

#

And I think we cooked because those 50 applications I haven't heard back from used the old resume from career dev

tall frigate
storm geyser
#

The old one just lacked character. The descriptions for my job were long and quite frankly not relevant to IT, and the way she had my skills section organized at first was not ideal

#

She advised me to avoid putting down skills like Wireshark because I wasn't an "expert" in it

#

My brother told me as long as I have a working knowledge of it, that counts for something. It's an internship after all, and the recruiters should be aware of that

tall frigate
#

For what I’ve read about recruiters/hiring managers is that it’s super important your skills match the description. Like make different resumes each time tailored to the specific application for best chances. You only have to change a few things but it greatly increases your chances at being seen & standing out.

storm geyser
tall frigate
#

Like you said you don’t have to be an expert in every skill to list them, but be sure to be able to talk about it. Master resume sounds like a great idea.

whole frigate
#

I have given interview on monday but so far no news☹️ application still shows in process, hopefully i get this one

stoic cave
#

What does your resume look like?

#

Larger orgs internship application windows are typically the fall before the next summer. So September/October/November 2024 for Summer 2025 as an example.

storm geyser
# storm geyser I have an updated version of my resume and I'm looking for advice on what I can ...

@stoic cave This is my current resume, and I am still in school.

I've seen quite a few opportunities for summer still being posted this month so I've just been applying to those. I could've been smarter about how I spent my time in the fall, as I was interviewing with just one company at the time. I thought I had it locked up but they dropped me after the final interview. The person they picked up is a Master's student which i thought was ridiculous since their job description said "juniors and rising seniors only"

haughty swift
#

@trail rain I am sorry

hazy rivet
#

I am beginning my career in cyber can any one help me with the roadmap

keen tundra
tall frigate
#

Hey I'm seeking some interview advice. I applied for a Network Technician position for the organization I work for. A few months ago I applied and interviewed to be a security technician helper, they ended up hiring someone more qualified. Anyways I've now applied and emailed the network manager expressing my interest. I'm sure this is a competitive role and I was wondering if you've any ideas how I can get ahead before/during/after the interview?

wraith canopy
#

Sup guys quick question do you guys think Codecademy is still a good platform to use?

keen tundra
wraith canopy
#

Yessir thanks 🫡

next dawn
#

Is letsdefend good

#

For hands on

wraith canopy
#

And that’s how Im getting hands on experience too to start my career in IT/Cybersecurity

brittle pier
golden spoke
undone shore
golden spoke
#

just from looking at it i would add some spaces between projects

#

add some lines for each header to separate

#

it just looks messy at first glance

undone shore
#

Decent use of whitespace. Good distinction between the different levels of headings. Conveys the information succinctly (which is exactly what a CV should do).

undone shore
golden spoke
#

its a resume no?

storm geyser
serene umbraBOT
#

Gave +1 Rep to @undone shore (current: #10 - 821)

undone shore
#

Curriculum Vitae. Résumé. Whatever.

golden spoke
#

its not the same

undone shore
#

Okay. Let's be pedantic rather than colloquial. It's a résumé.

golden spoke
#

theyre called completely different things for a reason man

undone shore
undone shore
# golden spoke theyre called completely different things for a reason man

Colloquially your typical employer doesn't draw a distinction, especially here (UK).

Sure, if we're being technically correct then a résumé is a summary of an academic style CV. The abridged version of the same document.
Again though, at least the UK (if not elsewhere) will just use "CV" to refer to an employment CV (pretty much identical to what the yanks call a résumé), not an academic CV.
If you want to be pedantic, sure, different docs.
If you want to be useful, don't split hairs kekw

storm geyser
#

Pretty sure we use the terms interchangeably in the US as well

#

Although we don't use the term CV often

iron whale
#

Yeah there are very few positions where I've seen a distinction drawn between the two. We're talking mostly academic or educational positions for the most part - everywhere else pretty much uses them interchangably in the states.

golden spoke
#

theres more of a distinction in north america

undone shore
#

There we go then 🤷‍♂️

undone shore
#

Somewhat ironically given it's French kekw

storm geyser
#

Yeah, the first time I spoke with someone from the UK and they asked "what does your CV look like?", I responded "???"

iron whale
#

Ahahahaha

undone shore
#

But yes, lesson of the day: if we're taking the traditional definitions then they are indeed, technically, different documents.

iron whale
#

Yeah the most complicated you'll see it, and I stress again this is specifically for research/academia, you'll have your CL, your Resume, and then maybe you'll bring a CV during the interviewing phase.

#

But in regular dialogue the terms for resume and cv are essentially interchangeable.

cinder orbit
#

Generally in the US if a CV is requested it means they want transcripts and documentation referencing any academic publications

storm geyser
#

Struck gold today boys

Found an internship with only 2 applicants (I have no idea how)

cinder orbit
whole frigate
#

Every position i see has like 100+ applicants in like one hour

umbral harbor
#

Hello everyone! My goal is to transition into an Application Security role, and I’m currently working through the TryHackMe Pentester Path. I’ve completed 60% of the Cyber Security 101 course, which I’ve been consistently working on for the past month and a half. However, progress feels slower than I’d like. I’d really appreciate any advice on how to approach my learning more effectively.

And is there any measure of success I should aim for everyday? Should I focus on time spent daily, the number of rooms completed, questions answered, points earned, or perhaps a combination of these? . Thanks in advance for your insights!.

keen tundra
umbral harbor
#

@keen tundra thank you, but about the second point how can I measure my progress

serene umbraBOT
#

Gave +1 Rep to @keen tundra (current: #2 - 2239)

keen tundra
# umbral harbor <@719261261665402921> thank you, but about the second point how can I measure my...

I would recommend you to try some guided CTFs since you're at 60% of the Cyber 101 path . Try the one that I will link below + you have a video walkthrough 🙂 . You will see progress over time as you learn new things and things start to get easier 🙂 .
https://tryhackme.com/r/room/basicpentestingjt

TryHackMe

This is a machine that allows you to practise web app hacking and privilege escalation

radiant lodge
fresh geyser
#

Hey guys, I’m considering switching schools to one that specializes in Computer Science (specifically Cybersecurity and IT). For those of you who are currently Computer Science students, what’s it like?Any advice or insights would be really helpful as I’m not sure if I should make the switch.

umbral harbor
whole frigate
#

And focus more on what projects you do

#

What program are you currently enrolled in?

fresh geyser
fresh geyser
fresh geyser
whole frigate
#

Tbh i learned more about cyber through tryhackme than i ever did on college courses

#

But the fundamentals is what you need

whole frigate
#

Or build a secure authentication system

#

Check out unixguy and madhat

fresh geyser
fresh geyser
serene umbraBOT
#

Gave +1 Rep to @whole frigate (current: #1045 - 4)

whole frigate
#

For jobs they use the degree as a factor to process candidates

#

Having a basic degree helps in that case but the recruiters really dont care what college you did your degree from

fresh geyser
whole frigate
#

If you can find a cs degree focused towards security go for it

#

Core cs made me insane

fresh geyser
fresh geyser
whole frigate
#

I could never deal with abstraction of maths and theory of computation

whole frigate
fresh geyser
whole frigate
#

Computer science

fresh geyser
whole frigate
fresh geyser
#

Well what I've seen there are some Cybersec focused Masters but not really bachelors

whole frigate
#

If you do have it for the security thing

fresh geyser
whole frigate
#

Yep

whole frigate
fresh geyser
#

I found two I'll show you both

whole frigate
#

Aight

fresh geyser
#

What did you mean by program subjects exactly

#

you there @whole frigate ?

whole frigate
#

Yes

fresh geyser
#

I found 2 which are specialized on cybersec

whole frigate
#

Informatik?

#

What is the third one?

fresh geyser
fresh geyser
whole frigate
#

Click on it and show me anything related to it

fresh geyser
whole frigate
#

Hold on

#

So three options

fresh geyser
#

But in order to be able to go to any of these I need to complete the school I want to transition to

whole frigate
#

I dont really know what supsi means

whole frigate
#

?

fresh geyser
fresh geyser
#

its like a college

whole frigate
fresh geyser
#

but I'm thinking about going to IMS which is like a computer science focussed college

whole frigate
#

The only english taught course was information science course with cs subjects

fresh geyser
whole frigate
whole frigate
fresh geyser
whole frigate
#

Deffo not cyber for sure

whole frigate
fresh geyser
whole frigate
#

Know more about subjects they offer before jumping in

whole frigate
#

Send it here if you can

whole frigate
fresh geyser
#

and different subjects are probs Math,english,german,french so on

whole frigate
#

But languages depend on where your school is

fresh geyser
fresh geyser
whole frigate
#

Make sure they teach OS, networking, software, databases, programming languages or something like that and lots of electives

#

Focusing on security

whole frigate
whole frigate
#

For masters you do have cybersecurity focused degrees but thats for later

fresh geyser
#

there are also bachelors with cybersecurity programms that you can choose

fresh geyser
# whole frigate Nicee

This is what the school I want to transition to say on the website: The core of the education is the subject of Informatics, with ten lessons per week. Additionally, you will deepen your knowledge in subjects you are already familiar with (languages, mathematics, etc.) and learn new subjects such as finance and accounting or business and law. You will apply theoretical knowledge practically, work in groups, and learn programming from the ground up. Furthermore, you will be introduced to the fundamentals of systems engineering. You will also learn how to organize yourself and work independently.

#

I don't know why they add finance and accounting

whole frigate
fresh geyser
#

its the college not the bachelor

whole frigate
#

I thought it was part of the program

fresh geyser
fresh geyser
#

That is bachelor tho

whole frigate
#

This is ideal

fresh geyser
whole frigate
#

Just make sure you practice through tryhackme as well regularly

fresh geyser
#

But I'll have to complete college first

whole frigate
fresh geyser
serene umbraBOT
#

Gave +1 Rep to @whole frigate (current: #896 - 5)

fresh geyser
whole frigate
fresh geyser
warm hinge
#

should i get an NCAE accredited bachelors in cybersec at a big college for the networking or would i be able to get away with going to a smaller accredited uni or even a remote one like WGU?

tall frigate
#

Do not choose big college only for networking. This can be achieved more affordably aside from being an enrolled student there.

earnest star
#

WGU is based in Washington State?

#

I'm a senior in highschool, with coding minor experience and and a passion for cyber security and Dev. My math record is very poor. I have only taken geometry and algebra one in highschool as where I am from an engineering class counts as a math and I only need three math credits to graduate HS. What maths do I need to even begin thinking about what degree I want to go for in either sec or dev?

bright spruce
#

I have applied for around 300 jobs from the past year and still haven't found a job as frehher. Most of them asked for a prior experience but I don't know how to get experience without a job. From these 300, I have been selected for interviewed for less than 10 jobs and then rejected eventually for unknown reason. Any person here that can guide me?

#

I am Indian

whole frigate
#

Tailor your resume to the specific jd or role or apply to those jobs in particular. And make sure your resume is formatted well. Another reason might be if you have less experience as a fresher, so do more projects and display that relevant skill on your resume

#

You can do some tryhackme labs and practice with those tools or you can setup your own labs in vm and do it as well

#

Also try to apply as soon as new postings are listed, chances of getting your profile processed is less if the posting is like a week or more older

#

Half of my applications are like that, January is a good month for new opportunities so keep trying and dont give up

bright spruce
#

doing the same

#

all the points following

undone shore
#

@bright spruce @whole frigate What kinda jobs are you applying for?

undone shore
#

Remember: cyber is not an entry level sector, as a general rule. Jobs with zero experience requirements are few and far between

bright spruce
whole frigate
#

And cloud sec roles too

whole frigate
undone shore
#

If you go straight into cyber then SOC is likely to be your best bet, so that's a good start.

whole frigate
#

Soc analyst L1 is probably go to

#

There are some companies offering internships as well

undone shore
#

Any previous IT experience?

wraith flax
bright spruce
whole frigate
#

I got through an interview for a finance company its more or less early career graduate role but if i get that confirmation i can scale up anytime later

whole frigate
#

Did an internship but its not heavy related to cyber although the project we did was related to it

tropic cedar
undone shore
whole frigate
undone shore
whole frigate
#

Did quite a lot of projects during my college that actually sticks with cyber

#

Like firewalls, vulnerabilities scanner and authentication system we built

undone shore
# bright spruce no

All else fails, that's how most people get into cyber. Through something like help desk / software engineering / systems administration, etc

whole frigate
#

Infosec course saved me in prefinal year

wraith flax
whole frigate
#

Idk elsewhere

tropic cedar
undone shore
whole frigate
#

Almost all companies liek that

#

Cope

wraith flax
tropic cedar
#

yup

tropic cedar
whole frigate
#

Might i ask which college?

tropic cedar
whole frigate
#

Ah np

#

So you are looking for cyber roles right?

tropic cedar
tropic cedar
whole frigate
#

Just core cs

tropic cedar
#

core is gold

whole frigate
tropic cedar
#

salute

whole frigate
#

Linkedin pushing new roles

#

I am literally camping 24/7

tropic cedar
whole frigate
tropic cedar
wraith flax
whole frigate
#

Within the one hour i missed scb, zerofox and kpmg pushing their posts

tropic cedar
#

goodluck though, I hope you get a good role soon.

tropic cedar
whole frigate
#

Mone

whole frigate
#

@undone shore you look cracked kind sir🙏🏻

#

Thanks for giving insights

whole frigate
tropic cedar
#

gotta be sure lol while giving compliments but yup, that pentesting job is noice

whole frigate
#

I should give pentest a try after completing the soc path on thm

elfin flame
#

Hi to everyone ,

Does anyone know what’s the situation on the market for entry level jobs ?

elfin flame
#

United Kingdom 🇬🇧

keen tundra
elfin flame
serene umbraBOT
#

Gave +1 Rep to @keen tundra (current: #2 - 2280)

fleet breach
#

What months would you guys say are the best in terms of jobs becoming available ?

stoic cave
fleet breach
tall frigate
# fleet breach If you don’t mind me asking, have you finished your degree at WGU and if so do y...

No im over halfway done though. At this point ive earned A+, Net+, Sec+ though and could already make a career change (which im trying to do by applying to various roles). Theres a best way to do it that involves doing research on your courses and studying them for free before enrolling. If I could go back perhaps I’d really exhaust my free resources before hitting the ground running. People have earned a bachelors thru WGU in 6 months doing that.

fleet breach
fleet breach
serene umbraBOT
#

Gave +1 Rep to @stoic cave (current: #20 - 490)

tall frigate
fleet breach
stoic cave
tall frigate
fleet breach
tall frigate
#

If you’ve already got those certs you really only have a few more to get thru the program mixed with some essays

whole frigate
#

Coz these certs are mad expensive if i was to take it without any vouchers

stoic cave
fleet breach
whole frigate
#

Thats cool

fleet breach
# tall frigate Yes

You also mentioned the career and development center they have there. Have you used it? I wasn’t aware of that and I feel like it’s something super helpful

stoic cave
fleet breach
stoic cave
tall frigate
fleet breach
# stoic cave If by grinding apps you mean the shotgun approach, I don't recommend that. You s...

Yea I’m tailoring each one and refining all my points to best hit each point for the job. Quick question just want some insight. This is my first IT role but previously, I did work in food service for 4 years. Does it still benefit me to keep that role on there or should I get rid of that and make room for some more points in my current role or just another section? Reason being is that I’ve seen it emphasized a few times that customer service and soft skills are important in this field that’s why I’ve kept it on there.

fleet breach
serene umbraBOT
#

Gave +1 Rep to @tall frigate (current: #440 - 13)

storm geyser
tall frigate
dense vigil
#

Does anyone recommend completing the Google Cybersecurity Certification and moving onto CompTIA Security+ After?

tall frigate
dense vigil
#

Yeah to begin with, I'll continue doing courses as I work my way up the ladder

#

I have a basic understanding on general IT, I just need to get my foot through the door tbf

#

alongside the knowledge and learning as I go

storm geyser
serene umbraBOT
#

Gave +1 Rep to @tall frigate (current: #405 - 14)

tall frigate
#

Attach your resume/CV/LOI

storm geyser
tall frigate
#

Yes

storm geyser
#

Will do

dense vigil
#

In general it's always better to liase directly with companies

#

Recruiters will just be the middle man and realistically their looking to claim their COMM from placing you sometimes reducing your pay rate etc

tall frigate
tall frigate
storm geyser
#

Taking a look rn, I'll have to check their company page

tall frigate
#

Absolutely.

dense vigil
#

Easiest way to find them, this is what I used when I was previously applying for roles in a different industry

dense vigil
tall frigate
dense vigil
#

It's always been of interest to me however, I just never managed to study Computer Science or go University

#

I appreciate the help and advise

tall frigate
#

Someones gotta run the cables, replace the cables, install the switches & server racks… install the WAPs/manage the vlans, etc 🤣

#

Help desk too. There’s a few pathways that merge well with Cyber. There’s an analogy for cybersecurity like a homebuilder whose been an electrician or a plumber has more insight into how a home is built/best practices building a home versus a homebuilder whose only focused on laying foundations, or roofing, or drywalling or something.

fleet breach
#

@dense vigil ima also throw in my little bit of advice. If you have a public library or access to one, you can get a library card and it may give you access to udemy for free and there’s so much security related content on there. From certs to tools to scripting all in one place it’s great

tall frigate
tall frigate
fleet breach
tall frigate
tall frigate
fleet breach
dense vigil
serene umbraBOT
#

Gave +1 Rep to @tall frigate (current: #381 - 15)

dense vigil
dense vigil
fleet breach
dense vigil
#

Yeah, I'll check it out for sure

#

Thanks for the help!

tall frigate
# dense vigil Yeah, I planned on including this into my study schedule. Do you have any recs f...

Yes you can study for the CompTIA Trifecta of A+, Net+, Sec+ all through YouTube playlists. I would couple this with practice tests that can be found in various places. Theres a great one on iOS thats just called the name of each exam. There’s a few in particular that I used but the golden sheet is the competencies that CompTIA lists on their website. Find a resource that includes those. Read it and know the acronyms. Use Cisco’s free simulations, those will be very helpful for the actual exams. Find and study as many PBQ based questions as you can on YouTube, even the ones with only a couple thousand views.

storm geyser
#

Rev out here dropping free game

dense vigil
serene umbraBOT
#

Gave +1 Rep to @tall frigate (current: #365 - 16)

tall frigate
tall frigate
serene umbraBOT
#

Gave +1 Rep to @storm geyser (current: #472 - 12)

tall frigate
serene umbraBOT
#

Gave +1 Rep to @fleet breach (current: #1710 - 2)

wraith sandal
#

Hello folks, i was wondering if there are any resources/guides to transition into a pentest/appSec role from software engineering. Almost a decade of experience with backend/fullstack development, cloud, etc.
Thanks.

unkempt osprey
#

Hi guys! I am learning bug bounty and also following the SOC path in try hackme, I would like to know if anyone would like to make a studying group and try to find some bugs!

unkempt osprey
#

thank you 🙂

flint fossil
#

I am trying to start my career in cybersecurity currently I’m using free sites like try hack me and free code camp to learn because by June 2025 I want to enter a bootcamp. but I feel like I could be doing more? Any advice or am I on the right track?

fleet breach
flint fossil
#

So in terms of experience I’m just a baby 😅

whole frigate
#

Holdup

#

The complete step-by-step roadmap to land your first cybersecurity job in 10 months or less.

❤️ Join this channel to get access to perks:
https://www.youtube.com/channel/UCWv7vMbMWH4-V0ZXdmDpPBA/join

✋ Stay connected:

▶ Play video
#

Mosh also teaches python which is insanely good for beginners

#

Check it out

fleet breach
flint fossil
#

Ooo so this is a good way to start?

fleet breach
fleet breach
flint fossil
#

I’ve seen that as well but honestly college is bit too much one my plate right now that’s why I’m considering the bootcamp

whole frigate
#

I have seen some that charge like hefty only to teach nothing

fleet breach
whole frigate
#

I found this really helpful for visual learning

#

For all IT networking concepts

flint fossil
#

Thank you guys I’m still fresh but I hope I’m a year my skills will be up I don’t expect a career right off the bat but I still want to give something others can really see and acknowledge ya know?

whole frigate
#

Do some basic projects as you go

fleet breach
#

^

whole frigate
#

To demonstrate your efforts taken so the recruiters would know

fleet breach
#

I just did a project rn my brain is fried lol

whole frigate
#

You want to learn

whole frigate
fleet breach
# whole frigate Which

Josh Madakor’s cloud SIEM. Setup a VM in the cloud as a honeypot and then collected logs from it to display on a map showing login attempts

flint fossil
#

Where do you guys do these projects? Like what programs do you use?

whole frigate
#

I was gonna try to do that

#

Since i have way less experience with SIEMs might as well do it

fleet breach
#

Azure has changed a lot since he put up the video so it was slightly more difficult but comments do a good job of explaining it

fleet breach
whole frigate
#

If you want to build a system lets say password checker or authentication system, python is the way to go atleast for me. Setting up a web app through flask is easier but you can use any programming language like javascript(html, css for style and visuals) and connect it to backend

#

Other projects like firewall can be done with basic setup requires minimal coding

#

Youtube has so many project ideas you can take notes from and do

flint fossil
#

Oooo these are all good ideas thank y’all because for a sec I was so confused 😭I mean I would go on freecode camps everyday and I just started thm but I felt like I needed more to learn

whole frigate
#

But its just that thm gives good practical knowledge

#

Plus thm’s gamified approach makes learning fun:3

fleet breach
#

Constant learning

whole frigate
#

All that incognito browsing gonna be my downfall

craggy loom
#

Question for all, is being a pentester a good option, from everything i see in the hacking community it seems like such a saturated title, so I simply am unaware if jobs are actually often available to them?
?

tall frigate
tawny linden
#

So if you wanna break into the IT field and don’t really have a lot of IT experience is the SOC analyst the right way to go or is there something else to get started?

wheat quarry
#

that's a good path, so is GRC if you have limited IT experience

wraith sandal
#

Any paths for general Appsec if you have development experience?

wheat quarry
#

so you can do strait appsec (dast, sast) - I so app sec reviews for my org

#

you can help with SDL training, and also DevSecOps, depending on the type of dev you did

#

Knowing the OWASPS for web, api, and mobile would go far

tall frigate
swift kestrel
#

lots of people call it the "beginner role"

#

since you're just using a lot of GUI, and mainly performing high level analysis and maintaining systems

#

lots of splunk

sand mason
#

Question: School vs. Self-Study/Certifications

Hi, I live in Norway. A couple of questions and some info: I’m looking for a way to enter IT. If you have time, take a quick read:
1. I can’t join a regular college because of work, family, etc. I also can’t sell my apartment.
2. I don’t mind spending money on certifications, TryHackMe, etc.
3. I can attend an online college for $37,000 over 3-4 years to get a bachelor’s degree. The program I can enroll in offers this Bachelor’s course: Digital Assurance and Security Management.

I can provide more details, but in short, the focus is on jobs within these roles:
Career Opportunities
After completing the program in Digital Security Management and Supervision, you can work in roles such as:
• Cyber Risk Manager
• Regulatory Compliance Manager
• Security Specialist
• Internal Auditor
• Information Security Manager
• Privacy and Compliance Officer

4.    Alternatively, I could use TryHackMe and earn certifications that are valued in Norway. Based on job openings, it seems Microsoft and Cisco certifications are the most in-demand. I’ve looked at around 40 different cybersecurity job listings. Only two mentioned CompTIA, while the rest prioritized Microsoft and Cisco certifications.

I could also try to find a first-line IT support job that requires minimal knowledge as a starting point.

The problem: 90% of jobs want a college degree or lots of work experience.

Goal/Plan:
I want to get into cybersecurity, specifically a SOC or blue team role.

I talked to a cybersecurity professional here in Norway, and they recommended starting with these certifications:
• AZ-900
• MS-900
• AZ-104
• SC-300

Thanks for reading! If you have any tips, I’d love to hear them.

  • Edit, spell check ++*
fleet sundial
#

Hello

wheat quarry
fleet sundial
#

What job or position in cybersecurity does the Cybersecurity 101 certificate make you competent for?

wheat quarry
#

sort of all around entry level digital security

#

it gives you a little bit of everything, but getting a job will usually require an industry recognized certifciation like CompTIA Security+ or similar, and/or work experience

fleet sundial
#

The CompTIA certificate is expensive though🥲

wheat quarry
fleet sundial
serene umbraBOT
#

Gave +1 Rep to @wheat quarry (current: #510 - 11)

wheat quarry
#

WIth Soc you want to know your tools, interfaces, and how to do reports

quick brook
#

a lot of soc jobs are considered entry level from what ive seen so id assume some dont require you to be super certified right out of the gate

#

at least the jobs i have seen arent like that

wheat quarry
#

yeah A Sec+ or ISC2 CC is usually enough to get past HR

#

then the hiring manager is gonna want to know what experience and knowledge you have

quick brook
#

yea, depending on the job, some ive seen just require bare bones knowledge

wheat quarry
storm geyser
#

Starting to wonder if I should just start applying to jobs instead of these damn internships

wheat quarry
#

@jake or both

quick brook
#

at least for entry level positions, im sure the requirements will change depending on experience level they want

wheat quarry
#

for sure

storm geyser
#

Thats good to know, really

#

I've been getting discouraged by the job market because I feel as though I have a good resume and lots of experience through school and I can't seem to get calls back

wheat quarry
#

I've seen a lot of need for like Linux Sysadmins and DBA's with little to no experience, basic idea of SQL or CLI 😄

storm geyser
#

These internships are so competitive there's 100+ applicants within 24 hours of a job being posted

quick brook
#

ive applied to a few and 1 contacted back but i declined for the programs they wanted me to download

storm geyser
#

How many is a few if you don't mind me asking

#

I'm just trying to get an idea

fleet sundial
#

Wait, doesn’t all that also depend on which country you in?

quick brook
#

i delete the ones that decline from my applied tho, but most likely around 15

wheat quarry
quick brook
wheat quarry
#

Indeed, I only look for remote as well

quick brook
#

i dont live near a city all the ones that pop up for in person is 45+ minutes away

wheat quarry
quick brook
#

the only job that responded back wanted me to install a program where they can anyviewer as a manatory thing

#

on my personal device, like nah im good

wheat quarry
#

yeah, nah, I agree man

quick brook
#

i could care less if they provided me a device but not my personal

wheat quarry
#

we're doing a big BYOD push and in a very stubborn market 😄

#

some don't even have smart phones 😄

quick brook
#

and yet they want us to use their programs on our personal devices

#

job listings are funny too, seen one that wanted you to be clean cut, suit and tie, completely virtual job 😭

wheat quarry
flat sedge
tawny linden
serene umbraBOT
#

Gave +1 Rep to @flat sedge (current: #11 - 797)

flat sedge
#

Any jobs board or job seeking website is going to be a decent enough place to start looking at what is expected for those kinds of roles

candid rock
#

Subject Network+/: Anyone here purchased the MastersCert from CompTIA for the hands on labs and performance based questions (PBQ), if so, was it worth it??? Or is there a better way. Already have Security+. Completed Pre-Security and 50% Cyber Security 101 labs on tryhackme. I think I almost talked my Boss into cross training me for Cyber Security and pivot off the factory floor, to which I was stuck in for 10 years, without any IT experience.

main thorn
#

🇮🇳👍

cinder orbit
cinder orbit
tall frigate
# candid rock Subject Network+/: Anyone here purchased the MastersCert from CompTIA for the ha...

I used certmaster but only bc it came w my school program. Use Ciscos packet tracer or GNS3 to prep for PBQ’s and watch all the YouTube videos you can find about Net+ PBQ example. There was an indian fellow who would always start his videos like “Hello Frens!” His were helpful. Please please use the free cisco simulations and trainings tho it will help the most. There is also a great app on iOS called CompTIA Network+ exam prep or something, has tens of thousands of positive reviews, use that to study for multiple choice & familiarize yourself with terminologies

tall frigate
near junco
#

Hello everyone, I hope my question is not too off-topic for this channel. I recently had a first-round interview for a specialist information security position as a student. I have the second round coming up in a few days, and the interviewer mentioned that I should have a browser ready for some scanning tasks.
I have no idea what kind of questions might come up in the second interview. Has anyone experienced a similar practical test before? The interviewer didn't provide any more details about the practical part, and since it will be a live test, I'm feeling a bit stressed.

whole frigate
#

Atb for your interview

near junco
serene umbraBOT
#

Gave +1 Rep to @tall frigate (current: #294 - 21)

crude kraken
#

Hey there, hope everyone is doing good. I just want to ask something, I'm gonna start my internship in February as a soc analyst, and I want to be the best prepare possible. I know the company work with google cloud so im getting a core fundamentals cert in coursera, the interview was full about networks and it went well so good in that way, I'm just open to advices of things I should know to go there and star my career the best way possible.

modern pelican
#

Hello all ! I was wondering if any of you lovely people could help me out. I'm very new round here and I'm in search of a major career change. Does anyone know of any courses i can enroll in to get a job on help desk ? or even a route into being on the blue team or in this area? Any help would be amazing. Thanks guys and hope you're all having a lovely day! 😄

fleet breach
tribal mortar
#

does anyone have any suggestions on where to take CompTIA exams? Either in person or online? I've heard mixed things regarding taking it remotely

keen tundra
cinder orbit
tribal mortar
#

thanks guys

humble cosmos
tribal mortar
tall frigate
# tribal mortar does anyone have any suggestions on where to take CompTIA exams? Either in perso...

If pearsonvue messes up, which it has for me on multiple exams.. there is a possibility you have to reschedule and retake. Thankfully I’ve never experienced this. Unfortunately since both in person & remote testing uses Pearsons proprietary software it doesn’t really help to go in -as long as- your system meets all requirements and you have no issues with peripherals like webcam or anything. I’ve been in the middle of an exam when ATT was having major outages & it cut my webcam feed. Thankfully I did not have to retake because eventually it corrected but it can be a very stressful experience if something goes wrong..

tribal mortar
broken idol
#

Probably.

tall frigate
broken idol
#

As you can access a web browser on it.

tribal mortar
#

@broken idol do you have any suggestions/preferences for online vs in person

broken idol
#

I've seen some horror stories about people having their exams revoked for stupid reasons.

mystic drum
tall frigate
fleet breach
#

@tall frigate I had a wgu question. Not sure if you’ve taken one yet but those assessments they do, the ones that aren’t cert exams, do they proctor those?

fleet breach
# tall frigate yes they do

Is there only specific times where you’re able to do this? Just asking cuz I work full time and was wondering how that worked

tall frigate
#

It's been months since I've scheduled a WGU proctored exam so I don't know the exact dates and times they're available but I've never had any issues with them.

tribal mortar
#

preciate you guys

humble gull
#

Thoughts on how comptia certs won't carry the same weight because of certs like the ones given by THM, TCM, and HTB that demonstrate practical skill?

#

I've seen multiple cyber recruiters post on linkedin about how these other platforms make much better candidates

tall frigate
# humble gull Thoughts on how comptia certs won't carry the same weight because of certs like ...

Depends what role you’re trying to get into. The certs you named like THM & HTB are relevant to specific industry roles like pentesters, soc analysts, and other higher level positions like that. Those can best be compared to CompTIA’s Sec+. However, if you are trying to get into something more hardware/network oriented then the A+ and Net+ are good. Cisco also has great, nay, the best certifications when it comes to Networks. Their hardware is used in a ton of workplaces. If you’re going for a SOC or pentest position then your THM/HTB certs are more valuable than A+ or Net+ “)

humble gull
#

yeah it seems theres more clear paths popping up for soc analysts which im excited for

#

and pentesters

#

Im glad these platforms are coming out with so much material but I wish they had done it sooner lol

#

I've worked in IT for a couple years now following the path to work up to cybersecurity

#

but if I could've used these platforms years ago i feel like it would have been a way better use of time but hindsight is 20/20

tall frigate
#

To give CompTIA credit regarding Sec+ and what I know about SOC related positions, their certmaster has like 40 labs, some extremely useful for learning bare bones Windows security practices. (They have many labs using a Kali VM too) I’d say it would help more applying for a SysAdmin role where the org uses Windows workstations. There’s a little bit of vulnerability management in Sec+ but they have completely different certifications for that kind of specific stuff. Also something to consider about the A+, some people are just looking for a job at Best Buy on the geeksquad installing/repairing hardware. That cert will certainly (no pun intended) help you land a role doing something like that. “)

jolly wyvern
tall frigate
#

Sorry about that

jolly wyvern
jolly wyvern
tall frigate
jolly wyvern
#

So you got labs to help with Sec+, im jelly

tall frigate
#

Yes but I dont feel they helped with Sec+ but rather prepare you to do practical tasks. They’re completely optional

#

The PBQ’s on CompTIA exams are always so mundane

tall frigate
#

Learn packet tracer

jolly wyvern
#

I didnt like my practice test scores and I thought labs would help, but oh well...

tall frigate
#

Trust blobfingerguns

jolly wyvern
tall frigate
#

Some labs might help but I didnt feel like they did for what I got

#

The labs are very real world scenario oriented & honestly every PBQ is too

jolly wyvern
#

Im going to have to work my way through the certmaster again. My problem is THM and Cysco hold my attention better and are more interesting to me

tall frigate
#

But still extremely unrelated. Funny enough the CompTIA exams grading rubric is confidential, so we don’t know exactly how much the PBQs weigh.

jolly wyvern
tall frigate
jolly wyvern
#

Ive been studing for Sec+ for a while I feel like I should have more understanding. practice exam score was 68% smh

tall frigate
#

PBQ take me between five and 15 minutes that’s one reason to save them for after the multiple-choice another is that you may pick something up from a multiple-choice question that helps you on the PBQ

#

If you have an iOS device, I suggest downloading the security plus app

#

Diversifying your training methods is the best way to prepare for the multiple-choice

tall frigate
#

Have you done domain review for each chapter?

fair pilot
#

Not entirely sure if this is the best place to ask the question but wanted to get the nudge and make sure im looking in the right direction.

Currently studying for the Pentest+ after getting my CySA+ and ISC²:CC this past fall. Doing the Masters in Cybersecurity and Information Assurance at WGU. Wanting to use more hands on with TryHackMe in addition to some other platforms like Udemy, Certmaster, Practice Quizzes/Exams. Especially when listening to videos is more challenging during the day while logged in to work.

My question is would the Jr. Penetration Tester be a good pathway to start with? I have 0 experience in regards to the Pentest+ minus what I've done so far with Udemy and some Certmaster. I'm also curious if there are others who have been in a similar to place as me and what they found useful specifically with TryHackMe.

merry axle
#
TryHackMe

CompTIA PenTest+ is for cybersecurity professionals tasked with penetration testing and vulnerability management. Use this pathway as supporting content and pre-preparation for the CompTIA certification exam. Upon completing this pathway get 10% off the exam.

fair pilot
#

I just added it to start tonight

#

I know it might be tough but my goal is to certify within the next 1-2 months. Life been getting tough with time in the day and in the way to get started sooner and really dig in.

#

I'm also trying hard this go around with THM and utilize this discord more.

merry axle
#

Sweet, also they have a voucher so you’ll be able to save some money on it

#

I’m sure you’ll do great

fair pilot
#

WGU provides "paid for" vouchers since the cert/exam is part of passing the course

#

Thanks man

#

I appreciate it

merry axle
#

Oh nice! That’s awesome

fair pilot
#

Also wanting to start networking on here, more just meet others out there

merry axle
#

Since you have CC take advantage of the ISC2 meetups

#

You’ll find some like minded people in your area

#

Help land a job around you

fair pilot
#

Yeah, I need to do that. I read about it recently but havent taken the time with it

#

I'm pretty happy with my current job as a wfh system admin but the goal is to add certs to my "toolbox". Switched careers last summer from Teaching (retired after 10 years) and jumped right into my current job and has been a great job, experience, learning, etc.

#

I appreciate you taking the time @merry axle

tall frigate
#

Thanks @merry axle

serene umbraBOT
#

Gave +1 Rep to @merry axle (current: #408 - 14)

merry axle
merry axle
warm hinge
#

Anyone here in Web App pentesting/App Sec that I could ask some questions about pathways etc?

keen tundra
warm hinge
#

Inclusive of THM pathways yeah, looking to seek advice on entering the industry and whether my approach is appropriate, e.g. platforms, certs I want to tackle

torn quest
# crude kraken Hey there, hope everyone is doing good. I just want to ask something, I'm gonna ...

i'm currently a security engineer, but started as a security analyst intern. if I had to start over I would've setup a home lab sooner.

For a home lab I would do the following (if resources allow), i'd suggest setting up three VMs one running a Wazuh server, one running a domain controller, and another running a windows workstation (and add in a Linux server if you want some more experience). I'd install the Wazuh agent on the domain controller and windows workstation, then work through this course https://www.youtube.com/watch?v=VXxH4n684HE. When you're going through different attacks, observe how they are logged in the SIEM, then create your own Wazuh rules to try to detect those attacks. Also, the MITRE ATTACK framework is your friend, it's basically a database of different tactics and techniques that adversaries use as well as how to detect (this is very useful for creating SIEM rules) and mitigate them.

Some might argue that this is overkill, but doing all this will more than prepare you for an internship and should prepare you for a soc analyst position. Also, don't worry if the company you're interning for uses a different SIEM than Wazuh, the skills you learn will be transferrable.

#

good luck at your internship!

keen tundra
crude kraken
serene umbraBOT
#

Gave +1 Rep to @torn quest (current: #2617 - 1)

torn quest
crude kraken
# torn quest you're welcome!

I'm literally a script-kiddie listening of Wazuh for the first time, Wazuh is a consider a tool, right? Just to make sure cause looks pretty similar like a Cybersecurity framework

torn quest
crude kraken
serene umbraBOT
#

Gave +1 Rep to @torn quest (current: #1714 - 2)

crude kraken
#

Also thank you for mention the MITRE Attack framework, I'm gonna start to read it.

torn quest
# sand mason Question: School vs. Self-Study/Certifications Hi, I live in Norway. A couple o...

I can't speak to the market in Norway (I don't know enough about the employers, their hiring requirements, what they're looking for, etc), but in the US I broke into cybersecurity two years ago by doing the TryHackMe paths, getting certifications, and setting up a homelab. I then got an online bachelor's degree which helped me advance my career. I suggest following a similar pathway, but would speak to professionals/hiring managers in Norway to see if this would be a good strategy for you.

I started out as a security intern. At that point I had no prior IT experience and only had a high school diploma. However, I was going through community college (2 year college) for an associate's degree in cybersecurity, had completed various TryHackMe pathways, and had the CCNA (I highly suggest getting this certification) and eJPT certifications. I also had a strong Linux foundation (I run it as my main operating system) and decent python knowledge (You can learn both of these through an online course or a community college).

A year later I got my bachelor's degree in Network Engineering and Security at WGU, which helped me switch jobs.

At my old company, I interviewed many candidates for cybersecurity internship positions and often found that people who only had college degrees were less likely to be able to answer technical interview questions and more likely to struggle on the foundational questions. I did notice that those who did TryHackMe pathways and had a home lab did considerably better at answering the interview questions and had a much better grasp on cybersecurity in general. As for certifications, it was a mixed bag, sometimes the candidates knew what they were talking about.

This is the pathway I followed: High School (Linux & Python) > TryHackMe > Community College & Certifications & Homelab > First job > Online Bachelor's Degree > Job Switch

torn quest
torn quest
# torn quest I can't speak to the market in Norway (I don't know enough about the employers, ...

I'm not sure if you have something like this in Norway (or even if you would get the same experience), so this advice may be invalid but it could be useful to people in the US. I'd look into community colleges as a serious option, I am so glad I went to a community college and then did an online degree instead of doing a regular university. The professors for my classes were active in the field and had a lot more experience (20+ year veterans) than professors at regular colleges/universities. the quality of my education was great and I saved a lot more money too

ALSO, don't sleep on internships at small companies. I gained a lot of experience really quickly by working at a small company. I'd prioritize searching for cybersecurity internships over doing something like help desk if your goal is cyber.

calm sentinel
#

Why are alerts from the same incident not related in the queue? cri

#

in SOC simulator

calm sentinel
jolly wyvern
dawn veldt
#

Hello everyone. Any freelancers here? If so, how goes it. Care to explain what you typically offer and how g ya make?

tall frigate
silk robin
#

Good morning. Anyone here has any tips after getting a CompTIA Sec+ ?

rugged delta
silk robin
#

At moment I’m focusing on my soc analyst skills and hacking.

ornate echo
#

I'm probably going to keep studying no matter what, but as someone who once aspired to get into cybersecurity, I often feel like I'll never really be "ready" to get a job. It feels like the bar just keeps rising to be effective/knowledgeable/etc. Does anyone else ever just feel like it's always going to be out of grasp?

humble cosmos
# ornate echo I'm probably going to keep studying no matter what, but as someone who once aspi...

well, you're not alone. A few things I can say that I hope it encourages you.

In this industry, you're always going to have to keep studying no matter what. It's part of the job, it's part of technology evolving a lot. You're just going to have to keep up one way or the other.

But the beauty of that is that you don't have to be perfect at everything in Cybersecurity....in fact...I don't think anyone can. There's no such thing as "I've learned everything there was in Cybersecurity"......and if someone says otherwise, they're full of themselves lol.

Sometimes I do get in that mindset but I quickly realize is wrong.....at times I'm like...dang, I wish I knew as much as this person...or I wish I was at experienced as much as this other person....but I also have strenghts that other people lack and I'm pretty sure you're the same....and that's where you shine.

Security is so broad you can go about a lot of roles that you can do. Choose one category that you're passionate for, keep studying, keep networking along the way, keep knocking on doors and I assure you that you'll see things happen.

Don't get intimidated from the "experts"....everyone is different, everyone has a unique background to how they got into Cybersecurity. Most do that 24/7, and some others do it "good enough" but also focus on other hobbies non-tech related (which is something I always like to suggest to have -- get your mind off of security things).

Anyways, don't give up is the main message here lol.

humble cosmos
# silk robin Good morning. Anyone here has any tips after getting a CompTIA Sec+ ?

tighty up your resume and update your LinkedIn with your cert wins. When I passed mine, I did a post on LinkedIn with the logo and everything, there is a community of recruiters that get to look at things like that, you can get exposed from there.

If you want to tackle another cert while you're focusing on your current skills, I'd recommend the CYSA+.

silk robin
#

@rugged delta @humble cosmos Thank you for the reply’s. 🔥👍

serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #21 - 452)

ornate echo
serene umbraBOT
#

Gave +1 Rep to @humble cosmos (current: #386 - 15)

tall frigate
serene umbraBOT
#

Gave +1 Rep to @humble cosmos (current: #369 - 16)

tall frigate
#

Question to anyone who has been in Networking: I have an interview coming up in about a week for a Network Technician role at a school district. Is there any advice you would give me going into the interview about specific services/processes/tools that may impress the interviewer?

humble cosmos
serene umbraBOT
#

Gave +1 Rep to @humble cosmos (current: #351 - 17)

frozen jewel
serene umbraBOT
#

Gave +1 Rep to @frozen jewel (current: #2619 - 1)

ornate echo
fleet breach
tropic fjord
#

Anyone know of good android apps to learn code and stuff?
Secondly any good areas for practicing CYSA+ I still have access to the labs but reads and practice before I get the courage to do the exam!

keen tundra
cinder orbit
#

freecodecamp modules are actually really good

tropic fjord
#

Amazing I've done the python and have a little bit of experience but sort of wanting to head towards the. Forensics stuff so looking C++ than lower level after that

whole frigate
#

Is IT trainee role a good start into cybersecurity

#

?

#

How is it different from helpdesk or support ?

noble beacon
#

dont know if this is a good place to put my question but i am working on my security plus cert and was wondering if i get that can i get a entry role in cyber security and what kinds i have no IT experence where is best to start

fringe tide
#

Servus!
Does anyone know if the Harvard X CS50 Introduction to Cybersecurity Certificate is worth it's price?

fringe tide
# noble beacon dont know if this is a good place to put my question but i am working on my secu...

Certificates are always a good thing, but contrary to what many people say, it is not a mandatory requirement to get a job in this field.
If you have no previous work experience or practical experience, it would be most likely that you would start in a general IT position that may not be directly related to cybersecurity.
If you have some experience and are convincing, you can of course still get a cybersecurity role right from the start. It all depends on what position it is and what skills are required.
The following link provides a good overview of possible career paths in the field of cybersecurity: https://www.cyberseek.org/pathway.html

Hope this helps 🙂

sick ocean
#

can a cybersecurity certificate replace a bachelor's degree? If so, which ones?

native dragon
serene umbraBOT
#

Gave +1 Rep to @fringe tide (current: #2621 - 1)

stiff oriole
#

Lately I've seen a lot of jobs categorized as "remote" then they ask you if you live near the office. Example: Remote job for a business in salt lake city. Nothing in the job description says on-site or remote other than a tag on Linked in (I know LI isn't the best). Then one of the application questions :Are you comfortable with commuting to the Salt Lake City Utah office"

cinder orbit
# stiff oriole Lately I've seen a lot of jobs categorized as "remote" then they ask you if you ...

its common especially for technician positions to mark them as remote, because you wont work at a central office, but at remote client locations - imo these should be listed as hybrid because that more adequately suggests that being close to a specific area is important.

alternatively, there are also remote positions that some employers have tax benefits for employing in specific regions which can be local, state or regional.

putting remote on a job post that has specific location requirements beyond national( for visa ) is a bit of a bait and switch

stiff oriole
cinder orbit
stiff oriole
#

Right. thank you for the validation. I definitely wanted to make sure it wasn't just me noticing the issue.

cinder orbit
craggy lake
#

hi friends! i'm new to the community and happy to be here! i'm currently gearing up for a security architecture interview -- does anyone happen to have any resources on general security protections from a high-level system design standpoint?

bright cosmos
#

Hello I wanted to ask would you guys recommend getting the CompTIA A+ certificate or skip it and get the network +. Also as a complete beginner how do homelabs help you to become a better candidate in cyber, and what are homelabs exactly also how could i build a homelab any resources that people recommend.

merry axle
#

Since you’re a complete beginner get A+

bright cosmos
#

and any good resources to study

merry axle
#

Professor Messer on YouTube

#

One of my main resources

bright cosmos
#

and how about homelabs, i am trying to build some projects related to cyber, i am a sfotware eng and most of my project are coding based projects

merry axle
#

Just stick with tryhackme and other resources until you get a good understanding of hacking. Then you can practice by launching a virtual machine and hacking that machine. You can find machines that you can hack on https://www.vulnhub.com/

#

If you want a project to work on maybe make automation tools or start a blog documenting your progress

bright cosmos
#

if you dont mind me asking what is a homelab exactly and i was looking over the past messages some people where talking about wazzuh what is that exactly

merry axle
#

Wazuh? The Siem?

bright cosmos
#

i think so

merry axle
#

You don’t need a “home lab” a home lab is really anything with a computer lol

#

It’s a broad term

bright cosmos
#

so a home lab is a VM

merry axle
#

Basically a computer you mess with

#

Can have a virtual machine on it yeah

bright cosmos
#

make sense, also how do the CompTIA certs make u a better candidate compared to other candidates my dad has been stressing me about so i can get it

merry axle
#

The end of your question broke my head

#

But yes the certs can make you a better candidate. But at the end of the day it’s a piece of paper. You need to know the stuff so you can discuss it without a problem

bright cosmos
#

so i would assume it helps build solid foundation in IT

merry axle
#

Well you learn that yourself then take the test to prove you have the knowledge

bright cosmos
#

if you dont mind me asking do you have the CompTIA certs

merry axle
#

I have the Pentest+ yes

bright cosmos
#

do you think it had an impact on you and your knowledge in pentesting

merry axle
#

What do you mean by that?

bright cosmos
#

like did it help you career wise

merry axle
#

I’d say not really lol. Recruiters don’t look for Pentest+

bright cosmos
#

interesting what do recruiters look for then

merry axle
#

They look for one or multiple of the trifecta typically for IT careers

#

Like the A+, Network+, Security+

#

CompTIA wise

bright cosmos
#

make sense well thank you for your help

merry axle
#

No problemo

#

Hope it helps

old girder
cinder orbit
merry axle
warm hinge
#

@keen tundra sorry for the tag, do you know if tryhackme has a general guide for comptia sec+?

keen tundra
# warm hinge <@719261261665402921> sorry for the tag, do you know if tryhackme has a general ...

Not specifically for Sec+ but it has for Pentester+ but it has some overlap 😄 . You can check it out on the link below 😄
https://tryhackme.com/r/path/outline/pentestplus

TryHackMe

CompTIA PenTest+ is for cybersecurity professionals tasked with penetration testing and vulnerability management. Use this pathway as supporting content and pre-preparation for the CompTIA certification exam. Upon completing this pathway get 10% off the exam.

warm hinge
#

Thanks man

cinder orbit
whole frigate
#

Python or any language you can do it

warm hinge
keen tundra
warm hinge
cinder orbit
keen tundra
warm hinge
#

Thank you both very much, sounds like I've got a bit of homework haha

cinder orbit
cinder orbit
warm hinge
#

Will do blobfingerguns

forest hornet
merry axle
unkempt cedar
#

Any insights on which is better for an intermediate cert; Cysa+ or ECTHP? Any reviews about either?

forest hornet
serene umbraBOT
#

Gave +1 Rep to @merry axle (current: #265 - 25)

tall frigate
#

has anyone here been a network tech/admin? I'd like to ask you some questions if you don't mind ")

stark bay
#

can recruiters need someone?? It impossible to get a job right now

keen tundra
polar hinge
#

folks, how long does it take to land a job as jr. soc analyst?

#

and is landing a remote job even possible?

torn quest
#

for those who have transitioned from FTE to contract work, about how many years of experience did you have and what skills did you find the most useful in getting hired for your contract roles?

I'm currently in the US, and am thinking of moving to fully remote (not just WFH) contract work in the mid-long term (4-5 years), advice would be appreciated.

torn quest
torn quest
torn quest
#

the pathway on tryhackme? no. I did the intro to cybersecurity, pre security, jr pentester, complete beginner, web fundamentals, and half of the red team path

#

I was also doing lot of stuff outside of tryhackme though, like getting the CCNA (highly suggest Jeremy's IT lab on YouTube if you're interested) and going through an associate's degree in Cybersecurity

zealous ice
polar hinge
#

and its fun ig

#

worth every penny spent

zealous ice
#

how much u pay

polar hinge
#

i just got it for month, thought i'll finish this course

torn quest
zealous ice
polar hinge
#

if that was be the case there are writeups answering everything would be a piece of cake

#

i think the questions make you look for stuff; instilling familiarity with tool and scenarios

#

also building the habit to look up for something

zealous ice
#

did u tried the premium stuff

polar hinge
#

but the thing is i go a bit fast and tend to forget things so its kinda difficult for me

zealous ice
#

oh

#

is heck the box better than try hack me

pearl scaffold
#

Hey guys some scholarships are asking for any projects Ive worked on in the recent months. I got a month or two before they are due, so what projects should I start on that are cybersec related?

zealous ice
#

try home lab

polar hinge
#

eh that's my pov

zealous ice
#

oh

pine isle
pearl scaffold
#

Yeah thats fine by me

pine isle
#

Or you could also try a hardware project where you can make your own tools as well

pearl scaffold
#

Id prefer doing a coding project, i cant do much to get hardware or make a lab right now

pine isle
#

But as to what the coding projects are idk, im assuming tools? But that abt it.

pearl scaffold
#

I already made a network monitor but it kinda sux

pine isle
#

Sorry if it wasnt too useful

pearl scaffold
#

Its ok

pine isle
#

List what its faults are then make a 2.0

#

And present both as a project to show how you improved your understanding?

zealous ice
#

does cyber secuirty anaylyst need coding?

tall frigate
fringe tide
#

Does anyone have the Havard CS50 Introduction Cybersecurity Certificate and can tell me if it’s worth the money?

fallen estuary
fallen estuary
warm hinge
tall frigate
warm hinge
#

Hm, in my experience the junior positions were a lot more personality based than knowledge based to see if you fit right with the team.
The knowledge questions will be around troubleshooting steps to see how you breakdown problems.
Probably get asked some basic networking questions to confirm you do have an understanding of protocols.
Some questions might be like
"What is the OSI model and give me an example of how it applies to troubleshooting"
Or "Someone says they can't connect to the internet, how would you determine where the problem is?'

serene umbraBOT
#

Gave +1 Rep to @bright quiver (current: #1715 - 2)

zealous ice
#

how good is hands in lab of try hack me?

keen tundra
fathom granite
#

I wish they'd open KotH rooms to anyone to spectate. Be interesting and a good resource for lower skill level people to watch

keen tundra
#

Set you account level to Intermediate in your account settings in order to be able to access KotH

fathom granite
keen tundra
# fathom granite do i still need a spectator invite code?

I don't think , maybe just for some private games 🙂 . Go to your account settings and set Technical Ability level to Intermediate or Advanced to be able to join KotH. You can also verify on the Discord and join #koth and #koth-voice-chat channels 🙂 . Follow instructions from the link below to learn how to verify 🙂 .
https://help.tryhackme.com/en/articles/6495858-discord-how-do-i-verify-my-tryhackme-account

fathom granite
keen tundra
sly obsidian
#

Is it possible to get a Helpdesk Technician role starting from nothing (no degree, no certification yet.. working on my Security+) And if so, are they in-person or online positions and how do I find them 😭

zenith drift
#

Hey guys, do you think it's realistic to get an entry-level cybersecurity position without a degree but with all the necessary certifications? I would like to do a gap year before going to university, so if I get all the certificates now, will it be enough?

broken idol
#

The problem with that idea is if you get certs that expire before you graduate.

pulsar tiger
sly obsidian
vapid kiln
#

is there a channel for resume review?

keen tundra
vapid kiln
#

Finished my associates and some entry level certs, going to school fully online and looking to apply for ft positions while at my current internship

I heard sticking to one page is good? but i have so much stuff to put on a resume, lmk if theres stuff i should delete if i should stick to one page
any any advice is appreciated

pulsar tiger
sly obsidian
#

Thank you

vapid kiln
#

@zenith drift if you are in the united states...or even abroad ig

#

look into WGU, it has an affordable online degree for cyber security and the certs are included in the tuition

#

so the coursework there will train you for the certs, etc...but its not a well known school ig if you care about prestige or something

#

you take all these through out your 4 year degree

tranquil flame
#

Hello everyone,

I’m looking to start my career in Cyber Security and would like to know the best way to get started.

I’m considering enrolling in a 2-year university course. What are your thoughts on this approach?

zenith drift
vapid kiln
#

not sure how pay works for that in other countries

zenith drift
#

I’ve heard that cybersecurity degree doesn’t mean much, and you should just get a CS one instead

vapid kiln
#

some cyber programs are outright shitty or at least most of them are

#

but that one i sent is good

#

my friend is working at capital one now from that school

#

For internships certs matter more than schooling

#

but ft the cs degree can help you have a leg up

#

i went to a shitty online school and have offers from t20 comps

#

so it dont matter

#

for itnbernships not ft

zenith drift
#

Yeah, I think that online education isn’t really a thing for me, and the cost is quite high compared to where I live, but I’ll definitely consider this option 👍

vapid kiln
#

Pick the degree that interests you, i would go comp sci if i was you

#

Get Security+ and skip network+/A+ if you have the fundamental's down already..save that money for CCNA or CEH/OSCP if you decide blue or red team

#

if you can get sec+ freshman year or before you start school..apply for security internships/it support internships

#

i started out with an it support internship, networked internally and moved up to a sec internship

#

tons of internviews from big comps like that with that roadmap

#

just dont burn urself out tho