#cyber-and-careers

1 messages · Page 54 of 1

honest coral
#

I will keep that in mind

#

Thanks for the advice

civic belfry
#

Hi guys, I am new here. I am just a non-IT guy, graduated with business major, no IT background, no knowledge about cyber security whatsoever, but i want to change my career and started looking online for my very first step. I am planning to take a google cybersecurity certificate on coursera, try to get CompTIA exam, learn python on some guys on youtube. And then i may do a master's degree. Does it sound like an okay plan? Or am I missing something? I am a slow learner, not that I am dumb, just learn things slowly and kinda hard to concentrate for a long time. But i really really want to change. What do you guys think? Thanks for reading this long post. Lol

fathom gorge
# civic belfry Hi guys, I am new here. I am just a non-IT guy, graduated with business major, n...

Rather than saying you're a slow learner try to frame it as, "I learn differently". There really is no one way to learn, even if many people in IT/Cyber may think otherwise. Having a degree in business is not a bad start. Whether people like it or not at the end of the day, for most companies, cybersecurity is a business decision. "What is the minimum we need to do to stay compliant" for example. Cybersecurity is rarely seen as a money maker.

Make sure you do practical exercises too, most career paths require practical experience. If you can manage to get to a position where you both speak the IT lingo and business lingo you could set yourself up real nice for a decent cyber career. Make sure you have a plan on what you want to achieve before you start studying all these things. Much easier to have a goal and figure out what you need to do to achieve it then to just start doing without a sense of direction. Have you considered GRC for example?

inner gazelle
#

what are some begineer level free certifacte to get started with !

tired fern
#

Hi guys, I am looking for a decent OT cyber sec cert , I am aware of 62443 and GICSP and they are expensive . Any Ideas what alternate cert we have ?

fathom gorge
#

Also CompTIA is working on an OT cert, but I think that wont be out until Q1 2026

#

Not sure if there are any free certs that a potential employer would really care about. You can get plenty of "Certificate of Participation" through TryHackMe CTFs that will list your place on the leaderboard. Depending on your situation you may be able to find some financial support or scholarships.

tired fern
#

thanks mate

shadow viper
#

hii guys, does tryhackme help me understanding on offensive security? as i want learn it and at the same time i got free CEH exam this 16/10 that i need to take seriously if want persuade it.. can it be either freelances or full time job if i persuade it?

keen tundra
shadow viper
#

alrdy try free and seems promising for me who less knowledgee

knotty trail
#

Hi new to here. I recently started leaning this field using tryhackme as main source. honestly im loving what im doing but at the same time i sometimes feel overwhelmed by watching those really skilled pentester, ethcal hacke and stuff feeling how do i even get there. did you guys go through where i am now? is it really abt consistency?

keen tundra
keen tundra
plain path
tulip gate
#

hello guys, if i studying soc roadmap on tryhackme, what other resources and certificates i need to get so i can get a job as soc analyst? + does anyone here get a job after studying at tryhackme? what did you studied more?

solid plover
#

i am a student in computer sci first year and i know nothing about cyber-security and i want to learn and work in cyber-security i started with switching to kali linux as my main os and i am doing good with that but still don't know how to learn ctf pentration testing and be a soc for an example does supscribing to try hack me premiume will help or there is a course i have to take?

gusty bone
#

Hello anyone here tell me how many years took you to get a good salary job

fathom gorge
serene umbraBOT
#

Gave +1 Rep to @fathom gorge (current: #590 - 11)

fathom gorge
# knotty trail Hi new to here. I recently started leaning this field using tryhackme as main so...

Don't compare yourself to those who've been doing pentesting for years already. If every runner compared themselves to those running in competitions we would have no amateur events anymore! Work your way through the THM paths one step at a time and you will see improvement every week. Then at some point you'll be able to understand what those pentesters are doing and learn from their methods.

worthy shoal
fathom gorge
serene umbraBOT
#

Gave +1 Rep to @fathom gorge (current: #547 - 12)

molten lichen
solid plover
solid plover
tulip gate
desert gyro
#

Been blown away by Tryhackme and the learning paths to get hands on training, i have done security+ network+ A+ google Security certificate all this year and studyed so hard but something was missing it really did feel like it was theoritical knowledge, did not make ready to put myself thru interviews and jobs. Tryhackme has been the key to unlock the knowledge and that with some of the amazing walkthrus by memebers (Shout out to THE HELPFUL HACKER) it really embeds the concepts to real life.

Added to this I now use GROK AI to help me also with scripting / shells for instance to help me breakdown what is happening and why, but also how i can conduct an investigation or alert to detect these remote sessions, I am just addicted to the learning my curosity on how, why, what and having that information at hand and Labs to actually do what you learn is just next level. I am working towards the tryhackme SOC Level1 now.

Anyway I thought I would share my experience, I am moving to Perth AU early next year if anyone knows of any companies there that have SOC Operations Teams.

tulip hearth
#

Hi , I want to ask what should I do when I finish network basics and networking essentials.cause I'm a little bit confused,should I go directly to tryhackme(which room should I start with ),or go to security+,network+ gcsc.

daring flax
#

Hi guys, so currently i'm in my final year of high school and want to pursue computer science in university after I graduated out of HS. Aftwards I want to work as a pen tester/red teamer.

Just finished Pre-Security and currently doing Cyber Security 101. Once I finished cyber 101 I shall do the PenTester path.
Is this a step in the right direction?

fathom gorge
# tulip hearth Hi , I want to ask what should I do when I finish network basics and networking ...

Try Hack Me is excellent to gain that hands-on experience and put everything you learn into practice. The Sec+ is to show you understand the terminology and security practices, Net+ is the same but for networking . The question you should ask yourself is what are you trying to achieve? Do you want to be a Network Analyst? Or a Pentester or one of the many other fields Cybersecurity has to offer. Once you figure this out you can start more targeted learning. A great way to figure this out is to start with the Pre-Security and Cybersecurity 101 learning pathways on TryHackMe

fathom gorge
tulip hearth
#

How can I choose

fathom gorge
#

What is it that interests you? Do you like figuring out how somethings works, understanding how you could avoid authentication for example. Or are you more interesting in figuring out if and how an attacker got into a system.

fathom gorge
#

Learning the basics of each and then really dive into the one that you prefer the most.

daring flax
# fathom gorge Yeah absolutely, since you still have a little time also checkout the other lear...

Yeah for sure I'm also gonna do the other paths once I'm done w the pen testing. Good to be an all-rounder.
But the thing is, what can I do to up my portfolio so that I can get into internships when I'm in uni at any of those roles once I'm done with learning all those paths?

I know that for software engineers/programmers it's to build programming projects (beyond to do list and basic calculator) to show your capabilities and solve leetcode problems in the interview. What about cyber security? What can you do to prove your worth?

formal smelt
#

Hi everyone, I studied Data Science and Econ in college and worked as a data analyst. I want to pursue a graduate degree and was considering cybersecurity cause I find it interesting but I have no background in it, academic or professional. Do you think that it is possible to pursue a Master's in Cybersecurity with no background? If you have any suggestions on what I should study before doing that, please let me know!

fathom gorge
# daring flax Yeah for sure I'm also gonna do the other paths once I'm done w the pen testing....

Homelab would be a very good project for you, setup a homelab, setup up some detection and then try and attack your own lab. Analyze the logs afterwards and either create a write up of all of this or a well documented video. Since you're going into CompSci, the Security Engineering path may also be very interesting to you. You could combine a lot of you CompSci knowledge with the Security Engineering role.

fathom gorge
fathom gorge
tulip hearth
fathom gorge
tulip hearth
#

Okay so I shouldn't bother my self about which room to chose

#

Taking the easy one is enough for me rn

formal smelt
daring flax
serene umbraBOT
#

Gave +1 Rep to @fathom gorge (current: #508 - 13)

fathom gorge
daring flax
fathom gorge
fathom gorge
# daring flax Alright good to know, feeling quite lost when I had no one to talk to about this...

Haha yeah I come from a Software Engineer background myself and Cybersecurity initially does seem overwhelming. I may be biased but it is a really good place to start from. You'll understand so much of how things work behind the scenes already. Once you learn one or two programming languages you'll start to see patterns and can easily read other languages too. Very useful when analyzing Malware / Payloads.

daring flax
fathom gorge
# daring flax So you must've had created a learning system by this point. So what would you sa...

TryHackMe's learning paths are really well layed out, often times the next learning path that you follow builds on knowledge you learned in the last.

What works for me is to focus on a single topic for a few days. I took my Security+ exam before I really started digging into TryHackMe and that was a mistake. While I did pass with a decent score, I had no idea how most of the terms asked about in the exam were actually applied. Kerberos, yeah sure some kind of key and ticket system. But then I did the Directory room on TryHackMe and that is when it clicked.

If you hop between different types of room too much you'll likely forget new knowledge. Focus on SOC or Pentesting, take notes as you go and use those notes in the challenges at the end of a module. There is a concept called "learning by teaching". After a challenge, create a report in which you pretend to teach someone else how to complete that challenge. It will help you figure out where you struggle and force yourself to make sure you really understand what you did. This last part can be a big game changer but it does depend on how you learn.

#

This is also where, in my opinion, you'll find the difference between two people using TryHackMe. Writing out everything you learned in a way that you could teach a class about it will take time. You likely wont make it to the top of the leaderboard that week. But I promise you, you'll gain knowledge for life. If you take your time, and make sure you really understand what you learn in each room you'll never be number 1 on the leaderboard, but you'll also never need a write-up from someone else. CTFs will be so much easier, and once you get into an interview with a recruiter you wont just be copying the dictionary definition of a term. You'll be able to explain why it is important and how it is implemented.

daring flax
#

Yeah lol I was kind of worried about not scoring that much in the leaderboard (fear of getting demoted lol) a bit more than I should have cared for.

#

And idk why but initially before talking to you here I feel like I "need" to finish a lot of these rooms as quickly as I could, often skimming through the boring but important parts

#

But anyhow, I'm glad this clears up a lot of confusion

fathom gorge
# daring flax And idk why but initially before talking to you here I feel like I "need" to fin...

That is perfectly normal, the down side of gamification is that it become a game of points. Gamification is a great way to keep people coming back but the focus may shift to the wrong priorities. I wont lie, the more practical parts can be a lot more fun ha. But if you're serious about making a career out if it, make sure to, at least every so often, take the time to read and understand what you're doing.

It is also important to understand that a part of both the professional SOC and Pentesting roles is writing reports. SOC level 1s need to be able to explain why they escalate a ticket. Pentesters need to report on the vulnerabilities they found and recommend ways to solve those.

daring flax
fathom gorge
daring flax
#

Will do

viscid vigil
#

Hey everyone, I am new to cybersecurity, so can anyone help me out on how I can start a career in this field, and provide free resources to study

junior cliff
#

I guess come back here when u done that

civic roost
junior cliff
civic roost
#

theyre 99% of the time just inroductions

flat pelican
#

he needs introductions

#

not practice

civic roost
#

I mean this is like just taking the first lesson of every room

junior cliff
#

It’ll still pay off

#

And hack the box

civic roost
#

not really

#

if you dont pay then there is way better free sites~

flat pelican
#

if u have free sites suggetions please enlighten us

civic roost
#

idk if its against the rules here

#

but ill go ahead

#

college.pwn

#

is good

#

its fully free

junior cliff
#

Oh fr bro ?

#

😂😂ur putting me on let’s hear them

junior cliff
civic roost
junior cliff
civic roost
#

use ur brain bruh

civic roost
junior cliff
#

For example hack the box

junior cliff
civic roost
#

dude are you indian

junior cliff
#

What ?

dusk wedge
junior cliff
#

What has that got to do with anything ?

civic roost
#

your english is bad

#

i dont really get what you're saying

junior cliff
#

Bro what

flat pelican
#

guys chilll out , u gave us a good site , thank u no need to heat things up

junior cliff
#

I was being nice to bro

junior cliff
civic roost
#

"why would you not tho everyone does all the time for example hack the box"

#

what does that even mean..

junior cliff
#

🤦🏽‍♂️

civic roost
junior cliff
#

Bro u Carnt say that 🤦🏽‍♂️😂

civic roost
#

dude are you a youtube shorts kid?

#

the heck are u saying

junior cliff
#

You said “i was wondering if its allowed to share other sites that is not try hack me” so I answered "why would you not tho everyone does all the time for example hack the box"

junior cliff
flat pelican
#

guys please this is funny , why are u guys fighting , stop it and man up , go learn skills and make money thats why we re all here for , Stay focused

junior cliff
#

😂😂😂I’m chill like the inside of a freezer

viscid vigil
serene umbraBOT
#

Gave +1 Rep to @junior cliff (current: #648 - 10)

junior cliff
torn narwhal
plain path
#

@keen tundra message spammed in multiple channels.

grand phoenix
#

I'm on the fence of whether I should just study up and get the CISSP.. Any thoughts on that from pros? Maybe holders? How has that affected your experience in IT and management in general?

fringe spade
flat sedge
#

It is expensive though, if you can get your current employer to pay for it, that is the way to go

balmy dove
#

there's also some requirements for how many years you've worked in infosec and you need a sponsor

fringe spade
#

Also, you can take the exam without any experience, but you won’t get the certification unless you satisfy the 5 (or 4 in some cases) year experience requirement

winter basin
#

Hi. I want to get into cybersecurity career ,which is best for fresher role because i have zero experience in cyberfield ?

plain path
fathom gorge
snow zephyr
#

Do people think that it’s worth it to devote time/energy to studying data analytics in order to get better at cybersecurity?

fathom gorge
#

A SIEM is basically a large collection of data that needs to be analyzed, so there is overlap there.

river jacinth
#

im learning system admin things with networking and then going to focus on SOC analyst but learning the fundamentals first

charred coral
#

does anyone know if you have to only use the tools available to you in the eJPTv2 exam. is it possible to transfer tools over to the in browser kali? if not how did anyone who passed it pivot, im used to using sshuttle and chisel.

spiral gull
#

you cant transfer anything you are basically going to be using attackbox

#

its their own attackbox with no internet connection

#

you might be able to copy and paste some simple open source tools though into their vm idk (never tried it when doing exam)

spiral gull
magic cypress
#

I'm redoing my resume focusing for analyst positions. Is it good to include links to my linkedin and github (i put writeups on there) in the resume, or will people not check it out due to security reason (not clicking links)?

plain path
#

Maybe you could email them and ask the question.

charred coral
plain path
#

Hmm you can 100% copy the script of linpeas and run it.

#

The others I don’t know.

charred coral
#

ah okay thats nice. and for pivoting would i have to use proxychains, metasploit? im unfamiliaar with that methods

#

also does anyone know an estimate difficulty for enumerating, exploit and priv escing for these ejpt machines/network compared to any specific tryhackme machines?

plain path
#

Metasploit 100%

#

I’m doing the EJPT prep labs now for the EJPT exam. And for exploitation it’s going to be Metasploit.

plain path
charred coral
plain path
#

It’s based on a real scenario.

plain path
charred coral
#

only thing ive done for pivot practice is wreath nwtwork on tryhackme.

#

that was very fun

plain path
#

Nice

plain path
# charred coral only thing ive done for pivot practice is wreath nwtwork on tryhackme.
Notes by Nisha

Earning the INE Security Junior Penetration Tester (eJPT) certification has been a significant milestone in my cybersecurity journey. In this blog post, I’ll share my experience with the eJPT exam and the strategies that helped me succeed. Whether you’re considering this certification or preparing for the exam, I hope my insights will be use...

#

I found this blog

#

Of a person passing the exam has some really good information.

#

Like what tools we are going to be needing and what rooms are good to practice before the exam.

#

She even said some rooms for tryhackme.

charred coral
#

oh nice, ill look into it. when are you thinking about taking the exam yourself?

plain path
#

I have like 77 days left of my subscription and you need an active subscription to take the exam.

#

So yeah hopefully in like 2 months.

#

That’s why I would recommend buying the prep bundle it’s cheaper than buying exam and subscription.

Also look out for sales because I bought with 50% off so it was 125 dollars. Which is really good price.

charred coral
plain path
#

Ah oké, yeah look out for the sales they come out for no where.

spiral gull
#

because if it is to finish the prep course i would not recommend doing the entire thing

plain path
plain path
#

What parts in your opinion are the best?

spiral gull
#

once you get passed halfway they repeat the same lessons over again, i mean literally verbatim the lesson with the same length some of them are literally just doing the same thing

#

you will notice it quickly 3 times how to exploit smb

#

3 times how to use metasploit etc

#

it got me quite a bit pissed off actually so i didnt finish it and used my first attempt to see how it was and passed

plain path
plain path
spiral gull
#

its about 70% of the way i dropped it iirc

#

when you feel like there are way too many repeats id say drop it

#

mostly what you have to do is just remember/note take the exact payloads they teach you for the enumeration for their specific tools since you are restricted in toolset in their box

plain path
#

In how many hours you finished the exam?

spiral gull
#

besides that its really just running them properly on the machines they give, make sure you pay attention to the section where they tell you how to do post modules with msf for grabbing hashes and etc becuase that it important for some of the questions

#

was less than 20 iirc i think 11 hours were left 88%

serene umbraBOT
#

Gave +1 Rep to @spiral gull (current: #549 - 12)

spiral gull
#

also i only remember their being 1 pivot

plain path
spiral gull
#

np

plain path
spiral gull
#

was very easy just a host discovery iirc and you answer the questions nothign to exploit on it

#

question was something like which server is the pivot or close to it and how many hosts are present

plain path
#

Ah oké. So you really move from phase to phase in the exam?

spiral gull
#

its a lot of machines

#

my methodolgy was a bit chaotic ish so i was kinda just scannign everything and notetaking but you could just do it one by one

plain path
#

Oke, so in the prep videos. Metasploit, enumeration and payloads are the most important to keep an eye on?

spiral gull
#

yep

spiral gull
#

enumeration metasploit and post with metasploit most important

plain path
serene umbraBOT
#

Gave +1 Rep to @spiral gull (current: #509 - 13)

spiral gull
#

np man

plain path
#

What cert is next for you?

spiral gull
#

doing pmrp with tcm

#

im not really into pentesing because i hate webapp tbh lol

plain path
#

Hahahaha

plain path
#

What’s your dream job then in the cybersecurity space?

spiral gull
#

probably like first malware analyst/reverse engineer then incident responder, digital forensics,

#

i checked on ine btw its about 48% of the course i did for prep

plain path
spiral gull
#

all of these were skipped

plain path
spiral gull
#

i had a bit of exp with htb though

#

before the exam

#

the academy atleast

plain path
#

Nice, good move. I found that the tryhackme rooms help me also in this EJPT prep rooms. Speeds ups the process.

spiral gull
#

yeah definetely

plain path
#

I was like if you have to go blind into the EJPT rooms you have no clue what is going on 🤣

tacit moon
#

What are the remote work opportunities in this field like?

fathom gorge
thin cloud
#

hey guys , a quick question ...
im new to this field and i've seen so many roadmaps to reach where i wanna be
my question is should i take all the certs that they mention or i can start with just practice labs and stuff like that without the need to take any certificate like a+ net+ and sec+
thanks

winter basin
#

can anyone suggest me career related to cyber field with no prior experience?

keen tundra
winter basin
#

you mean it support

serene umbraBOT
#

Gave +1 Rep to @keen tundra (current: #1 - 5763)

lean needle
#

Hello. I am currently in France. I have probably a stupid question. Is it really to find a first job in the field of cybersecurity or in the nearest fields (for example, in networking), if I don't have an academic diploma? Almost in all propositions in LinkedIn it's written that a degree is necessary

molten basin
#

Hey everyone I’m looking to pivot into Detection Engineering and would love some advice on where to start.

I’ve got 3+ years of cybersecurity experience (SOC, threat detection, SIEM tuning, vuln/patch management), and I was recently laid off — so I’m especially interested in free or low-cost resources to skill up for this path.

A couple quick questions:

Are junior Detection Engineer roles even a thing?

Based on my background (below), where would you recommend I start?

Quick background:

Former SOC Analyst (Bank OZK) – focused on phishing, malware, BEC, detection tuning in Azure Sentinel & Google Chronicle

Vulnerability/patching work with Tenable, Nessus, PDQ

Strong in process docs, compliance (NIST, CIS), and optimizing security tools

Currently taking TCM Security’s Practical Junior SOC Analyst course

Would really appreciate any advice, resources, or guidance from folks here Thanks in advance!

fathom gorge
# molten basin Hey everyone I’m looking to pivot into Detection Engineering and would love som...

Detection Engineer is a fairly niche field, have you considered a Threat Hunter position to start with? You may have an easier time finding those positions. Since you've got a nice amount of experience another thing you can consider is find companies that have Detection Engineering positions, apply for a SOC / Threat Analyst / Security Engineer role first. Many companies will post roles internally first, this would allow you to pivot at a later point with much less competition.

have you taken a look at this https://github.com/infosecB/awesome-detection-engineering ?

#

Not the right channel for that and probably illegal

cobalt escarp
#

Please do not ask for help cracking wifi passwords here.

delicate viper
#

Hey everyone,
I’m a 23f BsC Software Engineering, cybersecurity/IT professional based in Birmingham, and I’ve been actively job-hunting for months now with no luck. I have a background in IT support and junior SOC-style work — including experience with tools like Wazuh SIEM, building dashboards, and creating hands-on labs for cybersecurity training. I’ve also completed a number of courses (CompTIA-style content, TryHackMe, Coursera, etc.).

Despite this, I’ve been getting ghosted or rejected at every stage — even for entry-level roles. I’m starting to feel discouraged and wondering if there’s something I’m missing or doing wrong.

My situation: • Based in Birmingham (but open to relocating anywhere in the UK) • Experience in IT support, threat monitoring, basic SOC workflows, and content creation • Consistent hands-on exposure to tools like Linux, Windows, SIEM dashboards, log analysis, detection rules, etc. • Looking for Service Desk, IT Support, SOC Analyst (Level 1), or Junior Cyber/IT roles • Eager to learn on the job and grow with a company

Has anyone been in a similar position? Are there any companies, agencies, or tips you’d recommend for actually breaking into that first role? I’m happy to send my CV or portfolio if anyone is willing to take a look or share feedback.

Thanks so much — honestly just trying not to give up on my dream IT career 💛

stray vessel
fathom gorge
# delicate viper Hey everyone, I’m a 23f BsC Software Engineering, cybersecurity/IT professional ...

Not too familiar with the market in the UK but you can try this one, it is a good company and the position is meant exactly for people like you. It is more of an OT role though. If the UK market is anything like the US then right now is a very difficult time to get started in Cybersecurity. I've seen recruiters mention they're seeing an unusually high number of applicants per position and often very qualified people too. So keep trying, the fact that you have some practical experience already is a big plus.
https://job-boards.greenhouse.io/dragos/jobs/4800390008

#

And if you or GY are a little more advanced they also have a Senior role open.

#

Big tip is to also start following recruiters on LinkedIn, many are sharing open positions not only within their own company but also positions they find elsewhere. It seems that Cybersecurity recruiters are a lot more likely to find and share positions that are not within their own company.

stray vessel
#

i’m located in the US

#

but yes let me try reaching out to recruiters

#

it’s a scary time

fathom gorge
#

It can also be useful to search for IT / CyberSec jobs in fields that you won't necessarily consider IT fields. Think of Healthcare / Home good stores, and then make sure you apply through the career pages of the organisations themselves. That will make you standout more than being the 200th LinkedIn / Indeed application.

stray vessel
#

thank you 🥹🥹🥹

fathom gorge
#

For you, GY specifically, HomeDepot, CVS, Spectrum, Humana, LexisNexis are big ones.

stray vessel
#

definitely going to look into it 🥹🥹

warped fog
#

Hi everyone, I just joined the channel and still learning all the great information on here. I'm 26 years old in the USA and venturing of to learn cyber security. If anyone has input on the best process to start with/certifications to aim for I would greatly appreciate it. I am very very new to it all .

fathom gorge
void mountain
#

anyone in here hiring? I'm currently a cybersecurity student and the lead OSINT investigator at a non profit if that sweetens it any.

warped fog
#

I appreciate the input greatly . I'm not to certain what field I wanna get into . But I wanted to have a start to see my options and go from there @fathom gorge I know the information is probably going to be over whelming but where do I find this"tryhackme " information?

fathom gorge
warped fog
#

Thanks a lot 🤞🏽🤞🏽

stray vessel
#

is there any other discord channel that i can follow with direct job posting or more in depth work careers opportunities?

stoic cave
stray vessel
#

thank you!

ancient prairie
# molten basin Hey everyone I’m looking to pivot into Detection Engineering and would love som...
  1. Jr. DE roles are sort of a thing but probably not a title you see, I currently work in a DE role and it is something you grow into a bit so really anyone new on the team will be a junior - you need to learn the processes and procedures for the particular environment regardless of your experience and expertise.

  2. Based on your background I would try to find another SOC role but specifically look for companies that have dedicated DE or Threat Hunting roles, it will be infinitely easier to pivot to another role from within a company you are already working at.

  3. For upskilling, it seems like you could use some more experience in actual engineering, learn about the detection lifecycle and how CI/CD + automation works in relation to detection deployment and management. SIEM architecture and engineering are also crucial to get hands-on for because you will often need to advise on getting logs into a platform and properly parsed

ancient prairie
#

Generally unless the position specifies "must be US-based" - I would always encourage EU/UK folks to apply more to US companies

serene umbraBOT
#

Gave +1 Rep to @fathom gorge (current: #472 - 14)

winter belfry
#

I have 5.5 years experience in a small boutique MSP that had one high profile hospitality client, did something else for 3 years then came back and worked the last two~ years as an IT Technician while studying cybersecurity and recently earned my Security+. With how the market is right now, any suggestions on next steps to break in? Decent % of local entry level jobs require security clearances that I do not have.

bold nimbus
# winter belfry I have 5.5 years experience in a small boutique MSP that had one high profile ho...

Sometimes the same companies posting jobs asking for a security clearance will have other lower-level positions posted on their website where they are willing to provide you with a clearance if eligible. I personally just had a recruiter email me stating that they moved forward with another candidate for the SOC analyst position I applied for, but they offered me a helpdesk position where they would provide me with a Secret clearance if I am eligible. Maybe you could try something like that and try to pivot into one of the other positions once you get the clearance.

winter belfry
serene umbraBOT
#

Gave +1 Rep to @bold nimbus (current: #3072 - 1)

vestal stream
#

Hi all, wasn’t sure where to post this question. Let me know if somewhere else is the right place to post this. In a nutshell, I graduated from asu and then joined Amazon as an SDE. After working there for 6 months in aws, i feel exhausted and realized, being a firefighter/red team in security might not be the ideal job for me. Saying this as in aws, everything is urgent and everything needs to be delivered asap. Considering this will be the case in red team as well.

Need some career guidance.

  1. I am thinking of going back to college and do some research/ go into teaching. That feels peaceful rather than this daily standup/hourly update culture. Is that even the case?

One more reason I want to be back at college is that I always wanted to do research and become a professor.

  1. I am interested in security and trying to break into it for a while. Any blue team security roles I could aim for without too much pressure? 😞
feral warren
boreal fern
#

Hi everyone, I’m excited to be here and looking forward to learning from this amazing community and hopefully get to become a contributor too someday.

I’m 20 years old from Nigeria and recently got started with the basics of cybersecurity.

I’m really interested in diving deeper into ethical hacking and would greatly appreciate any advice on the best way to get started, including which certifications or learning paths to follow. I’m completely new and ready to network also.

Thank you 🙏

keen tundra
steep anvil
#

Hey guys I just started and i have opened tryhackme but at intro to lan section its not free is that for the whole other courses as well and if not what is free ?

dusk wedge
feral warren
lethal pilot
serene umbraBOT
#

Gave +1 Rep to @fathom gorge (current: #447 - 15)

steep anvil
serene umbraBOT
#

Gave +1 Rep to @dusk wedge (current: #64 - 152)

dusk wedge
#

hacking and reverse engineering wont be needed for l1 soc i think but its nice to have

#

it can complement eachother

steep anvil
#

Thank you so much ❤️

dusk wedge
#

no worries

#

there might be others here who can give a clearer answer

worldly pier
#

hey are there any volunteers opportunities in TryHackMe?

cedar wolf
#

Does anyone here have a government security clearance I could dm to talk about the process with?

obsidian rose
worldly pier
#

I'm basically looking for volunteer roles within the cybersecurity community where i can contribute and learn new things to improve my knowledge about how attacks works, and thinking from red-teams perspective etc etc

worldly pier
obsidian rose
worldly pier
#

i don't want to sit around and wait so i'm starting to look for volunteer roles

fathom gorge
rugged delta
worldly pier
fleet breach
ancient prairie
# vestal stream Hi all, wasn’t sure where to post this question. Let me know if somewhere else i...

Amazon has a unique culture, you likely feel exhausted after 6 months there because the culture is not a good fit for you personally (or most folks from accounts I've heard) - in general you will most likely be much happier in the same role at a different company, if you want to teach then go for it but your career opportunities will be severely limited and you are likely to become very disconnected from actual day-to-day security work unless you work in some security research role

fathom gorge
fathom gorge
fleet breach
serene umbraBOT
#

Gave +1 Rep to @fathom gorge (current: #426 - 16)

fathom gorge
serene umbraBOT
#

Gave +1 Rep to @fathom gorge (current: #410 - 17)

pale mist
#

Who has finished the security engineer path? What’s next?

weak bolt
#

does anyone want to join a beginner group for cybersecurity??

keen tundra
weak bolt
hidden kite
#

Hello

fathom gorge
hidden kite
#

How are you

rare night
fathom gorge
#

New to THM but already working in the IT field I noticed in the intro channel?

rigid wyvern
#

hi there im thinking to purchase thm subscription any monthly discount coupon

fathom gorge
charred coral
#

hi. ive watched countless videos on the usual "what i would do if i started over" thing. and many videos explaining what certs to go for for your first junior pentest role. however ive recently realised that many jobs of that calibre in my area are asking for CHECK and CREST certs. As ive never heard of these in any videos from people in the industry, can anyone explain if they are important and why nobody talks about them in the videos?

worthy shoal
#

Both of those are very valuable in the UK afaik and maybe a couple other countries. I imagine many of the videos you have watched were US based and which certifications are desired varies a lot by country.

flat sedge
night forge
#

Is there any cyber security experts I want some suggestions

hollow sierra
#
CyberPeace Builders

Cybersecurity for social impact. Employers: Partner with the CyberPeace Institute to attract talent by providing financial support and skilled volunteers. Nonprofits: Gain access to Cybersecurity experts to assess, monitor and fix your cybersecurity gap.

#

Does anyone have experience with this ngo? I was looking at organizations i could volunteer for as a part of building experience, and this seems like a good fit;

#

Theres also this one which i was looking into;

#

For those in vancouver already employed in cyber this seems like a good event. I was going to apply to go but looks like since im not employed yet i dont qualify;

hot knoll
#

Hey folks! I’m working on a small research project to understand how people upskill in cybersecurity (especially hands-on stuff).
If you're learning for certs like OSCP, CEH, or just trying to get job-ready, I’d love to ask a few questions about how you study and what you wish existed.

No spam, no promo. Just trying to learn from real people. DM me or drop a 👋 if you're open to chat 🙏

orchid dragon
fathom gorge
# hollow sierra https://cpb.ngo/

Sounds very interesting but seems to require being a cybersecurity company not so much an individual? More like companies giving back to the community.

#

Volunteer must be employed by a private company: we do not accept volunteers from public organisations, academics, students, self-employed individuals, etc. The company the volunteer is currently working for will be vetted against the values and principles of the CyberPeace Institute.

Volunteer also need to have at least 1 year of professional experience in cybersecurity and to have passed the probation period in the current position.

echo nova
#

to anyone who has a job in cybersecurity, what is it, how much do you make, do you like it?

severe arch
#

I had to drop out of university because I ran out of funding. However, with my free time, I'm planning to complete all the TryHackMe pathways and earn both of their certifications within a year. Do you think this is enough to land an entry-level cybersecurity job? If not, what else would I need to do?

flint root
spiral gull
severe arch
# spiral gull fafsa not available or country equivalent?

I'm in the US, and I get funded from the Veteran Affairs, however, it was more of my health getting worse. So, they felt that funding wouldn't be in my best interest, since I have way more appointments to attend to on a daily basis.

boreal canyon
#

if yall need help hacking i can help you guys

obsidian rose
fathom gorge
boreal canyon
obsidian rose
#

Sure... how?

severe arch
serene umbraBOT
#

Gave +1 Rep to @fathom gorge (current: #390 - 18)

fathom gorge
hollow sierra
noble crow
#

Hi guys, just joined. I am studying Computer Science and want to break into cybersecurity, I've started learning about a month ago and I feel like I'm doing great so far. Does anyone have any advice on how I can get my career started and what experience I need to get my first job/internship in the field? (And also what and where I should be looking)

fathom gorge
marble cave
#

Hey everyone! I just finished 12th grade and I’m totally new to cybersecurity. I want to learn ethical hacking, but I don’t know where to start. Any help or beginner resources would be amazing 🙏

plain path
keen tundra
cunning shadowBOT
#

Done!

lusty ivy
# noble crow Hi guys, just joined. I am studying Computer Science and want to break into cybe...

Hey! Welcome to the madhouse 🤪
Good start, keep grinding like a boss!

1)Smash TryHackMe, OverTheWire, Juice Shop — hands-on beats theory every damn time.
2)Own Linux, networking basics, and security stuff — no excuses.
3)Build your portfolio — GitHub, notes, memes, whatever shows you hustle.
4)Hang out on Discords, jump into CTFs, meet your future hacker squad.
5)Hunt down internships, entry jobs, or freelance gigs — no shame in starting small.

Remember: patience + hustle = the cheat code. You got this, champ 💪🏻!

serene umbraBOT
#

Gave +1 Rep to @lusty ivy (current: #3074 - 1)

noble crow
#

@lusty ivy what should be on my portfolio?? aside from bugbounties

past storm
#

Hi all, I havent really posted here but I need some advice. I did Computer Science in university and then worked as a developer and consultant for a good 8 years. I have wanted to switch to cyber over the past year/two. I got my CompTIA Sec+ to start with but that gave me the bug and now I'm looking at doing a part time cybersec masters. I guess the questions that come to my mind are:

  • Is that worth it and would it help me get a job in cybersec space?
  • The two/three programs I am looking at have specifications - one is pentesting/red teaming and the other is more consultancy based (supposedly studying off real life projects) and the third one is somewhat more general. I wonder if there is worth specialising or doing something more general until I actually choose the pathway I want to go on?

I also dont want to fully lose my experience either so I would love to hear what people think.

lusty ivy
# noble crow <@1391461062808698982> what should be on my portfolio?? aside from bugbounties

Honestly? Put in everything – but do it smart. I’m no expert, started less than 2 months ago. No IT school, working 12–18h shifts, sleeping 3h a day… and I figured: better to have something in my portfolio than nothing.

From my point of view:

  1. Reports & notes – write down everything you learn. You don’t have to share it all; do a “rough” version for yourself, then polish some parts for GitHub or socials.

  2. Not just bug bounty – show how you think when solving problems. Methodology is a big plus.

  3. Automation & scripts – with explanations. Shows you can make your work easier and understand the process.

  4. Case studies – e.g., incident analysis. Even as Red Team, understanding Blue Team makes you better at getting in xD.

  5. Sample reports – technical or in your own style. I personally hate corporate-speak but can use it if needed.

If you wanna talk specifics, DM me. I’m not a “battle-hardened pro”, but in 2 months I went from zero to doing full passive/active recon and putting up my own Fiverr gig – so maybe I can help.

TL;DR: Show everything you can – skills, thought process, scripts, and reports. Methodology > just results.

#

Oh I almost forgot - and 80% of my work is done on my phone, in Termux – so no excuses xD

fathom gorge
# past storm Hi all, I havent really posted here but I need some advice. I did Computer Scien...

Hmm it wouldn't hurt getting a master in cybersec on top of your compsci but the 8 years of experience is already pretty good and would make you qualify for most entry level positions or higher depending on what your consulting was in. That second question really depends on what you're interested in. Personally I believe you're much better off focusing on red of blue teaming, otherwise you're competing with a lot of other generalists with similar experience to yours.

#

Especially in this market you're looking for experience that helps you stand out

past storm
serene umbraBOT
#

Gave +1 Rep to @fathom gorge (current: #356 - 20)

serene umbraBOT
#

Gave +1 Rep to @lusty ivy (current: #2025 - 2)

lusty ivy
frigid lion
#

Is it normal for someone to become a pentesting team lead within 1 year of work? (They are good at web pentesting and average at mobile/AD)

#

Is this paid?

#

oh wait you said volunteers

dense dagger
#

It depends on what a lead does though. Not everyone who is a lead is necessarily a better pentester. There are cases where they manage over other pentesters and are better talkers in front of clients.

warm hinge
#

i have already submitted the form so reach me soon

frigid lion
dense dagger
cosmic grail
#

Has anyone done MSc cybersecurity in university of
London

#

I would love to hear about your experience

fathom gorge
hollow sierra
serene umbraBOT
#

Gave +1 Rep to @fathom gorge (current: #345 - 21)

hollow sierra
#

Its depressing that government wont pay people for literally defending clean water services though;

#

Then again there are volunteer firefighters too;

fathom gorge
fathom gorge
hollow sierra
#

This one right?;

fathom gorge
#

Yees Track 5

hollow sierra
#

Looks like this one is focused on usa volunteering, i will probably look into if there are equivalent organizations i can join for canada;

fathom gorge
#

I think CyberPeace Builder is headquartered in Switzerland

hollow sierra
#

This seems interesting too;

#

Will add this to my growing list of cons i want to go to as well;

fathom gorge
#

Oh yes BSides are also great for networking

flat stone
#

hello noctem may i have more infor around this one?

hollow sierra
#

One of these days going to work on creating a year calendar for networking and volunteering events for specifically the vancouver region;

#

Might add it to my growing goals for my professional/personal website;

fathom gorge
hollow sierra
fathom gorge
serene umbraBOT
#

Gave +1 Rep to @fathom gorge (current: #336 - 22)

hollow sierra
#

Not to mention if it can also help my career thats awesome;

flat stone
#

@obsidian rose may i have more information around this one? fi its okay? very interested

magic cypress
#

what's a good site to apply to cyber security or IT jobs in North America (besides from Linkedin and Indeed)?

fathom gorge
tired ore
#

Hello! I am young in my career (1.5 years in) and have been working in SOC l1 and 2 in that time frame for a Fortune 500 company. This is my out of college job and I actually really enjoy it (outside of normal SOC gripes), but I feel myself coming to a close on triage and getting a bit burnt out I also have no drive to move onto DFIR or anything like that. What is a good path for me to aim towards and is moving companies a good idea early on? Is SOC experience a pretty good thing to have on a resume and start looking for higher level roles?

Thanks and appreciate any help I can get here!

waxen crest
fathom gorge
# tired ore Hello! I am young in my career (1.5 years in) and have been working in SOC l1 an...

Maybe stay in another half or year and a half and you can move on to senior positions (also the market is rough right now, you may not be able to find something else in the next few months), you could consider Threat Hunting if DFIR is not your thing but it all somewhat overlaps. If you want to switch things up start doing pentesting exercises, use your SOC knowledge to come up with attacks that may be harder to detect or use it to emulate an APT.

tiny thunder
#

Hi everyone switching careers and I have no idea what I’m doing any places where I can hone my skills to land a Cybersecurity job

hallow sinew
#

With all these threats of being replaced by Ai, CEOs replacing most jobs with Ai, and the insane job market going through multiple rounds of interviews, even with certiifications does it just blow your mind how the job market is nowadays ?

snow zephyr
#

I'd be grateful for advice on this. I deal with cyber issues from the legal side, but would like to get more involved on the technical side. I don't have any technical degrees. What I've learned, I've learned on my own through CompTIA Network Plus, through some SANS classes, Try HackMe exercises, capture the flags and Coursera programs.

Would people recommend a Master's in cybersecurity to move me to the next level? if I'm really interested in focusing on the tech side of cybersecurity, pen testing for example, how do people recommend that I move into this?

balmy dove
#

I am not sure a Masters would matter much for that level

crisp wolf
#

hi

dusk wedge
#

hi Smith welcome SchoenWave

crisp wolf
#

thank you for welcomeing me

#

so whats happening in these days

flat sedge
regal egret
#

I have no knowledge on cyber sec, I wish to learn but where to start and how to begin setups or whatever is involved is a maze in itself

fathom gorge
fathom gorge
# hallow sinew With all these threats of being replaced by Ai, CEOs replacing most jobs with Ai...

The thing is, Cybersecurity is not really a technical problem, it is a people problem. If you look at where the big need is for ~80% of the small / medium businesses in the world, it is in training their people on best security practices and understanding which assets they have. Cybersecurity is also a business (money) decision, how much is a business willing to do. Bare minimum to be compliant? A little more because insurance wants it? Or maybe attempt to limit the damage of an attack attack. You can throw all the AI at it if you want but if Bob from the helpdesk falls for a social engineering scam you'll still lose everything. Or if finance blindly trusts an email from a supplier with new payment details or using password123 for the admin accounts. You can check the talk Bryson Borts, Scythe CEO, gave on BSides Las Vegas.

If you look at the CIS Community Defense Model 2.0 for example, their data shows that simple " Essential Cyber Hygiene " can prevent 77%-86% of the most common attacks. Those are cheap simple things a business can do but may need technical help with. Think of changing passwords on default accounts, removing admin privileges from users that don't need it.

AI is great in assisting on alerts, maybe help write reports (although it may hallucinate half of it), but right now it is overhyped and overpromised. In my opinion it would be much wiser to let AI assist your employees in ways that actually help instead of acting like it can replace them.

novel olive
#

Good evening team,
Please I am new here and I just received a certificate in introduction to Cybersecurity. I want to be a blue steamer and I want to subscribe to premium. I want someone from the team to guide me on what course to take and what order to take them to boost my knowledge in the field. I am currently undergoing a job shadowing program and I have been introduced to a lot of apps and siems. Please guide me.

fathom gorge
fathom gorge
serene umbraBOT
#

Gave +1 Rep to @fathom gorge (current: #322 - 24)

novel olive
#

Is there any online classes that one can join? Where I can meet tutors real time and ask questions

fathom gorge
novel olive
fathom gorge
# novel olive These streams are embedded in the rooms right?

Some rooms have videos yup, but they also do live streams every so often in which you would be able to ask questions. You can keep an eye on the announcements channel for that. Tyler Ramsbey also covers rooms quite often in his live streams where he answers live questions.

novel olive
#

Thank you sir. I really appreciate

novel halo
#

Hello guys I want serious advice.
I have read linux command line book by starch press Also read python crash course by starch press reading A top down approach of netwoking currently Doe some rooms also in htb and thm
I just wanna ask I m super confused
Im in 2nd year. And I wish to get an internship till 6th sem.. Even if I didn't get internship
could I even get a job after the end of 4th year. Or is it really difficult to land one in cyber sec.
Or impossible
Or do I have to do Mtech and stuff?? So that I could postpone my unemployment under masters??.
Masters is mad costly though

fathom gorge
# novel halo Hello guys I want serious advice. I have read linux command line book by starch ...

Not entirely sure I understand what you're asking. You're currently starting your 2nd year in a degree (which one?), want to do an internship in or after the 6th semester? If you're that early into a degree, no one can really tell you what the market will look like by the time you finish. Focus on your studies, figure out what you want to be doing in 5 years but realize that this may change as well. Internships will provide you with some valuable experience that no book or class can teach you, if you get that chance make sure to take it.

hallow sinew
#

Does it feel that so many people out there make Ai replacing our jobs in cybersecurity more bloated than anything. And making people people in tech freak out more than anything i know most tech giants are firing and laying off people constantly and have Ai replace them. I dont think Ai can replace everything especially in cybersecurity.

blissful dagger
#

any tips on how to get a junior job as soc analyst etc? i'm from poland, so even 40-45k a year is really a lot, especially for entry level.

#

wouldn't it be easier to get underpaid (for ppl living there) job from usa than normal paid at my country?

fathom gorge
# hallow sinew I feel so many people out there want to make people out there generally scared.

I don't know if making scared is the right word. I'm assuming you're watching a decent amount of videos about this topic. Remember that often times when it comes to online content, creators are abusing tactics to generate more views. "AI is taking all the jobs" generally just gets more views than "LLMs can assist employees in these tasks".

I'm also not sure if AI is really replacing people at a massive scale already, it seems to me that it is much more of a funding issue. Running AI is not cheap and there is still a hope / promise that it will repay the investments. This might mean that rather than investing in people a company is dumping that money in an AI system and not hiring any new people. Somewhat similar to how in 2021 companies started hiring just about anyone in IT because they wanted to have them on staff even though they did not really have that much work for those people.

fathom gorge
# blissful dagger wouldn't it be easier to get underpaid (for ppl living there) job from usa than ...

That might be difficult from Poland, even underpaid jobs you're competing with a lot of people who are living either in a native English speaking country or who are actually in the country. If you go too low in your compensation companies, might not believe you have the correct skills too. There is no harm in trying of course, but I wouldn't get my hopes up. Many positions in cybersecurity are also starting to require citizenship in the USA because they do deal with sensitize data these days. You may be better off trying to get another IT/Software job first with a startup either in the USA or UK, I know some people who manage to make that happen. Western Europe has a big need for people in IT Networking if you have any experience with that.

blissful dagger
#

at this moment im working as erp systems administrator, but it doesnt have much to do with cyber. i've sent applications to every entry-level job and now waiting for response. if that won't work im just gonna start trying for sysadmin/network admin positions

#

i have even considered moving out to warsaw, that wouldnt be a big deal tbh cause i dont have neither kids or a loan to pay off

hallow sinew
fathom gorge
#

Estonia also has a big tech industry

blissful dagger
rain stone
#

.

blissful dagger
#

"oh no ai is gonna take my job", yeah i can't wait to see ai vaping in a toilet 5 minutes after clocking in on hungover

charred coral
urban junco
#

hi! I was curious to know if anyone from germany/europe in here does helpdesk aside college. What is required to land a job like that? I‘ve seen some require a finished bachelor in IT/ CS etc but is that actually needed? Can I land one just with A+ and some general knowledge on IT and cyber?

lapis cairn
graceful quiver
pale mist
#

Any recommendation I’m trying to pursue a path that I can be able to work remotely since it is hard to get a job offer and visa for a person from a 3rd world country?

fathom gorge
serene umbraBOT
#

Gave +1 Rep to @fathom gorge (current: #316 - 25)

serene umbraBOT
#

Gave +1 Rep to @flat sedge (current: #12 - 848)

bold nimbus
# snow zephyr Thx

A bit of a follow up on that since thats exactly what I did. There are a lot of tutorials out there that will show you how to setup Active Directory with virtual machines. I personally followed one of MyDFIR's tutorials where he sets up an environment with a Splunk server, AD, client machine, and attacker machine. Once you get that environment setup you can play around with making users, simulating attacks, im even using it to learn PowerShell lol

novel halo
fathom gorge
spiral gull
#

gonna post this in two places my school is offering ceh exam bundle with discount voucher for only 528, has course material book labs all included..... thoughts?

fathom gorge
spiral gull
#

USA 528 USD im around DC on the east coast

#

my focus ideally is blue team but even blue team job postings have been reccomending CEH (?) for some reason

#

titles (ideally) are like malware analyst incident responder threat hunter malware reverse engineer after graduating if things go reaaally well for some reason

ancient prairie
#

If you plan on applying in the DC area, although it is pretty objectively a bad cert - CEH fulfills the DoD 8140 compliance certification and has for a while, hence why you see a lot of DC-based companies or federally contracted agencies requiring the certification. I believe PT+ satisfies 8140 as well and I would feel much better giving CompTIA my money - also haven't checked prices in a while but for roughly 500 USD you can probably do 2 different CompTIA certs with their student discount

spiral gull
#

that explains it a bit more and I agree i would rather go for pentest+ i think i can even get a student discount but at the same time I do already have Security+ which i think covers 8140 compliance? I havent researched this in detail much

flat sedge
stoic cave
spiral gull
#

thanks for the advice all

#

I think that if i end up getting considered for a role that sec+ isnt covering ill do CySA+ instead as it covers the higher end compliance req and since my focus is blue team and ill just ignore the voucher for ceh for rn

novel halo
edgy orchid
#

Has anyone here taken the CC from ISC2? I can't afford the Security+ until I find a job, so someone recommended checking the CC since it's temporarily free. Just curious if y'all had any tips or comments on it, as I just enrolled

fringe spade
edgy orchid
fringe spade
#

Yeah

#

If it's free and you have some spare time then why not 😄

edgy orchid
#

Because like I said, I can't afford the Sec+ unless I manage to find a job but I've been actively applying (for both roles at my skill level and above, as I was suggested to do) for close to five months now and I haven't gotten a single interview

edgy orchid
fringe spade
edgy orchid
# fringe spade Do you have experience in IT/any other certs?

Professional, no, but I've been doing a lot of IT stuff for most of my life, as I grew up with a massive love for computers. I only started studying it in a serious/professional capacity for almost 3 years now, as I started off studying it at a really slow pace until I realized I was going too slow.

As for other certs, nope. No degree, either. I'm looking into ways to do some home lab projects, that's basically the only option I have, but I'm honestly not sure how I'm supposed to express those projects if I can't even get an interview

fringe spade
#

A home lab is a good idea, what roles were you applying for? offensive/blue team?

#

If you're interested in web apps you might try reporting a few CVE's, that's not too hard

edgy orchid
#

Well, truthfully, I'm not set in stone with which path I'd prefer but I'm studying and applying for blue team as I figure it's a little easier to start out that way than to expect to be hired as some no-name trying to legally break into systems lol. I do have interest in offensive security but I figure it'd be better to start as a blue teamer and gradually work toward that

As for reporting CVEs, I'm not sure where I'd start with something like that. I'm generally down to try anything to increase hireability, provided it's feasible for me at my skill level

#

On the subject of the CC again, does anyone know just how much time it takes to get through the learning material, provided you also have other commitments that take some time? I just saw you only have 180 days access to the training, which I'm starting to get a little concerned about, depending on just how much material you have to cover in that 6 month period

pale mist
# fringe spade Do you have experience in IT/any other certs?

Someone can be working in IT for 10 years but if nothing happens and they are dealing with small network what experience are they getting. Where as someone who has just started in IT with maybe 1-2 years in an enterprise environment has seen a lot of technical and hands on has more experience

pale mist
fringe spade
fringe spade
#

But it's very hard to estimate, everyone's learning capabilities are different

urban junco
fathom gorge
#

I imagine germany is the same

#

May just need to be near a big city

graceful quiver
#

If anyone could answer, I have certs like Google IT Support and IBM Cyber Sec Analyst that are similar to tryhackme certs, should I just start from where I haven't learned or does tryhackme hold more weight from an HR's perspective?

spiral gull
#

google it support isnt worth much for security or even it roles (i have it aswell) and is technically a certificate not a cert

graceful quiver
#

so essentially it could be seen as maybe little to no exp?

spiral gull
#

yeah id grade it like that i dont even include it on my resume with the other certs i got

graceful quiver
#

🙁

#

thats unfortunate

spiral gull
#

it did give me a ton of transfer credits for college though

#

i think like 9 total

graceful quiver
#

ah, I don't think between the 2 i have would even qualify for year I guess

urban junco
serene umbraBOT
#

Gave +1 Rep to @fathom gorge (current: #310 - 26)

fathom gorge
#

Yeah I do think in Europe degrees count more than certifications

graceful quiver
graceful quiver
fathom gorge
# graceful quiver in the US its the same

I don't know man, I have lived and worked in both and in the US i'm seeing a lot more "can compensate 2 working years for 1 year of college". The US is a little more picky about specific degrees, Europe just tends to want a certain level.

graceful quiver
fathom gorge
#

Ah yeah that is true

fathom gorge
graceful quiver
#

Has anyone landed an interview and had TryHackMe on their resume and if that was brought up in the interview by HR?

graceful quiver
#

well what ive heard

#

I'm new to tryhackme, was just curious if it was another "Google Cert" kind of platform

fathom gorge
#

I think TryHackMe is more on the level of GitHub, I don't think it will get you hired on its own but if you mention it in a cover letter that you actively keep busy learning and CTFing it can give you some bonus points.

graceful quiver
#

last question lol, thoughts on linking your THM account to LinkedIn?

fathom gorge
# graceful quiver last question lol, thoughts on linking your THM account to LinkedIn?

What I have done is create write-ups for certain rooms and use some of the challenge rooms to create mock-up incident reports. I have had recruiters refer to my mock incident reports, it allows you to have something real on there without having to deal with the approval of an actual company. I posted them on a personal website but you could host it on github too and then link to it from your resume and LinkedIn.

graceful quiver
serene umbraBOT
#

Gave +1 Rep to @fathom gorge (current: #305 - 27)

warm hinge
#

If there anything that really stands out in the portfolio, as in a (Project) for someone getting a SOC job? I want to add something along side the resume

unkempt bay
#

Hello folks, I have recently earned my A+ cert. I do not have higher education related to IT. I have been applying for "entry level" IT support roles with no luck so far. Is there anyone that could give me tips or some help on landing myh first IT position? Please and thank you!

fathom gorge
ivory wind
unkempt bay
ivory wind
unkempt bay
serene umbraBOT
#

Gave +1 Rep to @ivory wind (current: #3077 - 1)

languid stream
#

Can anyone help me I've got 2 certifications of CEH so how can apply for a remote job I've no experience but I'm familiar with most of the red teaming.

languid stream
#

One is from Cisco and one from gov

cedar grail
#

Can anyone tell me how does Tryhack me PT1 cert compares to eJPT?? I’m trying to get certified next month and idk which one is going to actually hold weight

dense lynx
#

can anyone speak to the current iteration of sec560 compared to say OSCP

pallid dawn
#

It is much, much harder

#

Pt1 is newer and not many people know about it. Ejpt has already some reputation.

modest knot
#

25 years in tech as a software engineer.. is there a real path for me to get into cyber security at this point and get a job soon? I dont mind working my way up. I have scars 😉

fathom gorge
#

Where in the world are you?

modest knot
modest knot
#

open to everything but west coast time zones

#

my network is mostly unemployed devs at the moment so it's been a challenge this year.

fathom gorge
# modest knot NY, but looking to work remote in the USA

Yeah try and get familiar with the concepts of the Sec+ exam, would be even better if you pass the cert. Should be easy with your experience. I know Home Depot / CVS are looking for people with your leadership experience to lead Cybersecurity team.

modest knot
#

that's great to know. So if there's one cert go for Sec+?

fathom gorge
#

I think with maybe a month of studying you might even be able to get the CISSP

modest knot
#

I don't mind putting the work in.. been trying the niche job market of elixir, rust etc.. even that has been hard to get a foot in the door

fathom gorge
modest knot
#

oh yeah! last two gigs have been gov related.. we lost our budgets..

#

litterally overnight

fathom gorge
modest knot
#

ive worked in everything but crypto at this point

modest knot
#

i'm honestly looking for a change of scenery too.. with ai making tech heads think they can easily replace us

#

ai.. great tools. but they're just that.

#

ive been coding since assembly language in school heh

fathom gorge
#

I wouldn't be surprised if we'll see a massive hiring increase in a year or so when managers realize that that is what AI is, just a tool that can aide an employee not replace them.

modest knot
#

it's way better autocomplete heh

#

i've had to work with cyber teams too.. used to read 2600 way back in the day too

fathom gorge
modest knot
#

tell me about it..lol i have it turned off in vscode

#

i use the chat and the agent

fathom gorge
#

And with 8 -10 years work experience required you should have far less competition

modest knot
#

sweet thanks 🙂

#

ive had many late nights dealing with china trying to break into various clients of mine working with the security teams

#

you know you made it if you're getting hacked by china lol

fathom gorge
modest knot
#

even better for us lol.. nice payband too!!

#

i had a lead dev interview for a company in texas and when we talked about money it was 30-50hr.. i was like.. for real?

#

i could coast at mcdonalds and make close to that low end LOL

fathom gorge
#

Yeah I think cybersecurity is flooded with people who are entry level or maybe 1 to 2 years of experience. But people with 10+ years and a little bit of leadership experience are in high demand. Most people who have worked in software / IT have at least some level of security experience. It may just not have been called that in their role but you're not just launching a project without checking security

modest knot
#

what's your specialty?

fathom gorge
#

I made the move from software developer to security engineer, mostly checking applications now

#

only 10 years of experience, in software development, though not too much leadership and only started a security role this year

modest knot
#

cool! I'll be bakc.. have to do the dishes LOL

fathom gorge
modest knot
fathom gorge
modest knot
#

I used to work for ibm for a while and we all had to be in the office. All of our meetings were online with video cameras

#

I do enjoy being wine and dined though, so I’ll be there for a party

fathom gorge
#

Ha IBM is also the perfect example of why AI is not quite ready to take over yet

#

Fired 8000 and then had to hire 8000

modest knot
#

Yup. Watson wasn’t great when I was there years ago too. A lot of hype . It did very well on certain things but not everything.

#

It was also very costly

#

Guess what AI is very costly

fathom gorge
#

Oh yeah, isn't that why OpenAI removed all older models except for their v5 which I'm not too impressed by

modest knot
#

Yup. That annoyed me because I had work flows for each model.

#

I don’t like version five so far

fathom gorge
#

4o did a decent job with code but 5 just seems to be giving generic code examples

modest knot
#

I used to use three on code and Serton four models for a creative

modest knot
#

@fathom gorge wanna join up on a team on the site or are you on one? I'm looking to join

modest knot
#

sure!

#

i love the tv show th eoffice so we are... Schrute Farms Cyber "Division"

#

our logo is a cyber out'd beet 😛

zenith kite
#

I’m starting my associate degree I should finish it a year what jobs u guys think I’ll be able to get ?

twin plover
#

hey guys, i know this might sound repetitive in a cybersecurity discord. But can someone please lend me a little help on finding my first job? 😭
I feel like my profile is ready but since I live in a place where only remote options are possible it's been really hard to just receive a negative response, and it's really frustrating, I've been applying for 3 months and I fr don't know what to change to get more possibilities.
Sorry if I stress you and thanks in case you'd help me 🙏

#

Also I completed the OSCP but unfortunately failed the final exam. I'd love to try again, or even get any other cert, but since I'm unemployed it's really hard for me economically

fathom gorge
fathom gorge
twin plover
twin plover
#

And since a driving license here costs 1300€, plus the car and the mantainance isn't cheap either, I really can't afford it

fathom gorge
#

Anything else in your background that you could leverage?

twin plover
#

I started applying to everything I felt like might be appropriate, cybersec, IT helpdesk, developer, devops, I'm lucky if I even get a rejection. Atp I really don't know how to improve my possibilities of landing a job.

twin plover
#

but still can't seem to get advantage of it

#

I know it might sound strange, but it's a combination of a low economic possibility and an absence of jobs where I live, so I have to resort to only remote jobs, and the entry barrier there is MUCH higher

fathom gorge
#

Italy?

twin plover
#

and I'm really out of resources. Sorry for the rant but it's been really deteriorating

twin plover
#

plus cost of living is way too high for relocating and salaries are also way too low

#

median here is like 1400€ net per month but cost of living easily reaches 2000€ in big cities where you find work

fathom gorge
#

Hmmm yeah I've lived in Italy for a few years, that is a though situation. Have you looked at jobs in the Netherlands and Germany? Your English is really good btw

twin plover
serene umbraBOT
#

Gave +1 Rep to @fathom gorge (current: #296 - 28)

fathom gorge
#

Okay that is at least one thing you have going for yourself there

twin plover
#

Mind if I ask you to review my cv/linkedin real quick? Maybe I could improve something and I would appreciate any type of help really much

fathom gorge
#

Sure shoot me a private message and I can take a look

twin plover
#

I don't really like to resort to having to waste other people time but it's really my last resort

twin plover
fathom gorge
#

Did you look at Estonia ?

twin plover
fathom gorge
#

Hehe yeah makes sense

twin plover
#

I applied to ALL jobs on linkedin I'm just sniping new ones

raw flicker
#

Hi guys can anyone help me

fathom gorge
ancient prairie
meager geode
#

Does anyone know good certifications for cybersecurity?

#

i want an associates plus certificates but i do need advice on the process and how to get into internships and jobs

flat sedge
#

Certifications are an employer's problem, not your problem. Don't worry about certifications unless it's absolutely required for jobs in your area. The reason for that is certifications are a way for the business to prove competency to customers or to auditors that they are hiring the right people for the right jobs.

If you are spending your own money to get the cert, you are basically giving the business free money that they should be spending.

meager geode
#

so then i just push for my degree?

flat sedge
#

Degree is a good step. Look for jobs where your degree can help you, and you may have a college internship or workstudy program as well

meager geode
#

where can i look for jobs that can help with my degree, im about to start my associates but is there any companies or sites you recommend?

junior cliff
#

Hello is anyone from the uk (Birmingham based ) or know about uk job system etc ,and can help with advice with requirements for entry lvl jobs Soc etc and also were to look etc

echo nova
#

any entry level jobs i should get into? ive already done some IT/helpdesk/fixing/replacing/adding-data-base-stuff work from an intern

keen tundra
#

Please don't self-advertise your services here

keen tundra
safe venture
#

Hi guys, as someone who has basic knowledge in cybersecurity such as a few labs and one information security internship, I was wondering how do I decide which field and niche I might want to head into. Like I am trying THM pathways but I don't feel satisfied with what I might want to head into yet.

meager geode
#

Thank you guys!

warm mauve
#

Guys, I am joining a college this upcoming 20th, I have completed Web Application Pentesting, Pre Security, Web Fundamentals, Jr Penetration Tester, Cyber Security 101 Paths, what else should I learn to get a internship in my first year? I am so very confused.

fathom gorge
fathom gorge
#

Imagine any internship would happen in the second semester? That would give you some time to get started with school and figure a couple things out

warm mauve
#

I am confused about my skills, like am i am skilled enough to get an intern or not

fathom gorge
#

I would recommend going through the SOC Level 1 module too just to get familiar with it, do you know if your school will help you in finding an internship? Usually they have connections with much lower requirements since they know you're a student.

warm mauve
loud fern
rose lava
ivory wind
mystic cliff
#

How can I start my cyber learning

ivory wind
# mystic cliff How can I start my cyber learning

Honestly? Start with the basics and play around. Learn how the internet works (IP, DNS, HTTP — YouTube has tons of free vids). Get comfortable with Linux & Windows commands. Start doing TryHackMe’s free beginner path or Hack The Box Academy. Also pick one thing that interests you (pentesting, OSINT, blue team) and go deeper. And just mess around, break stuff (in labs ofc), and keep notes. That’s how it sticks.

toxic matrix
#

With regards to the "breaking stuff" maybe see if your mom and pop store is willing to let you use their network and try to test their stuff there.

tough mango
#

Which path should i take if i wanna get in intelligence?

toxic matrix
#

It can help add real world experience there

#

Tyrex! That is an exceelent question

#

I'd say Threat Intelligence

broken idol
toxic matrix
#

Got a better idea, go embark on CTF competitions

#

there

#

is that better?

broken idol
#

It's more legal and ethical.

toxic matrix
#

it seems like you would want to learn SOC1 and SOC2

#

and maybe do some Threat Intel rooms

tough mango
#

Okey it looks great

toxic matrix
#

someone who is a staff member here might be better than me on this

#

All I can tell you is that Threat Intelligence isn't an ENTRY level sec role

#

it is a more mid level/senior role

tough mango
#

okey.. so i should take something else before?

toxic matrix
#

Well Tryrex

#

where are you in THM rn?

tough mango
#

well I finished compelete begginer when it existed

#

presecurity, cybersegurity 101, web fundamentals and 10% JR Pentesting

toxic matrix
#

OOOHG

#

Ok I will tell you that is pretty good

#

however

#

Threat Intelligence is BLUE Team

#

so actually you have to backtrack a little

#

and do SOC1 and SOC2

#

then do any related threat intel rooms

tough mango
#

okey

toxic matrix
#

Also I believe you are on a subscription right?

tough mango
#

yes

toxic matrix
#

If so, you should do the Splunk rooms

#

and SIEM labs

#

and if THM has some EDR rooms

#

and SOAR rooms

#

do those as well

tough mango
#

okey okey many things jajajaj

toxic matrix
#

No worries

tough mango
#

thank u so much

toxic matrix
#

if you need help try asking me

#

no problem

tough mango
#

nice

toxic matrix
#

I did an internship in this stuff and took an online course on Threat Hunting

#

so that's how I know this stuff

tough mango
#

ooh so u know what u are talking about

toxic matrix
#

Sort of at least on a basic practical level

#

also it helps to know a bit of Malware Analysis for this stuff too

#

which is why yup

tough mango
#

i will take a look

toxic matrix
#

I am tryna learn myself some assembly

#

yes, learning assembly is crucial for Threat Hunting

#

I am not joking

#

I didn't learn this stuff well at school so I am learning from scratch

tough mango
#

assembly what is it? sorry cause english it's not my first language

toxic matrix
#

Nah no worries

#

it isn't an "English isn't my first language thing"

#

I don't expect someone that is starting out to know this stuff

#

basically what I am saying is that not knowing the low level programming language for CPUs when doing Malware Analysis is basically not a wise choice

#

let me show you an example of an assembly program

tough mango
#

i get it

toxic matrix
#

*Waiut before I do, is it against server rules to show code snippets?

#

For the sake if illustration

#

because if so, then demonstrating this concept would be difficult

broken idol
thorny moss
#

For someone who hasn't got their foot into the door yet, at events such as networking events and general cybersecurity events who should we be talking to and what about?

hushed relic
#

Over the next few years, how do you see AI impacting the cybersecurity job market, and which roles (Precisely)—if any—will remain resilient to these changes?

scarlet blaze
#

I have a small question.
These days, companies focus more on up-skilling their IT employees rather than hiring cybersecurity specialists in general. So, as a fresher or a person interested in making a good/strong career in Cybersec, what should i do? I know people say get certs, keep learning, and do other social stuff like making connections. But what should I do, which would make a company think to hire me as a Cybersec expert, rather than up-skilling an IT employee for cheap?

civic crag
#

I am currently a Software Developer (mostly doing web apps) and is interested in what the Blue Team does (I am interested in the Red Team too, but I need to start somewhere). What roles can I possibly get in to? I do not have any real-world experience and only do THM rooms, so I am having doubts if I can even start my cyber security career.

toxic matrix
vocal pecan
vocal pecan
# scarlet blaze I have a small question. These days, companies focus more on up-skilling their ...

A narrative I push is think about your personal brand, and consider yourself as a overall combined picture, your candidacy. You need to find ways to illustrate and bring value to a potential company looking to hire you. Is certs enough, sometimes. Education (Degrees), yeah its a great start. THM good on the resume, hell yeah.

THink about your candidacy in the format someone might see first. Your resume and/or your LinkedIN. Are you demonstrating enough to warrant a DM, or a first interview? THat is the biggest purpose of your resume, to get an interview.

vocal pecan
civic crag
vocal pecan
toxic matrix
vocal pecan
scarlet blaze
# vocal pecan A narrative I push is think about your personal brand, and consider yourself as ...

Can you elaborate a bit on what you meant by bringing value to the company? I don't know much about market terms. Would mean a lot to get to learn from a experienced person. (For info, I am soon turning 18 and gonna join college, but the current growing conditions of the market make me fear a lot. And I am scared that the big money my parents would spend on my college education would become dust if I don't be able to get a good Return on what I'm investing in. )

vocal pecan
# mystic cliff How can I start my cyber learning

There are plenty communities, Youtubers (Check out Tyler Ramsbey), among others. Find something you think you enjoy and focus on that.

It is much more digestable to say "I want to be a pentester, and if that fails, perhaps SOC or anything cyber"

VS

"I just want to work in Cyber" This phrase is too broad and generalised. Focus on something, be open to other stuff, but dont say I want to do anything/everything./

toxic matrix
vocal pecan
# scarlet blaze Can you elaborate a bit on what you meant by bringing value to the company? I do...

Lets use a security consultancy for eg.

If they pay you X, they would want a 4X return on that. If your skillset brings them value that is billable (Can make them money/profit) they are more inclined to hire you.

No company wants to hire you if you not going to be a value contributor to their overall success, unless it is a charity.

Will college help? Sure it will, it puts you ahead of many, but is it the silver bullet, definetly not. If you study CompSci for eg, which is a great foundation, you need to do other things to align yourself to Cyber. THM is a good way, the right internships, CTF's, Communities all add value.

vocal pecan
civic crag
toxic matrix
toxic matrix
#

and maybe try going into DevSecOps?

civic crag
serene umbraBOT
#

Gave +1 Rep to @vocal pecan (current: #1536 - 3)

vocal pecan
toxic matrix
#

I did not know that was a thing

vocal pecan
#

Pretty hardcoare stuff.

#

I have recruited in the space for about 5 years. Real tricky

#

Look up Exodus Intelligence, there are a bunch. Hire 100% remote from pretty much anywhere in the world.

civic crag
serene umbraBOT
#

Gave +1 Rep to @toxic matrix (current: #3079 - 1)

vocal pecan
toxic matrix
#

looks pretty interesting.

vocal pecan
#

Yeah

#

Good stepping stone is Bug Bounty

#

User Space is easier, kernel level stuff is whats in big demand.

toxic matrix
#

I see! For me that is my VERY long term goal. My short term right now is perhaps get into Threat Intel related endeavours

vocal pecan
#

Good move

toxic matrix
#

then pivot to Red Team stuff later

vocal pecan
#

Be sure to follow Will Thomas on LI

#

CTI legend

toxic matrix
#

I see got ya! I know Flashpoint isn't a bad company for Threat Intel companies goes but I think they primarily only recrut in USA.

#

do you know others I can check out?

#

And no, I am not scared to go to Dark Web, it is just that my skills with Deep Web search engines is rusty atm

vocal pecan
#

Might be some good talks on YT about this stuff, spoke at a con called...ConINT (Might be coming back)

#

For CTI?

toxic matrix
#

yeah

vocal pecan
#

Errr

Interupt Labs big in the UK
Zetier (Iv worked with them)
DF Labs (Dont think they have a site)
Binary Gecko (One of my clients)
Paragon
Cellebrite
Grayshift (Very iOS focussed)
Red Lattice
NullPTR

These are a few

toxic matrix
#

OOh thanks!

#

I will check them out when I get time

scarlet blaze
# vocal pecan A narrative I push is think about your personal brand, and consider yourself as ...

And one more question. Like, let's say I try to see from the POV of a hiring person in the company. I don't find it useful to hire an expensive Cybersec professional until something is serious, and I would find it much cheaper and easier to instead just contact a company like THM or any other to upskill my IT department people to avoid extra hiring or paying. And this would also make my company eligible for Cyber Insurance as well to save the company assets in case of any loss/breach. In the worst case, I can contact a security management company for a one-time testing/checking. Then why, as a "Hiring Person," would someone take me then? Even tho I got fancy certs and industry-level degrees or certs, but would require me to pay him $110k every year, instead of paying up maybe $50k to upskill my whole staff and maybe hire some security consultancy? All this for much cheaper?

#

I get ur point, but is it easy to get hired into a security consultancy then ? i mean, but generally these are very small groups of people as much from what i know.

#

unless ur some ass company like Mc-Afee which somehow survives idk how by selling malwares

vocal pecan
#

Because in the end it is cheaper and quicker to hire someone if your needs (As a company) are long term. Consulting is expensive, and adhoc at best.

#

Sure, you can upskill an IT dept, but then you need willing participants. Whats to say after this, they stay with the company

scarlet blaze
vocal pecan
#

Also take a avg but smart person, sign them up for OSCP, at best, that is a 6 month turn around

vocal pecan
#

But its not like someone rocks a 1 week course and suddenly they are an expert

scarlet blaze
vocal pecan
#

I think, could you give me a tangible IRL concept, and I can respond?

#

Typically if someone has the social proof and skillset to back up their cost, albeit a higher cost, it is fair to suggest they are going to deliver at a much higher level than someone on half the money in the same region and profession.

scarlet blaze
# vocal pecan I think, could you give me a tangible IRL concept, and I can respond?

Sure. For example, let's say a mid-sized retail company with 50 employees. They have 2 IT staff handling hardware, software, and networking. Instead of hiring a $110k/year cybersecurity specialist, they put both IT staff through a 6-month part-time program (say, OSCP or equivalent), costing $15k total. They also add a yearly refresher budget of $5k for conferences/training. This way, the company boosts in-house skills for around $20k, compared to $110k ongoing. The risk is if either trained staff leaves — but the benefit is avoiding the full-time hire until it’s truly needed.

vocal pecan
#

Alright

scarlet blaze
vocal pecan
#

So you have 2 IT people, they now train to be pentesters. Great. Now they are doing IT (Which can be a very intensive endevour), and now they are pentesting as well...but they are pentesting infra that they manage themselves. It kind of defeats the purpose. If they pentest, and all the things are bad on the perimeter....that means they did a bad job in IT.

#

Not unprofessional, its just that hypotheticals only get us so far.

scarlet blaze
vocal pecan
#

Now you have a IT Engineer, that does onboarding/offboarding, triage, tickets, network maintenence and then still Pentesting....Chances are, they gonna start dropping the ball on some of this.

scarlet blaze
#

If the employess have some brains themseleves they would demand for a big upraise and threaten to leave my company for a better job / pay. Since now they have better skills in their assets and experience

#

is this right?

vocal pecan
#

Perhaps a MSP solution is more equitable. You get a vCISO or augmented MSP to assist for a smaller retainer per month, long term...once a year you do a external pentest from a consultancy (To make sure someone else is marking your homework), you feed that advice and remediaton into a feedback loop. Get popped, you have a leg or 2 to stand on.

vocal pecan
toxic matrix
#

And welp I found an interesting looking company Angus, actually a couple, have you heard anything about Kela or Recorded Future?

vocal pecan
#

Is it fair to bump someones salary if they achieve something tough like OSCP, sure, of course.

vocal pecan
#

@scarlet blaze The challenge is, like with anything in Cyber, stuff is very nuanced and the word "Depends" will come up a lot.

scarlet blaze
scarlet blaze
serene umbraBOT
#

Gave +1 Rep to @vocal pecan (current: #1234 - 4)

scarlet blaze
#

is it okay if i can add you as friend on discord @vocal pecan ?

toxic matrix
#

OOH can I add you as a friend too Angus?

vocal pecan
#

Only in certain cases is it worth hiring a dedicated security person at (your example) $110k...sure. The same is true for hiring a CISO. At a certain headcount, endpoint, spread and turnover it becomes viable and almost demanded to hire a CISO. But before that you prob need MSP support...after that MSP with some internal focused talent...Then management....few layers down, oh damn, we need a CISO and CIO

vocal pecan
#

IF I have time I am happy to hop on a call, talk this out. Just remember, things are easier when you dont try fit a square block througha circle hole.

vocal pecan
#

Also, a good Security Consultant (External) or MSP will advise you when you need to ramp up things.

#

Like for me, I have an external bookeeper, CA and Audior. I pay them monthly and they do my books.

#

IF i 10-20X my turnover...and their services start becoming economically non-viable, I prob need to hire a bookeeper, and down the road a CFO

#

Maybe you, as a company, allow people to order Uber Eats on the company dime (I see this in startups) cause the company's Cost vs Time Loss in people going out to get food makes this spend worth it.

THen you get google, that have a canteen, snacks/drinks on the company dime. It makes more economic and production sense to have their own chefs, kitchen and dining onsite.

#

Apolgies for the typos, Its cold, my hands are numb so my typing is not my best

safe venture
vocal pecan
# safe venture Like how would I know if I like the red or blue team such as I tried some challe...

Thats a tough one.

On one hand, you gotta do what you enjoy. Yes, I am a recruiter/headhunter, but by doing CTF's I realised in Cyber I really love Forensics

So THM/CTF's is a great way to figure out what you want to do.

Now, Doing what you love and what you are good at is a win win, but I dont over value joy over success. That is something you have to decide for yourself

If it is a foot in the door you want, extract and lean on your past experience to determine your future.

Nothing stops you pivoting from blue to red. It is usually harder to pivot out of GRC though.

safe venture
#

Like I know I want to do things that involve being involved in the incident while it’s happening, but thanks. Yea I will look into ctfs

safe venture
#

😃

fathom gorge
serene umbraBOT
#

Gave +1 Rep to @loud fern (current: #257 - 35)

floral hollow
#

I'm currently trying to career swap into a cybersecurity role (currently interested in SOC1). So far I'm studying for CCNA to get a good networking foundation and going through tryhackme. Completed presecurity and almost halfway through Cyber 101. Anyone in the industry any advice for a newbie?

umbral valley
#

Hey guys, Im currently enrrolled in THM's path to cybersecurity and also in the Google Coursera's cybersecurity cert program, I plan on finishing both of these in the comming months and afterwards taking advantage of the Coursera's discount to take the Security+ cert

Apart from these two things what else can I do to get myself a job in entry cybersecurity? I want to change carrers and cyber seems fun, always been interested in how to keep the internet safer. Any tips? thanks in advance

ancient prairie
#

@floral hollow @umbral valley you both will get my general advice for career changers/people new to Cyber:

  • if you don't have a background in IT then focus on starting there in helpdesk/sysadmin/desktop tech roles
  • if you have a degree (even unrelated to cyber) or can start one that is a plus
  • CompTIA trifecta (Net+,Sec+,A+) + OSCP are great foundational certs that get you past most hiring "filters"
  • Network, network, network; go to cons/local tech-meetups (there are probably more than you think in reasonably populated areas), join other Discord/Slack/Signal/Telegram communities - be active, friendly and show you are willing to work to understand things and not just use community members as your personal Google
umbral valley
serene umbraBOT
#

Gave +1 Rep to @ancient prairie (current: #46 - 226)

ancient prairie
#

hmm I mean depending on the amount of credit hours you completed towards the C.S degree you likely fit the requirements for an Associate's which is notable for resume purposes

floral hollow
#

@ancient prairie apologies if you felt like it was using you as Google. I have used Google and got advice from different people I was just curious on what the personal take was for the members here. Thanks for the advice 🙂

serene umbraBOT
#

Gave +1 Rep to @ancient prairie (current: #46 - 227)

ancient prairie
#

haha no not at all, sorry I worded it that way lol - I'm more talking about the kind of folks who join a red-teaming focused community and their first message is "how do I run Metasploit?"

#

and honestly trying to google career advice for cyber is saturated with so much garbage from influencers this channel is somewhat the exception for "low effort" question - it's really hard to get a straight answer sometimes

floral hollow
#

Influencers really are hitting the cybersecurity space hard. Haha everyone saying different things and how their bootcamp or product will get people into big money jobs fast. 😂

safe venture
#

Hi @ancient prairie I saw ur profile and it’s says your a threat hunter. What got you into threat hunting if you don’t mind me asking

ancient prairie
safe venture
#

Would you say threat hunting is more red team then blue or still in blue side ?

flat sedge
flat sedge
umbral valley
ancient prairie
flat sedge
#

Does that mean that you should trust my advice unconditionally? Of course not. Look at your local job market, especially at the jobs you want, and evaluate whether or not it's really worthwhile to spend the money on a particular cert

#

I'll add also, that is someone does not have SOC experience and does have an OSCP, they are not going to be guaranteed to be top of my candidate list.

I need to be able to trust that my SOC analysts and sec engineers will understand boundaries of what they should and should not do, and I would have many questions relating to scope of pentest vs SIEM analysis before I could trust zero experience + OSCP to be responsible

#

Another thing I'm seeing in cybersecurity spaces is that the blind are leading the blind. People outside of Cybersec (even outside of IT) are giving job advice specific to the niche that is so fractally wrong, it is not feasible to correct in a quick response.

Be very very careful about taking advice from a place like discord, as very few communities vet advice-givers for a history and background in the space.

cold sky
#

@hidden whale I studied for about 1.5 month for the exam using Jason Dion's Security+ Udemy course, Boson's exam simulations (really good but a bit pricey), Cyberkraft's and The Networking Guru's PBQ playlists on YouTube. I also took lots of handwritten notes (my personal preference) and ran practice drills with ChatGPT.

Overall, what worked best for me was reviewing a lot of the simulation questions and explanations and practicing as much as possible with GPT.

On exam day, I got the tip to skip PBQs at first, mark them for review to return later, do the same for multiple choice you aren't too sure about. This was pretty helpful as I was way more confident about them after answering a bunch of questions.

mighty seal
#

Do you guys think that its best to do a google cybersecurity certificate first then CompTia?

rose lava
serene umbraBOT
#

Gave +1 Rep to @ivory wind (current: #2029 - 2)

vocal pecan
vocal pecan
# umbral valley Hey guys, Im currently enrrolled in THM's path to cybersecurity and also in the ...

Getting involved with the community is always good, find a local meetup or BSides. Build a online presence, Career change can be fun and challenging, but if it is what you want to do, it can also be rewarding. Biggest thing for you is extracting value from your past, and demonstraing future value on your resume, esp on page 1. Include all the things that could make a company consider setting up a call. THM, HTB, Certs, COmmunity stuff, it all matters

vocal pecan
vocal pecan
vocal pecan
loud plinth
#

How do you get started in the IT field with no previous IT jobs?
I have the A+ and Network+ certifications, and currently am taking CBT nuggets courses for them so I can move on to TryHackMe afterwards. I understand those very well, just no projects in VMWare for workstations pro yet… What should I design on there and Cisco Packet Tracer so I get hired as a Network Technican or Tech Associate of some variety? I’m very familiar with Word and Active Directory. I’m 26 months out of college studying all of that and no Tech job yet.

#

(84th percentile finisher NCL 2022 individual game)

high wasp
#

guys i told a guy what i want my careet to be he told me thats just a fancy word of being homeless

loud plinth
#

wut

fathom gorge
loud plinth
#

Do the National Cyber League

#

With TryHackMe prep- and get a team that can help you get hired?

#

Is that a good idea?

#

Google Cyber Cert is one of the best for beginners.

#

(popular!)

fathom gorge
#

Popular sure but for a cybersecurity role right now it wont make a difference when applying for jobs. You need something more practical. If not a cybersec degree then you're going to need to get an IT job first. There is just too much competition right now.

loud plinth
#

I interview every few weeks, and get no where.

loud plinth
#

100%, and podcasters have informed me too…

#

However, this one guy said ‘AI isn’t giving them the returns they want’, so cybersecurity is less worse off as a result.

#

It’s the electricity limitations of the new AI… I wonder about AI careers- where would I get started, Chat??

fathom gorge
loud plinth
#

Right? That’s what I heard! They need to wake up. Maybe a coalition of employees (who can’t be bought) could convince them- knowing full well how many millions of unemployed cyber professionals there are- and promising at that.

#

lots of cyber degrees and certified people out there- TryHackMe has like 4 million users in 2025.

vocal pecan
simple yew
vocal pecan
#

I get that, I live in Africa. I know its tough. What I meant was, Net+ is a great step ahead of others

#

Understanding networking is a solid fundemantal

tough ember
#

If I’m aiming for 2026 new grad security positions, will keep tracking linkedin the best option? Honestly, I don’t see security ng position that often, it’s all spammed with swe. Would there be any other specific job board?

void totem
#

Hello guys! I'm new here, and I want to start a cybersecurity journey. Rn I'm a Ruby on Rails developer (3 years of experience), I'm from Poland and I have a bachelors degree in IT and I'm a dad for a half a year now :).
I'm leaning toward security, as it always interested me the most. My plan is to start with TryHackMe paths, then probably HTB and maybe security+. I'm a big tech enthusiast, with a passion to cutting-edge technologies, like AI, blockchain etc 🙂
I'm aiming into red-path. My first thought was trying to get into blue team in some SOC, but I think (correct me if I'm wrong) that red-team might more likely to offer some remote/hybrid opportunities, it's important to me. Also red side attracts me more 🙂
I hope that I will stick to my resolutions and manage to change my job in the next few months.

If you are in similar position (beginner as me), or If you have any helpful advices, please reach out to me!

rugged delta
rugged delta
# void totem Hello guys! I'm new here, and I want to start a cybersecurity journey. Rn I'm a ...

So if you're starting off in cybersecurity, you should have a good grounding in Linux/Windows admin, some bash/python knowledge, Active Directory, Networking and core technologies. You can learn a lot of these skills through Trry Hack Me and the paths are set up to cater for people who want to work in the field. Having knowledge, experience and certifications go a long way in demonstrating your abilities, as do things like having a home lab, doing projects, partaking in CTFs, Bug Bounties, etc. You'll learn more about these as you progress in your journey.

Most people going into cybersecurity will have some IT/helpdesk/tech support/programming experience already but a lot of people join cybersecurity via the SOC and blue team roles and do quite well growing their skills through this path. Red teaming is a highly sought-after role and a highly competitive environment, expecting a high skill level. Red and blue teams need to understand a lot of the same tools and skills, as they compete with, and collaborate with one another to improve the security of the organisation, and many of the skills and knowledge in both are transferable and beneficial as your career progresses.

tough ember
serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #20 - 528)

void totem
# rugged delta So if you're starting off in cybersecurity, you should have a good grounding in ...

Thanks for the advices! I have some grounding in Linux, Windows, Networking and Python. I'll defenitely focus on deepening those fields, as well as learn AD, as it's new to me.

And I really enjoying doing practical stuff like overthewire for example 🙂

Recently I bought a thinkpad to my wife, and I added some extra RAM (32gb) so homelab with some VM's wouldn't be a problem (I was thinking about maybe some SIEM/Splunk/Honeypot as well as Kali and some machine to be attacked.

So you think that starting on a blue side might make sense? That was my first thought tbh. I'll just start learning now and applying to jobs maybe in a half a year so I guess that I will also apply to SOC and other entry level blue team jobs. I really don't mind broadening my knowledge, so it might me as good place to start as others.
Thanks for the response!

serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #20 - 529)

slender island
#

Hi, I’m a complete beginner in English and Cybersecurity. I have one question about THM: is it compulsory to pay for the resources? Because right now I’m broke, but next month I won’t be. Sorry for bothering you ❤️

charred coral
keen tundra
dim mirage
#

Hey i am varshi, from india, I am in my (3 rd sem)second year right now, I am doing computer science and engineering.
I am interested in cyber security,
I am afraid of start learning it because I see a lot of people tell me not to start your career with cyber because it is a vast field and you can't get job easily until your connection are strong in tech
I am right now learning web development, I don't know where I have to learn cyber or not . I am thinking of doing web development+ cloud security .it is right or not please guide me .

noble crow
#

I'm studying Computer Science and just quit my internship because I want to start focusing on cybersecurity. However I don't have any relevant experience in the area. Are CTFs good to put in your CV? what can I do to be "hireable"?

proven tartan
worthy shoal
noble crow
#

And since the classes are divided in semesters I had to choose between quitting now or in december

#

so I made the choice to quit now and chase something more in line with what I want

worthy shoal
#

ah gotcha gotcha. Well to answer your original question CTFs can help a little bit, but I wouldn't say they're going to be a major factor in landing an interview or anything. Experience, Degree, Certifications, Projects, CTF + Other is generally the rough order of importance for qualifications, though that can vary a bit based on country, company, and position.

noble crow
#

what can I do given i’m a relative beginner

#

also what could I do as far as projects?

worthy shoal
#

Internships or a job - anything tech related can be useful. Lots of people work in IT before transitioning into cybersec later down the line.

Projects could be a homelab or maybe some programming, automation is a big thing in cybersec.

noble crow
#

ooo gotcha

#

I’ve seen some homelab guides on yt maybe i’ll do that

#

and i’m job hunting rn as well

#

just looking for something a bit more relevant

worthy shoal
#

Best of luck with all of that

potent bear
jaunty plover
#

So I have made over 3 roadmaps for cyber and they are mostly of different fields
So do I focus on one or many for most efficiency? Also if I wanna do cyber but not into coding much would settling into SOC analyst do?

jaunty lynx
#

Hi

languid stream
#

Hello everyone I've completed an ethical hacking course and I have a certification from Cisco now I'm looking forward for a professional cert to get hired I've looked at CEH but got no good reviews now I have some certs in mind like eCPPT eJPT and PNPT so which cert do I take

obsidian rose
languid stream
#

Okay cool and what about PNPT

obsidian rose
#

Did not take it.

grand rune
#

Many companies dont hire outside of country meaning you’d need to acquire those basic certificates such as security+ net+ etc. come for master’s in a relevant stem subject and apply for internship in the same country
AND THEN GET INTO a company. Which is pretty tedious work

#

Not to mention specialization degrees require almost 10k usd which your company may or may not fund depending on the region

odd igloo
grand rune
#

BUT
Here’s the main case, most companies dont even hire part time IF U DONT HAVE MINIMUM WORK EXPERIENCE😭 (my country is so ahh)

grand rune
odd igloo
#

idk

#

maybe I'm going too far lol

grand rune
#

Hm but yo agree that companies dont really hire across countries due to taxation issues and law

#

Right?

#

Keyword “dont really”

odd igloo
#

idk, I'm not in the workforce

grand rune
#

Ah i see

odd igloo
#

I'm 14

#

lol

grand rune
#

😭what

grand rune
wise stirrup
#

for someone who wants to start a carrer as a red teamer, what is some advice people in the red team could give me to help

dense dagger
#

I would advise you on taking the CRTO by Zero Point Security. Its one of, if not, the best intro to red teaming courses out there. They recently revampped and have implemented regional pricing so if you live in a country that has less purchasing power versus somewhere like the UK, you can buy it at a discounted rate.

#

From there, build on learning fundamentals of red teaming so that’s building on MITRE ATT&CK and adopting the adversarial mindset. Learn to read different incident response reports and try to map their attack patterns to the MITRE ATT&CK framework. I suggest as well on reading Red Team Development and Operations by Joe Vest & James Tumberville. Its an excellent resource on building the adversarial mindset and what to expect on a red team setup.

#

You also build on technical foundations so that’s learning the basics of C2 infrastructure, learning at least a certain cloud technology, familiarizing yourself with your tools and the common indicators of compromise (IoC) they generate. You should also at least at a fundamental level also be able to have a working evasion plan for hosts like Windows and Unix. I’m saying fundamental as there are different roles in a red team and you may not always be the malware and evasion expert but its always handy to know how to do evasion, even if in a basic level.

toxic matrix
#

OOH that is a different perspective

#

than what I got in my IT experiences

#

I heard it is better to go Blue Team before Red

#

as it gets you more familiar with defensive capabilities first

#

and get more familiar with key vendors such as AV

#

and XDR vendors

dense dagger
# toxic matrix I heard it is better to go Blue Team before Red

You could also go that way, it helps you understand what an attack looks like and how a SOC would respond to certain attacks. It also helps build your awareness on your IoCs and what telemetry you generate when you utilize certain tools against vendors.

pallid dawn
warm carbon
#

anyone here who has passed oscp?

fringe spade
warm carbon
#

No, I don't

warm carbon
fringe spade
#

But I’d say that it’s possible for someone who has some basics (networking, linux, windows etc) to start in cybersec and pass OSCP in less than a year, as it’s a junior level pentesting certification

#

but pentesting isn’t considered entry level in cyber/IT

warm carbon
#

Ok Thanks, rn I only have decent knowledge in networking and windows, I wanna get a IT desk job first for experience

jaunty plover
#

Also how tough is it to go from 15 y.o Senior year high school in 🇳🇬 to SOC analyst in Australia, UAE, Or somewhere

gritty arch
#

Hey, So I have decided to go with the blue team side and Confused where to start? Ive already been in the red side in web pentests and bug bounty. I wanna learn the blue team as well, I am aware of the basics and stuff.

#

I need a good advice for thiss

tame egret
viral arrow
#

I need books to learn ethics about cyber from start.. can someone suggest or help.

echo nova
#

how did you guys even come across cybersecurity? when? how many years ago?

toxic matrix
#

then you can go into SOC 2 then SOC 3 (Threat Hunting)

humble flume
#

Hi everyone, I'm releasing my own book about cybersecurity and my journey. I want to encourage young people and women to get into cybersecurity. Can I share the link to my book here?

modern sedge
#

helloo
Can anyone help me with FIRST and TF CSIRT membership?

gritty arch
tight pike
#

im from slovenia, and in a gymnasium. in my country i think there aint any cybersecurity faculties or smth. even jobs. idk what to do

uncut dagger
#

Can anyone help me with the beginners task 4

solemn thistle
hollow sierra
#

one thing i was looking at as a part of finding ways to combine my experience with reporting, tech and cyber towards what I value such as human rights and accessibility advocacy. A subset that I haven't heard of until recently called Remote Policy Advocacy roles. does anyone have experience with this niche and what sorts of expectations are out there for ngos and gos hiring in these kinds of roles?;

inland iris
#

I've completed the cyber 101 path on tryhackme and done some machines on htb and wanted to start going for my first cert. I've heard comptia security+ to be one a popular first cert, how should I go about preparing for it?