#cyber-and-careers

1 messages · Page 51 of 1

chrome spire
#

But theres a bunch who dont do it

#

Anyways i hope i gave you some light on it

#

Best of luck choosing a career

keen relic
#

yeah thanks

edgy orchid
#

Many thanks for the advice. I'm really up in the air on what I want to do right now, honestly haha. I like aspects of all three of those fields but I'm not sure which would be the best fit for me as my main career focus. I've always been the "dabbler in many, master of none" sort with just about every subject, which has been both a positive and negative in my life. I guess we'll see where things go though!

serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #21 - 512)

pine forge
#

TryHackMe paths will cover the basics

fickle grove
#

@keen tundra

opal moon
#

please can anyone help me getting one month free subscription.

odd igloo
opal moon
#

how to get it

odd igloo
# opal moon how to get it

well, someone has to be giving away free subscriptions (usually for a few months or smth), and you can participate in it, and if you are luckily, you get one

opal moon
#

ok

keen tundra
opal moon
#

Yes, sir, but I was looking to cover the basics, the prerequisites step by step but many of them require subscription.

opal moon
#

Sir, my goal is to achieve SOC level 1. To achieve it, I have to go through the premium content.

broken idol
opal moon
#

so what should I do now 😦

pseudo ledge
broken idol
keen tundra
broken idol
opal moon
#

Even on doing a payment with different cards, it shows that your payment could not be completed this time. Please try again

crude sphinxBOT
#
TryHackMe's Email

TryHackMe's support email address.

opal moon
#

done

rugged delta
gleaming fiber
#

Heyyyy... anyone one free... i just need quik guidance

odd igloo
gleaming fiber
#

i am new for cyber security so need someone to talk. i have few questions

odd igloo
royal verge
#

Hello guys, as a newcomer into blueteam. What personal project will really hone our skill and highlight our resume? Anyone have tips? 😁

rugged delta
# royal verge Hello guys, as a newcomer into blueteam. What personal project will really hone ...

I would suggest ompleting the SOC1 and SOC2 paths, and consider a certification in blue teaming like the SAL1, BTL1, CDSA, CCD or other practical cert that gives you experience using and learning the tools, get comfortable with scripting/coding, create a home lab with virtual machines or spare computers and install the tools you would need in a SOC and configure them correctly and blog about it

gilded jasper
#

can the PT1 certification increase my chances into getting a uni?

rugged delta
# gilded jasper can the PT1 certification increase my chances into getting a uni?

If you're applying to a universtiy, you will need to look at the requirements of the application process, though sometimes that process does take account of your achievements in the field to date. A lot of roles in cybersecurity today can be achieved through certification and gaining and demonstrating your knowledge in other ways, like having a blog, doing writeups, CTFs, bug bounties, going to conferences, meetups, etc.

gilded jasper
#

so if I can show my skills and show the cert..is that enough?

keen surge
# royal verge Hello guys, as a newcomer into blueteam. What personal project will really hone ...

A home lab project is a worthwhile project to show.

  • Setting up your own home lab with a minimal SIEM and a couple Windows and Linux VMs is a good start.
  • Get all of them to send logs to your SIEM of choice.
  • You can expand by setting up TheHive as an IR platform.
  • Add a domain controller and onboard your VMs in the AD.
    Things like that. Even just the first step shows recruiters and employers that you can do more than answer guided questions and take flags. You demonstrate an understanding of how things work. Things will break or not work and you will have to fix them. If the goal is a blue team or a SOC then demonstrating that you can build even parts of your own SOC / detection environment is super handy.
shrewd hedge
#

is there anyone got job after completion of SAL1 certificate ??

#

i am doing soc analyst path L1

fickle grove
shrewd hedge
#

can we get remote job as a soc analyst ??

fringe spade
hollow merlin
#

Hey quick question for you guys here, i started a remote dfir role a couple of months ago but there is almost no follow up of my progress at all. You would think that the first few months that there is some guidance right? Or is that just the way it is with remote jobs in dfir

keen surge
alpine tartan
#

Hi I need help to scan nmap I am not getting the open ports
Plz help me

#

I am getting all 1000 ports are closed

keen surge
hollow merlin
#

Also i cant bother the seniors all the time

keen surge
hollow merlin
#

Its quite sad tbh because its probably the best place to learn but, now I’m learning almost everything on my own during or after hours which kinda defeats the point of switching jobs to learn

keen surge
#

I would say to use the resources you have available. Learn from your colleagues and keep a goal in mind to work towards. Find a reason why you can make it, in spite of circumstance. The threat actors win when we lose heart.

hollow merlin
#

yea understandable that you were pissy about it, it really sounds overwhelming

#

but indeed a great learning experience

#

but in your case i would be scared that I would get fired because you are figuring it all out on your own

#

thats what i have now as well

thick flax
#

I am pursuing a career in defensive security by offering my own services is it worth it or is the traditional route of applying for a job a safer option

keen surge
keen surge
fathom gorge
#

Curious to hear if anyone made the move from Software Engineering to Cybersecurity / Security Engineering and what path they took?

torn narwhal
#

Hey guys, I'm currently revising my resume a bit, tailored towards security.
The question I have is:

  • Is it recommended or applicable to use training platforms as projects?

I was thinking if I could, since it gives me something to talk about
what I am learning or had learned, I also have some home projects
that I am working on, but not yet finished.

fathom gorge
#

Instead of putting it under projects consider using "CONTINUOUS EDUCATION", lets companies know that you are staying busy upskilling yourself

copper mesa
#

Hey guys, wanted to ask. I'm currently looking for a SOC analyst internship in Europe. How useful would it be to include in a resume the fact that I'm in the top 1% of users on TryHackMe or that I have completed the SOC level 1 path?

flat sedge
copper mesa
shadow ore
#

I'm having some issues with my Kali Linux os, I can't connect to the internet I've tried many things but it seems not to work, I need assistance cus I need it to complete a project

stoic cave
stoic cave
serene umbraBOT
#

Gave +1 Rep to @stoic cave (current: #20 - 514)

stoic cave
torn narwhal
serene umbraBOT
#

Gave +1 Rep to @stoic cave (current: #20 - 515)

stoic cave
stoic cave
shadow ore
gilded jasper
#

is this channel good for tutorials?

hushed spire
odd igloo
keen surge
# gilded jasper is this channel good for tutorials?

Looks like sensationalist clickbait with little value like most cyber content creators. Whatever you're trying to learn, I'm sure there are better resources.

In general, if the title says "hack" and "kali linux" or the thumbnail has a guy in a hoodie, with a mask, it's garbage.

misty spindle
#

Hey, I'm looking for people to collaborate on short articles on cyber security. I have access to quite an audience so if anyone is interested just write priv 😀

dreamy surge
#

guys does anyone have good project idea that i can build on as i going for soc analyst entry level or pentesting job and want to do projects that can stand out i don't want to do something that common or which is already out thereany idea's

odd igloo
dreamy surge
odd igloo
dreamy surge
#

layman terms just looking for a project idea that that would stand out on a cv

odd igloo
dreamy surge
#

well its the wish of the person to tell or not i just asked and its not like i am stealing a million $ idea

odd igloo
keen surge
undone shore
#

Means they've got a reasonable idea about security controls in an enterprise environment. At the very least endpoint (and possibly cloud) controls.

keen surge
undone shore
#

That doesn't mean they need to "pick a lane" though. Nothing wrong with doing both.

#

Heck, if I saw a fresh-faced grad come in for a junior role who had -- in their own time -- configured a home lab with a vulnerable application + integration with a SIEM for monitoring, then tested it and analysed their own attack, I would be fairly impressed.

#

As, I suspect, would a SOC manager.

#

Not least because that also demonstrates a much more well-rounded attitude towards security. It isn't all or nothing attack or defence. Understanding both sides is always valuable. Demonstrating both at once is a bonus.

keen surge
#

Yeah I suggested a similar project yesterday to someone asking for a project. But op was looking for something novel, so I was hoping to narrow it down. You're entirely correct of course.

undone shore
#

Ah, now that makes life harder kekw

keen surge
dreamy surge
#

could you give me any ideas regarding projects

undone shore
#

I can't pin things anymore unfortunately

dreamy surge
#

is the try hack me cert good? soc1

odd igloo
keen surge
dreamy surge
dreamy surge
#

which one have you

#

done

keen surge
#

I think the SAL1 cert will become a solid cert to get. But it's still pretty new and it takes a while before certs get accepted fully by the industry. I see Security+ mentioned the most for entry level positions.

odd igloo
dreamy surge
serene umbraBOT
#

Gave +1 Rep to @keen surge (current: #2926 - 1)

odd igloo
latent minnow
#

What do you guys think about CRTA, MCRTA, CRT-ID, CRT-COI and CPIA? from cyberwarfare

urban hare
#

i worked for a telecommunications company for 6 years with 4 years being in tech and also have a uni degree in game deisgn, do they seem to care deeply about certs?

#

i guess to be a bit more specific like if i can prove i know the stuff with labs and what not do they care

keen surge
urban hare
#

I think my problem right now is knowing whether i already know the stuff because so far the stuff i have been "learning about" has been stuff i know other then acronyms and such

#

and red team blue team purple team etc etc

#

the networking i know pretty deeply

#

like i decied to try out the pen testing path on try hack me and feel very confident with all of the tools, but from what i have read SOC analyst is probably the best first shot

#

does this sound accurate?

keen surge
#

SOC analyst is a typical starting point mostly because it's a very structured environment, and easy to onboard low-skilled personnel. It can be a great place to start, but if you've been working as a software developer for 4 years for example, then you could get into appsec or devsecops or something like that as well. It's not all red team blue team :D

#

I think making a personal project could be a good idea for you, just to prove to yourself that you know what you're doing, since you're unsure

urban hare
#

well I am only really familiar right now with C++, C# I started learning about python yesterday and I'm trying to build little programs to learn about it.

#

as of this point I dont think i know enough about python to write an attack code or anythign but i think the fundementals i have at this point make it much easier for me to learn other laungues and i am finding python is actually super easy.

keen surge
#

do you code for work or what part of IT do you have work experience with?

urban hare
#

i guess that where im not sure i have no formal school for IT

#

but i supported network incident reports for outages and varies other things, device support from phones to mobile connected laptops, helping people setup networks apps etc etc

#

i have not coded for work yet no

#

game design is very difficult to get into so i was trying to find a more realistic option

#

that is still engaging for me

#

some people told me it was boring a long time ago but its clear they didnt know what they were talking about, but thats on me for listening lol

keen surge
#

Fair enough. It's going to depend a bit on your personal timeline then. You could probably interview for SOC positions right now. If you really wanted to focus on the programming aspects you could keep improving at that and maybe find a way into the industry that way.

Yeah game dev is an oppressive industry to work in. It's for the passionate, and if you are passionate about both game dev and cyber sec there are certainly ways to combine them. Games also need security. I can't really give you much advice on that part though.

urban hare
keen surge
#

Sounds wise. And only you will be able to figure out what that means for you. I think you'll do well

urban hare
#

Thank you

#

how long have u been in the industry?

#

what do you do specifically?

keen surge
#

So I basically suck at everything all at once :P

urban hare
#

wearer of many hats master of none?

#

lol

#

when u said write isms do you mean the whole plan for operation at a specific company?

#

or just part of it

#

oh so its kinda like when i had a write up data base for my old job and there were people who updated the polices when they needed updating

#

yeah it seems like there is a lot of cross over just different Acronyms

#

i was thinking just like an SOC analyst to start out and then branch

#

i dont wanna get to far in over my head

#

but pen testing would be sick out of the gate

keen surge
#

It's a good play. Getting exposed to a lot of alerts from many different sources is great experience to have.
Yeah a lot of people are drawn in by pentesting. Some are able to get into it right away so I'm not saying it's not possible. But for the most part I've found the old saying to be true: Entry level cyber security jobs are not entry level IT jobs. And entry level pentesting jobs are not entry level cyber security jobs.

urban hare
#

yeahh im noticing that about a bunch of careers

#

do you get to use the tools like cyber chef?

#

or splunk?

#

oo that makes sense

#

so how similar is it to things like cyber chef

#

if ur able to answer that

bright oar
#

very new to cyber sec, no relevant degree or experience in the field. how likely am i to get even an entry level position in a year or two if i really grind the material & get some UK-govt accredited certifications?

keen surge
#

I mean cyberchef and virustotal are public tools that you can safely assume most security personnel use

urban hare
#

ngl cyber chef is cool AF

#

I practiced writeing my own python prgram that bascially extracted IOCs first then found cyber chef

wise harbor
#

I would like some advice as I will need to start applying soon, I am graduating with a bachelor's in compsci with a concentration in cybersecurity (so taking classes along with some cybersec classes). I see that a lot of positions require or prefer(either or, 50% of the time), 1-2 years of IT experience. I am wondering if that is a hard rule for trying to get into a junior level SOC job. I am currently studying for sal1 and next semester I will be preparing for sec+, I am hoping to start setting up a homelab as soon as I can to practice some SIEM stuff and for general uses like jellyfish, etc. I am just wondering if there is anything I must do to circumvent such or if I will have to do helpdesk for a year or so.

urban hare
#

well as most people have been saying infosec isnt entry level

#

so it might be required to be in IT

#

but i dont know for sure

surreal cradle
#

anybody know any good cloud computing courses
for someone whos just starting
any languages recommend for this as well to be learned?

urban hare
#

everything appears to be written in python in some form

wise harbor
# urban hare so it might be required to be in IT

gues I'll have to apply for helpdesk then after graduation. though I have been looking at some places and they seem to be okay with no experience (for soc), just that it is preferred. kinda wish it didn't make my degree feel useless even though I know I need it to get where I want to be.

urban hare
#

yeah its a pain but it'll go by quick and u may even be able to move up in the same org

rugged delta
wise harbor
wise harbor
#

Preferably Taiwan otherwise maybe Norway or Germany.
If I can't, then Ireland or Australia. I just don't want to stay in my home country for all my life. It's been a goal since I was a child.

#

Granted though it gives me more time to be fluent and get certified for that language so maybe it's not all bad, the current market just worries me ngl 😭

urban hare
#

i feel that

rugged delta
wise harbor
rugged delta
wise harbor
rugged delta
wise harbor
urban hare
#

i think the hardest thing to come to terms with is realizing that degrees just give u a solid foundation and not expertise the rest is up to you sometimes if you cant find jobs that dont require some kind of years of experience no one is willing to give lol

#

thats why other people in my classes when i was attending college weren't on the same page coding wise in my game design degree because I coded on my own as often as I could during that time and even now. IMO I think real world practice is the best way to gain real experience and some time its got to be a free investment, as long as you look at it like that it will make it easier especially if your passionate about it.

#

and i started with no knowledge

#

tldr: you get out what u put in is the truest statement i think

rugged delta
surreal cradle
rugged delta
urban bridge
#

Hello guys, i'm looking to change career, just turned 30. Never had "formal" IT experience but always been tech savy. Currently self learning is my go to. Wanna get into cyber in the next couple years or so, would it be advisable to go IT Support role/certs first year then study cybersec/get cerf after?

keen surge
# urban bridge Hello guys, i'm looking to change career, just turned 30. Never had "formal" IT ...

It's possible to get an entry level cyber job without prior experience if you study hard and can demonstrate technical skill in interviews, but you can expect to be rejected a lot based on the CV before you even get to speak with anyone.
IT support or similar (sysadmin or network admin is even better if you can swing it) is amazing experience to have before transitioning into cyber. Having enterprise IT experience gives you a lot of context for the security work.

eternal musk
#

i heard a case where the mod hiring for jobs he find a man having oscp , cert , with 3cve but he can`t give the answer how you get this

bold dirge
#

I’m having account that I’m needing someone we can work on them

opal moon
urban bridge
daring totem
#

is it easy to get full distance job as a student / im strudent cybersec in sweden second year

keen surge
daring totem
fringe spade
daring totem
#

Do you get paid aswell as interns

keen surge
# daring totem I mean somewhere in this field

A fully remote job in cyber as a student is quite hard to land. IT support or something similar could be achievable. I would still count on a few weeks of on-site work during onboarding though.

odd igloo
keen surge
odd igloo
edgy orchid
#

I often see people mention internships in general, but I don't think I've ever seen an internship that doesn't require you to actively be undergoing a degree program of some sort. I really do wish there were internship opportunities for people undertaking self-study because I'd be more than happy to do that to help myself learn more about the work I'm trying to career change into

rugged delta
dusk wedge
#

i did 5 internships total in my school carreer, 2 in secondary school, and 3 in college

#

i think its also depended on where you are located

#

here you see internships at pretty much every level of education

daring totem
dusk wedge
#

Didnt need any while applying for them

#

And they helped ne greatly

#

I leanred way more at internships then in schoool

golden spoke
#

School just loads u with a lot of unnecessary shite

stoic cave
stoic cave
low shadow
low shadow
golden spoke
golden spoke
#

a lot of memorizing useless info u will forget

stoic cave
golden spoke
#

somewhat the same with certs but they hold more value and are more focused

golden spoke
#

But business courses and electives

stoic cave
golden spoke
#

For sure writing is important but you dont need the other stuff

#

Very easy to look up how a business operates if u need to

#

I have a good gpa it got me a great internship but it definitely made me realize how worthless school was

#

You need it though just for the credentials and possibly structure if u arent disciplined

stoic cave
#

Respectfully, I disagree, but I'm about to lose internet. At a high level, those extra courses round you out as a person and member of society. I, and other working professionals here can chime in, have probably used an aspect of every elective I took in college in my professional career. A large part of Cyber is also understanding how the business unit works, so that you can make effective decisions securing the organization. Even an art elective can help, think about making slide decks and diagrams.

flat sedge
golden spoke
#

But if its not focused on that its pretty useless

flat sedge
#

I didn't say the only useful ones. Just the most useful ones.

#

Those are the ones that taught me how to effectively communicate and demonstrate the ideas from every other thing I've ever learned and known in my life.

golden spoke
flat sedge
#

And you are wrong

#

That's ok, we are all wrong sometimes.

#

It's part of learning.

golden spoke
#

Im not remember some random course i took

#

unless it was important to me throughout university and to this day

flat sedge
#

How does that makes the classes not useful? If you encounter something in a class, you are more likely to remember that you learned it and have more success than learning it for the first time when it matters on the job.

But it's clear you aren't interested in matching your viewpoint to reality, so I'll just drop it there and wish you good luck in your career.

golden spoke
#

all good

flat sedge
#

A large part of my training is identifying bad faith actors. And when it sounds like a pigeon, and shits on a chessboard like a pigeon....

stoic cave
rustic coral
stoic cave
#

Public speaking was a degree requirement for me and I am honestly greatful. I regularly have to give briefs to all manner of people and it definitely helped.

edgy orchid
edgy orchid
outer lintel
#

Any content regarding cyber forensics

broken idol
#

There are loads, what are you looking for?

rugged delta
# edgy orchid The problem I see is that CTFs and bug bounties tend to focus on one specific so...

They were only suggestions. Obviously not everyone is going to do everything I suggested, or if they do, they're not going to do just those things. And it's very difficult to do all of them with consistency. You need to find your own way to express your interests. It's not just about getting a job. It's about building a life you can engage with and be happy and successful to your own satisfaction. Getting a job is a good result of all that, but the job is there to fulfill a part of your needs and goals

brave ledge
#

Any tips of looking for gettin job, just graduated with my major as cybersecurity and been applying for a lot of jobs, but no luck, It would much appreciated If I can get any suggestions..

rugged delta
# brave ledge Any tips of looking for gettin job, just graduated with my major as cybersecurit...

I would suggest reading one or more of the Tribe of Hackers books (a collection of interviews with experts in the field in various roles), improving your skills on THM, studying/reading/practicing lots, doing rooms, CTFs, bug bounties, going to meetups/conferences, look at the roles that you're interested in and take note of the certifications, knowledge and skills they're asking for and go learn what you need to be able to do those things.

You need to be somewhat capable with IT systems like Windows/Linux/Cloud/DevSecOps/Coding to some extent and build on those skills as you progress. Also, don't limit yourself to applying to just cybersec roles. Many people in the field started in roles like tech support/helpdesk, IT, QA, programming and other roles

brave ledge
# rugged delta I would suggest reading one or more of the Tribe of Hackers books (a collection ...

Hmm, I think i followed most the things you suggested like I attend conferences like b sides, participated in cybersecurity clinic in my university in which we helped a non-profit organization improve thier cybeersecurity posture. Also I've security+ cert, eJPT v2 cert, Google cybersecurity professional cert, and im top 4% in thm and I've a masters degree in cybersecurity. I've been trying to get into bug bounties but been busy searching for a job, i dont get what more I need to do 🙄...

#

Also I'll be giving the THM pt1 cert exam soon, as i got a free coupon from there recent give away 😁

dense dagger
brave ledge
#

Yeah, thinking of doin that

dense dagger
brave ledge
#

Oh..thats nice to hear

edgy orchid
# rugged delta They were only suggestions. Obviously not everyone is going to do everything I s...

No worries, I'm not trying to come across as ungrateful or rude. I just mean that it seems like some who try to get into this field (myself included) are struggling more than normal because of the current state of the industry and how security practice platforms/labs tend to focus more on offensive security. I mean, I'm absolutely interested in that side of things the most, but right now, I'm just trying to find any way to get my foot in the door with general IT or entry-level security jobs

paper dew
#

sometimes, it also depends on location

edgy orchid
paper dew
#

ohh fair enough

stoic cave
#

Entry computer industry roles, ie IT Helpdesk I, are true entry roles. What I mean by that is you can apply with no prior professional experience or degrees. If you have a degree or prior professional experience, apply for "higher" roles.

#

If you haven't already, redact and post your resume as an image here

wide mica
#

@high trail

marble relic
#

Anybody have any opinions on ISC2 cybersecurity certification?

flat sedge
#

CISSP is the most asked-for cert in all of info/cyber sec

#

Go look at a dozen job reqs, you will likely see CISSP on most of them

rugged delta
# marble relic Anybody have any opinions on ISC2 cybersecurity certification?

They are an organisation built to provide professional accreditation in the cybersecurity space, basically set up in the 1980s to establish a way to indicate knowledge of cybersecurity needs for organisations. They developed a Core Body of Knowledge (a book that's revised frequently that you can buy), and this lead to the CISSP, a certification that typically indicates 5 years experience in the field, with a broad range of knowledge and skills.

They have other certifications like the SSCP (their equivalent of the Security+), the CCSP, their cloud security certification and others. Recently they started offering the CC certification, an introductory certification for people new to the industry to indicate your intent to pursue a career in the field. It's usually free, with free training from them.

CISSP is accepted by lots of organisations, even required/requested by many. It's known as a qualification that's 'a mile wide and an inch deep', meaning you'll learn a lot of the concepts, theory and terminology, but you'll need to learn the tech and skills separately

#

And yeah, even though they expect 5 years experience in the field for the cert, many orgs request it from people new to cyber. It's usually not too hard to get someone already qualified to vouch for your security experience from previous roles if you're already working in IT/software engineering

marble relic
#

Thats great info, thank you so much

edgy orchid
# stoic cave You have to remember that qualification works in both directions. You can be ove...

That's actually a good point that I didn't consider. I probably could run a job higher than helpdesk but my concern is that I'm still learning a lot of the stuff I'd need for that 'next step'. For example, I probably could learn on the job for what I don't know when it comes to a level 1 SOC analyst position, but I am still learning a lot of the basics (finalizing the Cybersecurity 101 learning path on THM) and I don't have any degree or certs under my belt yet. As such, I'm not sure if it'd be a waste of time for me to try applying for those positions instead of helpdesk, especially considering my general lack of professional-grade IT experience. I have almost 15 years of experience working as a support specialist for a forum host but that was 100% remote and text-based, and a lot of what I did with them has been shuttered over time because of the decline of the service, so I don't have much I can show for it: just my word.

edgy orchid
# stoic cave Entry computer industry roles, ie IT Helpdesk I, are true entry roles. What I me...

And as for this part, a lot of them are asking for high-end certs, degrees and/or several years of experience. I've seen a lot of people on LinkedIn talking about how hiring managers are asking way too much for entry-level positions these days. I'm even significantly reducing my 'desired' pay specification below the state's entry-level average, just because I'm in desperate need of something to get my foot in the door

tender sequoia
#

Hey! For someone who is just entering the world of IT and interested in cybersecurity, SOC analyst looks like a good start to gain Industry experience.

But how important it is to be wizard in IT world before moving to security role. Currently I'm completing the SOC path, but I feel my fundamentals in computers lack.

So will doing A+ or Google IT support helps?? (Or SOC analyst do not require in-depth IT knowledge just networking and SEIMs)

dreamy surge
#

i keep seeing the job role and even the soclevel 1 job roles require 3 yr in exp it an entry level job at least the entry level job role needany any exp only its like a snake biting its own tail job === exp exp === job

stoic cave
near solstice
#

Hi guys, aAmisa this side. I am a fresher in the field of cybersecurity and currently enrolled in the pre-security path. I dont have much idea about the CTF's , or Cybersecurity based hackathons. I would love to connect with you guys and learn more about these if you have knowledge about it. (I am open to creating groups and participating as well)

smoky venture
glad needle
#

Is there really something as being overqualified for an entry level job?

flat sedge
#

Yes

#

Every role has a rate of replacement, that the business assesses when they open a job req. It's basically how fast they expect to have to replace that role - if a candidate is overqualified, there is a risk to the business that the candidate will outgrow the role before the promotion schedule and leave early.

Cost of hiring for a role is usually between 10 and 25% of the roles annual salary so it's non trivial, even beyond the time cost of the candidate onboarding and getting competent at the job.

glad needle
#

So if I get a master's and try to go into an Entry level role I'm effiectively SOL

flat sedge
#

I wouldn't necessarily say that.

But I would say that it will make hiring managers take a much deeper and stronger look at you which is not necessarily good or bad.

stoic cave
#

If you're interested in Cyber, why wouldn't you do UTSA or a university closer than you?

#

You also won't know you won't get in if you don't apply

#

I also don't think technical skills rank very highly on your college application. Being a well rounded student, with a good GPA and volunteering activities is probably going to rate higher

serene umbraBOT
#

Gave +1 Rep to @stoic cave (current: #20 - 516)

solemn python
#

im currently an IT helpdesk slowly moving to system admin and im looking for certificates but im honestly overwhelmed i heared security+ is a good one to start with is that true? and how can i improve in my free time other than the certificate

stoic cave
solemn python
#

i also heard about CCCA

stoic cave
#

It's actually the only one I would recommend you pay for out of pocket

stoic cave
solemn python
#

doubt i can make that happen

stoic cave
#

If your current company won't, time to move. Again, imo

solemn python
#

i mean, im a junior graduate im currently an "intern" in IT and in 3month ill start working full time as a system admin

#

anyways my company provides its own "certifications" but they're useless

#

any recommendations on what should i do in my free time?

#

maybe youtube vids you would recommend or courses to take

stoic cave
#

Whatever makes you better at your current job, you're very new by the sounds of it

#

Reputation is everything. Trying to move on before you're even settled doesn't really set you up for success

solemn python
#

i tried but i got overwhelmed

stoic cave
#

I'd say that's an exception. GTFO if you can

solemn python
#

im going back on track to my studies

#

trying to make a clear roadmap

stoic cave
#

It's good to have goals, but don't get stuck on defining a strict roadmap

#

Life has many different paths, with different curves and twists

solemn python
#

hopefully good twists lmao

flat sedge
solemn python
#

i heard its a good start as a cert

#

from many sources

flat sedge
#

For security, yes

solemn python
#

idk

stoic cave
flat sedge
#

For system administration? It's good once you understand how to manage the system

solemn python
#

whats the ideal one at the moment?

flat sedge
#

If you don't understand how to basic sysadmin stuff, sec+ is fluff won't help you do your job better

#

I gave you a list

#

The ideal one is the one your org will pay for

solemn python
#

none

#

im paying from my pocket

flat sedge
#

Unless it is guaranteed to get you a job, do not spend money on it

#

Talk to the hiring manager/team leads for what you actually want to do and maybe they can give you a path to move internally

solemn python
#

not guaranteed but as a fresh graduate it would be nice to put on my CV

flat sedge
#

Junior graduate? What does that mean?

solemn python
#

i just finished my studies

#

bachelor

flat sedge
#

if you have a B.Sc in an IT related field, none of the entry level certs will do anything for you

#

as a hiring qualification

solemn python
#

CS

solemn python
#

thought they would atleast get me in for an intern position

#

in the cyber field

bronze mountain
#

Hello everyone

solid hinge
#

Hi everyone

hushed carbon
solid hinge
solid hinge
edgy orchid
#

Just a heads up to everyone, including moderation, I was contacted by an account that had THM as a mutual server, claiming to be a recruiter that saw my messages here. This account wondered if I could share a bit more about my background to see if I might be a fit for any positions that were open. I was 99% sure it was a scam but I ran with it for a bit (with caution) to see for sure. Every single message detected as 100% likely AI in QuillBot. After I was completely confident, I reported the account to Discord and blocked.

Just figured I'd throw a heads up for anyone here to keep their eye out in case they let their guard down for something like that. Also, if any mods want me to list the account name so you can kick it from the server, let me know.

edgy orchid
near solstice
daring plume
#

Yeli

#

Yelo guys

cold hornet
#

Hello 👋, I'm giving my situation if anyone can give me suggestions about career and stuffs in Cyber security. I just finished my BE in CSE. I know some development stuffs. But i want to grow my career mainly in cyber security field. So what can I do? How to get job? Anybody can help me. Don't be shy to be open.

dense dagger
#

Maybe you can post your resume with redacted personal info so people can critique it and help it improve

cold hornet
dense dagger
#

I suggest in getting a job in IT first though, it gives you a solid foundation before moving into cyber

cold hornet
dark wave
#

yo guys, soon ill have a ctf assessment for pen tester job, which places are good for practices? The CTF is 24hrs long

sharp helm
#

Hello, if I want to pursue a career in incident response, what’s the best things I can do like, certification, event, learning? I really want to join this field and be competent, so if anyone is in this field or knows about it, I’m taking all advice!

winter estuary
#

Is anyone here a cloud sec engineer? Do you have to start off as an analyst?

serene umbraBOT
#

Gave +1 Rep to @winter estuary (current: #2934 - 1)

warm hinge
sharp helm
serene umbraBOT
#

Gave +1 Rep to @charred knoll (current: #331 - 21)

ashen eagle
#

Hello, is there anyone here who already works in security?
I would like to know how the rooms differ from a real-world working environment. And at what room level we start to see cases similar to real ones.

sweet pumice
#

hey i have an interview for malware re tomorrow any ideas ? for prep

thorny rampart
thorny rampart
#

We need experience in an actual SIEM environment, like Azure which is widely used in enterprise environments

thorny rampart
#

Not working in the field yet, but that would be my answer

stoic cave
stoic cave
#

Real life is very different from simulation

clever light
#

Guys please I have a real question

Have the people who dedicated years to TryHackMe found that it truly helped them land a cybersecurity job and improve their skills on the job?

midnight pelican
summer jasper
clever light
summer jasper
#

Besides, other peoples stories will differ heavily from your path. Some might be here for a month and land a jr role because of previous X Experience. Others might be sitting here for 5 years not getting a single interview because their CV has 50 mistakes and looks like it was made by a 3rd grader. "Technical" Skills are not even half when it comes to interviews, it's social skills and how you can sell yourself.

dusk wedge
clever light
serene umbraBOT
#

Gave +1 Rep to @dusk wedge (current: #87 - 95)

dusk wedge
#

however, i got very lucky with internships and the company i currently work for

#

its good but i dont think THM alone will be enough

fickle coyote
#

Hello, currently I’m a cybersecurity student (senior) but struggling to get internships specifically reaching interview stages. I’m part of a cybersecurity club, participated in a cyber case study, completed a Python project relevant to IT, and passed the ISC2 CC. I’ve used Wireshark, Linux, and MS Access (database). I’m planning on studying for Security+ and CCNA. My goal is to become a Security analyst. Any advice on what I can do to improve my chances will help a lot!

#

I’ve seen people recommend to try doing home labs and applying for help desk positions.

red patio
#

anyone wanna join me

#

like part time

#

dm me

dusk wedge
#

join what?

odd igloo
red patio
#

like doing work together

#

not a full time my friend

dusk wedge
#

yeah i would follow the advice of the poeple in #general

odd igloo
red patio
#

ok

dusk wedge
#

since this is not a recruitment server

red patio
#

where is the recruitment server guys

dusk wedge
#

idk

#

not here

#

just check in with one of the admins

grizzled prawn
#

Hi
Please does anyone know where I can get data analysis certificate

red patio
#

Wanna join me

dusk wedge
dusk wedge
#

we already told you

red patio
#

Bro

#

It's not a company noe

odd igloo
red patio
#

It's just two people

#

No .

grizzled prawn
serene umbraBOT
#

Gave +1 Rep to @red patio (current: #1921 - 2)

forest mountain
#

I’m currently trying to land a job in GRC, Any tips you can share as far as reinforcing my knowledge in the civilian sector? I recently separated from the USAF as an ISSO, and although I wished it was a more of a technical role, I’ve come to appreciate the knowledge I’ve gained over the past 4 years.

lethal raven
#

I’m tryna get an internship next summer frfr any recommendations on what to do this summer and in the winter when I’m not taking classes I was thinking getting a cert or something

dusk wedge
#

depends on your interests, the kind of internship and the level you are currently at

lethal raven
#

Well I’ll take anything related to cybersecurity I’m still a beginner probs I know the basics and I can code

rugged delta
# lethal raven I’m tryna get an internship next summer frfr any recommendations on what to do t...

What kind of role are you interested in? Typically an internship will give you a look at lots of roles in an org and to see if you fit in/it suits you. A lot of orgs will post internship roles on LinkedIn and other job sites, or the company's own job page so you should look at companies in your area. You should also speak to your school's career facilitator, as they'll generally have someone aware of/involved in arranging internships, or at least directing you.

If you're considering a GRC type roll, you might be interested in pursuing certs like the ISC2 CISSP or the ISACA CISA/CISM, but those certs are tailored for people with a lot of experience and knowledge in the field. You might also like to get a cert in pentesting/SOC skills, as being able to demonstrate your interest/accomplishments goes a long way. Certifications in cybersecurity are frequently fairly pricey but there are several new certs from Try Hack Me, The Cyber Mentor, Zero-Point and others you might consider after you gain some experience completing challenges.

You should make some kind of home lab, whether it's spare/old computers, virtual machines, a cloud platform, etc., for learning and playing around with things that interest you. Consider making a blog about such adventures, doing writeups of THM rooms, etc. You could also go to meetups or conferences and get on LinkedIn to network with people in the field. Make a habit of learning regularly, following paths on THM, etc. You can verify your THM profile by following this link:
https://help.tryhackme.com/en/articles/6495858-discord-how-do-i-verify-my-tryhackme-account

lethal raven
# rugged delta What kind of role are you interested in? Typically an internship will give you a...

I’m interested in the offensive side of things but honestly for an internship I’m just trying to get experience in cybersecurity especially since I’ve never worked before so I need experience somewhere before I can get a real job after graduating

I’m gonna talk to an advisor about it once my major change goes through since I’m currently a Econ major and my advisors don’t know anything

So far on thm I’ve done pre security and imma finish cybersecurity 101 in a couple days (I do like two rooms a day) I also set up a vm today and I’ll make sure to document the stuff I do with it.

I was thinking I’ll get one of the certs on thm and do some ctfs this summer but lmk if there’s something else I should/could do

PS imma bind my account but after I get past level 9 bc I don’t wanna be piss yellow ;-;

#

Thx for the advice :3

flat sedge
# lethal raven I’m interested in the offensive side of things but honestly for an internship I’...

Doing rooms is a good enough starting point, but the real work in security doesn't happen until you understand how things are deployed, how they break, and what has to be done to fix them.... even if you don't have hands on experience as a sysadmin, seeing the post-install policy scan to ensure it's trued up to approved configs is important.

Strongly recommend you consider experimenting with deploying things to a homelab to try things out, break them, fix them, and then break them again.

lethal raven
#

By understanding how things are deployed and break and how to fix them do you mean using the vm I setup to like deploy a web server or something and inevitably break it it’s kinda hard for me to understand specifically what to do

dreamy surge
#

i know thm soc analyst cert is not recognized and if i do it i also have to do the CySA from comp tia as that's what everyone ask for so I don't want to do both

dreamy surge
#

so cysa is better ?

paper dew
edgy orchid
#

To anyone who has put THM (without the certs) on their resume, I'm curious: what sort of things did you include, and in what way did you include them? I'm thinking about adding the few challenge rooms I've done but I don't know how I'd add them in a way that would actually catch an HR manager's eye

odd igloo
edgy orchid
#

I mean, THM is the only quantifiable education I've got in security so far

dusk wedge
#

Its a form of study, i would put it on there

odd igloo
#

again, not a professional so

edgy orchid
#

Would challenge rooms really be considered CTFs per se? I've only done a couple so far and I only remember one or two having a traditional flag which is why I'm wondering

odd igloo
dusk wedge
#

I did not have it listed on my resume, i did mention it in my letter of motivation and interview,

#

i do have it listed on my linkedin

odd igloo
#

like you can list it, may help a little bit, but won't like completely stand out or smth

dusk wedge
#

Idk, its in the list with the other certs

#

i think mentioning it could be good tho

odd igloo
odd igloo
#

adding something is better than taking it out in most cases

edgy orchid
# odd igloo yes, they will probably be considered like CTFs, and all of the answers really c...

Yeah, I've seen walkthroughs for the learning rooms so it doesn't surprise me. Either way, I'm just really struggling here. Can't land a single helpdesk interview despite definitely being qualified for it, so I'm essentially hoping for better luck with some Jr/level 1 SOC positions, since my resume has a lot of security-related mentions on it.

Honestly at a loss if that doesn't work.

odd igloo
#

idk, maybe I'm crazy

edgy orchid
#

After the Sec+, I'll likely go for the SAL1 unless I need something like the CySA+ and the like for a specific job

odd igloo
dusk wedge
#

You can always apply for soc positions, but it can be alot of factors why they are not calling you in for an interview

dreamy surge
edgy orchid
# odd igloo do you have anything else than thm?

A few months going through Cisco's Networking Academy courses, but that's about it. Oh, and I did an A+/IT fundamentals course through a course site called One Education, as I originally planned to go for the A+ before anything else (but chose not to for a few reasons, not the least of which is the cost)

odd igloo
#

you can write the stuff that you learned on your resume, try to get a job, maybe you will, maybe you won't, idk

edgy orchid
#

I've been applying for entry-level helpdesk positions for months now, not a single interview. So yeah, it has been INSANELY hard. It's taking every amount of effort for me to stay hopeful at this point. I can't exactly afford to pay off a cert if I don't at least have some decent prospects

odd igloo
dreamy surge
odd igloo
edgy orchid
# odd igloo since you can't get any certs, maybe create some projects or get better in tryha...

Home lab projects really are one of the few possible ways I could increase hireability but the primary issue with that is that I live with family, very little space to do much of anything, much less a full home lab setup. I'm blessed to have been given some unneeded hardware for it, which is great, but I don't know where the heck I'm supposed to set it up unless I get a place of my own again (which I can't do if I don't have a job).

That said, I am at least in the process of planning and documenting what I'd like to do so it won't take quite as long to set up if I can figure out the space issue

dreamy surge
odd igloo
edgy orchid
dreamy surge
#

i would suggest that first to find a income source that help you to get cyber certification

edgy orchid
# dreamy surge well there are loopholes everwhere you can get hired in upwork without exp also ...

I'm not so sure about that. Sure, I might land a contract or two with a small business but if I screw things up, or if they want me to do something beyond my expertise, that screws up my reputation. Part of why I'd prefer to actually have a job is so I can make connections, find a mentor or two, and work among a team as I ensure my skills are as up-to-snuff as I think and hope they are. I was chatting with a pro about this subject earlier and when discussing how good my networking skills are, I mentioned that I understand how stuff works and can troubleshoot issues, I could definitely work out things if I were part of a team, but if I were asked to do everything on my own I might have some trouble.

So yeah, at the end of the day, freelancing probably wouldn't work out for me. I do appreciate the suggestion though!

dusk wedge
odd igloo
#

because you're overqualified?

dusk wedge
#

Idk, every application that got denied for me was just an email

edgy orchid
warm hinge
#

try getting some certifications and also rewrite your CV

#

try using that site

wise harbor
flat sedge
flat sedge
floral yarrow
faint creek
#

Hey everyone!
I'm a Software Engineer and MERN Stack Web Developer, and now I'm looking to transition into Cybersecurity, starting with the CompTIA Network+ certification.

I'm currently preparing for the Network+ exam, and I wanted to ask—is it worth starting with Network+ as a foundation in cybersecurity?

Also, I'd love to connect with peers who are also studying for Network+. Studying in a group can make the journey more exciting, productive, and fun.

If you're on a similar path or preparing for the same exam, feel free to reach out—let’s learn together!☺️

red patio
#

Anyone wanna join me

odd igloo
wise harbor
red patio
odd igloo
fresh geyser
#

Is ejpt worth it?

wise harbor
#

If it's required for the position you're applying for

austere ember
#

Anyone in the UK managed to land a role in cyber with just sec+ and IT knowledge, few jobs in the market but getting an interview seems harder than I thought

wise harbor
#

IT experience or personal knowledge?

azure moss
#

Did somebody had a dual study / internship experience in Germany? I’m planning on doing it in the future but see some risks in terms of actuality (mostly because of university content). Thank you in advance

river musk
#

Failing to land any internship. Can anyone help me with some idea how you landed you first internship in cyber security. Offensive pov.

rich pilot
#

Why are you cross posting?

opal brook
#

Hey this may be a stretch but is anyone here from bina beyarok or know someone in that unit? I'm drafting to the idf soon and I'd like to get a modiin / intelligence role but I haven't had any luck with meitav.

austere ember
#

Will do thanks Kate

serene umbraBOT
#

Gave +1 Rep to @queen cipher (current: #2939 - 1)

obsidian rose
#

@queen cipher Hello! Welcome to the THM server!
Recruiting is only available to the people with the Recruiter role and limited to the #jobs-board channel.

queen cipher
#

@obsidian rose ohh so sorry about that, and thanks for informing me

serene umbraBOT
#

Gave +1 Rep to @obsidian rose (current: #45 - 218)

obsidian rose
#

Absolutely, no worries. 😄

queen cipher
#

👍

#

@obsidian rose but am not allowed to chat or post in the ⁠#jobs-board cahnnel, can you help

obsidian rose
#

If you would like to request it, I'll just have to get some information from the staff and I'll come back to you! 🙂

queen cipher
#

Okay thaks i really apreciate your kind gesture

light trout
# odd igloo because you're overqualified?

That happened to me 4 Times when I was trying to get an apprenticeship.

I got rejected four times because they were looking for someone they could train from scratch.

river musk
edgy orchid
# flat sedge Are you tailoring your resume/CV to the position? The automation is usually look...

Also addressing this to @warm hinge since you both had similar remarks. If I have to fully tailor my resume for every single job application, it'll take me two or three times longer to actually get applications out there. The process exhausts me as it is, even just sending them a resume tailored for the job title itself, let alone if I had to tailor it for literally every application. How on earth do y'all pull that off?

edgy orchid
edgy orchid
wise harbor
#

Because I'm pretty sure if it's a laptop for example, surely you could just set it up to not go to sleep even when you close the lid, allowing you to put it somewhere

#

If not then could always make a test one in a VM I think?

edgy orchid
edgy orchid
# wise harbor How big would the device(s) you are using be?

Okay, so here's the thing: I actually have a lot of hardware to work with. I have my main PC, three laptops and a ThinkServer with 4TB of storage in it as of now (a family member had one and didn't need it so they graciously gifted it to me for this purpose). I could theoretically use a laptop but I have dedicated purposes for each one. The only one I could possibly use for this purpose is a 2012 ThinkPad, only 16 gigs of RAM. I know RAM is extremely important for purposes like this, I'm not sure that'd be enough? Even then, I do have specific purposes in mind for that ThinkPad, it currently runs Mint and is supposed to be the machine I use to learn coding and test any sorts of scripts on.

In the long run, I'm just trying to figure out whether I can actually talk the family into letting me set up somewhere (already tried before and got a negative answer) or I'm going to have to figure out somewhere else to move. The latter isn't real feasible unless I have some steady income from somewhere but it seems to be the only viable way to actually get this lab set up the way I'd like

wise harbor
wise harbor
#

Dunno if it helps but I have a friend who has limited space and legit just kinda attached his Intel nuc to the underside of his desk

edgy orchid
edgy orchid
# wise harbor I get it man, just try your best is all

And I appreciate your input/advice, it really does help to have support from people in this time of my life. Really dealing with "it" right now (depression, frustration, feeling impossibly stuck) and the advice and help I've been given from people here and on other communities has been helping me to keep trying whatever I can try. Even if I'm not getting anywhere, it at least makes me feel less alone

edgy orchid
flat sedge
flat sedge
edgy orchid
flat sedge
#

I also store my resume as a type of programming language, which I version with my private git repo. I can make chagnes as I need, commit the change to the repo, and rollback if I need to.

edgy orchid
# flat sedge Do you want a job or not? Spray and pray is only going to be nominally effectice...

If I have to completely exhaust my mental capacity every single day customizing a resume, I'll end up applying to 2-3 listings every few weeks and I'll be too drained to want to keep going on anything. Temp agencies or placing services might be an option, I'll have to look into those but they're going to need to be able to look into remote jobs due to the transportation situation. Do you know if that's very common for those sorts of agencies?

flat sedge
flat sedge
edgy orchid
#

I think I'm just going to log off for now and take a breather. Trying really hard to maintain some sort of hope here but I feel like a half-blank resume is going to completely wreck any slim chances I had. How else am I supposed to discuss what I'm learning and working on?

flat sedge
#

Personal interest, hobbies, etc can be a good way to demonstrate that. If you are just starting out, having a homelab is a very common entry point to the conversation especially if you are deploying and building it in an enterprise-like/lite way

#

As a beginner, you are not expected to have the deep knowledge and resume that you currently have in mind. Keep it to topics you can legitimately share knowledge on. Basic networking, basic sysadmin are great places to start. If you expect to pass a certification exam within 30 days of hire, I think it's fine to say you are studying for it.

A large part of what you need to keep in mind is what the job req is actually asking for. If you are lookign for a junior level job, the background you need is to know what some examples of tools are for that role but not be an expert in them. List your interest, list your homelab and the things you are building in your lab, if you are attending actual university or college courses, don't necessarily list the coursework but do say when your expected graduation is.

edgy orchid
#

It really does boil down to the home lab, which then boils down to figuring out some way to build one up with a tiny space to work with. Not anyone else's problem, I know, just not sure what I can do at this point

muted tendon
#

Hey

obsidian rose
gritty arch
#

Hello there, Is there any Cybersecurity Internship opportunities open? I would like to apply to the same.

sinful tundra
#

Hello everyone, I'm new to cybersecurity and looking for advice on where to start. What resources and platforms would you recommend for building the foundational knowledge and skills needed to meet entry-level requirements?

keen tundra
muted shoal
#

Hi everyone

#

It been a while since I’ve been on this feed.I have been on my grind..graduated from DEVRY in December With a associates degree for cybersecurity but can’t seem get a interview I’ve been a little frustrated with the whole thing

fervent nexus
#

anyone wanna try and hack me?

#

wrong channel

undone shore
#

Wrong server kekw

past kraken
#

he got banned thank goodness

#

rage baiter

#

"i took cybersecurity try and hack me" if i knew how to hack him i would have because he was being a dick

stoic cave
past kraken
#

he shouldn't have typed that if he wasn't willing to face the consequences...

#

I take my craft seriously

stoic cave
past kraken
#

I’ve dropped it, I got a little heated

undone shore
south star
#

Hey guys

upper summit
#

hy

cobalt escarp
#

Hey please drop me a DM if you want to recruit here

shut lynx
#

Oh ok my bad

warm hinge
#

May I ask? In your own opinion, what do you think is an HR BUSTER certificate?

low olive
#

That's like an invitation for that kind of challenge

zinc girder
#

has anyone here done / does anyone here do cybersecurity consultancy? If so could you give me a pallpark on hourly rates please?

undone shore
#

Now, arguably there is indeed a challenge there though kekw

blazing briar
#

do people give projects to freelance pentesters?

void forge
#

Hi , i am Rubab a cyber security student, I am currently pursuing my bachelor degree in cyber security , i am in my 3rd year .
I have completed all the free rooms on tryhackme , should i buy the subscription and go on ? Which subscription would be the best ?
Are there any free certificates that i am suppose to do to get a entry level remote job ?

fringe spade
crimson rock
molten garden
#

please suggest some labs brother

void forge
crimson rock
#

try pwn college its a great free site

dreamy surge
#

hey guys is comtia sec + is certification should i go for as the first certification in cyber

stoic cave
dreamy surge
dreamy surge
rich pilot
dreamy surge
#

like

#

?

hearty jay
#

there's eJPT, ceh practical, tryhackme's jr pt

dreamy surge
#

so these are better than comtia sec +

#

but try hack me is also not asked for rn in the job req

hearty jay
#

idk about that, I was talking about Certificates that requires hands on

dreamy surge
serene umbraBOT
#

Gave +1 Rep to @hearty jay (current: #1455 - 3)

stoic cave
# rich pilot It's IMO a useless cert

Disagree. It's often a requirement due to contractual reasons and is one of the most listed certifications on job postings. The certifications that matter are the ones that appear in the requirements

stoic cave
#

@dreamy surge please refrain from sending unsolicited friend requests. It's against the rules

rich pilot
rich pilot
# dreamy surge 👍

What are your goals and ambitions? There are likely better certs out there depending on what you'd like to do

stoic cave
#

Money is often a finite resource that is hard to come by for people

hearty jay
#

what's the importance of dsa for a fresher who's planning to get into cyber security field, is it that important from interview point of view/coding round?

#

i know the basic concepts of dsa and can code but is a strong hold required?

rich pilot
stoic cave
#

Neither of those are entry and are too expensive for an individual at this point....

#

They're still in school

obsidian rose
#

If you're a beginner, I'm not sure why other certs would even matter.

rich pilot
#

OK, I guess I misunderstood the context

flat sedge
# blazing briar do people give projects to freelance pentesters?

When they do, they are making a mistake virtually every time.

Even independent pentesters should have a consulting company that they are either working through, or that they own. Liability for pentest is too much for an individual freelancer to just absorb, IMO.

flat sedge
vast totem
#

Hey Guys - Has anyone transitioned from DevSecOps into a traditional Security Engineer or Cloud Security Engineer? Any insights would be appreciated!

undone shore
# rich pilot Yes, and I did the OSWA an OSWE, which I think are a more useful type of cert. B...

Certs can be useful for learning, HR, or both.
Sec+ is often very useful for HR, and can be useful for baseline training.

OSWA and OSWE are good for learning web attacks and source code analysis, but aren't nearly as well recognised at the HR barrier (despite being from Offsec -- OSCP tends to be what orgs are actually looking for).

If you're after an entry level job, or to demonstrate baseline security competency, Sec+ can be very useful.

rich pilot
undone shore
#

Look on the bright side... It's more useful than CEH on every level kekw

obsidian rose
undone shore
slender hill
#

Hi everyone! I'm really happy that I finally found a Discord server with a cybersecurity community. I have a lot of questions about careers in cybersecurity, applications, and more.
For the past few months, I've been interested in learning and developing my skills in cybersecurity. I'm 16 years old and I live in Poland. I'm just at the beginning of my journey in this field, but I'm ambitious, a fast learner, and disciplined. I wanted to ask a few questions:
First of all, how hard is it to get a job as a cybersecurity analyst?
If I go through all of TryHackMe’s entry-level content, do some practical labs, and earn the CompTIA Security+ certification, would that be enough to land a job? What else should I expect to be required?
What are some common mistakes I should avoid?
Is it possible — and how difficult is it — to get a 100% remote cybersecurity job in a foreign company while living in Poland?
Do you think 3 years is enough to reach an entry-level position and find remote work for a foreign company?
I'd really appreciate any advice or guidance you can share.

warm hinge
#

can you guys help me dox somebody

keen tundra
brisk mirage
undone shore
#

How do you know that's a man..?

acoustic knot
manic bison
#

Is the tryhackme jr. pen tester certificate worth it for jobs

odd igloo
keen tundra
hard stratus
#

I just opened kali linux 😎

gritty arch
warm hinge
#

is anyone here interested in physical pentesting?

forest spear
#

Hello i'm a french student and i need to do an abroad internship to complete my studies.
I'd like to know if you had any advice/website to share to help me with my research.

thank you in advance !

silver pendant
#

What are the best courses or certs for mobile pentesting? Junior level

warm hinge
#

Hello
I've recently completed a 2 year paid internship (it wasnt that many hours per week but go to school so I didnt mind it)

And I was recently contacting non profits to see if they would like free cybersecuirty services
I was planning to help them meet compliance and create a vulnerbility managment program

But it turns out a lot of them are saying they dont need these services

I see a lot of posts of people saying that they volunteer for non profits and how they know a lot of organizations that need security but it seems like everyone I call dont need it.

Im just trying to volunteer and get some more experience and skill building while I search for my next job.

Any tips. Ideas. Really anything. It gets hard after hearing no so many times.

undone shore
# warm hinge Hello I've recently completed a 2 year paid internship (it wasnt that many hours...

Having completed a 2 year internship, do you feel comfortable taking charge and responsibility for cybersecurity in an organisation (non-profit or otherwise)?
If so, are you willing to stake your reputation, economic stability, and potentially freedom on that?

What you're offering them is usually called a vCISO service. As soon as you put yourself in the role of CISO, you're effectively accepting liability if anything goes wrong (e.g., if they get hacked).
Would not recommend doing that freelance, and I would definitely not recommend doing it off the back of a 2 year internship.

warm hinge
# undone shore Having completed a 2 year internship, do you feel comfortable taking charge and ...

I see. I have done external research and studying. While I didnt directly take a lot of certifications. I took a lot of the classes and self studied but I've hesitated on the certs because of cost.

I do see the concern with experience but I was mainly gonna do a vuln scan, write up a risk assement, then report.

From there i could prob do basic remediation but other than that I would say go find someone more experienced

undone shore
#

Depending on who you're calling, I would wager at least some of them are working for orgs which are too small to have the bandwidth to deal with a full scale cybersecurity / information security programme.

Others may already have things going, or they may acknowledge the need, but not trust your credentials.

warm hinge
undone shore
# warm hinge I see. I have done external research and studying. While I didnt directly take a...

Okay, what does that actually do for them?

Aside from the fact you're still shouldering some responsibility for their security posture (i.e., if they get hacked they can point at you and say "but they said we were secure!"), a small non-profit may not even have dedicated IT assets to scan. Think BYOD laptops and SAAS office suites (Google Workspace, M365, etc).
A larger org which does have stuff deployed on-premises but isn't large enough to have a dedicated security programme likely needs more than you can offer them with a vulnerability scan.

Equally, assuming they have stuff to scan, and you go highlight a bunch of vulnerabilities, what happens then?
As soon as they know about those issues, they're on the hook for them (which is why there are regulations around frequent scanning / pentests / adequate monitoring / etc).
So you've highlighted those issues, then buggered off leaving them to pay someone to come in and fix them, which is likely to be extremely expensive.

warm hinge
undone shore
#

Okay, gonna need someone with local knowledge to chime in on this one, but last I checked anyone dealing with medical data in the US is bound by HIPAA, right?

#

i.e., no matter the size of the org, if they're in the medical field, they're going to be dealing with cybersecurity already

warm hinge
warm hinge
undone shore
#

Again, I'm not US based though. That's a fairly generic answer.

warm hinge
#

but i guess thats what a lot of orgs do

#

its just a risk they take ig

undone shore
#

@urban sapphire this is your world. Care to comment?

#

Either way, would not recommend trying to gain experience by freelancing in this industry 😆

warm hinge
serene umbraBOT
#

Gave +1 Rep to @undone shore (current: #10 - 890)

undone shore
# warm hinge yea thanks I was initially afraid of possible consequences but i figures policy ...

Nah, it's all about liability.
The second you provide those services, you become liable for them.
If something happens -- especially something catastrophic like a ransomware attack -- you're the one who will be thrown under the bus.

Oh, we had beowulf write our policies. We assumed those would be sufficient because they offered their services as a cybersecurity professional.

Beowulf did a vulnerability scan for us and this didn't show up -- we would have fixed it if they'd told us about it!

Beowulf did our risk assessment and concluded this configuration was fine, so we didn't change it. You're saying that this is how the hackers got in?

There's a reason why consultancies have insurance policies for this stuff. If they get sued, insurance eats the bill.
They also have lawyers on call to write up cast iron contracts which alleviate as much liability as possible.

You don't have either of those things as a freelancer.

#

As a side note, that's also what usually happens in big orgs which do have mature security programmes in place.
As soon as something big happens, the CISO gets fired as the scapegoat.

warm hinge
#

wait you mind if I dm something rq

undone shore
#

That depends on what the something is

warm hinge
#

its what my lawyer wrote up for me (GPT)

#

kinda funny in a way
might just be that way for me

undone shore
#

Yeah, don't use AI as a substitute for a lawyer

#

There's precedent for that ending badly

warm hinge
#

im not actually gonna use it.
I just asked for advice

#

then tried it out to see what it would look like

undone shore
warm hinge
#

sure then.

warm hinge
#

either way thanks for the advice

viral socket
#

Does anybody have any tips for studying for the CySa+? I'm going through Mike Chapple's Sybex book right now and am about 1/4 through the SOC Level 1 TryHackMe path. Thanks!

slender hill
#

Guys i have a question what is better PT1 or CompTia Security+

stoic cave
stoic cave
flat sedge
#

Much like someone who emails their credit card data to a vendor, that is not a method of transmission PCI will apply to.

undone shore
#

By the sounds of it they're talking explicitly about medical non-profits -- i.e.,
healthcare orgs, no?
Either way, cheers for the input both of you ♥️

warm hinge
#

does anyone have any interest in physical pentesting

foggy gust
#

Hello. I am currently in the US Military and I am looking forward to getting out within the next year to pursue cybersecurity. I currently work in IT and have been trying to get as much experience as I can in this line of work, but I've always found myself coming back to relearning the fundamentals (CIA, AAA, basic cryptography, etc.), however, after getting the premium subscription to THM, this has been my first time into taking my own individual training for cybersecurity (CS) further. After much research, I have discovered. for myself at least, that its safe to start from the ground up and become a CS Analyst, or at least work anywhere within the defensive side of cyber. I've been working in IT for 5 years, and I currently have SEC+. I am now pursuing to get CCNA and going back to school to get my Bachelor's in CS at University of Arizona.

storm totem
#

YES

foggy gust
#

I don't really have an end goal right now in regards to CS, but I know that it is something I want to be involved in. If anything, I would love to work more with cryptography, which I'm sure is more the CS Engineer route. Anyways, my question to the community is what's next for me to do? I would love to get as much certs as I can from the military, but even that doesn't seem enough. I'm starting to look at jobs now and even for some entry level positions, they still want some sort of degree under your belt, yet all I usually see is the opposite. They have degrees but no experience, or plenty of experience, but no degree along with certs/skills that don't even match the positions responsibilities. This honestly makes the decision to get out a little tough on me because of job security. I even got offered a $80K bonus to stay in the military for 5 more years and get the opportunity to work as a cyber analyst... but thats the catch. Stay in the organization that I've been telling myself to get out of for years, and now they'll do whatever to keep me in. I'm not that special but it's clear that they need numbers. Most will say that'd it would be silly not to take the opportunity, but I would honestly sacrifice my mental stability and happiness just to work in somewhere where I don't feel like I belong. There's a lot more to that I won't share here, but any input on that is welcome.

#

To sum it all up, I'm still leaning towards getting out and I have 1 year left. I know THM courses alone won't get me too far, but it has definitely been a great start. I got no regrets with my purchase. I'm just going to make the most of it, of course. What are some ideas or skills I should need to pick up before I put together a resume and start putting myself out there?

fleet nest
junior cliff
#

Hi guys

#

Hey everyone wanted to ask the experienced people or anyone advice … so I’m currently starting a cyber security lvl 3 boot camp ,I want to freelance in cybersecurity (ethical hacking with programming /codiing ,pentesting/redteam ) after the boot camp you get a guaranteed job interview and I wanted to ask advice on what you guys would pick, Paid IT APPRENTICESHIP, business administration and office based roles,customer services or call centre roles ,data entry or analyst roles ,IT entry lvl roles ?

warped pelican
#

hello

warm hinge
junior cliff
#

Yes that what I was thinking

#

If I show you what my course offers can you tell me the value

warm hinge
junior cliff
#

Ok

spice plover
#

Finally got a help desk tier 2 job! Praise the lord!!!

odd igloo
solar hinge
keen tundra
quasi minnow
#

@spice plover Congrats!!! coolguy

warm hinge
#

they also need some level of cybersecurity to meet the requirement for certain grants

flat sedge
warm hinge
undone shore
warm hinge
hazy dagger
#

Just asking

warm hinge
#

yes I've only recently got into discord

#

is there some problem?

hazy dagger
hazy dagger
warm hinge
hazy dagger
warm hinge
#

for cyber security no. well not really.
On discord yea I am

warm hinge
#

i did get some feed back on it thanks to muiri

hazy dagger
warm hinge
hazy dagger
warm hinge
#

well good luck. lmk if I can do anything to help you.

hazy dagger
serene umbraBOT
#

Gave +1 Rep to @hollow prawn (current: #2955 - 1)

warm hinge
#

👍

flat sedge
warm hinge
#

i might be mistaken so please feel free to correct me

spark light
#

Realistically, do you think it’s truly possible to get a job in cybersecurity without any formal educational background?

warm hinge
#

I think help desk is kinda the more common/basic cyber starting job

#

so basically grunt IT jobs

urban bridge
warm hinge
#

That will get you some experience but after that it really depends on your experience and the sort

#

your skills, certs, education, experience, etc.

#

I could potentially help you more indepth if you want to dm

#

and it depends on what type of experience you are looking for

#

either way anyone is free to dm me for questions, complaints, or anything really

foggy gust
#

So with that kind of experience, you can at least show that you know how to break down something complicated into something that is understandable to anyone. In my 5 years of IT, I always stumble across someone who doesn't understand what's going on around them. So if you have that ability to break it down into simpler terms for someone who has zero awareness of cyber security, then you actually know what you're talking about. Sounds silly to put it that way, but you would be surprised how many people in this field don't know what they're talking about. It also shows you have great communication skills as well.

#

Again, help desk is help desk. You can go anywhere for that sort of experience. It's crucial in this field because if you can't break it down to a customer, you're going to fail at explaining what's happening to your boss and other essential personnel in your team and get yourself fired instantly. Getting A+ will just verify that you know the basics of computers and good security practices, but you can get that knowledge anywhere for free

rustic coral
flat sedge
granite hornet
# rustic coral I would disagree on cyber security being an easy pivot. Yes, it is possible to t...

Yeah and based on conversations I've had with my classmates, some of whom are very experienced in the industry, it can be very difficult if you don't have a background in ITC. If you're doing a "180 degree" career change it's going to be tough. If you've been a sysadmin, developer, or network engineer etc you've got directly relevant skillsets. I guess some people do a lot of complicated home networking and set themselves up media servers and such so they'd perhaps have some foundation skills there, compared to someone like me (linux user "good with computers").

wooden timber
#

How about someone who has been in QA for 4 years and then switched to cyber and worked as a Security Analyst (but only for 8 months now)

#

and after that 8 months , am not working anywhere , but now on a jobhunt for the past 4 months

granite hornet
wooden timber
#

I have a Masters Degree in Cybersecurity from a french university

#

I had a AWS security cert which expired in 2023

#

Now I'm learning through THM

granite hornet
#

cool

#

What was your undergrad?

wooden timber
#

I consider myself a rookie in Cyber still after all these quals , I have an impression that there is too much to learn and update everyday .. and each and every job demand a specific in detail skillset (for eg, they don't demand just an experience and knowledge, they demand working experience with a certain specific firewall like F5 or Akamai.
Or a working experience in MITRE ATT&ACK, STRIDE, PASTA, VAST .. etc etc)

#

It feels IMPOSSIBLE to have gained such experience , and I am not getting any answers for Entry level jobs or fresher cyber jobs

granite hornet
#

Knowledge of Mitre Att&ck seems pretty fundamental to me, that's a core framework.

#

But you're right, there's SO much to learn. This is what I'm finding tough rn. Figuring out whether there's any point in persisting, and if I do, what to focus on. Feeling a bit overwhelmed.

granite hornet
# wooden timber It feels IMPOSSIBLE to have gained such experience , and I am not getting any an...

Maybe your resume/CV needs work? My first job application with a government agency here, when I asked for feedback, I was told mine needed to be more focused and I needed to ensure I addressed the criteria. So I pruned my cover letter and CV massively - even totally left out some jobs, just focused on tightly relevant skills - and the next application got to the interview & referree follow-up stage.

wooden timber
#

Exactly the same, My family wants me to give up on my cyber dream and get back to QA so that there will be money for now atleast.
Tough times

distant glen
lethal spade
# wooden timber Exactly the same, My family wants me to give up on my cyber dream and get back t...

Well, I speak as a person who has been unemployed in moments of crisis, and I am now XD. You could get a job to have some money for your stuff and still search for vacancies in cybersecurity.
But see with AI what she thinks about your curriculum, that is something that most people started to say on LinkedIn, as a lot of RH uses it now, it is an excellent help to find where you could improve your curriculum. And check if your country offers any assistance in finding a job. Sometimes, there is help available for enterprises that contract unemployed individuals.
That is what I am doing now.

wooden timber
#

Are you still searching for a job?

lethal spade
wooden timber
#

Best of Luck mate

wooden timber
serene umbraBOT
#

Gave +1 Rep to @distant glen (current: #2957 - 1)

sonic trout
#

looking for what to do , i am a graduation student in my last year and want to pursue a carrer in cyber security and have a skills of linux , shell scripting , js , networking and operating system

dusk wedge
#

depends on what you wanna do after

#

because cybersec is a big area

sonic trout
#

well what can be good for a fresher in this industry as a blue teamer

rocky sundial
#

Well, hopefully this Job board will be my saviour, just got told my team are going to lose their jobs

snow goblet
#

I would like to be a bug bounty hunter but i don't know what i should learn to achieve that

wooden timber
raw jackal
#

Hey guys. Little help for getting a job in cybersecurity. I passed eJPT certification recently, top 5% on THM and preparing for Comptia Security+. I can program a bit and have my portfolio and github where i post my programming projects, tutorials or articles. I'm also a master student in cybersecurity. Could you tell me what else should I do to get a first job? I'm thinking like I have a good profile but it's still enough... what's the reality of that

#

I'm also more into red team

#

I'm open for any role at the beginning, tech support, penetration tester or even some compliance stuff

#

any tips?

versed gorge
#

hi guys im new here i need hackers and spammer friends

warm hinge
#

not easy. Easier.

warm hinge
warm hinge
warm hinge
#

Again. If anyone disagrees with me. Feel free to correct me. 🙂

stray breach
#

@warm hinge if you were to start over, (at less say 30ish hahaha) where would you start? which certs would you pursue?

raw condor
#

Hey guys! Aiming to get some certs after my semester is over. I was considering getting EC-Council's CEH but I see the reputation of it has taken a punt even if most companies ask for it as an HR buzzword lol

I have an option to get two of the following: eEDA, eCDFP, eCIR eCTHP, eJPT, eCPPT, eWPT, eMAPT and eWPTX, certified by INE. Would love to know your opinions!

warm hinge
#

I wouldnt say I have a particular preference to the path you take because the industry has changed throughout the years.
Madhat I believe the channel is called has some advice I would agree with.

#

I think there was even a decently recent video on certs

forest spear
#

Hello i'm a french student and i need to do an abroad internship to complete my studies.
I'd like to know if you had any advice/website to share to help me with my research.

thank you in advance !

rugged delta
forest spear
#

i already checked linkedin but didn't see many

rugged delta
forest spear
ivory pier
#

How do I get a basic entry level job in a field that can lead to security analyst? Will an associates degree in IT Cybersecurity even get me a basic job?

#

Are there any skills or things I can do to improve my chances?

#

Also, is it possible to start in the field remote?

frank basin
#

great question, i certainly cannot believe one would have to have a degree to get a job in the field. have you found or mitigated any vulns or tried any bounty programs?

#

those always look great in interviews or on resumes. certifications are extremely helpful too

granite hornet
warm hinge
#

especially if its from a tech job

ivory pier
#

I've been working through THM rooms a bit where time allows

#

Only 5 completed rooms so far.

frank basin
#

mitigate vulns in a corporation you work for to put on a resume. for example - let's say your company configures an AD system that exposes all users in plain text. you find this, escalate it to the appropriate team to resolve. document that stuff. you want yourself to shine when youre attempting to go after a job position

#

it's not all about certifications and degrees and practice exercises. what i'm saying is take initiative and write that stuff down. it may seem minor now but it looks really good later.

#

does that make sense?

ivory pier
#

Yes it does make sense.
Except I'm currently not working, I switched careers from healthcare to cybersecurity. I got burned out from the beaurocratic BS and hoops I had to jump through as a nurse just to take care of a patient.

frank basin
#

lol, listen, i made that transition too. i got burnt out on patient care, so i know exactly what youre going through

granite hornet
ivory pier
#

I understand it's early, I like to plan ahead so I can figure things out and be better prepared when things inevitably go wrong.

#

Doesn't Sec+ require like 2+ years in the field?

warm hinge
ivory pier
#

Other test?

warm hinge
#

comptia sec + right or am i tripping

#

wait ignore me for a sec

granite hornet
frank basin
#

good plan, i can appreciate that. dont focus on the degree or stuff that'll take years. youre doing the right thing by taking these rooms and exercising you critical thinking skills.

warm hinge
#

nvm i was thinking of smth else but yea its a content based one

granite hornet
#

My experience of tertiary study is the associate degrees aren't worth much BUT if you can afford them, they do provide structure and motivation, and show commitment. They can also connect you with a cohort of professionals.

ivory pier
frank basin
#

i wish i could like @granite hornet message

ivory pier
#

At this point, I have two more semesters left, I figure I might as well finish it

frank basin
#

he is right, the degrees are worth nothing. your experience and initiative will make the difference

granite hornet
ivory pier
#

Yeah, I learned that AFTER lol. But, it took me being in school to find out that school was useless.

#

IT Cybersecurity

granite hornet
ivory pier
#

Lol, all good.

granite hornet
#

But it should be proving you with some decent foundations if you select good subjects

frank basin
#

well, not entirely useless. i was being overly dramatic.

#

my point - youre doing the right thing. keep focusing on what youre doing. take the knowledge you learn and apply it towards the next company you work for. let's say you become an accountant somewhere. but you have this knowledge in security and you realize your company has a blatant misconfiguration (sql injection) on their site. notify the IT team. you dont have to solve it, that's not your problem at the time

ivory pier
#

IT Fundamental 1&2, Principles of Infosec, Network security Fundamentals, Network attacks & firewalls, Network defense & countermeasures, microsoft servers.
Those above are all completed. My next semester this fall is going to be
Ethical Hacking
Scripting
Virtualization
Emerging Innovations in Technology

granite hornet
#

So like it's your starting point, good on the CV, demonstrates commitment. Now you want to complement this with some home lab study and an industry cert. The degree should set you most of the way to Sec+ prep. Plus do THM labs that focus on industry frameworks and tools such as SIEM, log analysis etc.
Those subjects you've listed look great!!!

frank basin
#

document that stuff. bring that info to an interview. that stuff adds up. and says - i know what i'm doing and i am trying to contribute to our company in a meaningful way. i will protect our systems

ivory pier
#

Alright. Thank you for the help everyone. I'll keep working through the rooms, and try to find some other things to do that you have mentioned.

granite hornet
#

why doesn't this server allow emotes, it's driving me nuts.

ivory pier
#

Could I potentially get hired as a Junior Security Analyst at this stage or is that even something that would take more skills/experience?

#

I forgot to ask about that earlier.

granite hornet
ivory pier
#

I've made the Dean's List twice so far. Grades aren't my issue, thankfully.

#

Being a nurse taught me a lot about preparation.

granite hornet
ivory pier
#

Good point. Not sure I could remain unbiased when confronted with the inevitable drama and BS.

#

Is that something I could do remote?

granite hornet
#

I guess it depends on whether you want to use that 'career capital' or pivot completely

ivory pier
#

I may have to swallow a pill and go back. I'd choose a completely different hospital group though.

granite hornet
#

I know quite a few remote itc folk, though I think it can be challenging to find entry level remote. I should poll my student discord group and see what they're all doing.

sweet yew
#

Are you a teacher?

#

or a student in a student discord group lol

granite hornet
#

Most of the group are already security professionals upskilling, plus some career changers.

sweet yew
#

ah I see

fading spire
#

Once a person knows the cyber sec basics (like a few starter courses and prac), does anyone here have recommendations on the specific avenues that are best to get into (offence, defence, social engineering etc...)?

keen tundra
fading spire
#

Thank you!

granite hornet
#

(I'd add that everyone and their dog wants to be a pentester, because hacking is cool; my suspicion (just an opinion though, do your own research) would be that blue team, security analyst would offer more job possibilities, particularly at entry level. Maybe look towards developing into red teaming once you know how defence operates. Just a thought, anyway.

fading spire
#

I appreciate it :> Makes sense.

cobalt arrow
#

Hi guys

dusk wedge
#

hi

finite robin
#

Hi there 👋 looking for some help and guidance on how I should start out if I wanna get into bug bounty hunting, and if THM has any pathway that helps get into this field ?😅 complete beginner here, thanks!

graceful magnet
junior cliff
#

Hi

#

Hi guys I’m a beginner I originally was red team and was starting that but I got into this online boot camp and this is what I learn = Week 1: Understand Cyber Security Principles
• Week 2: Threat Intelligence in Cyber Security
• Week 3: Cyber Security Testing, Vulnerabilities, and Controls
Week 4: Cyber Security Incident Response
• Week 5: Understand Legislation and Ethical Conduct within Cyber Security
• Week 6: Professional Skills and Behaviours for Cyber Security

So would it be smart to switch to blue ?

Advice

warm hinge
#

The switch the blue is entirely up to you if you want to

#

But if you’ve never tried it try and learn some if you’ve only ever done red teaming

round hemlock
#

Hello, I am also a newbie here but I am nursing a Passion for Cybersecurity, especially Penetration testing. If anyone could be of great help to mentor my way, as in giving me some pointers so that I will get the most out of the midnight's oil that I burn, I would be very much pleased and grateful. Thank you.

rugged delta
round hemlock
serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #21 - 516)

rugged delta
serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #21 - 517)

junior cliff
junior cliff
#

Week 1: Understand Cyber Security Principles
• Week 2: Threat Intelligence in Cyber Security
• Week 3: Cyber Security Testing, Vulnerabilities, and Controls
Week 4: Cyber Security Incident Response
• Week 5: Understand Legislation and Ethical Conduct within Cyber Security
• Week 6: Professional Skills and Behaviours for Cyber Security

#

That’s everything I learn in the bootcamp

#

It’s 8 weeks

#

But you see how it’s blue tan

#

Team

white socket
junior cliff
#

Yhm

#

Yh

#

I originally wanted to do only red team but after getting on that and it’s blue I’m thinking might aswell switch to blue along side it ,due to the steep and realistic learning curve of red

white socket
#

What’s the cost?

junior cliff
#

No

#

It’s a bootcamp that you have to get in

#

It’s free

white socket
junior cliff
#

Interview

#

I’m from uk

#

It’s funded

white socket
#

Oh, Im from us : (

junior cliff
#

Ahhh damn

dawn quartz
#

hi I'm Jamil

#

new here, got into CS not long ago, still learning...

celest sequoia
#

Hey guys.
Friend of mine from USA, recently graduated with computer science degree and would like to get into the software development field as a career.
Anyone have any advice for him or potentially people I could forward information about to him ?

rustic coral
#

no one talks about that though....

#

I just went to the Bsides Seattle conference back in April and a big talking point was mental health for Cyber Techs.

ivory pier
#

Oh great. Yeah that's a ringing endorsement to go back to that shitscape of hell.

#

Healthcare used to be a good thing, now it's just a money pit for greedy douchebags.

#

Someone needs to 5/9 healthcare records lol.

rustic coral
#

Some doctors are a bit much too but... thats another convo

ivory pier
#

Being told how to treat a patient by some suit who's never touched a medical record in their life.
Chef kiss

#

And not just once either. Once a week.

rustic coral
#

sounds about right

dawn quartz
#

if there are CS professionals here, at what point does one start job-hunting? like after 2 or 3 certs....or....? whats the vitals to know that if one has this , he/she can get a job

#

need y’all insights fr

abstract prism
#

hi

#

is there anyone who is a peneteration tester?

granite hornet
granite hornet
honest kelp
atomic siren
#

anyone who's working in any cybersec domain from South Asia for foreign company remotely? how did you guys get the opportunity? i am pretty sure most of the international company don't hire remote employee due to security restrictions and stuffs.

rugged delta
rugged delta
dawn quartz
dawn quartz
serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #21 - 518)

graceful locust
#

Also i m new to cybersecurity. Bought TCM pentesting course and its going good.
Also started with free roadmap for tryhackme.. can anyone tell me that path is good enough for entry level penetration testing? And is there any way to sort machines like complete beginners to level up? I mean step by step? Bcz i have not done any web penetration thing..
any help and suggestions will be appreciated.

keen tundra
keen tundra
graceful locust
serene umbraBOT
#

Gave +1 Rep to @keen tundra (current: #1 - 5360)

willow jolt
#

Hey I am a newbie so can anyone suggest me which certifications should I prefer to build a offsec career

elfin sluice
#

Hey everyone, I’m looking for some honest advice from students and professionals here.

I live in India and my dream is to work in government cybersecurity roles like CBI, IB, or State Police Cyber Cells. That’s why I initially took admission in a BSc Cybersecurity course, thinking it would help me.

But now my college is saying I’m the only student in Cybersecurity, so they want to shift me to BSc Data Science along with some additional Cybersecurity certifications.

Some people told me that a Cybersecurity degree isn’t much valued in the private industry and that Computer Science or Engineering is better. But my focus is government cyber jobs, not private companies.

I’m also preparing for SSC CGL, targeting technical and cybersecurity-related roles in the government.

Can anyone here share their opinion — is it okay to go for BSc Data Science + Cybersecurity self-study for my goal, or should I look for something else?

Honest guidance would mean a lot, thanks in advance!

willow jolt
elfin sluice
#

Okay I will ask them and then informed u

willow jolt
#

Yup

willow jolt
ivory valve
#

hey, im new to cybersecurity

hazy dagger
willow jolt
ivory valve
#

and not having premium in thm, can anyone suggest me how should i start

hazy dagger
willow jolt
willow jolt
willow jolt
hazy dagger
willow jolt
#

Started in 2020

#

Then I quit because I was in military school

#

Then I again start in 2024

patent badge
south monolith
abstract prism
rugged delta
trail abyss
#

second flag

meager perch
#

Is there possible for an individual to work remote as PenTester nowadays ?

#

I mean, is this behaviour still encountered these days ?

willow jolt
willow jolt
willow jolt
south monolith
willow jolt
#

Okk

rustic fossil
#

test

sweet folio
#

Hello everyone, a newbie/amateur seeking for a mentor

lilac oasis
#

I'm looking for my first job with cybersecurity... any recruiters around here? (Newly graduated and I'm from Brazil)🙏 🥹

keen pawn
#

has anyone here passed ejpt?
do u need premium plan or is fundamentals sufficient

fringe spade
keen pawn
#

Ine

craggy jay
#

hello, is there a good free resource, preferably video, for learning M-365 administration?

fringe spade
severe furnace
#

Hello guys,
I'm a language teacher and looking to transition to cybersecurity. I have covered some basics like intro to IT, linux basics, python basics and I'm unsure about what to do next. I have researched a lot and their are manyyy opinions and it's honestly overwhelming. Chatgpt, gemini, youtube, medium, roadmaps. I'm cooked..

keen pawn
serene umbraBOT
#

Gave +1 Rep to @fringe spade (current: #282 - 28)

severe furnace
jaunty gorge
severe furnace
#

Should I watch something for it first? Where do beginner friendly ones can be found?