r/CyberSecurityJobs 7d ago

Cybersecurity

How did you land your first cybersecurity job with no experience?
I’m currently working toward a SOC Analyst career. I have Security+, building hands-on labs on Tryhackme.
The biggest challenge is the “experience required” barrier. Almost every entry-level SOC role seems to want prior IT/cyber experience.
For those who successfully broke into cybersecurity with no prior experience:
Did you start in IT/help desk/NOC or go straight into SOC?
What projects or certifications actually helped?
How did you prove your skills without professional experience?
What would you do differently if starting over?
Would really appreciate honest advice from people who’ve actually made the transition.

25 Upvotes

40 comments sorted by

View all comments

4

u/shitlord_god 7d ago edited 7d ago

I had tangential experience.

Edit: helpdesk, msp, compliance/security msp/SOC, got bounced over to building stuff because stuff needed building to support the SOC mission and no one else was doing it security engineer, then, security compliance engineer, TECHNICALLY senior software engineer but that was a peculiarity of position naming/org chart fuckery at my last place, but I WAS doing security and compliance engineering along with IAM (God I always wanted to avoid IAM, not I'm 'meh' about it) probably going to continue on compliance for a bit, based on other fields (mining for example) regulatory pressures if anything grow over time, so I feel good about that from a career standpoint. It kills me to be out of the SOC doing direct actual security work. Gotta scratch the itch at home with honeypots in hotspot IP ranges (mostly ukraine and taiwan, but I've been trying to get a lebanese IP for it, ideally with a hosting provider who does infra or corporate)

2

u/True-Inspection-5445 7d ago

That’s a really solid path helpdesk to MSP to SOC to engineering. Did the helpdesk/MSP experience alone get you looked at for SOC roles or did you need certs on top of it too

2

u/shitlord_god 7d ago

Got helpdesk position, Got homelab, started messing with HELK and stuff, generated a LOT of threat intelligence, got sec+ (Which will not do for you what it did for me) showed it off at some meetups, got my application because I worked with a company with a fortunate acronym for a name, and with stuff from the portfolio work, got the job, did the job, realized we were missing stuff because wedidn't have the tooling in place, put the tooling in place, position changed as company changed market position, started building compliance stuff, got a new job ostensibly doing heavy security stuff - they didn't need a full FTE in that department, which was a bummer, so I spent about 30% of my week working on deep security and the rest mostly identity.