#cyber-and-careers

1 messages · Page 46 of 1

whole frigate
#

Call myself “founder” on linkedin

rustic atlas
#

Ah rip

#

Hahaha

#

Why not get IT?

#

Help desk

whole frigate
fringe junco
whole frigate
#

I tried soc, but no entry level roles, so i thought why not helpdesk/it support, still no luck

#

Almost all entry level positions need like 2 years exp

whole frigate
whole frigate
merry axle
#

You can expand during your interview. Tailor your answers to boast your qualifications and experience that align with the job

rustic atlas
#

I’m just gonna go for any entry level cyber role

#

And at career fair that’s all I’ll look for

#

My new resume so far, I’m gonna optimize project key words though

#

-need to add GitHub
-I’m leaving education and training low since they don’t really pertain to Cyber

  • will make skills bullet point
#

I wonder if even with a year left I could apply to some entry level Cyber positions for nights and weekends

whole frigate
#

I was using this harvard template for resume but its too hard to fit it into one page, i cant seem to make two columns on latex editor

flat sedge
fringe junco
rustic atlas
#

Okay I’ll narrow it down

#

And I guess not bold, maybe I’ll put a small space between each one

fringe junco
#

Also for the certifications i suggest you put it somewhere up in the page

rustic atlas
#

Yeah that makes sense

#

Should I do “Skills and Certifications”?

fringe junco
#

for skills just put like 2-3 words max. at the end hr is gonna have like a 15 second look at your resume for screening

#

also for the projects

#

just put headings and the date and link them to your GitHub

#

make your resume as clean as possible

flat sedge
# rustic atlas Should I do “Skills and Certifications”?

No. If you are going to include skills, they should be in their own section. Certifications are industry recognized, if you have any, employers will want to know.

Skills are more subjective and arbitrary; it's extremely common for Dunning-Kruger to affect how someone represents themself.

spice plover
#

I have my CYSA+ with minimum help desk experience and still can’t get a job haha 😂

warm hinge
#

yoo people

rustic atlas
warm hinge
#

i have my eng exam tom

rustic atlas
#

I guess worst case I’ll just work as an engineer and keep applying

rustic atlas
#

Right now yeah I have a company I could go to after college that actually fits my major

#

Cybersecurity is what I’m passionate about, I don’t like engineering but it’s better than nothing

warm hinge
rustic atlas
#

It’s around 85-95

warm hinge
rustic atlas
#

My degree isn’t CS, but I’m minoring in it

#

Yeah I should’ve done a different major

#

My degree is electrical systems

warm hinge
warm hinge
rustic atlas
#

Nah I have 1 year left

#

I graduate in 14 months

#

Just gotta cross my fingers and hope I get SOC or any entry cyber role

warm hinge
#

its fine then go for comptia and other exams + work on your skills coz if u dont have a degree it will be harder to get a job

rustic atlas
#

Yeah

#

I’ll complete degree and CySA+

#

I have Sec+

warm hinge
rustic atlas
#

Are you working in cyber right now?

warm hinge
rustic atlas
#

Ah ok

warm hinge
#

mhm

rustic atlas
#

Well good luck

warm hinge
#

all the best to u too man

rustic atlas
#

I’m gonna start applying in a few months and just see if I can get an interview

#

Even though I’ll still be in school

warm hinge
warm hinge
rustic atlas
#

Nah college

#

1 more year of college

warm hinge
#

oh ok

#

same btw

rustic atlas
#

Bet

rustic atlas
#

We will see

warm hinge
rustic atlas
#

No I haven’t

warm hinge
#

u should they are fun ngl

#

i attended my 1st hackathon yesterday

#

man i m telling u if was worth it

rustic atlas
#

Is it good for learning?

#

Interesting okay

warm hinge
rustic atlas
#

I’ll look into it

warm hinge
#

u meet new people with new skills and stuff

#

they are actually eally good for overall development not just technical skills

undone shore
#

Juun, 50% is 1:1 kekw

warm hinge
rigid lake
#

I am going for master in germany this year, anyone know about the cyber job market there?

#

im a fresher

rigid lake
#

can you please elaborate?

warm hinge
#

well so 1st it will be hard to make friends and all the social stuff except from that i dont think there are any better colleges for cybersecurity in germany as compared to us or uk ( west )... i m not trying to demotivate you i am just trying to be helpfull

flat sedge
#

my brain read what you said as 20% admin

rigid lake
#

so ill be focusing on that except only problem will language i guess and also im a fresher

flat sedge
#

to be brutally honest, certifications only matter if the organization has a business requirement for them.

#

Many businesses are private and do not necessarily care about employee certifications, because that business may not have a regulatory or business relationship requirement to have demonstrable competency

undone shore
flat sedge
undone shore
#

Yeah, I'm meaning "matter on an individual level"

flat sedge
#

direct reporting chain managers may be invested your career, but skip level and the business itself will not

undone shore
#

Orgs will be orgs. I don't expect them to care kekw

flat sedge
#

Yep

#

Morals and ethics are for people

rigid lake
#

i have seen many people from even core branches

#

are certificates like OSCP etc wortless...im confused

undone shore
#

At the end of the day, experience matters more than anything else.

#

As Juun said, certs satisfy requirements -- be that for hiring, or assurance.
OSCP is good for both of those things, which is why it's well respected.

#

Personally I found the course material to be useful as well, although I hear differing opinions on that.

rigid lake
#

so like can you tell me, what should be my roadmap for securing a job in cyber, if i am in my masters , and dont have any cyber security exp, just starting

#

although some exp in software dev for 10-12 months

flat sedge
#

If you are a masters graduate from a university in cyber and do not have any work experience, you are going to price yourself out of the lower level jobs you need to get the experience to be a senior or higher.

rigid lake
#

so what should i do?

flat sedge
#

If you are already in the MS program, find ways to learn the practical and contextual aspects of security. Your training and courses are going to focus on the theoretical and modelling parts, so the burden is on you to find ways to make that theory concrete instead of abstract.

rigid lake
#

no im not in master rightnow, but will go in september

#

i will just complete my bachlors in few months

#

which country are you from btw?

flat sedge
#

US

twilit forum
#

Just as a side note some companies get better insuarance if their employees have certificates

flat sedge
#

That goes into the business requirements of demonstrable comptency and expertise

twilit forum
#

I wonder what job i can pull up with 3-4 years of expirience and soon to have sec+ and cysa+

#

I need to upgrade

#

is 4k remote work reasonable 😄 ?

#

i think that is my end goal...anything above that is meaningless for me

wicked breach
#

guys anyone got any good resources to master networking fundamentals? because i feel like that doing thm i don't really get that much of a theory

wicked breach
#

I already did that module, but it didn't gave me really solid fundamentals...

rugged delta
# twilit forum i think that is my end goal...anything above that is meaningless for me

When it comes to remote work, you would have to check with the particular company, however, it would most likely need to be a company within your jurisdiction. It might be possible to do freelance work in some regards, or to participate in things like bug bounties. It's less likely that you would have a paid, international remote work role, due to security, technical and regulatory concerns

twilit forum
#

It really depends on companies structure I think

rugged delta
#

Remote might mean that you are able to work from home while communicating with a local/regional office and they would manage international requirements from that location

twilit forum
#

I guess I could compromise with hybrid...but I really want my next job to hit all the checkboxes...yes i had work from home before but it is not really my goal

#

Would you say maybe DevSecOps are more remote work suitable

rugged delta
loud plinth
#

Hi there. I'm new to the discord, and have been on TryHackMe since college 2 years ago.

Is A+ Certification worth it if its been extremely difficult to get any entry-level Cyber role after graduating with an InfoSec degree?
I'm almost ready for the Core 2 Exam. I'm going to get Network+ and Security+ afterwards.

Are there any courses on TryHackMe specifically anyone would reccomend if I'm looking to increase my chances getting an Entry-Level IT Job first, before starting in Cyber?
(it's kind of a de facto requirement these days, and I'm not sure which city I want to move to so my tech career can kick off- I live in the midwest U.S.).
I'm sure discussing 'how to get into InfoSec with a degree and no experience' would be an interesting and constructive topic to discuss.

wicked breach
loud plinth
#

Even if I'm just a cart attendant at walmart in the meantime?

#

I'm sure we've all been there tho

#

Can certifications alone... I've heard from some that's quite a leap if its been a few years since the degree..

loud plinth
#

Yay!!

#

Now I'll suceed and get that IT Job at a Fiber Internet place or wherever it is I choose!

golden spoke
#

A+ will mostly just get you a help desk or IT support job

#

honestly not sure how useful it would be outside of those

#

i imagine not very useful

cunning badger
#

I would like to pass the compTia a+ exam, has anyone taken it yet? Do you have any idea where to study from?

fickle grove
cunning badger
fickle grove
cunning badger
serene umbraBOT
#

Gave +1 Rep to @fickle grove (current: #12 - 772)

carmine sandal
#

Guys, If you're unsure specifically which part of Cyber you want to go into whats the like... "Best" way to find out? is it just by doing like modules and roadmaps on THM and seeing where you do well vs not so much

carmine sandal
#

Done it before, Just wanted to see if there were other opinions and whatnot too xD But if thats what someone else also gives that ill trust it xD

keen tundra
carmine sandal
#

yeee

#

Just wanted to double check more is all

#

Had multiple attempts with that test over several months difference when done it and got the same thing all 3 times xD

wary frigate
#

Other than CTFs, is there some small work I can do on the Internet to help get my name out there, and potentially figure out what I want to do?

wicked breach
#

contribute in github open source project or maybe do some blogs

warm hinge
#

hey there, for someone who wants to get a remote job easly, what do you advice him to learn, pentesting or bug bounty ?

wicked breach
#

pentesting and bug bounty are really close to each other

#

i would actually suggest to learn pentesting first then specialize in bug bounty

serene umbraBOT
#

Gave +1 Rep to @wicked breach (current: #1791 - 2)

keen tundra
wicked breach
dusk wedge
#

From there you can look for jobs or other things related to the things you like.

wary frigate
#

Is it feasible to assume I could just be contacted for a job if I do something interesting and worthwhile enough?
I might be drawing too much from fiction, but I feel as though the Internet could work as a crucible, where developing skill from ambition and effort could give me a chance to do something that decides my entire future for the better.
At the same time, now that I'm typing it out, it feels like a grift.
Though, I'm still certain that there's more to the world than mundane ideas. Cybersecurity just seems like one of those things that are difficult and technical enough that rising as a force of pure individuality and actualization would have very practical benefits.

dusk wedge
#

On linkedin there are plenty of recruiters that will reach out to people for an "interview" or just a chat to see if they can provide anything, but i dont know how that actually goes since i didnt follow through with any of them.

loud plinth
#

Rulez

tired sequoia
#

it could get you a tech support job

loud plinth
#

That’s what I need first.

#

Good to hear.

#

1 year of tech job plus network+ and security+ equals=

#

entry level cyber? SOC analyst?

static heron
#

Yeah maybe. You can get into enterprise firewall vendor frontline support with half a CCNA and some memorized protocol port numbers and a reasonable troubleshooting flow on a hypothetical scenario. Pivot into professional services or get picked up by a customer to push policy and file tickets for 6 digits, lol. Junior sysadmin stuff too. That still exists right?

I'm sure you're already familiar with the fact that people won't take an infosec degree seriously by itself and why. But this is fairly easy to rectify with the time-honored tactic of paying your dues in the trenches, taking it seriously, and standing out (not hard really, unless all your coworkers are just super moto for some reason)

#

You don't have to be the ultimate infosec wizard or anything, if you do basic stuff like take notes about things you learn, then compile and publish documentation for the benefit of others at work, people will think you're f***ing amazing and eyes will be on you in a good way

plucky spoke
#

hello, I’ve just decided it’s time to move on—my new team members seem like they might be the ones to cause a breach… 😬
I’d love to hear any insights on the current job market in the security space. Also, if anyone has information on global remote opportunities (preferably in the ANZ region), I’d really appreciate it!

rugged delta
# loud plinth entry level cyber? SOC analyst?

You should check out the individual stories section of the blog, consider getting your hands on some of the Tribe of Hackers books and keep building your knowledge and skills. You should check the kinds of roles advertised in your area and see what they're looking for, try and find local cybersec groups, go to conferences, participate in CTFs, make a blog, do writeups, bug bounties or any other opportunities to connect and improve your skills.

The SOC 1 and SOC2 paths will teach you a lot of good theory and give you some practical experience. Also, while CompTIA certs are good for learning theory about a job, and A+, Net+ and Sec+ are good indicators of your interests, a good practical cert like the THM SAL1, the BTL1 or similar SOC certification can demonstrate your ability to do some of the practical things a SOC analyst does

https://tryhackme.com/resources/success-story

TryHackMe

TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

loud plinth
#

Thank you all so much! I will get started and read into all of that!

#

This is a good community to discuss these things.

fair nova
#

Does anyone think a bachelors is a necessity to compete in the job market or no. Stressing out about all of this but i also feel like college and uni is a bit of a scam.

static heron
#

experience > certs > degrees, mostly, kind of

#

But experience and a degree is definitely better than just experience, especially for the initial entry into the hiring process

#

And not everyone involved in hiring has the same views/priorities on this. But if you have to choose between getting hands-on experience and getting a degree only, being able to speak to things you've built, screwed up, and recovered will be preferable

flat sedge
#

Vocational and entry level experiences teach you how to do things, but don't really teach you why. IMO, that's harder to understand but this way makes you more immediately useful to an employer.

The degree teaches you why, but not how. In the short term, the university graduate is less useful but catches up very quickly.

static heron
#

Yeah, you could be right. I know that vocational or self-taught types can excel if they have the drive to find out the why. And I know the university grads have a tendency to be stuck in lofty abstraction (it can be really bad, like almost impossible to have a practical, goal-oriented discussion sometimes). But I don't have any anecdata on how often the uni grads transcend their state vs. the other type

muted holly
#

Anybody here from Digital Forensics field?
Having experience in this domain

loud plinth
# static heron Yeah, you could be right. I know that vocational or self-taught types can excel ...

I was afraid of becoming like that so I decided to take some psychology courses to learn how to speak professionally and truly use ‘active listening’ and use ‘civic engagement tactics’.
The general education brings is useful for the remainder of their lives, but really they should make it so after you’ve completed the sad general education requirements and learn what jobs in society exist in those fields- as well as internships so you can see them for yourself- that should lead to you getting the ‘chosen major’ half of the four year degree, which leads you into entry-level jobs in that field, or even higher. I hope the coming state-by-state diverse educational reforms find some way to fix these issues.

fair vapor
dapper depot
muted holly
dapper depot
#

Cool. I figured I'd throw it out there but it seems you're beyond that point in your learning. Hope you find someone to mentor/assist you.

muted holly
#

I'd Happy to learn from you

dapper depot
#

I don't know what all you could learn from me but feel free to shoot me a dm. Happy to share anything I know 🙂

whole frigate
#

Guys is customer experience role same as helpdesk/ support role?

#

Coz i dont have any other interviews that actually went through, so should i just get this and pivot my way into cyber or look for better jobs?

warm hinge
whole frigate
warm hinge
#

Or if you're into networking, you could start with network admin.

#

If you feel confident that you are a good applicant for the Job then tailor the resume with key words and make it ATS-Friendly

warm hinge
whole frigate
#

Workday auto rejection emails are disheartening

warm hinge
#

It can be a lot frustrating when no response, but a resume with above montioned factors can be a helpful to get callback from recruiters

#

I hope i could help you 🙂

broken idol
#

@dusk gazelle please don't ask for help in this server regarding your challenge.

dusk gazelle
#

sory

fair nova
#

Whats everybody's opinion on western governors university (online university) course for cyber security or computer science? Ive heard a lot about them feom cyber related videos on university but kinda feel like the degrees would be looked down upon especially as i advanced through my career more.

dark fulcrum
#

Hello

onyx gyro
#

.

whole frigate
golden spoke
#

They probably have methods put in place but i think many people would not know how good it actually is

fading panther
# fair nova Whats everybody's opinion on western governors university (online university) co...

I just graduated from WGU with a bachelors in Cybersecurity last week actually. The program gets you multiple certs on top of the bachelors. I got Network+, Sec+, Project+, CySA+, Pentest+ plus all of comptias stackable certs that go along with those (I had A+ going into it). I also got SSCP and have a voucher to take CCSP cert exam for free still. You get a couple other misc certs in there too like linux essentials, and one of the ITIL ones. If you wanna know more ping me in here or shoot me a DM

fading panther
#

and I was able to finish all of that in 9 months too so I could keep the cost down lol

amber sail
#

ive been reading some conflicting stuff lately and was just wondering, is sec+ still a good cert to work towards (as someone with no tech background/infosec degree)? The plan atm is to work towards sec+ then maybe something that demonstrates network knowledge (and maybe some splunk courses too) before setting up projects and stuff to show practical cases of skills but if anyone has better ideas id love to hear them!

dark crest
#

can some help me my browsers got highjakced

warm hinge
warm hinge
fickle grove
warm hinge
fading panther
# merry axle how much did that cost?

Program cost is 4500 per six months before any scholarships or anything. That gets you access to all course materials and vouchers for exams. Only thing you could possibly need to pay for would be if you fail certification exams multiple times and need multiple vouchers (I think you pay after your 3rd fail but I’m not positive because I passed first try every time lol)

tall frigate
ivory swallow
#

Hi everyone. I am looking for a team to join for the new event (Hackfinity Battle) is there any team that might be interested?

ivory swallow
serene umbraBOT
#

Gave +1 Rep to @keen tundra (current: #1 - 3911)

whole frigate
tall frigate
whole frigate
#

😔

#

Tbh it seems to be a good choice rather doing masters in a physical uni

#

Cheaper too

tall frigate
#

Yes I think so too.

#

As long as you are a self starter and are comfortable with remote learning I think it's a great option.

#

Because you don't have a class schedule or anything which is good for some people bad for others, mainly younger people I think.

fading panther
tall frigate
warm hinge
whole frigate
serene umbraBOT
#

Gave +1 Rep to @charred knoll (current: #367 - 17)

serene umbraBOT
#

Gave +1 Rep to @fading panther (current: #2739 - 1)

dusk wedge
#

For resumes i really like canva. Works in the website and has alot of templates

static topaz
#

I have no relevant work experience, a bootcamp, and a sec+. can I get hired as a basic IT tech?

severe arch
#

🚀 Hey everyone!

I'm new to cybersecurity and transitioning from healthcare. I wanted to ask—can I land a job in either offensive or defensive security just by learning from TryHackMe and getting a degree? Or should I also focus on certifications? Will TryHackMe teach me everything I need to know to get hired?

Would love to hear your thoughts and advice! Thanks in advance! 🔥

onyx brook
severe arch
#

@onyx brook I start my first class for my IT degree in April. I started the pre security pathway on tryhackme yesterday. I retired from my first career. Im 39 and ready to embark on this journey. I have all the time in the world.

haughty patio
#

Hello there. This is Serkan!
I'm an ex-maths teacher. Two years ago I had my first cert eJPT. Last month passed the PNPT & today I got my OSCP+

I need some suggestions to land on my first job. Since I was a maths teacher, I have never applied a CS related jobs. It'd be delightful to hear the advices. Thanks in advance!

waxen vortex
#

Hi

rigid holly
#

@haughty patio congratulations 🎉💥💥💥

haughty patio
serene umbraBOT
#

Gave +1 Rep to @rigid holly (current: #2739 - 1)

rigid holly
#

@haughty patio you are welcome looking forward to learn from you

empty kite
rapid valley
#

who can help me w the tut vc?

keen tundra
obsidian robin
#

Hello everyone, I’m a third-year cybersecurity student aiming for a SOC role. However, I’ve noticed that internship opportunities are quite limited. Would it be a good idea to start with a sysadmin role (related to hosting services), or should I wait for a SOC internship?

obsidian robin
#

Thank you for the advice, i have been thinking about that for couple of weeks now. Its just that infosec is such a large field that i didn't really know what to focus on half of the time, even thinking about starting as sysadmin and then maybe in the future i may changed my liking to devops for what ever the reason

serene umbraBOT
#

Gave +1 Rep to @hallow sparrow (current: #56 - 160)

gilded jasper
#

I wanna ask, what are the websites that I can do for real penetration testing using my kali linux legally? Im so tired of doing courses..

keen tundra
gilded jasper
#

other than tryhackme..

#

I mean the commitment is there for tryhackme but then I wanna do like on actual vulnerable legal websites

keen tundra
gilded jasper
#

Just other websites other than tryhackme

keen tundra
gilded jasper
#

does burp academy requires subscription?

keen tundra
warm hinge
gilded jasper
#

thanks

#

Also why is it so hard

#

Im just beginning to learn backk

#

some can get to 25k

warm hinge
warm hinge
gilded jasper
#

is koth a free one?

warm hinge
#

It is free

#

Click the "join a public game" option

warm hinge
#

But it can be challenging

#

I hope I could help you

gilded jasper
gilded jasper
#

Yeah I cannot play korh

#

because Im not an intermediate or advanced

keen tundra
gilded jasper
#

can I play it alone?

lean lion
#

Hello guys, I am new to Ethical hacking field and i have my interest on offensive side.
Can someone please guide me on how should my approach be ( In what order should i do the courses )?

vale falcon
#

Do you have any exp in IT ?

lean lion
#

Currently i am pursuing BE in Computer science , so i would say i know the basics

vale falcon
#

then you can enroll the Jr Penetration tester learning path

#

and if you find it too hard you can always go back to "basics" learning path

lean lion
#

Thank you for your time sir.

rotund pond
#

could anybody

#

may refer as cyber security analyst

tough furnace
#

I applied for many cybersecurity internships but got rejected from all of them. I don't even know why. This is a sad and funny situation 💀

tough furnace
broken idol
tough furnace
#

my friends say there can only be one reason for this. It's the ATS system

broken idol
#

Could be, could also be manual.

tough furnace
#

I hope that maybe I would get some useful feedback haha

polar hinge
#

hey how can someone secure a remote junior soc analyst job? (as a person with 0 experience)

vocal silo
empty kite
#

Hi, can anybody tell me if i get a job in offensive security as a beginner with no experience with only one degree in cyberinvestigation. I finished junior pentesting path and practiced for a month mostly easy challenge. What's my next step ? What job could i get if there is any ? What practical certification useful i could get without needing to be an expert ?

wide mica
#

@empty kite what degree do you have ?

vestal solar
#

Hey everyone, I’m aiming to land my first junior role in cybersecurity and would love any advice on where to start. I’m currently working through the SOC Level 1 path for more hands-on learning and would appreciate suggestions on other steps I can take. I also have the Qualys Certified Specialist and Google Cybersecurity Professional certifications. I'm looking forward to hearing from you all!

gilded jasper
#

Okay so far..I only have the basics down after 3 months of leaving cybersecurity to focus on school, So far I have known how to get ip addresses for websites and networks and how to scan for ports. What should I do next for web pentesting for beginners?

keen tundra
#

@cobalt escarp

tight dew
#

when colleges say they teacher computer science, or cybersecurity what does that mean, because some people have different meanings when saying those terms.

#

MIT college

tight dew
cobalt escarp
#

Hey please don’t advertise here

tidal sedge
#

hi

#

If one wanted to test a website’s defenses—purely academically, of course—where would they even start?

tribal tangle
#

Hello i just got my 1st ever job position: soc analyst i don't have cert or exp i only do THM and others but i have high rank in my local THM rank i think that is why i got offer Thanks for the journey ❤️

unreal temple
#

Hey I've just start this course can anybody tell me it's real after this course we can get a job?

tall frigate
empty kite
# wide mica <@936507255451447297> what degree do you have ?

it's a sort of attestation from college in cyberinvestigation, it is not a bachelor. I also did business management study at college and drop out but continued my study on my side, i have good business and finanacial knowledge with investigation knowledge and now i develop my cybersecurity skill like i said i can do some basic easy ctf. There must have a remote job possible for me with the skill/knowledge i have. I would like a startup where i could manage some hacker and investigator.

tribal tangle
thorny bough
#

Hey I've been specializing in red team modules for the past few months, and now I'm looking at planning for doing certs, what cert would you recommend for my first? The SAL1 looks more blue team than I hoped, but if it gets me through the door I'm happy to complete. I can't see any other certs on the TryHackMe.com website, and OSCP is too expensive for me to do rn. Any recommendations from someone who's been there would be great. I could just save up for OSCP since my main hacking OS is Kali.

thorny bough
#

im comfortable with most easy and medium level rooms, and can usually get through a hard room with concentrated effort

bleak egret
#

hello, would a 3year infosec/ it forensics degree on uni land me a job? or still need certs etc?

thorny bough
#

I also have a BA in communication and many years of linux experience

dusky light
#

At what percentage on TryHackME top users can I start highlighting that and it be a point in my favor?

keen tundra
golden spoke
#

Keep ur grades up and put something on your resume to show personal interest in the field

dusky light
golden spoke
#

Idk about jobs

dusky light
keen tundra
golden spoke
#

Its still a plus

#

Much better than not having it

#

But yea if u dont want to waste your time then dont

keen tundra
dusky light
golden spoke
#

i feel like it would depend on whos hiring

#

in the end if you can answer the interview questions its prob fine

#

i could see why u wouldnt put it though

dusky light
#

I agree, I do think that the interview will usually show weither I actually did the work or if I just copy/pasted answers to the rooms after looking them up

golden spoke
#

i have heard some ppl dont like the top % thing so to play it safe maybe u could just put what u learned there relating to the job

undone shore
# golden spoke Much better than not having it

Disagreed from the technical recruitment side. If I see a CV come through with the percentage on it for anyone other than an intern, it's a pretty good indicator that you've missed the point entirely.

For an internship or a junior role, in lieu of actual experience, putting stuff like the paths you've done is good. As you say, that gives us something to discuss in an interview.

Top x% tells me that:

  1. You're in it for the points (which mean jack shit on a learning platform -- especially one where cheating is rampant), and
  2. You don't understand that the system is extremely easy to game, and there are quite literally tens of thousands of people who can claim to be in the top 1%. Hell, I'm top 1% and I haven't done any THM in about 3 years. It's a meaningless statistic. If you put stock in it then it tells me that you're out of touch with that, which is not a good look.

So, yes, if you have no relevant real world experience, putting what you've learnt is good when applying for a very junior role or internship. Anything more advanced than that you'd be expected to have experience, in which case saying that you do THM as an extracurricular activity is great, but we don't need details.

fading panther
undone shore
fading panther
fading panther
broken idol
fading panther
#

@undone shore @broken idol thank you both very much. I appreciate it

serene umbraBOT
#

Gave +1 Rep to @undone shore (current: #10 - 859)

fossil rampart
#

@undone shore Thanks for the insight, just passing by

serene umbraBOT
#

Gave +1 Rep to @undone shore (current: #10 - 860)

severe arch
#

Hey everyone! I'm new to IT with no prior experience, and I'm currently learning cybersecurity through TryHackMe. I'm wondering if I should start with a help desk role to gain foundational IT experience, or if there are entry-level cybersecurity positions I could aim for directly. Any advice or recommendations would be greatly appreciated!

fringe spade
thorny bough
#

look im in the top 1% of offsec, came to tryhackme after doing some hackthebox. skipped a lot of the pre amble for red team fundamentals

#

had a productive month

#

Ive been deploying raspotify linux servers for speaker systems for a while

#

i started learning with a RBPI 3b board

#

I always did this stuff because i loved it, not just to be paid

broken idol
thorny bough
#

but thats where the best malware hides 🙂

brittle pier
#

Don’t think that helps your case

thorny bough
#

its a joke

broken idol
#

Don't makes jokes like that in this server, illegal and blackhat activities have zero tolerance.

thorny bough
#

i have video links in it

#

im good if you looked

#

there

#

thats the pdf

#

happy, just trying to lighten the mood

#

but now no links to portfolio

#

pick your poison, zero trust, or some trust

broken idol
thorny bough
#

zero tolerance towards jokes? yikes,

broken idol
#

No, black hat/illegal jokes.

#

Please don't take what I say, and make your own narrative of it.

thorny bough
#

so accept your narrative at face value?

#

sounds fascist

#

if you read that right it says i was unionized

broken idol
#

I didn't say "don't make jokes", I said "don't make jokes like that".

Now that's clarified, somebody will help you soon on your resume. 🙂

thorny bough
#

a joke about malware is not black hat, how the hell do you diagnose anything

#

its a regular part of netizen life

broken idol
thorny bough
#

thats not a nice intro

#

hello scrubz im jradx or Jared

broken idol
#

but thats where the best malware hides

Sorry, you're joke gave that impression.

thorny bough
#

i said the joke after, check logs

#

is this the interview?

broken idol
#

Interview for what? kekw

Which area would you like a job?

thorny bough
broken idol
thorny bough
#

Im not firing myself

thorny bough
#

if im going to do this im going to be public about it

#

I contact cyber twitter friends all the time, with my legal name

#

im a open fucking book

#

unorthodox but truthful

merry axle
#

Spicy chat

thorny bough
#

is that too black hat

stone brook
#

Please stop guys. This server is not for arguments. Please go private or DMs

thorny bough
#

Future reference. Saying Hello im restricting your speech as an introduction usually doesnt go well

vagrant solstice
#

Hello guys am Newton from Kenya
Just completed my underrgraduate in IT and want to specialize in cyber security and Ethical hacking

nimble elbow
#

Hey everyone,

I am high school CS, Science, Math teacher and I have been promoting the field of Cyber Security to my students for a few years now. This year it hit me that maybe I should switch into it myself. I am 36, so not too old but not too young.

I have been working on getting my A+, network+ and security+ certs. Unfortunately my degree is in Kinesiology with only a few courses in computer science (enough to teach it).
This summer I was going to try to find a job in a remote IT help desk to get some job experience on my resume.

I was wondering if other people switched into the cybersecurity as a second career and how did they find the transition. What worked and what should be avoided.

gilded jasper
#

Hey are there any best ways for me to revise my cybersecurity knowledge on like notes or something? Because Im not on my laptop all the time and I wish for notes that can be opened on my phone anytime

keen tundra
keen tundra
gilded jasper
warm hinge
#

Whithout copying all of your notes to another ai provider and make it to quiz you

#

Theres can be done i a single window

warm hinge
gilded jasper
#

expensive yes

drowsy wharf
#

hey anyone is preparing for ceh practical exam?

broken idol
junior oar
#

hello everyone. i have a question regarding SAL1 cert. this might be a dumb question but is SAL1 cert accepted by employers worldwide? i live in EU and want to see when in am done with the soc pathway and made the SAL1 test, the employers would actually consider it.

fickle grove
junior oar
#

but the SOC pathway does teach everything that an junior SOC analyst position requires? Right?

fickle grove
junior oar
fickle grove
serene umbraBOT
#

Gave +1 Rep to @fickle grove (current: #12 - 784)

tacit saffron
#

ayo i'm confused between hacking and ai machine learning i wnat to make money as well as enjoy programming like ai but i'm confused what to choose ai or hacking so if i want three votes 1: hacking 2: AI

rugged delta
vagrant solstice
serene umbraBOT
#

Gave +1 Rep to @keen tundra (current: #1 - 4004)

rugged delta
languid prism
#

Just out of curiosity, how can one get their foot in the door for cybersecurity without any certifications? I have over 25 years of experience in IT, but no certifications.

rugged delta
# languid prism Just out of curiosity, how can one get their foot in the door for cybersecurity ...

You can show your experience in security skills through the systems you've been supporting, e.g. operating systems, firewalls, Active Directory, Identity and Access Management, etc. You can develop an understanding of the security environment through Try Hack Me, and reading books/doing courses like Security+ or the many books from publishers like O'Reilly, Wiley, Sybex, No Starch Press and others. Cybersecurity is a broad range of discussion, but you might enjoy learning about things like the SOC, penetration testing, etc., through practicing in the various rooms in THM.

I'd sugest checking out the Tribe of Hackers books by Marcus J. Carey. If you check out the Darknet Diaries podcast episode 83 there's a discussion with Marcus
https://darknetdiaries.com/episode/83/
or
https://www.youtube.com/watch?v=JemCG7y_2kc

Working on the tech side of the NSA doesn't happen overnight. It requires rigorous training, background checks, and a safe and secret place to let Chinese malware run wild.

Visit https://darknetdiaries.com/episode/83 for a list of sources, full transcripts, and to listen to all episodes.

▶ Play video
languid prism
serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #21 - 476)

tranquil robin
#

Hi Guys, I’m Jonny 28 year old and I come Italy, I just finished my high school diploma in computer science and I want to start my Career as an ethical Hacker/ Penetration Test, I was looking for advice from you more experienced in this field, would it be better to start a university study in computer security or study on your own and obtain the certifications needed to work such as COMPTIA Security + etc? Thank you very much guys for your advice 🙏

vague scaffold
#

Hello! I would like some advice from more professional fellas.

Tl;dr I work as an NSA for an MSSP that actually does Network Security Engineer (I think) tasks. While I have learned plenty, feel like job hasn't really taught me what it is to be an NSA and don't know how to move forward.

I've been having concerns about my current job and moving forward.

I don't really have any previous experience in the field, professionally, except a bachelor's degree. It may sound weird for many of you, but I work at an MSSP as a NSA, luckily they were willing to take me in at the time, even though I knew so little. I'm not putting myself down, the standards for hiring are just that low here.

Thing is, this job feels more like a Network Security Engineer... I've taken on some SOC rooms in TryHackMe and its very different from what I do now. I learned a lot at this job anyways, still and always am but it may be time to change things.

I would like to change to another role in Cybersecurity, but I'm afraid this job hasn't really taught me what is to be an NSA and I will potentially fail interviews or jobs for NSA.

I look forward to any help

cursive pendant
#

Does pentesting job required social engineering skills ?
or it's just a redteamer skill

fringe spade
serene umbraBOT
#

Gave +1 Rep to @fringe spade (current: #292 - 23)

static topaz
#

VC anyone? career talk?

queen osprey
#

Hey all, I had a question. I'm French and here we rely a lot on school diplomas. Is it true that in the United States they prefer certifications?

golden spoke
cyan fern
#

Does THM offer internships?

queen osprey
golden spoke
queen osprey
#

Yes, it's the same, weird

mint cloud
#

Hi guys, what digital forensics courses do you recommend? I'm looking for the ones with a practical approach and not just theory.

keen tundra
whole frigate
#

Guys i finally got a job😭😭

#

No more malding on this channel anymore

hearty tide
whole frigate
#

🙏🏻

#

LinkedIn really works

#

I almost lost hope

keen tundra
hearty tide
#

Hey guys ,I got a question is possible for me to get any cybersecurity job without a engineering degree or any other degree

whole frigate
serene umbraBOT
#

Gave +1 Rep to @keen tundra (current: #1 - 4028)

whole frigate
#

Some companies do require a basic degree for filtering but there are opportunities out there that dont.

#

It depends on where you are situated

hearty tide
lone plume
#

After i get the ejpt cert which would be the next best step? Oscp to get a job?

fading panther
tidal panther
whole frigate
tidal panther
lone plume
# dry acorn crtp

Is crtp gonna help me get a job tho? I thought ejpt already had red teaming too in AD?

dry acorn
#

it will help u land a good package

#

and is cheap too

lone plume
dry acorn
#

yea ejpt is good too

#

look for industry req in your country

lone plume
#

Mostly what i see is oscp yk the basic

dry acorn
#

oscp is not basic bro

lone plume
#

I havent really seen ejpt or crtp i think but i want to get those to get better so i can tackle oscp

#

I mean basic as in the basic requirement for alot of jobs yk

dry acorn
#

OSCP best to solve HTB live boxes by yourself first

#

if u can do that then go for it

lone plume
#

I wanna go do that after getting my ejpt yeah

dry acorn
#

also do AD my friend just gave OSCP it had 40% AD

lone plume
#

But is it worth getting the crtp? Or should i jist practice for oscp?

#

Oh fr

#

I might aswell do crtp then since its AD focused

dry acorn
#

yes

lone plume
#

Alright i'll do that then thank you

dry acorn
#

sure

lone plume
#

Did ur friend pass? @dry acorn

dry acorn
#

yes both OSCP and OSCP+

#

he is hreat

#

great*

wintry mesa
#

to enlighten us

whole frigate
lone plume
#

And btw what else did he gey alot cause 40% AD is alot

dry acorn
#

Web i guess

wintry mesa
#

i have some doubt guys.
I am a student and will be 20 this year. I really like cybersecurity and want to get a job in this field. I don't have much knowledge and so far everything I've learned is from self-experience. These days i am doing CTFs to get some knowledge but i want to do something which actually is future proof like cybersecurity engineer or something like that. Can any of you guide what should I do and learn for? (for example learn about this stuff or go for this certificate which may help) I really don't have much knowledge on how to land on a job. Your feedback will be appreciated

whole frigate
#

I had some Aws experience as well so i did some cloud projects as well

wintry mesa
serene umbraBOT
#

Gave +1 Rep to @whole frigate (current: #822 - 6)

whole frigate
wintry mesa
lone plume
dry acorn
lone plume
warm hinge
# wintry mesa i have some doubt guys. I am a student and will be 20 this year. I really like ...

Try to find what are the jobs in the cybersecurity in whole (red teaming, blue teaming)then understand each job's aspects and choose your desired job role. After all of this, make a roadmap, and start form the beginning make a solid foundations in networking, basic programing knowledge in (Python,javascript,html,sql,) shell scripting (bash,powershell), linux,hardwares etc. I believe jobs in cybersecurity are mostly future proof so find what you like and pursue what sparks you where you can be confident,contributed.

#

And continue learning… 😀

wintry mesa
serene umbraBOT
#

Gave +1 Rep to @charred knoll (current: #348 - 18)

warm hinge
#

Happy to help you

wintry mesa
warm hinge
#

IT helpdesk is one of the entry level jobs out there after helpdesk SOC analyst can be a entry level cybersecurity job to break into

wintry mesa
#

ive good knowledge related to programming and coding. Not really expert but yea ive developed some games and programs (just for fun they aren't that bigshot)

warm hinge
#

These factors can only be a plus to get pass the hr door 🚪

wintry mesa
#

I see

wintry mesa
warm hinge
#

Start from helpdesk

flat sedge
flat sedge
#

For entry level, attitude is more important than knowledge; you aren't expected to know things until you get past the junior level. Every role is going to be different though, entry level developer has a higher knowledge barrier than entry level help desk

#

Usually. Help desk for some companies is extremely technical, but that's relatively rare.

serene umbraBOT
#

Gave +1 Rep to @flat sedge (current: #11 - 824)

distant pier
serene umbraBOT
#

Gave +1 Rep to @distant pier (current: #19 - 518)

wintry mesa
#

all feedbacks are very unique and helpful

urban void
harsh anvil
#

Hey guys, I need some advice from the UK based people 🙂
I have a Bachelor's degree in Comuper Engineering and have been working as a Cyber Security Analyst for a year and a half now. I am planning on moving to the UK so I'm wondering how hard would it be for a foreigner to land a job in Cyber Security there? Also as an EU citizen, is it possible to work remotely for an EU based company and live in the UK? I am open for all options so if anyone has some personal experience or anything you can DM me or just share here in case someone else might be having the same questions 🙂

plain vector
broken idol
subtle raptor
#

Hello everyone! I'm slowley picking up skills from THM, but I'm going try to start working in bug bountries soon. Any tips/advice on how to get started?

subtle raptor
serene umbraBOT
#

Gave +1 Rep to @keen tundra (current: #1 - 4037)

harsh anvil
# broken idol Depends on the company, TryHackMe are 100% remote.

So it could work if I find a fully remote company, but that leaves a visa problem then I guess. Since the UK doesn't have a digital nomad visa?
I wouldn't like to spam too much here though since the topic might not completely align with the channel so if anyone has any info on the topic you can DM me 🙂

dusky storm
#

Hello, fellas..
I don´t know if should put it here (correct me if there´s a better channel to send doubts)

So i´ll try to be straight as i can:
I´m a major in IT but have little to no experience in the area.
I´m learning only now to code, but barely got past tutorial hell in python.

I´m focusing on python as a language and doing CISCO and TryhackMe pathways to learn more about cybersec.

My main concerns, and i believe it´s the same for all beginners is:

  • Should i try to first get a job programming and then migrate into cybersec? (it´s currently part of my plan since i don´t have funds to finance the certifications)

  • A friend of mine tipped that the best way to get really good, really fast at programing is to do projects head on, in this case should i do projects focused to cybersecurity or just focus in landing a job programming for webdev/Cloud?

OR

Should i focus immediately on the path i want (SOC for example, and how would i do that?)?

rugged delta
# dusky storm Hello, fellas.. I don´t know if should put it here (correct me if there´s a bett...

You've got the right attitude and direction. I know certifications can be expensive, but they can be something you progress to. And while they can be a stated requirement or something a potential employer desires, the goal of learning the content for a certification should be learning how to apply the concepts for whatever organisations you'd like to work for. It's also good to make it a hobby, and something you do for fun, out of habit (through repetition and exploration) and for the fun of the challenge.

You will eventually get there with the certifications, but as long as your intentions are to be better each day, to learn new things, to practice, to play; you're making progress in the right direction. It's important to have a good base of knowledge on things like networks, operating systems (some Linux and Windows admin stuff), coding (such as the Python you've been doing), and achieving the goals you've set. It's important to make progress, it's also important to take notes, get practice, and give yourself a break.

And yes, as for a job, many people will begin in roles in everything from programming or IT, or even helpdesk or tech support or QA and pursue the skills you need to be great at them. If you enjoy making learning a part of your daily processes and routines, if you get a kick out of breaking things and figuring out how to fix them, then you'll do fine. Make lots of mistakes, take lots of notes, learn from the things that don't do what you expected. And yes, certifications will benefit you, but other activities like progress in THM, your other courses, eventually trying things like CTFs, making a blog, having a home lab; can all benefit you

dusky storm
serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #21 - 477)

rugged delta
# dusky storm thanks man, that´s insightful

There's a lot of information for you to juggle when pursuing something like cybersecurity. It's important to dedicate yourself to your goals, but take your time. Certifications are frequently a requirement by some organisations, but training/certification should be their responsibility/expense in most cases. The thing is, you need to demonstrate to them that you have the skills they require, so you may need to fork out for some level of training/certification yourself to get recognised, or to meet their requirements to demonstrate that you've learned certain things.

And frequently, the certification is a stepping stone, or one of many. Being active in your learning, taking advantage of things like the daily streaks or certificates from the learning paths on THM, the little indicators of progress when you're getting flags, completing rooms, doing lessons on your Cisco course and completing chapters, etc... One step at a time and you'll see it add up

plain vector
broken idol
#

Ah it didn't work.

runic blade
#

how do i connect with people in cyber industry as a cyber student?

rugged delta
runic blade
#

oh i thought i had an account already

rugged delta
runic blade
#

ohhh Okay i was looking for the token on discord lol

#

did i do it?

rugged delta
runic blade
#

sweet

#

recommended channel to make connections?

#

mentor wise, path wise

rugged delta
runic blade
#

bet thx

spare canyon
#

Apologies if this is the wrong channel but could any cyber professionals speak to whether a networking class or cloud computing class would be more beneficial to take in terms of getting hired? I’m trying to choose the last elective for my degree.

carmine sandal
#

Question. Say you are starting from the VERY Start basically. To Get into Cyber Sec How long would you estimate if say everything goes perfectly right, Like you do training/certs > Help desk > Specific job in Cyber

#

Okay for the sake of simplicity Lets say, Incident Response

#

Just casue thats what ive been reccomended from the aptitude tests off 3 sites xD

#

Geographical Is Australia.

#

Cool thank you 🙂 Just cause yeah had a start on THM a year ago gotr stopped due to life stuff and now back to getting into cyber so Hopefully ill be able to do some stuff. Helpdesk realistically that hard to get into or just like a retail esc level of ease to get

#

Ohhh Thats why the Cert is there. Been wondering and asking about that and no one really gave me a clear answer lol

#

Thats fair. I am starter basically So i'll probs just go through the roadmap on THM and then go from there i guess, once finish that do the certs

#

True. And then atleast even if i fail and they do say hey look will give you a shot A. cool got a job but also B. if extra lucky they might front up for the cert lol

#

Interesting. Yeah cause i know for a fact my brains like Oh no i have to go Fast to make up for lost time but yeah that kinda also just reinforces that idea of. Take it slow, Make sure i understand everything and to take notes

#

yeah valid. Look either way commitment is fine on my end been in the same job basically for 8 years through 2 different places of the some company lmfao

#

albeit god i cant stand my job anymore lmfao people just are bleh xD

pastel plank
#

hello, looking to transition into cyber sec from a software development career (5+ years) ... any particular order for certs to go for? any other advice is also greatly appreciated

tall frigate
hybrid egret
#

Quick advice I’m net THM haven’t used any other resources started this one recently shall I smash all the labs before I progress to something else I’m a noob btw

hot bear
#

Hello ,
I recently switched majors from general cs to focusing more on cybersecurity, however the class load now projects me graduating by 2029. I’ve been doing school part time for about 5 years now and working full time. Does anyone have any recommendations on what to do to speed up my process so I can begin working in the field? Is there any certificate that would allow me to begin entry level work?

modest mauve
#

Does the SAL 1 cert help in any way towards the CySA+ cert? TIA

vagrant warren
# keen tundra Complete Cyber101 path before moving to challenges 🙂 <https://tryhackme.com/pat...

Sorry to bother you. Is there a thread that covers the must have certs to get a look in a jobs for newbies? I see some jobs posted want no end of experience and certs for a pretty low wage. That said in my many deep and meaningful career discussions with ChatGPT, they seem to be under the impression I could smash out CompTIA Sec+ and walk into a Junior Pen Tester Role or take the ISO27001 Lead Auditor training and exam and using my historical experience and that cert to move into a GRC role. Is there somewhere on this area that answers what are probably painful questions for those of you who have lived and breathed cyber for a while?

keen tundra
chrome spire
#

Hows the job market

whole frigate
nocturne yacht
#

hey, I have programming experience and I'm interested in cybersecurity. so I'd appreciate any advice, how is the job market? how long does it generally take for someone putting the hours learning, to hit an entry job ?

shut zinc
#

Is the comptia pentest+ a certification for learning or for impressing hiring managers?

pastel plank
radiant cave
#

It really depends on the position you are seeking

#

Pentest is specific so if you want a pentest job then it’d be beneficial

flat sedge
radiant cave
#

^ Good point as well, try finding startups. Demonstrating your knowledge is also key so find pentest projects you can add to a portfolio

flat sedge
#

How would you add a pentest project to a portfolio?

radiant cave
#

Say you score a bunch of bug bounty's around vulnerabilities, you can record or document the process. Adding that shows you understand how to do the job you're applying for, you'll still be tested but still.

golden spoke
#

the basic comptia ones will prob give u a chance to get into an entry role

#

but honestly im not sure if they do much beyond that

radiant cave
golden spoke
#

like i feel like they matter very little past your first job

#

unless its a slightly more advanced one

#

like ccna for ex

radiant cave
#

Well they show that you are continuing to learn, and grow which is what most companies want

golden spoke
#

like ik for comptia a+ once u get that help desk experience its pretty useless

#

and for comptia network+ u might as well get ccna after first job which is better

radiant cave
#

Nobody really knows if the amount of certificates you have impact your first job, except for the people hiring you.

#

I think a lot of people focus on certs and experience but if you dont have the personality the company is looking for then shrug

golden spoke
#

both are important yea

#

need to interview prep

radiant cave
golden spoke
#

nah

#

i just mean that interview prep is important

#

i personally just used the practice video recording ones

flat sedge
flat sedge
radiant cave
#

And remember you dont always have to check all the listed requirements

golden spoke
#

and i heard security is not a beginner field as well

#

im sure SOC analyst is beginner friendly

#

thats the only one i know

radiant cave
#

Comparative to other common tech fields

chrome spire
#

You think cybersec salaries will increase in the coming years?

radiant cave
#

here ya go

fringe spade
trail tartan
#

Hlo everyone!
I'm new to this sector can any one tell me is this good for future means is there much scope with good amount of salary??

kindred prairie
#

I am currently pursuing the CompTIA A+ certification and plan to follow it up with Network+ and Security+. Additionally, I am considering learning Python to strengthen my programming skills (which have long faded since community college). My goal is to secure an entry-level IT position while continuing to build my expertise. After completing the CompTIA certifications, I intend to focus on hands-on learning platforms like TryHackMe and HackTheBox, as well as preparing for the OSCP (Offensive Security Certified Professional) certification.
Does this sound like a solid path for someone aspiring to become a red team cybersecurity professional?

clear owl
#

Hi, I'm holding 2.5 years of experience as cyber security engineer, currently looking for new opportunities. It would be gratefull if anyone could provide any reference for any current open positions. I have worked in Anti-phishing, Anti-spam and Threat Hunting projects, I have CEH certification from EC-Council, Currently preparing to get SOC and ComptIA Security+ certifications.

clear owl
chrome spire
chrome spire
#

But if your up for the challenge def go for the ccna instead

tall frigate
nocturne yacht
#

Hi ! , I'm interested in cybersecurity but what turned out from my search, is that cybersecurity isn't an entry job and the best way to pursue it, is by starting from an IT help desk or similar positions.
so my question now, how can maximize the chance of hitting that goal ( mainly remotely or getting a visa ) so I can work while learning more in cybersecurity and being able to afford certifications and get experience at the same time

rugged delta
# nocturne yacht Hi ! , I'm interested in cybersecurity but what turned out from my search, is th...

Yes it's true that a lot of people in the industry spend a while starting in jobs like help desk or tech support or another area of IT as they progress. You would be expected to learn a lot of IT-based skills, such as Windows/Linux administration, perhaps some coding (with perhaps Bash or Python to start), and how networks operate. You can learn a lot of these skills through THM as you progress, and build up your cybersecurity knowledge as you go. As you gain skills and confidence, you can pursue certifications related to the areas you wish to work in.

Most people entering cybersec would start in a SOC, after acquiring the necessary skills. The THM SOC Level 1 and 2 paths on THM provide a good introduction to the skills you'll need. Certifications like the new SAL1 from THM, the BTL1, etc., can be beneficial in demonstrating your skills. You should look at roles in the places you would like to work and see what qualifications they're requesting for particular roles. Cybersecurity requires a broad range of skills and hopefully you'll develop them here as you progress

serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #21 - 482)

tranquil sparrow
#

Good evening. Just a random beginner seeking some tips or guidance.

I have almost finished the JR penetration tester path on THM. Of course with all previous paths for networking and pre security, yet i feel totally lost and i need to get started with bug hunting soon.

Question is: do i really need to master a programming language to begin with? If yes, what's the best language to boost my start.

And i didn't go to any tech university, is there any background that i need to learn besides the THM path? Like cs50 or something or am i good to go?

Thanks in advance.

hardy harbor
#

Hey everyone. Looking for some career advice here. A pentest company is offering an opportunity to join their team with the condition that I need to complete one of the following certs by EOY: OSCP, eCPPT or CPTS.
What would you suggest, in terms on time, cost and difficulty, considering that I have little to none experience in Pentest.

hardy harbor
worldly whale
#

Cpts is good knowledge wise

#

And eCPPT is pretty shit nowadays

hardy harbor
serene umbraBOT
#

Gave +1 Rep to @worldly whale (current: #824 - 6)

rapid pecan
#

can i get job in this without any certification

worldly whale
fringe spade
tall frigate
kindred prairie
tall frigate
# kindred prairie No. I have an associates and I am in the US.

I highly, highly, recommend you look into the cybersecurity program at WGU. Im enrolled, have completed much of the coursework (A+, Net+, Sec+ certified, they pay for 2 vouchers per exam and you get access to certmaster which is like half the cost of 6months of WGU tuition if you were to go through compTIA) and have landed a job in networking.

kindred prairie
serene umbraBOT
#

Gave +1 Rep to @tall frigate (current: #257 - 28)

tall frigate
fringe spade
#

Hi, in cybersecurity/pentesting having deep programming knowledge is not really a requirement, although having some basic programming skills, like the ability to read and debug code is definitely mandatory, but you don't have to be able to write advanced programs.

fading panther
# kindred prairie Thanks. I’ll look into it.

I also just graduated from WGU's cybersecurity program. The certmaster material is dense and not the easiest to follow sometimes imo but they also give access to udemy training as well as a couple of different books to review from

kindred prairie
serene umbraBOT
#

Gave +1 Rep to @fading panther (current: #1811 - 2)

fading panther
#

No problem, I'm also available to DM if you have any other questions

tranquil sparrow
serene umbraBOT
#

Gave +1 Rep to @fringe spade (current: #288 - 24)

fringe spade
tranquil sparrow
empty sigil
#

Hey everyone!

My name is Juan Rendón, and I’m an Ecuadorian cybersecurity professional currently based in Seattle, WA. I recently completed my Cybersecurity Technologist degree, earned the Google Cybersecurity Certificate, and I’m now working towards the Security+ certification.

Before transitioning into tech, I spent over a decade in public administration as an analyst and assistant, managing compliance, documentation, and operational processes. Moving to the U.S. pushed me to adapt quickly, working in high-paced hospitality roles in New York City and later relocating to the Seattle area.

Now, I’m actively looking for my first opportunity in tech, ideally in cybersecurity, SOC analysis.

I’m passionate about security, problem-solving, and continuous learning, and I’m here to connect, learn, and contribute to the community. If you have any advice, job leads, or just want to chat about cybersecurity, feel free to reach out!

Looking forward to engaging with you all!

tranquil sparrow
# keen tundra JS and python 🙂

Thank you for your advice. But the question still is the same: when to know where to stop? I will be learning python first as everyone is recommending it. But i am not a fan of programming, so i wanna know what's a good point to stop programming and keep focusing on other aspects of pentesting.

Like, is learning oop enough? Also, is there a specific resource you would suggest or should i just do my typical googling 😅

serene umbraBOT
#

Gave +1 Rep to @keen tundra (current: #1 - 4102)

keen tundra
tranquil sparrow
serene umbraBOT
#

Gave +1 Rep to @keen tundra (current: #1 - 4105)

warm hinge
#

I am wondering if my experience might help people here

#

I would love to help people remove barriers

#

I feel that I am experienced yet, that also comes with some jaded behaviour, so am willing to listen also

#

a two way street 😄

lone plume
#

anyone here done cpts?

left hatch
#

Hey Guys anyone here got knowledge about CTF's, if yes Can you guide me right now to setup and practice for CTF's in TryHackme

rugged delta
mystic cosmos
#

Hey everyone!
I wanted to share a bit about my journey and get some advice from those who’ve been in the field longer.

I’m currently working in a NOC role, but I’ve realized that it’s not what I truly enjoy. I’m more passionate about network engineering and security, so I’ve been grinding on my own—studying CCNP ENCOR, doing labs on Cisco DevNet Sandbox, and practicing Linux.

The challenge I’m facing is that I don’t have mentorship or hands-on experience in engineering tasks, and most companies here in my city seem to focus on NOC rather than deep networking or security roles. I also have university commitments, so balancing everything is tough.

Right now, I’m exploring ways to transition into a proper network engineering role—I’ve been refining my resume, looking at job listings, and even considering cold emails to companies. But I want to make sure I’m on the right track and not wasting time.

I’d really appreciate any insights or personal experiences you can share. Thanks a lot in advance!

rugged delta
# mystic cosmos Hey everyone! I wanted to share a bit about my journey and get some advice from ...

It sounds like you're making some good progress. If you want to be taken seriously as a network engineer, the Cisco certifications are widely recognised. Working in a NOC can open opportunities to work on a lot of the technologies in a network, from switches/routers/firewalls to servers, virtualisation and cloud platforms. While their certs are very much focused on Cisco's own products, there is a lot of knowledge of open/standard technologies which you might come across. Learning some coding skills would help where automation is widespread.

When it comes to job applications, look at the skills/certifications being requiested, and use an ATS checker to check your resume/cv against the role. As you are working in a NOC, it would be worth your while seeing what training/certification support/opportunities your employer provides and taking full advantage of it

mystic cosmos
# rugged delta It sounds like you're making some good progress. If you want to be taken serious...

I totally understood your perspective but actually my current role is in an isp and it is not an international one. So the actual operations they are performing are at layer2 and they have a separate noc for layer 3 operations. Also I am not getting much mentorship and attention there because everyone is most of the time chilling with their friends or basically busy in completing their rotational shifts which includes resolving tickets about connectivity issues which include (as far I see) vlan, ports, etherchannel, svi configs. So I feel like even after I spend much time there and learn that then tbh it wouldn't be a much bigger deal because these stuff can't fullfill my thirst for security side learning which is the sole reason I started with networking. The only thing keeping me back from resigning is that I have no experience if I leave this and then the hurdles would much increase in finding a more engineering suitable job. That's the reason I am grinding ccnp atm and also I have learnt Python at my uni so just have to look some more in network automation. I must try to grab an enterprise network engineering role where I would be able to do some hands on stuff and play with security including ids ips firewalls and polishing my documentation skills. Now enterprises don't post these critical jobs on social sites so that's why I was approaching them through cold emails. And tbh this time I would be specifically applying to multinational firms and banking sectors because I hope they must not have noc roles disguised in network engineering lol.

winter parcel
# nocturne yacht Hi ! , I'm interested in cybersecurity but what turned out from my search, is th...

honestly I spent almost one year in IT support and is the job where I learned the less. depends on your experience, IT helpdesk would be just plug cables to screen and push trolleys. best case for me was run a script prepared by someone else that you don't have even the possibility to see.
So I hope to get some skills from THM while it seems more a platform for someone that already is a FullStack Developer with some knowledge of data.

whole lynx
#

I want to do something in my life idk how to do it .my dream is to me a ethical hacker but there no roadmap for me
I m doing bachelor is CS have basic knowledge of Linux web programming languages .Is there is anyone how show me path to the cyber security
I know All the basics

merry blade
#

search networkchuck on youtube, he made a video on that

amber sail
#

Hey everyone, as it stands I was planning on working towards the sec+ cert, but was taking a look at the cybersecurity sub Reddit and saw this roadmap mentioned: https://roadmap.sh/cyber-security

This suggests getting an understanding of operating systems, hardware, etc, which I do have a decent understanding of, but probably not to the full extent that say would be present in A+.

I was just wondering, as someone with no IT background if it's more worth it go for A+ and Sec+ or stick with sec+ and skip A+ and just learn as I go kind of thing

roadmap.sh

Community driven, articles, resources, guides, interview questions, quizzes for cyber security. Learn to become a modern Cyber Security Expert by following the steps, skills, resources and guides listed in this roadmap.

radiant cave
# amber sail Hey everyone, as it stands I was planning on working towards the sec+ cert, but ...

A learning path I’ve come across is learning either software or full stack development before fully going into cybersecurity. This gives you the upper hand in creating applications or websites that you’ll like be protecting in a cybersecurity job. You’ll be able to security test your own projects, etc. Having that experience can also open more job opportunities or better pay if you only seek cybersecurity jobs.

#

tldr is you’ll find a lot of value in doing development prior to cybersec certifications etc

amber sail
serene umbraBOT
#

Gave +1 Rep to @radiant cave (current: #2762 - 1)

radiant cave
#

Codecademy is another option in the freecodecamp style of learning, but personally I don't like them as they are very fremium; looks like a lot of courses are free then you get stuck with paywalls, etc.

#

But if you're end goal is strictly cybersec I wouldn't spend any money to learn simple development stuff and just go with freecodecamp; but if you want the certifications for those fields too why not

#

oh well yea you get free certifications with codecamp so there ya go

amber sail
serene umbraBOT
#

Gave +1 Rep to @radiant cave (current: #1816 - 2)

radiant cave
gloomy prism
#

Is anyone here a network engineer or an entry-level network engineer? I'd like to ask some questions about the job. Is that ok?

tall frigate
gloomy prism
#

Since i see a lot of people online say Certs are more important.

tall frigate
# gloomy prism Will a 2-year degree be enough to get a networking job or do I need a cert along...

Certs help the entry process a lot, when hiring managers and recruiters are reviewing resumes, but it’s possible to get a networking job without one. Though, your chances of getting an interview are much slimmer without something to demonstrate your competency in networking. A CCNA will help, absolutely, many organizations use cisco hardware and software for their networking systems. You should probably wait to apply for networking roles until you have the CCNA, unless you’re in dire need of a networking job right now and don’t mind having lower chances of getting a foot in the door. If you really sell yourself on your resume and kill the interview you could get one without a cert, but you have to show that HM/recruiter you’re knowledgeable on your resume.

gloomy prism
tall frigate
# gloomy prism If you don't mind me asking what do you do in a networking job is it a lot of ha...

From what I know and where I’m at, it depends on your role and what your organization does. In my org there are network techs and network engineers, (then the managerial roles) generally techs are more physical oriented and engineering are more software/logic oriented. For my organization its the techs that touch the hardware/wires, while the engineers monitor the overall topology of the network and much more i dont know about. For example, it will be pretty standard at any organization to be hands on with switches, routers, WAP’s, ethernet cables, IDF’s, MDF’s, protocol analyzers, tools to diagnose/locate said hardware, etc.

amber sail
strange crypt
#

i want to pursue my carrer in the field of cybersecurity can any one help me for a guidence from where should i start

serene umbraBOT
#

Gave +1 Rep to @keen tundra (current: #1 - 4136)

jagged abyss
#

Off Sec and Pen Test Intern role, they ask for how much salary; what would y'all say?

fringe spade
dawn walrus
#

Hey everyone! 👋
I’m Aadel, from Belgium 🇧🇪. Currently doing my master’s at Université Libre de Bruxelles, yesturday we had our first intro class to cyber.

While exploring the field a bit, I came across the Threat Intelligence Analyst role. At first, it kinda feels like a data analyst but focused on cyber threats? Not sure if I’m off here. Also, I keep seeing roles like SOC Analyst, Cybersecurity Analyst, and Threat Intel Analyst but honestly, I’m a bit confused about how they’re different.

Anyone here working in those fields who could shed some light? Would really appreciate it! and any people from Belgium around? Would be cool to connect 🇧🇪

Thanks a lot 🙏

fallow basalt
#

hi all i am from pakistan

tall frigate
#

i know someone in Okara

gilded jasper
#

@tall frigate this is what they offer in the core study area

tall frigate
#

because if you wanted a degree, you would need to go to another university after that.

#

im researching the gmi diploma rn

gilded jasper
tall frigate
gilded jasper
#

have you researched about it?

tall frigate
left hatch
#

I am competing a CTF right now anyone willing to help and join

broken idol
#

I don't think that's THM

rugged delta
# mystic cosmos I totally understood your perspective but actually my current role is in an isp ...

I understand where you're coming from. I once worked for a telecoms company where we were dealing with mostly the layer 2 anc connectivity for their major clientls.cables and fibres from NY to London to anywhere in the world and local links too. It was a lot of fun making connections there though and the tech I got to see was during a time of rapid advancement in networks and server tech too. Always projects to be finding out about and working your way into if you could... While you're in that job, try to maintain it. It's much easier to get a job if you're already working

vapid thunder
#

Hey guys, may sound like a stupid question,

#

but how much would CTFs actually like, help me getting a job in this field?

#

Does doing a lot of them and achieving good results mean a lot to employers?

fresh herald
#

To people that have a job in cybersecurity would y'all go to a university for studying cybersecurity or stick to community college? Rn I'm trying to decide between UTSA and ACC

rugged delta
# vapid thunder Does doing a lot of them and achieving good results mean a lot to employers?

Doing CTFs can improve your abilities to use your pentesting skills, but they tend to be quite game-based a lot of the time. They can be serious challenges, and a lot of fun. And if you score well, it can demonstrate to a potential emploer your engagement with developing your skillset. However, CTFs differ from pentesting, in that the objective of CTFs is to complete the challenges outlined. The objective of a pentest is to produce a report based on finding and testing all the vulnerabilities within a scope. Being able to gain and elevate access is a desirable outcome, but the objective is to be able to explain your findings to a client so they can reproduce them and then rectify the issues as per their processes.

Many employers who integrate cybersecurity into their business practices do encourage partaking in CTFs and other training, such as THM and may suggest resources like PicoCTF, Pwn.College, HackerOne's Hacker101 or PortSwigger Academy; to learn good hacking practices, and to be more effective in ethical hacking, CTFs, Bug Bounties and pentesting as your skills grow (these 4 are free resources provided by their academic and enterprise creators)

While partaking in CTFs, it's not always necessary to mention your achievements in detail on your cv/resume. And usually you would include it in a professional development or hobbies/pastimes section or mention and offer to discuss it in an interview

rugged delta
# vapid thunder Does doing a lot of them and achieving good results mean a lot to employers?

You'll learn a lot by learning how to get better at CTFs, and this video is probably good inspiration for why you should. This is what led to the formation of PicoCTF in Carnegie Mellon University
https://www.youtube.com/watch?v=6vj96QetfTg&t=218s

Presenter: David Brumley, CEO, ForAllSecure

Do you want to know how to build a top-ranked competitive hacking team? It's all about the system. In sports, we understand systems that coaches can use to build a system for identifying talent, recruiting them, training them up, and competing in big games. Learn our proven system for building an elit...

▶ Play video
vapid thunder
#

Thank you so much

vapid thunder
#

Would it be like, wasting my time as a cybersec noob?

balmy tangle
#

how's today's job market treating everyone 😄

rugged delta
# vapid thunder One more little question, what exactly is like, the skill ceiling? For instance,...

So, as an academic going into the professional world with a masters in computing, you'd be expected to take on the same kind of low paid entry level jobs as most professionals in a lot of scenarios, or else go into programming or IT for a little while to gain experience. With a masters it's expected you wouldn't want to stay in a junior position so your goals would likely be gaining skills and promotion to a more prominent role (something quite achievable in a few years if you work at it). A company would probably want you to stay on a promotion track if they're providing training resources for you but your direction would need to align with theirs.

As for certifications, there are a number of them you might be expected to acquire, either by your own hand or aligned with an organisation's goals. They might, for instance expect you to have Linux/Windows/Networking/basic security skills/knowledge, maybe hold the Security+ with ambitions for OSCP/CISA/CISM/CISSP at some point in your future. Having an academic qualification reduces the typical 5 year path for CISSP to 4 years. You should really look at roles in your locality and see the skillsets and qualifications they would like you to pursue, and see if that aligns with where you want to be in a couple of years.

For instance, when you do get a cybersecurity role, it'll most likely be in a SOC environment, and doing things like the relevant THM Learning Paths and certifications (SAL1 just released recently), or perhaps the BTL1, another well recognised SOC certification. While it's typically expected that an employer should be paying for your training/certifications, sometimes you'll need to take the first steps yourself (the price of the BTL2 is more focused on what an employer can afford, for instance)

soft meadow
#

Hey folks! Is there anyone here who was a developer for many years and then started working with offensive security?

I'm 35 years old and I've been a web developer for many years, I consider myself a senior (and I currently have this job). But thinking about the future and the absurd growth of AI, I don't see a promising future for this area. I'm considering moving to the cybersecurity area, specifically pentesting/red team. When I was a teenager, I was a script kiddie and did some bad things lol, I always liked this area. I think this area won't be replaced by AI, at least not in the next 5-10 years. I'm confident that I can learn all the stuff but I'm unsure if I could get a job due to "switching profession".

rugged delta
# soft meadow Hey folks! Is there anyone here who was a developer for many years and then star...

I know a lot of people are concerned about developments in AI, and the uncertainty for the future, but as it stands, you should still be able to find some rewarding roles. With regard to pentesting/red teaming, yes it's a highly competitive area to work in, and can be quite rewarding. It also opens up the doors for a lot of other roles within the cybersec industry, as a lot of the skills are transferable. When speaking of pentesting/red teaming, it concerns ethical hacking, so you won't be encouraged to perform any activities without prior written authorisation from the client, and in line with the specific scope of the work you'd be doing.

While AI is still finding its feet, it is a topic being spoken about frequently in the cybersecurity industry these days, and it might see more widespread use in facilitating the work that professionals do. Becoming familiar with it in the coming years would be a good idea. As for pentesting/red teaming roles, they would generally require you to be very comfortable tin things like Linux/Windows admin, understanding/working with coding, networks, etc. It's a gradual but consistent endeavour, and even seasoned ethical hackers practice and learn new things all the time. Try Hack Me is a great place to learn a lot on the path to your dream job, but there are lots of other roles to consider that benefit from those skills

keen tundra
neon pulsar
# keen tundra Just doing CTFs probably won't get you a job but they are a great way to test an...

Hi @vapid thunder! 🙂 Indeed, @keen tundra is right: CTFs are a great opportunity to ensure that what you've learn is truly acquired and anchor in your memory (while having fun with your friends during CTFs 😉 ), but this is not really the best way to get a job.

I'll recommend you to choose some learning paths, following the rooms as they are displayed on THM, improve your knowledge and skills and learn and practice as much as you can trough the huge amount of rooms and CTFs available on THM, until you feel ready to get SAL1 certified! 😉

oblique fable
#

Hi

neon pulsar
#

Hi @oblique fable! Don't hesitate to ask question in here about CS careers: lots of great people are going to provide you awsome answers! 😄

serene umbraBOT
#

Gave +1 Rep to @neon pulsar (current: #1817 - 2)

oblique fable
neon pulsar
rustic shuttle
#

I’m developing a AI program using Python would anyone recommend a different coding language?

#

It seems to be the best so far for it

fallow basalt
#

hi all

soft epoch
odd crater
#

Hello everyone I'm new here

white badger
#

Study partner/guide for oscp, anyone interested please ping

keen tundra
rugged delta
plain vector
#

hey everyone Im planning to implement AI to my learning path. Im thinking about IBM AI engineering certificate program to start, and my question is that does anyone of you started or already implementing AI on cybersecurity I would like to get advices from you guys thanks.

mystic drum
#

@flat sedge @dense dagger I would love your input on my updated resume. I incorporated your feedback from the last one. Juun - I wasn't comfortable formatting my resume with LaTeX as you suggested, but I included everything else you mentioned.

Guys, if you have any feedback for my resume, please send it my way. Thank you!

P.S. Resume is for generic Security Engineer Position

serene umbraBOT
#

Gave +1 Rep to @flat sedge (current: #11 - 827)

sand mortar
#

Hi, does anyone know cybersecurity like careers that require a deep understanding of cryptography and rely on it a lot?

#

if possible i want answer from someone that had experience or something similar , not llm generated answers

ornate wasp
ornate wasp
stark frigate
dense dagger
ornate wasp
#

Question all. Is there a command to get out of a command that was run but is stuck?

#

got it

trail ivy
ornate wasp
#

Thank you!

trail ivy
#

No problem

high thicket
#

recently got selected for the Black Hat Asia 2025 student scholarship, but I really want to know if attending such conferences is actually worth it.

I’m from a developing nation where job opportunities are usually only accessible to students from top colleges, while the rest of us have to struggle our way up.

I just want to know if it’s worth going and if it could actually help me stand out from the crowd.

Apologies if I said anything wrong just looking for honest advice, and I’ll definitely take it into consideration!

prisma torrent
#

Black Hat conferences are renowned.. i don't know anything about potential career opportunities but as an organisation it has merit.

dapper depot
#

I see now that travel and hotel are the responsibility of the attendee so that is something to consider although Singapore can be very affordable.

languid prism
#

Anybody have any suggestions for getting my foot into the door for cybersecurity jobs?

rugged delta
rugged delta
# languid prism Anybody have any suggestions for getting my foot into the door for cybersecurity...

If you're interested in a role in cybersecurity, there are a number of ways to pursue them. You might get a degree in Computer Science, IT, Cybersecurity or a related field. Certifications also can help, but the most important thing you need to work in this field is a desire to learn new skills. There are a lot of job opportunities, and you will need to dedicate yourself to gaining the skills needed to be able to perform in the field. Simply having a certification or a degree might only be seen as an indicator.

Spending time learning in Try Hack Me can encourage you to improve your skills and find the kind of roles you'd like to pursue. There's a broad volume of knowledge you can acquire and a lot of ways to put it to use. You can take a look at the Individual success Stories on the THM blog here:
https://tryhackme.com/resources/success-story

I'd also suggest reading some of the interviews from the Tribe of Hackers books, which are collections of interviews with professionals in various roles in the field. If you're new to cybersecurity, you can go to #start-here

TryHackMe

TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

languid prism
serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #21 - 484)

rugged delta
languid prism
stoic cave
languid prism
serene umbraBOT
#

Gave +1 Rep to @stoic cave (current: #20 - 502)

stoic cave
#

You're welcome

hushed relic
#

Hey, i wanted to ask if anyone here had gone through the paradox of choice between Red Teaming and Blue Teaming?
Lately, I v been struggling to pick a side… I really enjoy both offense and defense, but I cant seem to commit to just one path

rugged delta
# hushed relic Hey, i wanted to ask if anyone here had gone through the paradox of choice betwe...

Well luckily for you, red and blue teams are actually working towards the same goal; the defence of the organisation. It's okay if you haven't picked a particular path at this stage, there's a lot of material to understand, and it actually helps if, over time, you learn some of the requirements of both sides of the fence. A lot of people going into red teaming/pentesting will have spent a while working on a blue team; and vice-versa, plenty of red teamers bring their skills to improve the effectiveness of the blue team by improving the rate at which attacks are recognised.

There's a lot to learn, and it's beneficial if you spend a little time on each side. Eventually you'll find yourself spending more time with one over the other and just naturally gravitate that way, at least for a while

cedar viper
#

Has anyone ever done the GT OMSCybersecurity?

high thicket
serene umbraBOT
#

Gave +1 Rep to @dapper depot (current: #323 - 20)

high thicket
dapper depot
high thicket
#

im most keen on AI summit and how it impacts in our cyber field

dapper depot
#

ive been to singapore a number of times so if you have any questions feel free to dm 🙂

gloomy mortar
#

roughly of course

#

is it near CCD, BLT1, or HTB CDSA?

#

just out of interest so no worries if can't tell

cursive pendant
#

can we generally use google translate during a certification exam ?

cursive pendant
gloomy mortar
gloomy mortar
warm hinge
#

Can anyone give me a work
I need to earn money

cedar viper
cedar viper
cedar viper
#

Omg

#

It actually is

#

That’s crazy

cedar viper
cedar viper
#

Bug bounty isn’t a traditional job you can literally make an account on HackerOne or something and look for bugs rn

undone shore
#

Treat bug bounty as a hobby which might bring in some extra cash. Don't expect to make a living doing it.

#

Some people manage it, but they are by far the exception, not the rule.

high thicket
#

all of the comments on this arre making me more excited

#

^^

cedar viper
river ice
#

do you guys think i can put thm as "experience" in my cv or naahh?

#

right now im not looking to apply for jobs, it's just an assignment for my university

#

but im writing it as if i was applying for jobs

wintry stone
fading panther
serene umbraBOT
#

Gave +1 Rep to @fading panther (current: #1378 - 3)

fading panther
#

Of course

river ice
#

i don't have a hobbie section in my cv, how do i make it clear that thm is a learning platform and not a web platform i made myself?

fading panther
#

have you completed any of the learning paths on THM (like Soc 1, Jr Pen tester etc)?

river ice
#

im about to complete jr pentester

#

only like 10 questions left and thats it 🙂

#

i have also completed the basic web explotation path and two begginer paths

fading panther
#

So I am currently applying for Soc analyst roles, I am transitioning from a career in retail management so I need to show employers that I have "experience" using the tools that I would use in a SOC. I completed the Soc lvl 1 path and have it listed as a project with some of the tools that I have used as part of that path

#

gimme a second and I'll grab a screenshot of it

river ice
#

all right

fading panther
river ice
#

thanks, i like the way you worded the title

#

cause i was only thinking "Try Hack Me" as a title

#

and that could lead to some confusion 🙂

fading panther
#

Im just using it as a way to hopefully strike up a conversation with a recrutier. Reminds me I need to update it to add my SAL1 cert onto my resume now lol

river ice
#

congrats on getting SAL1

fading panther
serene umbraBOT
#

Gave +1 Rep to @river ice (current: #1821 - 2)

river ice
#

also i have some experience as back end developer, i have worked for 2 companies, but i feel that i will give the wrong impression by listing that under the experience section, still, is the only real world experience i have

fading panther
#

why do you think it would give the wrong impression

hexed ice
river ice
#

but yeah, some work experience in the it field is better than showing no experience

hexed ice
#

nah put it as the headline, make it clear with certificates and your cover letter

#

i was in a similar situation but i was a front end dev!

river ice
#

cool

fading panther
#

I agree with @hexed ice . You know how the backend works and shortcuts devs taking levaing vulnerabilites exposed for someone on the red team to take advantage of

#

and if you can articulate that in an interview youre golden

hexed ice
#

absolutely!

river ice
#

thanks @hexed ice and @fading panther for your advice

serene umbraBOT
#

Gave +1 Rep to @hexed ice (current: #2774 - 1)

river ice
#

very valuable

hexed ice
fading panther
#

you've got this, don't sell your experiences short

granite sable
#

hey chat i'm looking for a job role as a security analyst/intern to start my career in cyber security field. i have done my master's in cyber security and a CEH v13, CPT . Please let me know if there is any opening for these roles. It will be highly appreciated.

cedar viper
dawn field
#

I’m currently working through the Google Cybersecurity Certificate and would love to find a study buddy to...Still new

tribal herald
#

Hi guys. I’m currently interested in this field for the kind of skills you can acquire. I am by no means have any knowledge or background in cybersecurity or tech. I’ll probably have to start from the ground up but don’t know where to start. Any tips?

keen tundra
warm hinge
# tribal herald Hi guys. I’m currently interested in this field for the kind of skills you can a...

Start by understanding what cybersecurity actually is and know more about what jobs are in this field, for example try tryhackme's career quiz
Then start from the beginning. A solid foundation is vital in hardwares,operating systems,networking,Linux,scripting(bash,powershell),basics of programing langs like (python,javascript). Try hackme have tons of modules you to get familiar with concepts but don't just rely only on it. Continue learning you will find the way when you take the first steps 🚶‍♂️ ✨️

torpid shale
#

Hey everyone! 👋 I’m a junior Cybersecurity major at university, minoring in Information Technology and Computer Science. I’m looking to break into Cloud Security Engineering, as I see it's a high-demand field. I know it’s competitive, so I want to make sure I’m taking the right steps.

Does anyone have any advice on how to get started? Would interning at a data center be a good move, or are there other recommended paths to gain relevant experience? Any insights would be greatly appreciated!

Thanks in advance!

torpid shale
serene umbraBOT
#

Gave +1 Rep to @keen tundra (current: #1 - 4221)

boreal tusk
cedar viper
#

Is the ine ICCA cert valuable?

keen tundra
torpid shale
serene umbraBOT
#

Gave +1 Rep to @keen tundra (current: #1 - 4224)

gloomy mortar
#

Oh well, I'm a wizard! (0xA) Harry I'm away for my yeezy's to celebeb!

olive relic
#

What’s up y’all. I’m very new to Cybersecurity and decided to start my learning on Tryhackme.

I’m thinking my goals are going to hopefully align with learning everything blue team. Looking for any tips, advice, resources etc. that I should know about. Anything is appreciated.

hybrid tinsel
#

Anyone here has installed Tails Linux before?

#

If yes, did you face something like systemd-journald.service failed to start?

cedar viper
storm sinew
#

Hello team, I just got my first job as a Level 1 SOC Analyst, and I am very happy! I would love to hear any advice from those who are already in the industry.

Until now, I have only practiced in simulated scenarios on TryHackMe, but this will be my first real experience. I would really appreciate any recommendations or tips you may have.

Thank you in advance!

dusk wedge
#

It really depends on the type of soc work your doing i guess.

drifting depot
storm sinew
drifting depot
drifting depot
# storm sinew None at the moment, I just prepared for the right questions at the interview, an...

Well I can give you some general advice.. Treat the job like it's the golden ticket. Your probably going to get stressed and think they are asking to much of you but just remember that is managements job. They are always going to ask more than they think you can do and pretend like it's the end of the world if you can't do it. Give it your best and realize that's all you can do. Never be late, and be willing to learn something new everyday. Many people out there trying to get their foot in a door. Treat the job like it's your golden ticket, it might not be where you stay forever but it might just be the step you need to get where you want to be.

hollow rivet
#

Hello everyone, I'm nearly done with high school and am planning to enter college for computer engineering. Is my course a good choice or should I consider other courses instead? I'm really confused rn 🫠

dense dagger
keen tundra
hollow rivet
dusky light
#

I just got through my first internship as an Information Systems Intern. What Job titles would be good for me to pursue?

bleak plaza
#

All, can you help me with an average income as begginer in CS but part-time?

radiant pecan
#

Hi! I'm new here. I've worked as a web developer for two years and I completed some of the easy learning paths in THM. I was wondering if there are pentesting jobs focused on web pentesting rather than general pentesting, so I can focus on that field instead of learning eeeeeeeeeeeverything.
I hope this message is in the correct channel. Thank you!

rugged delta
bleak plaza
#

if you are working remotely country isn't improtant anymore and about experience is for a begginer. The reason for my question was that i want to know if i can be about average in my contry regarding the monthly income. Thank you for your response!

serene umbraBOT
#

Gave +1 Rep to @cunning warren (current: #2778 - 1)

fringe spade
#

Also for beginners, it’s quite hard to get remote jobs, as employers often prefer onsite training for new employers and might not even allow you to work in a hybrid environment for the first months/a year.

fickle grove
fickle grove
#

Haven't taken it but would suggest comparing the topics covered in the course material with what is/are covered in the Web App Pentesting path.

#

You might want to look at Portswigger's Web Security Academy as it is free anyway.

ancient prairie
#

maintain a technical blog with professional-standard reporting, have a lab environment to get hands-on experience with tech stacks, try volunteering/interning, get creative with your past job experience by highlighting soft-skills - someone will take a chance on you eventually, good luck!

noble mortar
#

Hello everyone,

I’m nearing the end of my unemployment period and am in the process of transitioning into cybersecurity. I’m actively looking for my first role in this field. Below are the certifications I’ve obtained:

  • OSCP (Offensive Security Certified Professional)
  • CCNA Cyber Ops
  • CCNA (Cisco Certified Network Associate)
  • CARTP (Certified Azure RedTeam Professional)
  • CRTE (Certified Red Team Expert)
  • Sektor7 (in progress)
  • BSCP (in progress)

Practical experience:

Currently ranked 23/8945 in HackTheBox season 7
"Pro Hacker" rank, globally ranked 553
Pro Labs: Zephyr, Dante, Rastalabs, Offshore

RootMe 5305 points, rank 1165

Altered Security Red Labs platform: ranked 24th

I am motivated, curious, and ready to apply my skills to new challenges. If you have any advice, opportunities, or leads to share, please don’t hesitate to reach out, it would be a great help!

gilded cargo
#

Hello, i'm looking for a good organism in france to train and pass the CISSP Exam. Any tips ?

rough sequoia
fringe spade
hardy pine
#

anybody can have a coupon code for a monthly subscription

chrome spire
#

How hard is it to land remote jobs with high salaries? Is it not very common?

noble mortar
hollow falcon
#

Inquiry, and this for those that actually have exp with what I'm about to mention.

Say, you get hired to conduct a pentest for a client. However, after a couple of days or weeks, don't matter, demostration purposes. Let's say that after conducting a pentest you find no vulnerability, whether it be due to the client's security implementations or an insufficient skill level.

What do you say and report to the client in this situation?

chrome spire
#

Ur fine

#

U seem over qualed on paper tho

#

Idk

#

But u got no work experience

#

But im sure ul be good

#

Just market urself well

#

Would doing SWE be better to get into cyber? Ion mind swe but its a bit boring

hollow falcon
#

Thank you

serene umbraBOT
#

Gave +1 Rep to @hallow sparrow (current: #54 - 168)

noble mortar
hollow falcon
#

Last question; promise I'm not trying to be annoying.

In your honest opinion (doesn't have to be long.), what would you say distinguishes a Cyber-security Specialist and a Pen-tester?

#

Would you say they're the same?

#

Ah, understandable.

#

Understood! Does social engineering count in these engagements or are clients mainly looking for non-human related vulnerabilities?

#

Understood, and thank you again

serene umbraBOT
#

Gave +1 Rep to @hallow sparrow (current: #54 - 169)

undone shore
#

Yeah, that's not true at all.
It's very possible to get tests which legitimately have no findings.

You just note in the executive summary the reasons for that, and move on.

hollow falcon
#

Huh, now I'm curious

undone shore
#

e.g., an application which is tested annually for compliance, but hasn't had any feature updates.

hollow falcon
#

Ah

undone shore
#

Or a test where the client have requested a tiny scope.

hollow falcon
#

Guys, please don't confuse me. Lol jk

undone shore
#

Or a client who have their own security professionals working with the development team.

#

Or just outright developers who know their shit.

hollow falcon
#

True! Understandable

undone shore
#

Lots of reasons why a test may have no findings.

#

Be that as it may, your blanket statement that "no findings == skill issue" is still utter crap lmfao

hollow falcon
#

Okay, would there be some data regarding successful engagements vs. unsuccessful I can get a link to?

#

Articles?

undone shore
#

How do you define success?

flat sedge
undone shore
#

Nope smh
Your lack of experience is telling there Zumi. Just because tests in your specific niche nearly always have issues, doesn't mean that will always be the case.
Yes, there are some test types where chances are you'll always find something. OT, for example, or hardware, sure.

And yes, the majority of tests will include something, even if it's scraping the bottom of the barrel.

That doesn't mean every test will though. It doesn't mean that it's impossible to have a test with no findings. It definitely doesn't mean that there's a knowledge gap if you do fail to find anything.
That last opinion is outright misleading. It just compounds the CTF player problem.

I will not agree to disagree on this. You have made a blanket statement, presenting an opinion as fact, which is just outright incorrect. Again.
By all means feel free to go and get that verified though 🤷‍♂️