#cyber-and-careers

1 messages · Page 55 of 1

rugged delta
#

The Security+ is good structured general cybersecurity knowledge and employers see it as you having an understanding of the processes in the field; but it is a multiple choice question cert, not indicating your practical knowledge. Having that and Net+ are good indicators you have an understanding of the basics. There are official and non-official study guides you can buy, many people use Professor Messer's free course. CompTIA have their own training options as well. Any one or a compbination of those would be more than sufficient to learn everything in 3-6 months

fair radish
#

What is the gold standard certificate for a little advanced blue teamer job role (that will walk over the entry level roles), i am not trying to certificate hop and cant afford to get multiple certificates either. Please tag me with your response. I appreciate in advance for your feedback.

shut violet
fair radish
shut violet
#

blueteam isnt really the same with certs

fair radish
shut violet
#

i feel like theres not a ton of 1-1 equivelents

#

wheres that certmap

#

like honestly i wanna say something SANS but thats really innacessible

fair radish
shut violet
fair radish
#

All i can do now is grind studying, which i am with full enthusiasm. However, i am saving money but for 1 certificate only, this is the budget i have and i gotta do the best i can with whatever i have

#

@shut violet

shut violet
#

hmmm

#

why a cert? @fair radish

fair radish
shut violet
#

do they specify what certs?

shut violet
fair radish
shut violet
fair radish
shut violet
fair radish
#

Okay wait

#

Cyber Security Analyst Job 1

Relevant tertiary qualifications (e.g., computer science or IT degree), industry certifications (e.g., CISM, CISSP, TOGAF, GIAC) and/or relevant industry experience

Job 2

5+ years in Security Operations or similar cyber security roles.
Bachelor's or Master's degree in IT, Cyber Security, or related field.
Industry certifications highly regarded (e.g., CISSP, SANS, CISM, CEH).
Strong analytical and investigative skills.
Proven experience in threat hunting, incident response, vulnerability assessment.
Proficient in SIEM/IDS tuning, scripting, and automation.
Sound understanding of risk and compliance frameworks (ISO27001, NIST, ISO31000, etc.).
Experience with Microsoft security controls and cloud environments (AWS, Azure, GCP).
Comfortable supporting audit and regulatory compliance initiatives.

Job 3

Relevant certifications such as CISSP, CISM, or CRISC

fair radish
#

There were more jobs so you can see the average of certs, but i cant post that long message here

shut violet
#

yeah, youre not really gonna get those

fair radish
#

So took 3 jobs

shut violet
#

focus on the other requirements

#

like experience

fair radish
shut violet
fair radish
#

All?

shut violet
#

almost exclusively sans not all

#

dont worry too much about certs right now

#

you can get your company to pay for them when you get hired

#

especially when it comes to blueteam because agian, there isnt really an equivelant to like, oscp

fair radish
#

Okay, i see your point, ill grind studying until then

#

@shut violet thank you for being a fabulous community mentor 😇

serene umbraBOT
#

Gave +1 Rep to @shut violet (current: #74 - 133)

shut violet
fair radish
shut violet
fair radish
#

No i do not, but i can arrange it, i have approximately 5-6 old but usable laptops

#

Can that work?

#

@shut violet

shut violet
#

ehmmmm it COULD

#

IDEALLY you have one powerful machine/server and a couple laptops/workstations, a switch, wireless router if you need it

shut violet
#

some people disagree but i think homelabs are super worth it

fair radish
#

Before we get into that, tell me one thing, since thm, and htb have pen testing paths that are equivalent to oscp level training and cpts is always referred to as a bit more difficult than oscp. Do we have such coursework or learning material that can prepare me for SANS level certification? @shut violet

#

For blue teaming

shut violet
#

but

#

im not really knowledgable enough to say so

#

you dont really have challenge boxes and shit like you do with redteam you know

#

i didnt really learn much blueteam outside of school and work

fair radish
#

So we rely on sans coursework for their certifications?

shut violet
#

yeah and experience

#

homelab would help depending on what you do

fair radish
#

Well thats a bummer

#

I have to get into homelab then

shut violet
#

idk maybe @vital laurel can spout some wisdom

fair radish
#

I want to be able to explain the employers with a “i couldnt pay for the certificate, but with your blessings and my skills i can pass it”

shut violet
#

he knows a lot more about certs etc

fair radish
#

Thank you for pinging him

#

You are on the red teaming side?

vital laurel
#

Nothing prepares you for a SANS cert, like the SANS course

#

and I don't think you can just take the certs, I don't think that's a thing. i might be wrong, but i've never heard of it

shut violet
fair radish
shut violet
#

heres something i might do

fair radish
#

Because if that is the case, then ill stick to my oscp path and finish thm pen testing coursework, at least i can get a decent paying job and then switch to blue teaming later? @shut violet @vital laurel

vital laurel
#

well, I think the problem is the expecatation that you can just go directly into a pentesting job....

shut violet
#

get a decently powerful computer and put proxmox in it. run opnsense. set up a SIEM in a network, run caldera from an attack range host

#

look at logs and build detections

vital laurel
#

The vast majority of people are hired into some other role and then move internally

#

and idk if you looked, this is the worst job market like... ever bascially

shut violet
fair radish
#

Where i am located, skills is the number 1 factor in getting hired, because theres a big market gap, many jobs, less graduates. The second important factor is certifications, because theres gap is so huge, they are hiring people and training them. I wanna take advantage of this situation and stand out with a degree AND a certificate

shut violet
fair radish
#

Trust me when i say this, market gap is so huge they have a training and development program, bring your bachelors and leave the rest, for me, i wanna get certs before bachelors end so i can get started with work and support my family

shut violet
fair radish
#

Sans was my number 1 priority, or WGU masters, but then again, ill be stuck doing odd jobs, raising money, feeding money in tuition and and endless cycle

shut violet
vital laurel
#

Blue Certs, are hard to get that get you in the door directly.

fair radish
#

A little yes, most people are moving to cloud here

shut violet
vital laurel
#

SANS Are the only ones I know that directly open that door, but like I said right now...... SANS can only help so much too

shut violet
fair radish
fair radish
fair radish
#

But im equally enthusiastic for cyber space

shut violet
vital laurel
#

I think right now

shut violet
#

but job market borked

vital laurel
#

Focus on max learning, max effiecncy

#

Don't focus on gettting a job

shut violet
#

ye

vital laurel
#

What is the best ROI on your Time and Learning for costs (CPTS is good here) to make you better and ready to conquer when the market shaeks out

shut violet
#

@vital laurel whadya think about homelab for roi

fair radish
#

IT technical security analyst role

Certification in auditing, security controls and risk management. (Certified Information Security Auditor (CISA), SANS GIAC, CompTIA Security+ or CISSP are highly desirable.)

fair radish
shut violet
#

i mean, could grab security+ i guess 🤷‍♀️ so entry level though

vital laurel
fair radish
shut violet
#

i think homelab is one of the biggest ROIs

vital laurel
#

But it helps to put it into a context of a SIEM and a basic logs

shut violet
#

use the money you would have used on a cert for a homelab

#

you can learn windows stuff, linux stuff, domain stuff, attack stuff, defend stuff, firewall, siem, detection engineering

#

whatever you damn well want

#

and how to set up the infrastructure for all of it

fair radish
#

And how do i learn it? The coursework

shut violet
#

there is no coursework

#

you learn by researching

fair radish
#

Okay, its starting to make sense, homelab will be equivalent of what ill do in my day to day job and sharpen my skills, which i can demonstrate to employers?

shut violet
#

you gotta ask yourself questions like okay. how do i host stuff? now that i can host stuff, how do i connect stuff?

shut violet
fair radish
#

and you mentioned networking jobs, how does one get into it?

shut violet
fair radish
#

companies here have told me networking is dying because theyve moved to cloud, it didnt make much sense to me

shut violet
#

sayingh hi to people

fair radish
#

Yeah im really good and confident

#

I will start to attend conferences and seminars and i have signed up to be vice president for my uni’s student association

shut violet
#

building VMs, networks, etc

fair radish
#

What work is that?

shut violet
#

idk what the titles would be

#

network engineer, cloud engineer, that kindastuff

vital laurel
#

Yo ualways need networking for blue and red

#

the internet works over networks..

shut violet
fair radish
#

I appreciate your advice today, both of you, i thank you for it. I will continue the grind and save money from work and see what happens during that time.

#

@vital laurel thank you, and thank you @shut violet

serene umbraBOT
#

Gave +1 Rep to @vital laurel (current: #42 - 251)

fair radish
#

And im gonna build a homelab from my old computers and start simulating

shut violet
#

ive neglected my homelab completely but still love homelab stuff

fair radish
#

Why do people talk against it alot?

#

I saw people in general too saying against it

shut violet
#

idek

vital laurel
#

lots of bad takes. it's a thing

shut violet
urban bridge
#

as someone switching to it, and no prior it experience (leaning towards cyber sec). Is it better to get a comptia a+ and get a help desk then while working that job study for sec+ or get network+ then sec+? thinking network+ would be nice to have as its a foundation to getting good at security.

blissful dagger
#

actually from smh like 15 applications i got one interview booked for tomorrow

#

method is working, but honestly i dont think ill get the job. it was just for recon purposes

#

if i were you i'd just go on indeed and other local job sites in your country and throw cv's at every position that doesnt look very difficult

blissful dagger
fiery rose
#

are we allowed to add the skills we learned from the platform to Linkedin and mention that we learned them from Tryhackme?

#

Hello @vital laurel, can we talk please since you have CEH and my term is starting soon

toxic matrix
#

But I’d wait for a mod to answer

verbal cipher
#

hey i need help with how to learn red teaming

#

im on level 0

fiery rose
verbal cipher
#

i dont have money to pay the site

fiery rose
#

there are free rooms u can use

verbal cipher
#

they are so limited

fiery rose
#

yes, but they are pretty good to get the basics

verbal cipher
#

i finished pentesting up until Ohsint!

#

do u know any resources?

fiery rose
verbal cipher
#

👍

fluid dock
#

hello

floral crest
#

hi

fathom gorge
fathom gorge
fiery rose
fathom gorge
fathom gorge
fiery rose
#

they didn't say mods, they just said: ask in the channel of careers on Discord

fathom gorge
#

Ah I see, you are allowed to share on LinkedIn. But the real question is perhaps "should you?" Depends on your situation. I wouldn't put it as your main achievement, especially not single rooms / paths but there is nothing wrong with creating a post mentioning that you completed a path or CTF.

shut violet
distant whale
#

I’m interested in cybersecurity, but I’ve heard it’s tough to get a penetration tester job since most roles are senior-level and require expensive certifications. Do you think I should go for CS or cybersecurity?

warm hinge
#

Id say if you are well versed in c++ and Aseembly you could be a cybersecurity engineer.

#

theres also less pen tester jobs then blue team in general

#

whatever you want tbh

hearty plank
#

How do you guys go on about taking notes from multiple sources in obsidian? Especially when it comes to learning the same tool or topic but with additional tips or even additional material that wasn't covered in other sources? I assume this can become quite a problem later if it's not solved in time

cloud egret
#

I’ve been thinking for a while about starting a personal project for my portfolio. The idea is to build a full enterprise network (6-8 different VMs) for pentesting completely from scratch, including things like Active Directory, web exploitation scenarios, opportunities for lateral movement, and privilege escalation paths. Do you think this would be a good project to showcase on my CV?

fathom gorge
fallen sky
#

Anyone got opening for me? I have OSINT, CTI, phishing/ takedown, and brand protection skillset. got over 1.5 years of experience. I can do python and scripting. Am fine with Windows and Linux. I do reporting and while am analyst, i also deal with clients on daily basis.

Looking for remote jobs

#

While my skillset are listed above, i am trying to get into RMA so any offers on that side is also great for me. I spend time studying it too

cloud egret
blissful dagger
#

interview was like about an hour, went good

#

but holy fuuuuuuuuuuuuuuck

#

i fucked up python questions

#

like half of them

#

if it will work out i'll be moving to the capital, 350 km from my hometown

blissful dagger
#

or what types of attacks i know

bold snow
#

is comptia security+ a good starting point in terms of certs or is there a better one? so far only got some entry-level microsoft certs

bold snow
warm hinge
#

Sorry should've asked this here instead of #general but for grad school in cybersec (wanting to pursue a PhD, haven't decided a niche yet) are certifications important or cgpa and research matters more?

fathom gorge
blissful dagger
#

i hope too! i dont care about moving from my home, it has no matter to me

subtle gull
#

hey guys i'm new to cybersecurity and I need a roadmap i will learn cybersecurity by myself who can help me?

dreamy meadow
#

@obsidian rose Sec+ is a good entry level cert that alot of company's look for, You defiantly need to know the material in Net+ to understand how networks work. I started with my Sec+ and now finishing my studying for the CYSA+ which is an intermediate cert

#

@obsidian rose sorry that was to node

obsidian rose
#

@bold snow

distant sedge
#

How do I prepare for this? Please recommend some rooms or even other websites

distant sedge
#
shut violet
#

palantir evil

distant sedge
#

Man I just want an internship 🥀

shut violet
#

not worth it

distant sedge
# shut violet not worth it

Job market is so bad I kind of don't care 😭 🙏 Also it's just an college internship I'm not committed to the company I just want the experience

keen tundra
rugged sable
serene umbraBOT
#

Gave +1 Rep to @keen tundra (current: #1 - 5860)

dim radish
#

Hello, I am looking to get some career advice. I have been doing thm for maybe like 1 and a half years now and i have done a tthreat modeling internnship as well as completed my diploma in IT and about to finnish my bachelors of Cybersec. I play around with many tools and network alot. I am having trouble landing a role. I would like to break into Threat Hunting or DFIR. I also would love to start a business in this field because i genuinly do enjot it and find myself enjoying it more when i progress in it. Does anyonne have anny advice? Much appreciated :)

slim swan
#

Is anyone in devsecops here? I have a few questions

weak bison
#

Hello, I am interested in a career in ethical hacking. Which certifications do you recommend getting started?

violet crater
#

Hello i am learning cybersecurity which exam should i go first ceh of pentest?

blissful dagger
#

if it will be your first certification, CEH would be the last one i'd choose.

#

learn networking and give a take for network+/ccna (depending on ur knowledge) and then imho security+ from comptia. you can skip the networking part of certifications, they're not necessary, but hr ladies really like seeing that one on ur resume along with security certs

rugged delta
# dim radish Hello, I am looking to get some career advice. I have been doing thm for maybe l...

It's great that you're enthusiastic about it. You should read the Tribe of Hackers books. Also, when starting to work in the field you should be open to IT roles at all levels. Helpdesk/techsupport, IT/Network admin, etc., and not just the specific role that appeals to you. There's a lot of options but for a role like Threat Hunting/DFIR, it's generally expected to have several years experience in SOC roles too

dim radish
# rugged delta It's great that you're enthusiastic about it. You should read the Tribe of Hacke...

Thanks for the message. I am open to any roles but the issue is i cant even land them. I feel like they are soo saturated now because there are soo many ppl trying to get into cyber through them. I have consistently uploaded all 150 days of my streak on thm into my linkedin and done projects and uploaded them. They picked up a fair bit. I had seniors from rapid7 and sophos comment on them as well as recruiters but just no luck :(

serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #20 - 530)

rugged delta
# dim radish Thanks for the message. I am open to any roles but the issue is i cant even land...

Yeah I know it's an awful situation out there. Last year I had a recruiter looking for someone with my skills in Identity and Access Management tell me he wouldn't put me forward for a role because, even though my skills covered all the same protocols and case requirements, because I didn't use their specific system, he didn't think I'd be a good fit... Recruiters and HR people are generally not technical people. They don't realise that just because an interface is different looking doesn't mean we won't just slide right in and be up to speed in short shrift 😆

red wasp
#

Hello, Im looking to get CCNA certification, any suggested THM courses?

rugged delta
red wasp
#

thanks

dim radish
fathom gorge
kind vessel
#

I hear comptia a+, network+, and security+ are recommended in getting a cyber security entry job, is that true?

fathom gorge
#

For cybersecurity usually either Sec+ or Net+ is a preferred ask, no need for both. But unless you have experience in the field you'll likely need to start with an IT support job which may favor Net+.

sacred remnant
#

Hi guys I am not sure if I am in the right placecompletely unrelated topic but, I have just done my first SOC home lab on Microsoft Azure, how on earth do I put it on Github, I have been struggling for some times now. Any help is appreciated! Thank you 🙂

dense dagger
sacred remnant
dense dagger
sacred remnant
#

I see

haughty vault
#

👋 Hi everyone, I’m AdexnanoSec, a certified cybersecurity professional (Cisco Networking Academy).
I specialize in penetration testing, vulnerability assessment, and website/network security.

I enjoy helping people understand security risks and how to fix them, and I’m always looking to connect with others who are interested in cybersecurity. 🚀

Looking forward to learning, sharing knowledge, and collaborating with this community

obsidian rose
#

This is not the place for it. Do not do it anymore. Last warning.

junior cliff
#

Hi everyone I wanted to ask how worth it is the security + cert ? Is it really worth investing and putting time into for a first cert ? Or should I take try hack me and hack the box serious etc

#

I need to start pre security etc

river shuttle
#

Hey, with the CCNA, does anyone know what kinda jobs you can get with it, if I have no prior IT experience. I’ve been interested in becoming a network engineer but feels like there aren’t any entry level roles for that, any reply would be great.

vital laurel
dim radish
tidal island
#

Hey Hi iam just completed my 12th and iam trying to enter in cyber security path
Any suggestions

keen tundra
queen dirge
#

I am not sure if this is the right place to ask as I am new to Descord and cybersecurity. I am asking a person who has recently completed his initial (beginners) journey in cybersecurity. I need help from them. If there is any way to connect with me personally, please contact me.

vocal pecan
vocal pecan
vocal pecan
bold snow
#

not sure if i should get network+ first though PepeHmm

rugged delta
last gyro
#

Does the tryhackme gives a discount for their premium account ?

crude sphinxBOT
jade basalt
#

Dear All,
I currently work as an SAP Basis Consultant with 6 years experience. Will it be a wise decision to move to Cybersecurity or what challenges to expect ?
Also, when switching domains should I expect a salary cut.
Directly switching to Cybersecurity is a better idea or should I transition first to SAP GRC/IAG, work for sometime and then switch to cybersecurity eventually?
Even a little guidance is highly appreciated !!!
Thanks

hollow sierra
#
Vox

Vox is a general interest news site for the 21st century. Its mission: to help everyone understand our complicated world, so that we can all help shape it. In text, video and audio, our reporters explain politics, policy, world affairs, technology, culture, science, the climate crisis, money, health and everything else that matters. Our goal is ...

#

Tldr, you are not alone. This is a systemic issue if you cant find work atm;

hollow sierra
#

Also if you happen to also be in bc canada, and also are dependent on disability benefits, this program may be a good one to investigate;

patent badge
fossil heath
#

Hi, I'm done with my Jnr pen tester course on TryHackMe and I want to know if I can use the cert to apply for a job or I need to get a CompTia cert

dense dagger
fossil heath
dense dagger
#

But if youre only applying for entry level jobs like a jr. developer or jr. support engineer, I would assume they aren’t asking for any certifications.

fossil heath
#

So what do you need for entry level jobs then, if they aren't asking for any certs? And for the senoir level cybersecurity do you need advanced certifications like CISSP and CISM

carmine venture
#

Does someone know why when I use hydra to crack passwords on a site using rockyou.txt or something else it finishes telling me 4-8 passwords that do not work? It should all be correct including the error message

odd igloo
dusk wedge
#

its the same site

#

same guy

carmine venture
#

Im not doing that anymore

#

but I want to know why hydra does this:

#

What is wrong?

#

the command is this right?

keen tundra
dusk wedge
#

this is not related to a thm room

mint mason
#

Are u guys share here CVs to discuss what is wrong/missing etc? ( obviously without PII )

left prairie
#

Guys i am 16 year old, i done cyber security course (offline) from craw.in and i am on rank legend in THM, my course on craw.in is about to end (that course just establishes base in both offensive and deffensive security), i want to be vulnerability researcher, what should i do next? i am very confused... need some advices

stuck pond
#

hello everyone, im working on VDP right now maybe someone can guide me to get my first bug on hackerone, im still cannot understand about the description, and still confuse how to aproach the target, thanks

mint mason
# keen tundra Yeah you can do so 🙂

Alrighty, roast me 🙂 ( hopefully I removed all PII if not please let me know)
First and second page below. Last sentence of the summary always need to be changed depends on the job title.

flat sedge
# mint mason Alrighty, roast me 🙂 ( hopefully I removed all PII if not please let me know) F...

You have a background in compsci, the first thing I would say is use a LaTeX template for your resume/cv instead of a word doc. You have technical skill from your CompSci degree, leverage it in the elevator pitch. Be sure to include in your Projects whether a project is personal interest or required coursework. If you wrote code and it's open source, include project links to the git repo where the code is stored.

mint mason
glass wolf
#

What can I do to increase my chances of getting a job after I graduate? I'm studying "IT and leadership"...

quartz forge
#

Hey guys! I'm quite new to cybersecurity. I just finished the first module of Intro to CYS in Pre Security course. I got a doubt that I couldn't find the answer for. What's the difference between a 'Red Teamer' role and 'Pen Testing' role 🤔

stoic pier
#

Hey guys im 17 just getting into cybersecurity and i was just wondering, Is paying for and getting the CompTIA A+ cert worth it? or do employers not really care about that

mental zephyr
#

Hello! Are there any Canadians here that went to ABM for cybersec? Just wondering what your exp was like if you did!

subtle hill
# stoic pier Hey guys im 17 just getting into cybersecurity and i was just wondering, Is payi...

hey, i'm also "young" and in my opinion, since you're just getting into cybersec, you should wait till you have like a solid base, labs and "experience" with the learning itself. Anyways, it depends on what do you think of the price and your financial conditions, when you're a little older i think you should consider it to get employed, it helps a LOT, and most of the jobs require certificates like comptiasec+ as something "different" and that kinda puts you "on top" of the list of options to hire.

thick steppe
#

hi guys im currently a junior at uni trying to break into cybersecurity. i'm not sure whether i should target becoming a soc analyst or get into pentesting. I'm interested in pentesting but I'm not sure what would be enough to stand out in the job market for my resume and if i'll have enough time to learn everything before i graduate(so that i can get an internship). likewise for blue team if i want to become a soc analyst. are the soc analyst and pen testing pathways enough to provide projects to stand out in the market to land an internship/job? i already got my comptia security+ certification, im just looking to have hands on experience now or to do some hands on projects to stand out and help my resume so that i can land an internship asap

#

im also considering cloud security, so im most likely going to work on getting the aws ccp

#

so is it worth spending time to get the sal1 cert?

dense dagger
thick steppe
#

i already got the comptia sec+ but they don’t have hands on stuff so idk if the cert here is necessary

dense dagger
#

For projects under SOC, you can definitely do a homelab with an attacker machine, ELK stack, and a machine you will attack like Metasploitable for example then you attack it and simultaneously learn how to pick up common telemetry, etc.

#

Then you can extend it to a cloud-based honeypot for example.

thick steppe
#

alright thanks

#

so would you still recommend i use thm?

#

or just focus on homelab projects

dense dagger
#

Yeah, they have the SOC Simulator and table top exercises which are helpful for aspiring SOC professionals

#

You can always interchange them, there’s no reason to drop one thing just for another

thick steppe
bold snow
#

are there any paths that can help me study for security+?

dense dagger
verbal yarrow
vital fractal
#

I am going to buy the anti-virus program code
if anyone have it, pls contact with me, thxxx

fossil heath
atomic pollen
weak flower
#

I know there's a SOC simulator, but is there an alternative for people who would like to have hands on experience?

#

like, bounties?

vague vale
#

Hey guys, im really having an hard time choosing a certification in the blue team realm, more specific for havin better chances for landing a L1 SOC position in the next year. I currently have google cybersecurity professional certificate, Security+ 701 and thats it (80ish rooms in on Thm and going for SOC level 1 path in the next month on the platform). I'd need a certification aimed at the Canadian jobs market (im italian but i ll moving there in 5/6 month from now). Any suggestion? I do have some experience as an IT support for a medical company. Thanks

rugged delta
# weak flower I know there's a SOC simulator, but is there an alternative for people who would...

The SOC simulator and practical certifications are generally good ways to see how a SOC functions in a practical way. You should consider reading the Tribe of Hackers Blue Team book. That series is usually affordable. They're a series of interviews with cybersec professionals in various roles in the field put together by a former NSA hacker. Check out Episode 83 of Darknet Diaries if you want to learn more https://darknetdiaries.com/episode/83/

rocky field
#

I am still very early in my career, not into cybersecurity quite yet but soon can transition into it. General IT at the moment.

I am scared if technology is the right industry to get into, I am seeing a lot of people saying to stir away from it due to how insanely competitive it is and other factors like outsourcing/AI.

vague vale
#

dont be scared if u are passionate about it and u like it

#

almost everything nowadays is more competitive than it used to be 10 years ago

#

like gaming for example. lol

acoustic roost
#

hi guys i got a question for the pentesters or anyone in cybersecurity. How constant do you have to keep up to date with new updates or newly found vuln, and what websites do you guys use. I'm new to cybersecurity and it sounds hard to keep up to date with everything

drowsy flame
# acoustic roost hi guys i got a question for the pentesters or anyone in cybersecurity. How cons...

Keeping up with new vulns, exploits, and general infosec happenings is just as important as learning the basics and vulns of old. It is daunting for sure, but there are tons of ways to passively keep up. Podcasts like Hacker and the Fed, Darknet Diaries, and Smashing Security are entertaining options. Others are newsletters and communities like TLDR and the fine people here in THM. Just find a method of ingesting the info that works for you and soon, you won't even realize how up to date you are! You got this!

acoustic roost
# drowsy flame Keeping up with new vulns, exploits, and general infosec happenings is just as i...

But realistically, and I don’t mean to offend anyone, but does it not stress you out about having to keep up with so many updates weekly? Like is it possible to get fired from your job as a pentester if you don’t keep up with new vulns or exploits? Cause I lowkey feel like if there’s new vulns or exploits every week, you’re just gonna be like on your phone/pc reading those new vulns/exploits 24/7 and it just sounds very exhausting

vague mist
#

any indian here who is working / knows about the career options here? need guidance..

random parrot
#

Hello everyone, I’m currently taking the goggle cybersecurity course on Coursera. I only have basic IT skills and my goal is to take the CompTIA sec. Do you guy know anything else that could help me pass the exam?

junior cliff
#

Has anyone got the sec + certs

#

And also worked or currently work in IT support

dusk wedge
#

i did IT support

keen sluice
#

hey guys im currently working on my SEC+ and was wondering if anyone had any tools they found very useful for studying for it ie.(quizlet practice tests ect)

fossil sentinel
#

Good day everyone, please I'm trying to learn or work in cybersecurity, but currently I'm in my second year Computer science major. I only have a router, a dell latitude e5570 core i3 6th generation, 8gb ram, 256gb nvme ssd

#

Currently I don't know where to start from, thinking about it alone seems overwhelming, but I think I would love being a pentester or a cybersecurity engineer, but no path to follow, and also can't afford any of those certs at the moment because they are too costly, I need a guide please

left prairie
#

Guys i am 16 year old, i done cyber security course (offline) from craw.in and i am on rank legend in THM, my course on craw.in is about to end (that course just establishes base in both offensive and deffensive security), i want to be vulnerability researcher, what should i do next? i am very confused... need some advices

quaint wren
#

If I'm trying to break into the field asap without a degree (even if I must go through IT first), should I gain skills/knowledge from starting SOC Level 1 path on THM or focusing on studying for Sec+? I just finished Jr Pen Tester as I was told it's important to finish due to the general knowledge it gives

versed sparrow
quaint wren
#

I ideally just really want to skip A+ unless that's absolutely necessary

#

But like I'm fine with doing IT Support/Help Desk/etc., I'm not sure if Sec+ can lead to those roles

versed sparrow
#

To be honest, you have to be able to sell yourself well. I myself come from gardening, but my hobby has always been hacking. To be honest, I only wrote two applications for this and was lucky enough to get a job at a SOC. The references from THM helped rlly... and i doesn't have actually comptia sec+...

quaint wren
#

So you applied with no certs?

versed sparrow
#

jupp

quaint wren
#

What did you finish on THM before doing so

versed sparrow
#

I have proven my abilities.

#

the basics... metasploit, exploits... etc...

versed sparrow
#

Then you'd better do Comptia Sec+ or comptia Cysa+

#

comptia sec+ for 1st level SOC and cysa+ for 2nd level SOC

thick steppe
stoic cave
quaint wren
#

I do just want SOMETHING that gets me like towards security within the next like 6 months though

stoic cave
quaint wren
#

oh I see

#

So then what would you say is a better use of my time, studying specifically for Sec+ or SOC level 1

#

I feel like the cert would probably help but idk if no experience and Sec+ would get me a job somewhere

stoic cave
#

Do you have a degree? Based on the previous conversation, I'm assuming you're not working in a computer adjacent industry currently

#

Certifications are used to quantify professional experience. They don't really stand on their own

quaint wren
#

Nope, no degree. I want to try to break into IT at least without one which I know is really difficult but not impossible

#

and I have a good amount of time to study/home lab/etc

stoic cave
#

OK, so you need to start building your professional experience. That means getting a job in IT with something like Helpdesk

quaint wren
#

So does that mean spending time on A+ is pretty much necessary, or is that doable going into Sec/Net+

stoic cave
#

I wouldn't even worry about certifications right now

#

Start applying for entry Helpdesk roles, they don't require anything

#

Unless you haven't graduated High School or have a GED

quaint wren
#

I seeee, I do have a diploma, I'll definitely start applying, I though a cert was like required even for that

#

I just want something asap that'll start giving me experience in the tech field so

#

That's what I was looking for

stoic cave
#

No, it doesn't require anything. Helpdesk I is ground zero for the industry

quaint wren
stoic cave
quaint wren
#

Does anyone mind looking at my resume if I dm it to them? Redacted ofc I just would rather dm it

acoustic roost
#

hi guys i have another question, lets say you're keeping up to date with new cybersecurity vulns, exploits, etc. How long will that usually take, does it take like 30 -60 minutes, hours, how long?

pseudo ridge
#

Can depend tho, if there is something aws related ill go further into detail and research since thats what i work with

hollow falcon
#

What are some applications/techniques I should be aware of to help pass an interview for a SOC position?

dusk bolt
#

What about the the compTia Network+

hollow falcon
#

What IDS would I most probs be using?

#

I know grep well

#

I use Linux all the time

dusk bolt
#

@junior cliff has anyone finished the course

hollow falcon
#

We can do Splunk, little exp with that. I know OpenVAS fairly well

junior cliff
hollow falcon
#

I mean, its a public sector position, can't be that challenging

#

School district lol

#

Gotcha

#

Me?

#

It's for an entire school district

#

5th largest in the US

#

Gotcha!

#

I work here

#

Im a SBT

#

Already in the District, just now got an interview for their cybersec department

#

Some do, yes, many others not really. Trust me, if you met these same people you would know bad info

dusk bolt
#

Hey guys am new
And am interested in cyber security 😀

hollow falcon
#

I love OSINT

#

Have a book on it

#

I was gonna messege the CTO(?)

#

About it

#

I need to find their email, easy tho

#

I know their name

#

I can look them up in our directory

#

That's kinda how I got the cybersec interview

valid sentinel
#

Hey peeps

sharp basin
#

Hello

lean talon
#

hello fox how its going, what is opinion about apprenticeship ? i had few interview before with google but i fail in the last stage for them :c i didnt have more calls , what would be the best way to get one , send emails to the company asking if the are interesing to get apprentices ?

summer flint
#

hey folks

#

where can I start AD pentest ? I always play web linux privesc

keen tundra
viscid vigil
#

Can someone help me decide what I should do next in TryHackMe? I started with Cybersecurity 101, but now it is asking for purchasing what should i do guide me guys

dense dagger
#

Other than that, I suggest doing your own research and looking for available free resources. There are tons.

viscid vigil
#

@shyz2busy8387 @shyz2busy8387 thanks guys btw what way you guys study for cyber? Like paid version of tryhackme or freely by researching?

dense dagger
viscid vigil
#

So what you recommend to do own research and study or go with tryhackme then own research?

#

One more thing certification they are way more costly for that what is the solution?

balmy dove
#

write code, write blogs, join CTFs, contribute to groups

cobalt prairie
#

Hey everyone! Its been a while since ive joined this server but I'm not really active here. The reason why i joined this server was to get some guidance, how to land an internship in this field(as I've heard and experienced aswell that the entry level roles are a tight competition). I have completed some learning paths like jr penetration tester, red teaming, web fundamentals, etc but I have no professional certifications as of now. I would love to learn or hear your experiences, thanks : )

vague vale
junior cliff
#

As anyone done CISCO courses ?

latent iris
#

im going to collage but i just dont know what study i should follow, i can choose like linux sysadmin, windows sysadmin, cyberops in the field, cybersecurity from a hackers perspective, practical threat intelligence or linux server security
i want to be a penetration tester tho so what should i do?

#

i got 19 classes i could follow but ill have to send the pics in dms cause i printed it out

weary lion
atomic pollen
livid needle
#

Hi guys, I have a question

#

I somehow managed to land a SOC internship but it’s unpaid, should I go for it?

atomic pollen
gusty sinew
#

Cybersecurity specialist skilled in hacking, data recovery, and gaming security. Focused on protecting systems and optimizing performance.

livid needle
atomic pollen
livid needle
dense dagger
#

There’s also no guarantee of getting a return offer.

#

That’s like “hey, do 24 weeks of work with us and maybe we’ll consider you.”

livid needle
#

Well the thing is, I don’t have much any other options. All my online applications have failed despite having the best resume. I only managed to get this one because I met the CEO of this company in a networking event

dense dagger
#

Think about 6 months down the line if you think it’s worth it to commit to that without being paid for your services.

#

You also have to consider your expenses like commute, lunch, etc.

livid needle
#

Well, I won’t fully go 6 months unpaid, I will try to ask them for paid role earlier than that like 2-3 months and see what they say

dense dagger
#

It’s possible to negotiate with the employer if a salaried position is possible. Research about what is the minimum wage where you live and try to compute your costs around that.

livid needle
#

Worst case scenario I will quit, not paid but at least I got real life experience out of it

#

I will have an onboarding meeting with them next week so I will ask them these questions

#

I won’t let anyone exploit me

dense dagger
#

It’s still up to you but you should consider all your options.

junior cliff
junior cliff
livid needle
atomic pollen
livid needle
#

And also I signed up for a tafe SOC course and paid 1500$ but they delayed it 2 times so I cancelled and got a refund, but at least this intern will give me experience for free

atomic pollen
livid needle
livid needle
#

And I like blue teaming

#

And this one checks the box

#

Considering online applications mostly fail, I see this one as a rare opportunity because I only got it because I met the ceo of company

#

There are paid graduate jobs out there but they are rare and damn impossible to get unless you can hack nasa

obsidian rose
atomic pollen
livid needle
#

Yeah, it’s the employers market, unless you’re a senior engineer and have good skills to set terms but when you’re a junior with no experience, you should take whatever you can take

junior cliff
#

Hey everyone how do you guys go about structuring or documenting try hack me progress on cv etc ? I have git hub but don’t know about it fully alot

#

Plus linked in

#

But to show people and proof etc

livid needle
livid needle
#

What are your thoughts on this? @atomic pollen @dense dagger

dense dagger
dense dagger
# livid needle This is what chatgpt said about this: you don’t have to stay the full 6 months ...

That’s true but the problem is, they’re hooking you into the idea that there might be a job offer down the line which may not always be the case. There can be cases where they tell you to extend maybe 2 more months just to “fully” evaluate you. The workload can also be taxing depending on what they’ll give you. Also, 2-3 months is not an ideal timeframe to “prove” your worth. Its more of a transitionary period in understanding how the business and operations work.

#

It kind of sounds like I am being pessimistic but these should be real concerns that you need to take into account.

#

As I said, its up to you entirely if you want to push through with it, I’m just providing you with perspective on how you can look at this offer.

atomic pollen
# livid needle This is what chatgpt said about this: you don’t have to stay the full 6 months ...

That is true, internships often lead to a contract, but as Mknukn said, it's not guaranteed. I'm just thinking about grabbing opportunities as they come, since that's what you have to work with now. You can always walk away if it doesn't work out, but at least you'll gain some real-world experience and get a sense of what the job is like day-to-day. You could keep job searching on the side, but my concern is that your time might be stretched thin with everything else going on.

obsidian rose
cobalt prairie
flat sedge
rugged delta
# cobalt prairie I mean as of now ive only done red teaming but i would love to break into soc an...

Is it that you've done some red teaming paths but you want to do some blue teaming paths? You can take a look at the SAL1 certification page and if you click the 'Get Started' button, you can then click the Recommended Learning section on that page and see which rooms and paths are suggested in your pursuit of the SAL1 certification. You can do those paths and rooms without pursuing the certification, but it may make you more confident discussing such topics when pursuing those kinds of roles

https://tryhackme.com/certification/security-analyst-level-1?ref=discord

TryHackMe

Stand out with Security Analyst Level 1 (SAL1). A hands-on, entry-level security analyst certification built by industry experts. Prove your skills, showcase real-world experience, and launch your cyber security career.

hexed mauve
#

I'm working on that now. Would you say that plus other tryhackme labs and maybe a home lab running snort or zeek would be enough to confidently apply for a soc job?

#

might get the cysa+ after as well while i'm grinding. I already have the network + and security + and 3 years of helpdesk but still feel like I have a lot of gaps in what I should know going in.

quick brook
#

Depends on what job you're applying for, yes

cobalt prairie
cobalt prairie
hollow drift
#

I haven't been required to write any scripts as an intern, but have definitely written some for automation purposes. It depends on the environment you're working with but I'd say understanding powershell/bash is a must and then being able to differentiate between malicious/benign code in whatever language the place uses is a nice to have

#

most cases of what?

dense dagger
#

That depends on the company’s policy. There may be policies that only approved AIs (e.g., your company uses Google Workspace, so Gemini is the AI of choice) can be utilized. Even then there are also policies to consider like don’t upload customer info to the AI, etc.

hollow drift
#

again depends on which company it is, I'd say generally frowned upon (as of now). Usually someone in a more senior position would handle scripting if it's needed for parsing logs or tussling with connectors. Most likely you're gonna be handed a SIEM and told to address offenses

#

I guess I'd sum it up as probably not needed but incredibly useful to know

hollow drift
#

We had been kicking the AI problem can down the road until that point

dense dagger
junior cliff
#

What would be suggestions for a free learner rn ? In terms of certs ,learning material …? Everything and anything please

pastel sky
#

Do you guys think Chat GPT could be an effective answer for career planning?

pastel sky
modest coyote
pastel sky
#

Thanks Everyone. I don't either know peers or people in the industry.. So I gonna ask here and get some help.

dusk wedge
#

people here are always open to help

#

probably

quartz forge
#

Can I jump in and ask career advice for me as well?

modest coyote
#

As bad as LinkedIn's content is, it is actually useful to find people working on a field of interest. You can usually add someone and ask for some tips or advice, most people I've tried have been receptive to that

languid oriole
#

Hi everyone
I’m a high school student from Italy and I’m very interested in cybersecurity.
I’ve been studying on my own and doing some courses, but I’m still at the beginning.
I’d like to understand better what working in cybersecurity is really like, not only the study part or challenges, but the day to day job in companies. Do you have any advice or resources for someone like me who wants to explore the field and get a clearer idea of possible career paths?

Thanks a lot for your time

prime pewter
#

Hey,

Does anybody know good resources for AppSec? I would like to learn AppSec but can not find good resources.

hexed mauve
#

hey guys is snort or zeek more mainstream for corporate security? or are both used?

languid oriole
#

Thanks a lot for your reply, it’s really helpful!
I forgot to mention that I’m especially interested in penetration testing, even though I’m still exploring the different areas of cybersecurity.

I completely agree with you that practical knowledge is more important than just certificates. Right now I’m trying to build skills step by step, and i’m starting to do some CTFs.

serene umbraBOT
#

Gave +1 Rep to @misty jungle (current: #3119 - 1)

pallid rune
#

hello

#

could i get advice from somebody experienced in the cyber industry

#

in a sophomore rn in college i wanna do security engineering when im out of college

fiery rose
#

@obsidian rose I am starting with CEH as first cert, u think it's worth it? I still didn't pay yet

pallid rune
#

rn im doing picoctf

#

and i’m gonna start overthe wire

fiery rose
pallid rune
#

idk how i can learn py script

obsidian rose
fiery rose
stoic cave
obsidian rose
#

What field do you want to work in? Do you want to work in Morocco as well?

fiery rose
pallid rune
obsidian rose
#

The US and France would be very different for example.

fiery rose
obsidian rose
#

Pentetsing, OSCP is widely recognised across europe. Some countries prefer a degree however.

fiery rose
#

also most companies here ask for offsec certs, CEH only a few, for example Deloitte asks for Offsec

stoic cave
obsidian rose
fiery rose
#

which one will give me better skills

obsidian rose
#

OffSec. CEH is MCQ mainly.

#

But OffSec is a big investment.

fiery rose
#

okk, thank you

fiery rose
serene umbraBOT
#

Gave +1 Rep to @obsidian rose (current: #27 - 381)

loud plinth
#

“Ha ha, hahaha.”
cyber-and-careers what about it?

kindred osprey
#

What yall think is a good project to have on a resume. It needs to stand out and should be pretty advanced. Not like very beginner friendly

thorny moss
#

my goal is soc analyst
I am almost finished with the SOC level 1 path
Once I am finished, I am thinking of doing SC-200 and/or SAL1
Which should I do, or if I should do both, which should I do first
And also, should I do the SOC 2 path or do the JR penetration tester path

tardy meteor
#

Question guys, is it better to follow the whole learning roadmap on tryhackme? or is it better doing specific rooms such as Jr. penetration tester, SOC 1, secuirty egineer etc?

keen tundra
void oak
#

Hey guys, do you think the MacBook Air M3, is a good choice for me?
I’ll be doing more on penetration testing

tiny pecan
stray wolf
#

Hello guys, I'm a non-IT student I likes to start my career in cybersecurity roles can anyone please help me, especially with resume I don't know what to keep and especially the projects section

tiny pecan
stray wolf
#

Had a little theoretical knowledge on networks, os, tools

tiny pecan
# stray wolf Had a little theoretical knowledge on networks, os, tools

For your cybersecurity resume toss in any relevant classes, maybe a cert like CompTIA Security+ if you can get it. And some cool projects if you have done any, like a home lab even. Show off skills like problem-solving, and add a projects section with 2-3 things like setting up a secure network or poking at vulnerabilities.

stray wolf
tiny pecan
#

Ok so that's a good start, add that on there!

stray wolf
#

Is EC-COUNCIL EHE cert worth?
And I don't know what projects to clearly add
can u or anyone say few, if possible please

#

@tiny pecan Thank u bro

serene umbraBOT
#

Gave +1 Rep to @tiny pecan (current: #3120 - 1)

drifting obsidian
#

Hey Y’all. I’m a 24 yr old from Pakistan. My name’s Ibrahim. I go by IB.

I’m a complete beginner. Less than a newb when it comes to tech.
I was wondering if anyone knew a pathway into cybersecurity. Like what I should learn and where from and how do I get onto it.

I would appreciate the help. I’m looking for a roadmap to lead me to cybersecurity

tiny pecan
# stray wolf Is EC-COUNCIL EHE cert worth? And I don't know what projects to clearly add can...

When you are starting out any Cert is worth mentioning.

For projects you can do some simple stuff and post a blog post about the results. Something as simple as scanning your local network using wireshark and nmap.

You can then say something on your resume under projects like:

Home Network Lab

  • Conducted a home network security audit using Wireshark and Nmap
  • Identifying and mitigating 3 vulnerabilities, including blah blah
  • Used my skills to enhance network security by 50%
tiny pecan
stray wolf
serene umbraBOT
#

Gave +1 Rep to @tiny pecan (current: #2054 - 2)

tiny pecan
languid oriole
#

Hey guys, I’d like to know if it’s possible to get a job with an OffSec Level 200–300 certificate without having a degree. My idea would be to start working after completing the course and then pursue a degree later on. Thanks!

trail fractal
#

Hey people!
So I’m trying to change careers from a self employed gardener into the cyber security industry. Getting closer to 40 and wanting to get a job that dose not require destroying my body.
My plan is to take the CompTIA Security+ & the SAL1 for starters. I have just completed the pre security course and now onto cyber security 101 (which i am throughly enjoying). I’m looking for remote work as I live in a rural area. Currently rebuilding my home network for a project using ubiquity hardware. What other recommendations do people have for becoming job ready as soon as possible?

fringe spade
stoic cave
stoic cave
languid oriole
#

No i don't any professional experience because i'm still an high school student. I'm 17 and since last year i started learning about cybersecurity trough tryhackme, especially now i'm pursuing cyber security 101. My question was what is the best path to became a penetration tester?

#

@stoic cave

stoic cave
# trail fractal Hey people! So I’m trying to change careers from a self employed gardener into ...

Career transition isn't something that I've dealt with personally, but I will say it's likely going to be hard to jump straight into cyber. Cybersecurity is not an entry level occupation within the computer industry. You're likely going to need to start on a Helpdesk somewhere as you're coming from a non-technical field. This means two things, the first of which being can you afford that change. The second thing is that you're likely not going to be able to find/obtain remote roles right away/for a while. I personally do not think Security+ or SAL1 will be helpful to you at this stage. A+ will likely be a better option, even if you know all the parts of a computer and what they do. At this stage, you're likely to receive a bunch of questions about why you're transitioning and "are you capable" sort of stuff.

stoic cave
languid oriole
serene umbraBOT
#

Gave +1 Rep to @stoic cave (current: #21 - 527)

stoic cave
languid oriole
flat sedge
ember fulcrum
#

.

vivid river
rugged delta
vivid river
serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #18 - 533)

warm vortex
#

All replaced by ai

chrome spire
#

Im using it rn lol

chrome spire
#

But that is a HUGE skip of steps

#

The OSCP is way above your skill level

#

lol

vivid river
torn narwhal
#

I know this depends on location, but this is just a general question that I have regarding entry-level Helpdesk roles.

Q1. Do you need background experience (job experience), certifications etc?

Q2. Is it normal to not know how to troubleshoot everything when working in a Helpdesk position (e.g, advanced network issues, applications issues, etc.)?

Thanks in advance.

olive citrus
#

Guys is there anyone whos SOC analyst

edgy orchid
#

Hey, if I'm considering switching my goal from being an SOC analyst and moving toward becoming a security engineer instead, would I have much luck? I know the industry isn't very entry-level friendly right now (which sucks for people like me) but I'm just not enjoying learning SOC stuff in the least. It wasn't really my endgame goal to begin with, I just started learning that side of security because I assumed (based on what I was told) it'd be the easiest way to get an entry-level position... but frankly, my interests seem to lie more in the security engineer side of things, at least for now, so I'm just curious what y'all think. I'm not decided either way yet.

edgy orchid
# chrome spire

Curious why the Linux+ is listed before the Sec+ in this, considering how I've been told the Linux+ is significantly more challenging than the Sec+ and Net+ 😂

languid oriole
edgy orchid
languid oriole
serene umbraBOT
#

Gave +1 Rep to @edgy orchid (current: #658 - 10)

edgy orchid
# languid oriole Ok, thanks. So if you don't have that certificate, you can't work in cyber?

Not necessarily, but certs are the primary method of proving your capabilities and getting your foot in the door, so you'll definitely have better luck if you get one. I don't have any of my own yet, but I'm currently studying for two (ISC2's free "Certified in Cybersecurity" and the CompTIA Security+), as I have had absolutely no luck finding an entry-level IT job, let alone one in cyber, and I know those will at least partly boost my chances

remote hemlock
edgy orchid
languid oriole
#

So, would you recommend that I get these certificates during university, or maybe later while working, for example? I just need to get a general idea since I'm still in high school and I have two years left. My goal would be to finish the TryHackMe red team path before starting university. Thanks for your time.

edgy orchid
languid oriole
serene umbraBOT
#

Gave +1 Rep to @edgy orchid (current: #604 - 11)

edgy orchid
remote hemlock
abstract agate
# edgy orchid Hey, if I'm considering switching my goal from being an SOC analyst and moving t...

im pretty much in the exact same boat, have some internship experience in software dev before i decided i was more into cybersecurity, so I got my sec+ going for a soc analyst entry but my endgoal is security engineering. at this point, i personally decided to learn and make projects possibly looking a bit overqualified for SOC, just to give myself options. Im trying to follow a roadmap where I'll learn enough red/blue team skills then hone in on what I need once i land a role.

#

soc seems boring but it needs to be done

edgy orchid
# remote hemlock Yeah. Tbh Im personally skipping A+ and Net+. Im going CCNA route. Still doing s...

Yep, I decided to skip the A+ myself because it's expensive and if you're capable of stuff in Sec+ or Net+ (or CCNA, in your case), there's a good chance you already know your basics. I'll probably just go with the Net+ myself, as I know the CCNA is more challenging and I don't know if I want to invest that much time and effort into it when networking isn't my primary focus, and I'm definitely going to grab the Sec+

edgy orchid
# abstract agate soc seems boring but it needs to be done

Well, it's not so much that it's boring to me, it's just that I find myself struggling to follow along with all this crazy amount of data analysis and I'm also not keen on the idea of basically just watching logs and IDS/SIEM stuff all freaking day 😅

But yeah, I'm sure I'll pick back up on the SOC path at some point or another, even if I switch, as I know it's important stuff. In many ways, this consideration is just sparked from being overwhelmingly frustrated with the Snort room, which I genuinely loathe for some reason 👀

#

On the subject of the Snort room, I may just return to it with a video walkthrough, or watch a more in-depth video course, because I was feeling lost and frustrated. I also feel like it'd be a thousand times more useful as a tool if it had a GUI because it's challenging to actually read so many walls of text in a CLI (even though I actually enjoy using a CLI for a lot of things)

remote hemlock
abstract agate
edgy orchid
edgy orchid
# abstract agate yeah i get that, ive tried looking into other roles such as sys admin or cloud e...

That's similar to my issue. I've been applying for IT jobs for half a year now, I intentionally went with entry-level helpdesk simply because I don't have IT experience and I figured that'd probably be the only thing I could actually be considered for... but even after 6 months of regularly applying, not one interview. Not one. I'm not expecting my chances to be better with any applications regarding cyber, but I guess I can only do whatever I can do 🤷‍♂️

And as for burnout, I've experienced that something like 4-5 times already and it always takes forever for me to get back into the swing of things NotLikeThis But again, I can only really do whatever I can do and have faith for things I can't change

remote hemlock
edgy orchid
# remote hemlock Totally understandable honestly. The price tag is daunting. And I've been consid...

Yep, especially if you can't even get your first job to pay for it in the first place 👀 And yeah, probably wouldn't hurt to get yourself some gear if you can, hands-on practice and home labs are good to pad out where you lack experience.

I'm hoping to build a lab for myself, just trying to figure out space requirements, probably going to have to move just to get that done... fortunately, I have a different family member I can move in with who actually has some free space, but still, gonna take forever to actually get that move done

remote hemlock
edgy orchid
remote hemlock
edgy orchid
remote hemlock
edgy orchid
abstract agate
# edgy orchid That's similar to my issue. I've been applying for IT jobs for half a year now, ...

yeah its very rough right now, I've had a chance to work with helpdesk for a bit and it seems like they usually require A+ or hardware knowledge, I dont know if you've tried these jobs but if you have any interest in hardware, I would look into computer technician job maybe, if not a geeksquad agent at best buy since that requires little to no experience. I feel the same way with burnout though, it makes me not want to even look at a terminal sometimes. hang in there.

edgy orchid
# abstract agate yeah its very rough right now, I've had a chance to work with helpdesk for a bit...

Yes, helpdesk is basically all I've been applying for. My main issue in terms of opportunities is that I live in a rural small town, next to no companies with proper IT departments (let alone hiring), and I don't have a car so I can't exactly travel to the nearest city. Really limits my opportunities since I basically can only work remotely. Sucks, but I've tried to figure something else out and I've got nothing 🤷‍♂️

Thanks for the encouragement though! Like I said, I just keep pushing forward, doing whatever I can in the meantime. No idea whether I'm wasting my time or not but hopefully not lol

serene umbraBOT
#

Gave +1 Rep to @abstract agate (current: #3124 - 1)

remote hemlock
serene umbraBOT
#

Gave +1 Rep to @edgy orchid (current: #563 - 12)

edgy orchid
remote hemlock
grim radish
#

@edgy orchid are there any internship options available in your country? Not suggesting it's financially solid plan, but at least an opportunity to get a foot between the door.

edgy orchid
# grim radish <@1365104771693809798> are there any internship options available in your countr...

It's funny you mention that because I had considered doing so. Right now, I live with family and thus my expenses are somewhat low (though I do have other things I really need to be saving for), so an internship would work at least to start. Problem is, I have yet to find a single internship that doesn't require you to actively be enrolled in some sort of university degree. Definitely can't afford, nor do I desire, to ever go to college so that sadly won't work out

grim radish
#

I see, that's unfortunate. I'm in a somewhat similar situation, where I'm trying to find my first cyber security job. Though I started my cyber "studies" 25 days ago on TryHackMe :D. I worked previously as a web developer so not entirely alien to many of the concepts. Anyway, still very green when it comes to hacking. In my country the local employment agency organizes several tech trainings, and after taking the web development training got extremely lucky to land an internship that turned into full-time job. Dunno if something similar is available where you live. Now starting an Cyber Security Expert training via same agency, and trying to find the place to do an internship in.

edgy orchid
serene umbraBOT
#

Gave +1 Rep to @grim radish (current: #3124 - 1)

grim radish
#

There might be some entirely online. You could also consider taking a MOOC (massive open online course) e.g. Helsinki Uni in Finland offers Cyber security courses for free: https://www.mooc.fi/en/courses/
Ofc, I'm not a recruiter so might be that Certs are the way to go, but I doubt doing some free uni courses would hurt. Cheers for the rep 🙏

chrome spire
# languid oriole get the point, the first are of comptia right?

I would go for Sec+ or the isc2 CC as I said the OSCP is very challenging and you cant just jump into it. The OSCP course will be in a differient language to you if you dont understand it. But you dont have to go farm up all these certs like the A+ and stuff. Depends though.

chrome spire
quartz forge
#

Hey folks! 👋
Final year B.Tech CSE here. While most around me are chasing SDE jobs, I’ve recently gotten hooked on cybersecurity (crypto class + Kali Linux got me started).

I’m considering a Master’s in Cybersecurity (which means prepping for a competitive exam here in India), but I’m also wondering if I should first focus on hands-on skills / beginner-friendly certs before committing.

For someone just starting out, which path would you recommend?

hollow sierra
flat sedge
hollow sierra
#

ah ok so list specific projects done while on thm and add those, rather than just the fact i am doing thm?;

#

also is it ok to post my resume here for review/feedback?;

hollow widget
#

Anyone running multiple paths at the same time on THM

mild inlet
#

Hi guys I’ve just finished the jr pen tester path on tryhackme and I feel like I need more practise (especially on priv esc) but I’m not super confident towards a bunch of boxes (I end up having no clue what to do and feel like the only way to get through them is a writeup which I avoid) is there another path or some rooms people would recommend

rugged delta
mild inlet
serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #18 - 535)

edgy orchid
# chrome spire Jacob if u want me to do resume review for ya lmk

I've heard the Linux+ is pretty hard, definitely harder than the Sec+, but I haven't taken either yet so I can't confirm. And as for resume review, I appreciate the offer! I actually had someone take a look at my resume, though, he has a senior security role at a reasonably large company and he helped me optimize things a bit. The trouble is, I don't have any higher education and very little true job experience, as I've tried many different careers and failed at each one before I even got hired. Approaching 30 with very little job experience isn't fun NotLikeThis

unique gyro
#

Between a cybersecurity or a software engineer, which one has more creativity?

#

ty

rugged delta
chrome spire
#

thats the only way im ngl

tidal canyon
#

hi everyone, i was a user of THM around 2021, and bc of it i have now graduated with a bachelors degree in security. im trying to find a graduate job now in the UK but it has been tricky, so whilst applying for more i also want to do extra certificates but i'm not sure where to start. can anyone help me please?

#

i'm quite interested with Sec+ or CEH! but not limited to that

tidal canyon
#

also, i have a career fair tomorrow that i'm joining. if anyone could check my cv to give some opinions i would really appreciate that! animewave

jade scaffold
#

Hit me up

hollow osprey
#

I use arch btw😆

junior cliff
#

How to go about finding cyber jobs or IT support jobs ?

chrome spire
#

im bored asl if anyone want resume reviews dm me

chrome spire
chrome spire
tidal canyon
serene umbraBOT
#

Gave +1 Rep to @chrome spire (current: #2058 - 2)

tidal canyon
#

can we dm?

chrome spire
tidal canyon
#

anyone with Sec+ / CEH, i'd like to have a chat and know real experiences on how/where to start with to take the certifications!!!

stoic cave
fading lance
hollow sierra
serene umbraBOT
#

Gave +1 Rep to @stoic cave (current: #21 - 528)

hollow sierra
#

Also to answer your name, no i use searx;

hollow sierra
#

Here's the json for my proto-resume. my plan is to use this to help with creating specialized resumes based on the job posting and job title, since there are several job titles i could apply for and each would be customized to fit that role;

tidal canyon
serene umbraBOT
#

Gave +1 Rep to @fading lance (current: #3130 - 1)

untold geode
#

which path or room i flows for learning reverse engineering

nimble schooner
tidal canyon
#

we were encouraged about it and its also one of the top certificates (?) in the UK so im curious on to see what you mean!

nimble schooner
# tidal canyon :o wdym?

Top certs in UK? CEH doesn’t really provide any practical skills. It’s all memorization and the test is multiple choice. A monkey might be able to pass by just guessing. Not saying you’re at the level of a monkey but the exam has gotten heat in the past. The people who provide it (EC Council) have also blown their marketing out of proportion about it. They’re trying to make it a gold standard and that everyone must have it. Also EC Council has faced some scandals in the past so the credibility of the cert has diminished because of that.

However if you’re going into defense contracting it’s usually a baseline cert to have.

#

EC Council wants to put it on the level of CISSP but that’s never going to happen lol

#

Although you might be able to convince non technical recruiters you’re a god at hacking 😂

tidal canyon
#

jk, but i see! thank you for your input

nimble schooner
#

Of course. I mean it’s better than having nothing but it’s one of the baseline certs

#

Not like a CISSP

tidal canyon
#

i only know what ive been told, and yes we were encouraged to take it at one point during/after uni so its interesting to know its actually not worth it

nimble schooner
tidal canyon
#

hahaha don't doubt it. uni is a business anyways

nimble schooner
#

My company works with EC Council and they aren’t really what they seem 😅

nimble schooner
#

They don’t care if you get your degree lol

#

Kind of a load of horse poo but you and maybe you’re family are the only ones that care

tidal canyon
#

the reason why i went is mostly, in general, having a degree is better than not

#

but halfway i understood the certificates definitely matter more🤣😭

#

which cert would you personally suggest? i was told yesterday i can only take CISSP after 4 years of working?

#

experience*

nimble schooner
# tidal canyon totally

Honestly if you want to land a job with ease, start building your own projects. Those carry more weight than certificates nowadays since it’s hands on experience. Hands own training/experience is the new golden standard when it comes to hiring.

#

My uncle is a VP for a tech ed company and that’s how he hires people

#

I built my own homelab and run my own SOC simulator on it. I also set up metasploit and mess around with that. Stuff like that. Expose yourself to those things and maybe attend a few conferences. NETWORK with people in your field, you’ll land a job better that way than blindly applying for jobs.

tidal canyon
#

I feel like my skills are way too behind to build something on my own, I don't have anything to start with, except for a research I've done for my dissertation

tidal canyon
serene umbraBOT
#

Gave +1 Rep to @nimble schooner (current: #1249 - 4)

tidal canyon
#

i am going to a career fest today so hopefully i'm able to do something

keen tundra
#

We don't discuss things such as that attack here , please read the #rules 🙂

cunning shadowBOT
#

Done!

warm hinge
#

So, I'd like a little input from current professionals or hiring managers. I'm currently in law enforcement (10 years) and I'm taking courses on THM and plan on getting a few certs as well. I've also recently been approved to join a federal task force for cyber crimes and will be receiving training on digital forensics and will be eligible to further that area of expertise and also learn incident response as well. I guess the question is, If I choose to pivot away from my current career, with all that I've mentioned in this message, does this make me an attractive candidate for SOC or incident response roles? The certs I plan on getting are security+ and a splunk certification and maybe a blue team certification as well

dense dagger
#

For the certifications, Security+ is a good foundational cyber cert. There is also BTL1 and CCD for blue team related certs. Also look into GCFA and GCIH certs. They are relatively “cheaper” without the SANS training.

#

I wouldn’t focus on getting platform specific certifications unless they’re required by the job.

grizzled arch
#

Anyone know what I would look for if I’m looking to get into cybersecurity for robotics?

warm hinge
serene umbraBOT
#

Gave +1 Rep to @dense dagger (current: #22 - 467)

sturdy peak
#

are eJptv2 and CompTIA sec+ good / worthy certificates? im planning on getting a few fundamental certs in my early university years, and these two were the ones i thought of.

i heard some people complaining about how basic eJptv2 is, but i dunno. do i do the right thing by gathering a few fundamental certs earlier, especially the ones i mentioned?

obsidian rose
nimble schooner
nimble schooner
warm hinge
# nimble schooner Get your certs paid for by you job

I'd have to justify things like security + with a direct payoff for the department. The federal task force is entirely free for them so it won't cost anything and gives us more capabilities as an agency. I should receive certs from the task force though.

opaque comet
nimble schooner
#

Build your own SIEM

#

Or SOC sim

opaque comet
#

hmm

#

those seems like a bit advance stuff. but i suppose one need to start to get somewhere

nimble schooner
#

Start your own blog

nimble schooner
#

Cyber security 101

opaque comet
#

i have studied and used metasploit but i didnt know you can BUILD UR OWN

nimble schooner
#

Learn how to write good pentesting reports too. That’s like 50% of the job

nimble schooner
opaque comet
#

wow nice

nimble schooner
#

Essays lol

opaque comet
nimble schooner
#

If I were gonna hire you as a pentester I’d want someone who can give me good reports. There’s a THM room about reports

opaque comet
#

basically the findings now?

nimble schooner
#

Kind of

serene umbraBOT
#

Gave +1 Rep to @nimble schooner (current: #1078 - 5)

nimble schooner
#

If you can write good reports then it’ll put you above pentesters who don’t know how to write good reports

#

Also if you want to do the PT1 exam you’ll have to know how to write one

foggy stream
#

Guys, has anyone taken jrpt cert
i wonder if it includes more training or it is just an exam

late surge
#

🖐Hi everyone, I am junior Brian from Kenya

I am just starting out in IT / cybersecurity and i am also interested in entrepreneurship

I am here to learn share knowledge and connect whith like- minded people

Outside tech I enjoy movies
and reading,

Looking forward for growing and contributing here

fickle grove
tidal canyon
lyric ginkgo
#

I am new in this industry so you all please guide me in which field I should make a career. I found ai to be the best but I am a bit confused about subdomain, so you all please tell me what I should do.

tidal canyon
#

genuine question, what are you meant to do if every place needs more experiences but no one is willing to give you any

abstract thorn
#

Question for all the websecurity enthusiasts. Planning on deploying a website soon and need to get a TLS cert loaded and I am debating on what to use. My domain is through namecheap and I plan on using the site for ecommerce. Their OV/EV (which I learned is organizational validate and extended validation used to display higher trust to users) is $45 per year.

My question is: Is this "required/best practice" or can I use letsencrypt since it is free? First time launching a website so I am learning a ton and love getting advice from the community!

warm hinge
#

I posted this a bit before, but got side tracked and never really tried it out. I wanna do OSCP eventually, in like a year or so at most. Now I've heard ofc it's super super hard and stuff, but I think I can do it if I focus properly. So, question is, how would y'all recommend going about it? Currently doing some THM rooms, but would that be enough to get into it or do I need other resources?

undone shore
# warm hinge I posted this a bit before, but got side tracked and never really tried it out. ...

Believe it or not, it's entry level. The difficulty comes from having a solid methodology, not from the techniques (which are generally pretty straightforward).
I would recommend making sure you've got the foundations down (networking, web / software dev, simple scripting, basic active directory administration, etc), and a bit of experience with some of the standard tools (Kali, Nmap, Burp, sqlmap, etc).
Then do PEN-200. Make sure you're happy with all the techniques they teach you (again, pretty basic stuff in that department). Take a bit of time between finishing the course and sitting the exam. Use that time to go through the TJ Null list of OSCP-like boxes on HTB and Vulnhub (plus Offsec PG if you've got access). Build up a methodology, use a few of them to sit a mock exam under time pressure.
That should be plenty.

junior cliff
#

Does any body know about the uk 🇬🇧 England job market and can help me ?

warm hinge
serene umbraBOT
#

Gave +1 Rep to @undone shore (current: #10 - 903)

undone shore
fringe mauve
junior cliff
#

England

undone shore
#

Can't help you there then 🤷‍♂️

tidal canyon
junior cliff
#

Anyone that knows about the job market in Birmingham in England uk and how to find and navigate around it etc I’d love your help and advice if u can tag or dm me

fickle grove
# foggy stream PT1 from THM

From memory, the certification fee includes a three-month subscription to THM so it should have access to the learning path. However, depending on your background or experience, that three months may or may not be sufficient.

knotty oxide
#

I am new in cybersecurity (zero knowledge) and would let to get started somewhere. I know that THM itself wont land me anywhere in terms of job, my main goal is to gain knowledge and skill. How far will THM take me in terms of knowledge? Like will I be Junior level or Intermediate Level? I want to have my main focus be in Offensive with some knowledge in Defensive. I was wondering what learning paths would be best suited towards my goal?

keen tundra
knotty oxide
knotty oxide
#

also is THM a good way to learn the basics?

dense dagger
#

Even now, I’m actively taking their rooms

knotty oxide
keen tundra
junior cliff
fiery rose
fiery rose
halcyon crypt
sleek kindle
#

Hello, Is it a good idea to do LL.M in IP and IT laws if i want to go into GRC?

#

I have also done a Bachelors in Computer Science Engineering

#

and doing a Masters in IT security

neat stirrup
#

Hello everybody, this question is for people who did many certifications please 🙂
I'm 21 and still graduating (got at minimum 3years before joblife) , but I would like to do more certifications for later on in Pentest, already got 2 CCNA, but as I'm still on studies my budget is low, and everyone talks about OSCP and other certifications that are like 1500$ per try, do you think those certifications are an investment that I should do now ?
I don't really know which one to start with, I was thinking about the new PT1 certificate made by THM.
At the moment I'm only grinding on my knowledge with THM doing all kind of exercises.
Thanxs to any of you responding 🙂
(Sorry I'm not a native English hope everything is readable :D)

rugged delta
# neat stirrup Hello everybody, this question is for people who did many certifications please ...

You should certainly enjoy exploring THM and learning as much as you can about the field and where you'd like working. Certifications can play a big part in showing your abilities to an employer, but yes they can be expensive. The #pt1 and #sal1 are certainly going to benefit you, and if you go to the links at the top of each of those channels and click the Get Started button, you can look at the Recommended Learning for each certification as a path to improving your learning plan. The certifications are excellent junior certs which may stand to you when eventually applying to jobs in the future, but certification can be expensive. While you might be expected to get some junior certifications by yourself, most good employers provide a training budget you can take advantage of, and employers should be a part of funding your training, especially for certs like the OSCP and others, but you may still need to have done some by yourself. You should pay attention to the skills and qualifications that potential employers expect you to have and ask during interviews what training they might provide to help, as it's a mutual benefit for them to have people trained to the standard they expect.

neat stirrup
rapid salmon
#

Hello everyone,
I have recently completed mt SAL1 certification and passed it my main goal for taking SAL1 is to land a job in Cybersecurity career. almost 2 weeks passed after completing it and i am actively appling every SOC related job posting on LinkedIn, Indeed, Naukri, Glassdoor etc.. I am not even getting shortlisted for an interview. So, here i want to know in the mean time should i do Projects, SOC 2 path or go for jr. pentesting path? bit confused about this.

winged scaffold
rapid salmon
chrome spire
stoic cave
cunning shadowBOT
rapid salmon
stoic cave
# rapid salmon

OK, so taking a quick look, skills should be moved to the top and I would remove soft skills. Your skills are also generic. Look at your body of professional work and make your skills section reflect that. You should be able to talk to each skill listed at length.

Put your highest level of education in an education section.

THM certificates, other certificates without a proctored exam, and room completions are not certifications. Remove them.

THM and things you did on Google Cybersecurity are not projects as you did not create them. A homelab is an example of something that you can put in that section.

In your experience section, remove the little blurb about the company. Use punctuation. I think the bullets are kind of similar across all the jobs, I would work on them a little.

I'd remove the paragraph at the top. I personally don't like them and you can write a cover letter if you want a paragraph.

I'd remove SOC Analyst and Cybersecurity Professional from the top. Just have your name and contact/LinkedIn/etc. None of your experience points towards having worked in a SOC, imo.

silk robin
#

@stoic cave do you have an example of a good resume ?

stoic cave
#

Content wise, myself and other community mentors have given a lot of advice over the past few years that is searchable in this channel

foggy stream
tacit karma
foggy stream
# tacit karma yes just not the certification itself

I nearly done jr penetration testing path but im not confident much about my skills.
I dont know that if i missed main points that i should have paid attention to and THM designs this just for the very basic knowledge.
Would you mind giving me some advice on what to do next, switch to solve challenges or delve into specific skills like rooms in offensive pentest path
Thank you very much in advance!!!

serene umbraBOT
#

Gave +1 Rep to @tacit karma (current: #606 - 11)

tacit karma
#

but most importantly, you can keep going through the red path and you'll get more in depth with pen testing

#

some of the walk throughs will also give you links to challenges for practice

#

and you will find that some of the challenges are also inside that walk through path as well

foggy stream
serene umbraBOT
#

Gave +1 Rep to @tacit karma (current: #563 - 12)

tacit karma
foggy stream
#

again, thankss

tacit karma
#

no problem

south sedge
#

@rugged delta thank you to this cours

serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #18 - 536)

livid needle
#

Has anyone here landed a job with SAL1 certification?

late surge
#

Today I officially started learning cybersecurity .

Learned the basics o computer(CPU,RAM,ROM,OS,and storage.

Installed termux in my phone to practice Linux commands .

Committed to showing up every day even whith limited resources.

My goals,
Become a cybersecurity professional .

Build tech products.

Work remotely/freelance in future.

kindred swan
#

Hi and Hello everyone! Im rather new to all the Cybersec/IT stuff and have a question for yall.....can anyone give me any advice or how to find a mentor for Digital Forensics?? I am currently taking Cybersecurity classes and plan on going on to my Bachelors next year.

vast charm
#

Hello. I am a business analyst working primarily with import SQL queries into power bi to develop reports. I am getting bored of the role(too many meetings) , am underpaid and don't see any future in it personally.

I have a BS in information systems(2109), sec+(expires in 6 months), web dev bootcamp cert(from 4 years ago). I am wanting to get into a SOC analyst role. Any recommendations on what to do next? Should I just start applying and interview prepping or should i start doing personal projects? I feel like I have done a lot of self investment and intend to keep doing so, but I feel like I have done enough to have a good foundation to pivot quickly. Any insight is appreciated.

stone nova
#

SOME ADVICE please! Hello tryhackme comm! did you get trap for having a hybrid profile? Hot to abord it in your job search? To techie for GRC roles and to strategic-planning GRC orientation for SOC analyst role? by the way, I am transitioning from IT support L2 with some experience in System Support and development

tardy lance
# vast charm Hello. I am a business analyst working primarily with import SQL queries into po...

you're definitely well-positioned to pivot into a SOC analyst role.

I’d recommend starting with Cyber Security 101 and the SOC Level 1 pathway to reinforce core concepts and get familiar with Blue Team operations. If you’re serious about making the leap, consider pursuing the SAL1 certification—it’s industry-recognised and tailored for aspiring SOC professionals.

As for next steps, a combination of interview prep and personal projects would serve you well. Projects like setting up a home lab, analysing threat reports, or simulating incident response scenarios can really showcase your initiative and practical skills. At the same time, start applying — you might be surprised how quickly things move once you get into the interview pipeline.

sleek kindle
#

is it a good idea to do Masters of Law Degree in IT Laws.. if i want to transition into GRC?

#

or are the CISA and ISO certs enough

fringe spade
#

But the degree might help you

#

But if you have to pay a lot for the degree then it's not worth it in this case imo

sleek kindle
#

since Public Universities in Europe aren’t expensive

sleek kindle
fringe spade
#

Then it should be good, but I woudn't say it's a priority

serene umbraBOT
#

Gave +1 Rep to @tardy lance (current: #1082 - 5)

signal echo
#

hey guys! i'm currently a senior/lead java dev (working in finance for 10+ years) and seriously considering a switch, as red teaming has really sparked my interest. any advice on where to start (i'm quite familiar with linux/windows shells, and some networking concepts due to the nature of my work)?

junior cliff
#

Anyone who is based is the uk can we talk ? Or can help me ,would really appreciate it

stoic cave
rugged robin
#

Yh you need to give more context, I'm based in the UK but still might not be able to help

pliant thicket
#

Does anyone have any advice for someone with one year left without much internship experience? I damn tried but I have worked a makerspace job which has led me to do some physical stuff but mostly desk/equipment management and I did TA a data visualization course among learning cyber. Is it possible for me to start with something like business intelligence and transition to cyber or would I be better off scouring for IT jobs? Also it is a little annoying seeing some internships want you to be back to school after the internship and I am not particularly interested in grad school to give myself more debt

junior cliff
#

I’m Birmingham

#

Like advice for job searching

#

I’m trying to get like ITsupport or somthing

rugged robin
#

I'm from near Birmingham myself

junior cliff
#

Bro no way

#

Finally

rugged robin
#

I'm a student though so dont think I can help with job advice 😂

junior cliff
#

Damn

#

As in uni,

rugged robin
#

Yh, Newcastle though not brum

junior cliff
#

Can we connect ?

#

How the market uo there

rugged robin
#

I can't really say as I haven't really looked for jobs up here specifically, bc I'm applying anywhere

junior cliff
#

Same down here

#

Been trying

#

A lot of places already want a lot of experience

rugged robin
junior cliff
#

And apprenticeships there is loads of training providers but no employers really 😂🤦🏽‍♂️

#

All busy or full ig

rugged robin
junior cliff
warm hinge
#

Hello brothers 👋🏻
Lately I've been wanting to build up my portfolio, but I don't really know what to include. Can you guys please share some of yours? If its focused on Blue Teaming, would be great. Thanks in advance!

hollow phoenix
#

Yo people,
I have a Cybersecurity AD (Associate's Degree), a second IT-related AD (finished it in 2023), I finished Pre-Sec and just got finished with CS101.
I wanted to go for SAL1 now, but a recruiter recently asked me for CEH and I've been seen an increment lately in job postings asking for CEH.

Any recommendations or suggestions in here on which one to go for, am I qualified for a L1 position? And helping me with "Is CEH even worth it?"
Thanks in advance.

rain rapids
#

Ceh is good in getting noticed if you are trying gain more skills go for SAL1

hollow phoenix
serene umbraBOT
#

Gave +1 Rep to @rain rapids (current: #3146 - 1)

rain rapids
#

Think its great to have real world experience

hollow phoenix
balmy dove
#

take a look at some of the job postings to see what they list as preferred qualifications

hollow phoenix
balmy dove
#

sure

grim radish
#

Any suggestions for first cert in cyber security? The long-term plan is to become an ethical hacker/pen tester. But being still fresh in the field, I'd imagine the first job position to be from blue teaming 🤔

tribal pewter
#

Hey good morning everyone I just finished getting my A+, Net+, SEC+, and CYSA+ certs I was wondering if anyone here knew any leads for entry level SOC analyst positions.

#

I can provide my stackable certs documentation

wraith wave
primal canyon
#

is it worth doing cpent from ec council? i'm in india right now but not limited to it, i wanna jump out of it.

primal canyon
fringe spade
primal canyon
fringe spade
#

If you want to work in India then CEH might be a better option than CPENT

#

But in other parts of the world it is not as respected

primal canyon
#

like i have these kind of questions to ask to someone who is done several certifications like you

winged scaffold
fringe spade
#

INE is not as respected as OffSec or Comptia tbh

#

eJPT is fun but I wouldn't say it has too much HR value

#

You could check out Comptia certs like Sec+, it's quite a good cert, but not practical

#

BSCP is also an interesting choice if you want to do web app security, but you'd need to somehow get Burp Suite Pro

primal canyon
#

alright, thanks for these info.

wraith wave
#

it's an overrated cert tbh

primal canyon
#

ye that's why i didn't planned to do it

crude burrow
crude burrow
# fringe spade eJPT is fun but I wouldn't say it has too much HR value

This is also a vague argument since HR are not the ones doing the hiring. They handle the paperwork, and you will have interviews with the actual manager, team, seniors, etc. (with HR included ofc)

In most cases, HR have no clue what the cert includes or what knowledge it comes with. It isn’t something they need to have an understanding of.

It can be listed in the ad as preferred.

#

With that said it is more likely that HR will pass your application further to the team hiring if you have cert vs no cert.

vague mist
#

anyone from india here? need career guidance..

grim radish
# wraith wave depends on where you are from!! plus yea you are right about the blue teaming pa...

I often see the route of:

ISC² CC -> Security+ -> PT1 (/eJPT) -> OSCP

Just wondering if that's a relevant path. Obviously, it's going to take some time (possibly few years) before OSCP. Just thinking of different options.
EDIT: on the other hand I'm starting a cyber security training and there's an opportunity to take either AZ-900: Microsoft Azure or SC-900: Microsoft Security, Compliance, and Identity Fundamentals cert.

dense dagger
#

I would suggest PT1 as well but right now, there’s little traction with HR. Its a good cert, just not yet there in terms of HR standard compared to OSCP.

#

AZ-900 and SC-900 is honestly dogwater. Its like a Microsoft advertisement certification.

grim radish
# dense dagger Security+ -> OSCP

Hmm, so skip the ISC² CC. PT1 would make sense since I'm halfway done with cyber security 101 on THM and interested in pen testing. Should probably ask if those Microsoft certs can be replaced with something else. Always a good idea to start complaining about certs on a first training day 😆 . Anyway thanks, this gave me some clarification 👌

serene umbraBOT
#

Gave +1 Rep to @dense dagger (current: #22 - 468)

soft sleet
#

Hello friends, I need some advice from you. I am currently in my first year of training to become an IT specialist for system integration (in Germany).
My goal is to move into cyber security later on.
I have some prior knowledge of PC components, a little Java, and Python. I have just started with TryHackMe and wanted to ask you for some tips.
What should my next steps be to gain experience and improve my skills, or what should I do in general and where should I start?
Thank you in advance for your help.

#

(I am open to any tips. I need something like a guide or someone to steer me in the right direction or give me a push)

grim radish
soft sleet
serene umbraBOT
#

Gave +1 Rep to @grim radish (current: #2073 - 2)

grim radish
# soft sleet Thank you, I'll definitely take a look at that. Do you have any personal tips yo...

I'm pretty new to cyber security as well. Just bumped into this platform and have been enjoying everything so far. Started with pre-security and advanced to Cyber Security 101. The latter explores both defensive and offensive techniques, so some of those ideas is likely to interest you more and you can follow that route. I'd recommend to follow the structure given in roadmap (so start with pre-sec and move to cyber sec 101 after) and then move forward based on your interests (analyst, pen tester, engineer). Guess it boils down to being consistent (currently on 33 day streak) :).

soft sleet
serene umbraBOT
#

Gave +1 Rep to @grim radish (current: #1565 - 3)

grim radish
#

No problem, happy to help. And likewise, all the best to your journey as well blobfingerguns

soft sleet
fringe spade
fringe spade
#

The same can be said for CEH, you're more likely to be hired if you have the cert, but is it worth it? Not really... (unless it's India)

last lotus
#

hi im a fresher in btech cse just got a job few months in as desktop support engineer at a university IT team salary is fine for freshers so i took it and i want to go into cybersec as sson as possible i know basics of networking and basics of sysadmin stuff i learnt basics of wazuh and am currently following jr pentesting path anyone have any suggestion please feel free to tell me im open to learning just need guidance and support

crude burrow
# last lotus hi im a fresher in btech cse just got a job few months in as desktop support eng...

Hi, I'm a fresher in BTech CSE, just got a job few months in as Desktop Support Engineer at a university IT team. Salary is fine for freshers, so I took it, and I want to go into cybersec as soon as possible.

I know basics of networking and basics of sysadmin stuff. I learnt basics of Wazuh and am currently following Jr Pentesting path. Anyone have any suggestion, please feel free to tell me. I'm open to learning, just need guidance and support.

#

Just made it easier to read.

crude burrow
#

And for everyone not working in tech, that paragraph above without punctuation or commas is how Indian English sounds. But in written form

craggy ferry
#

Hello, what is comparison career wise about HTB certs especially in comparison to offSec ones?

patent viper
# craggy ferry Hello, what is comparison career wise about HTB certs especially in comparison t...

Honestly, HTB certs and OffSec ones r kinda diffrent. HTB is more like “hands-on hardcore labs”, shows u can solve tough machines and challenges, looks rly good for pentest/red team jobs. OffSec, like OSCP, is more structured, teaches u the metods, recon, exploit, reports… got more official weight for companies.

If u wanna shine career-wise, doing both is nice: OSCP for cred, HTB for showing real skills. But tbh, depends on the company and country, some dont really know HTB

rugged delta
errant crest
#

Hi, I'm currently pursuing a BSc in Computer Science in the UK. I'm quite new to cybersecurity and wanted to gain some sort of experience through a cybersecurity internship. Just wondering how should i write about the certificates/things ive learnt in my cv? Any advices on how to land a cybersecurity internship?

chrome spire
chrome spire
#

Its a bit more recognized then the pt1 and will make the oscp a cake walk

distant sedge
#

How do I prepare for an information security internship interview

crude burrow
crude burrow
craggy ferry
#

I am just curious btw, what challenges would you recommend that, after completing them i would be ready to land a job as a jr pentester or similar red teamer fairly easily. I started a THM a month ago, just completed cyber security 101 and moving forward. Sorry in advance if that is a silly question. I also acquired (i think) a good IT fondations (A+, AWS SysOps, CCNA), next i want to go for CPTS

rugged delta
# craggy ferry I am just curious btw, what challenges would you recommend that, after completin...

Working as a pentester, even a junior pentester is a highly sought-after position. I would suggest embracing everything you can about IT, computers, networking, etc., as you can. Learn about Windows/Linux/Networking/a little programming/scripting (Bash/Python/C/Powershell) and build upon these. Do rooms in THM, but also make a homelab (a few spare computers or some VMs or a cloud platform) and do things like installing and configuring software and systems. Consider a blog about your homelab or do writeups about THM rooms. Learn about CTFs and Bug bounties (PicoCTF and HackerOne's Hacker101 platform are good resources), read books (the Tribe of Hackers books are a good start), go to conferences/meetups (a lot of cities have meetups and the BSides conferences happen in cities all over the world, among others)... Be open to working in tech support or helpdesk and working your way up through IT/networking/cloud positions as well as considering cyber roles. Get to know people at events, show your abilities, be enthusiastic.

crude burrow
#

Might been one of the best replies in a long time @rugged delta

warm hinge
#

Hey there, I'm looking to get into cybersecurity as a complete beginner. What path/roadmap should I follow to get into this field and how would I be progressing my career? I also have been seeing that you need IT foundations before getting into cybersecurity but I don't know where I stand in terms of that, I sure don't know networking concepts but that is all.

#

Im also currently in 3rd semester in BS IT so some knowledge in terms of IT should be covered hopefully

crude burrow
#

Look above

crude burrow
#

Yes

warm hinge
#

alr thanks

crude burrow
#

That was a really good reply to anyone wondering how to move forward

#

Just having a homelab that you maintain, maybe running some docker containers, portainer etc gives you something to talk about in an intervju, it shows interest and a will to self-learn.

Even if half of the team might not know what you are talking about, they will not ask because they do not want to sound less-knowing 😄

#

I can not add much to the post above, its spot on

#

Have some talks from conferences running on youtube in the background when you do other things. Defcon, blackhat, bsides, etc. Youtubers like TCM, nahamsec, 0day, john hammond etc

warm hinge
#

I gave it a read and I have some questions:

  • Is having a homelab necessary? I don't have any budget to spare to spend on a homelab machine
  • Is learning windows required or is just linux good enough?
  • I want to get into blue team (soc analyst then security engineer) so would I have to do ctfs/bug bounties for that too?
crude burrow
#

Home lab is not needed at all, it is just a fun things for nerds that want to have an enviorment at home

#

Pentesting will involve AD, Cyber security/IT Security will involve AD accounts, (AD= Active directory in windows) so you need some knowlage here.

warm hinge
#

if i dont run a home lab but i have a vm where i can tinker with stuff, is that good enough?

crude burrow
#

Microsoft Entra, defender etc if you want to work in a SOC team

warm hinge
#

so knowing concepts on windows is recommended

crude burrow
#

I work as a SOC Analyst, we have 19k windows devices and a huge azure setup with a few K servers there with a bunch of diffrent OSes

warm hinge
#

as afaik security engineer is a more senior role so soc analyst is where you'd start after helpdesk/it support

crude burrow
#

I worked as a web admin/project lead and was doing bug bounty on the side, found bugs in my companys network. etc.
IT Sec manager told me that there was an opening and life have been great ever since 😄

#

Microsoft have a lot of free tranings for SOC

#

you dont necessary need the Cert, If you can show that you did the trainings on their platform it can be enough

warm hinge
#

is there like a roadmap that shows resources, preferably free, for every step in soc? like where to begin with soc, networking or windows in terms of courses, certs or any other resource

#

i start collecting topics in sequence in terms of what i need to learn but when i get into finer details i get lost on where to start and in what order

river wyvern
#

there is SOC Level 1 path on THM as well

warm hinge
river wyvern
warm hinge
#

got it

#

and i assume letsdefend would cover up all the IT fundamentals like networking, etc.?

river wyvern
#

there are different courses for all of them(netwoking, windows, different type of analysis), i would suggest start with soc fundamentals.

warm hinge
#

i see

#

that honestly cleared out a lot for me, thanks a lot

late lodge
#

hey there i am here to know about various carrier paths in cyber security i just completed my network basics

chrome spire
crude burrow
obsidian rose
#

Anyone in here who has worked as a CTI Analyst or in the CERT Team? Advice would be appreciated on what I should get ready for an interview in a few months and how to get my feet wet for both. Currently switching from IAM after 2 years of experience. I also have knowledge in OffSec and a few certs. Where do I go from there?

warm hinge
#

like a 1 gig ram machine

junior cliff
#

If anyone is from England Birmingham…or in general can help me or have advice for job searching for IT support roles etc …as a lot of them asking for previous experience…or I don’t know were else to look

indigo stream
#

how hard is it breaking into pen testing? Context: 0 years exp, BS in Comp Science, 4.5 years software engineering. Looking into getting PT1, Comptia Sec+, Comptia Pentest+.

dense dagger
#

Kinda confused bec you also have 4.5 yrs software engineering

indigo stream
#

yeah 0 years in cyber related work.

hallow sinew
#

I am a former programmer that turned Ethical Hacker and man i thought programming was tough.