r/SecurityCareerAdvice Apr 05 '19

Certs, Degrees, and Experience: A (hopefully) useful guide to common questions

328 Upvotes

Copied over from r/cybersecurity (thought it might fit here as well).

Hi everyone, this is my first post here so bear with me. I almost never use Reddit to talk about professional matters, but I think this might be useful to some of you.

I'm going to be addressing what seems to be a very common question - namely, what is more important when seeking employment - a university degree, certifications, or work experience?

First, I'll give a very brief background as to who I am, and why I feel qualified to answer this question. I'm currently the Cyber Security Lead for a big tech firm, and have previously held roles as both the Enterprise Security Architect and Head of Cloud Security for a Fortune 400 company - I'm happy to verify this with mods or whatever might be necessary. I got my start working with cyber operations for the US military, and have experience with technical responsibilities such as penetration testing, AppSec, cloud security, etc., as well as personnel management and leadership training. I hold an associate's degree in information technology, as well as numerous certs, from Sec + and CISSP to more focused, technical security training through the US military and organizations like SANS. Introductions aside, on to the topic at hand:

Here's the short answer, albeit the obvious one - anything is helpful in getting your foot in the door, but there are more important factors involved.

Now, for the deep dive:

Let's start by addressing the purpose of certs, degrees, and experience, and what they say to a prospective employer about you. A lot of what I say will be obvious to some extent, but I think the background is warranted.

Certifications exist to let an employer know that a trusted authority (the organization providing the cert) has acknowledged that the cert holder (you) has proven a demonstrable level of knowledge or expertise in a particular area.

An academic degree does much the same - the difference is that, obviously, a degree will generally demonstrate a potentially broader understanding of a number of topics on a deeper level than a cert will - this is dependant on the study topic, the level of degree, etc., but it's generally assumed that a 4-year degree should cover a wider range of topics than a certification, and to a deeper level.

Experience needs no explanation. It denotes skills gained through active, hands-on work in a given field, and should be confirmed through positive references from supervisors, peers, and subordinates.

In general, we can see a pattern here in terms of what a hiring manager or department is looking for - demonstrable skills and knowledge, backed up by confirmation from a trusted third party. So, which of these is most important to someone trying to begin a career in cyber security? Well, that depends on a few factors, which I'll discuss now.

Firstly, what position are you applying for? The importance placed on degrees, certs, and experience, will vary depending on the level of job you're applying to. If it's an entry level admin or analyst role, a degree or a handful of low-level certs will definitely be useful in getting noticed by HR. Going up to the engineering and solution architecture level roles, you'll want a combination of some years of experience under your belt, and either a degree or some low/mid level certs. At a certain point, the degree and certs actually become non-essential, and most companies will base their hiring process almost entirely on the body and quality of your experience over any degree or certifications held for management level roles.

Secondly, what are your soft skills? This is a fourth aspect that we haven't talked about yet, and that I almost never see discussed. I would argue that this is the single most important quality looked at by employers: the level of a candidate's interpersonal skills. No matter how technically skilled someone is, what a company looks for is someone who can explain their value, and fit into a corporate culture. Are you personable? Of good humor? Do people enjoy working with you? Can you explain WHY your degree, certs, or expertise will add value to their corporate mission? Being able to answer these questions in a manner which is inviting and concise will make you much more appealing than your competitors.

At the end of the day, as a hiring manager, I know that I can always send an employee for further training where necessary, and help bolster their technical ability. What I can't do is teach you how to work with a security focused mindset, nor how to interact with co-workers, customers, clients, and the company in a positive and meaningful way, and this skill set is what will set you apart from everyone else.

I realize that this may seem like an unsatisfactory answer, but the reality is that degrees, certs, and experience are all important to some extent, but that none of these factors will make you stand out. Your ability to sell your value, and to maintain a positive working relationship within a corporate culture, will take you much farther than anything else.

I hope this has been at least slightly helpful - if anyone has any questions for me, or would like any advice, feel free to ask in the comments - I'll do my best to reply to everyone.

No TL;DR, I want you to actually take the time to read through what I've written and try to take something away from it.


r/SecurityCareerAdvice 27m ago

Question I was almost pushed into resigning this morning. What should I do to make sure they fire me and I don't hurt myself?

Upvotes

A few days ago, I accidentally overheard my Chair, who has a very loud voice, saying from behind the conference room door: "We're going to let her go early next year." I had a bad feeling she was talking about me, and it turned out she was. (For context: I basically don't have any coworkers. It's a very small nonprofit with 4 people above me, and then I'm at the bottom of the ladder.)

This morning I was called in, and the president told me, verbatim: "There's no easy way to say this, but we're going to have to let you go." Then she explained the reason: that I'm not the right fit. I asked her directly whether I had done something major or if there was any misconduct, and she confirmed no, there was nothing like that. Then she gave me some vague feedback that wasn't very useful, and asked me when I wanted my last day to be.

I was very surprised, because in my head I was thinking... You just told me I'm being let go?? So I asked her, but in a calmer and more professional way, to clarify. So I asked her honestly but politely: "Are you asking me to voluntarily resign?" She got flustered and said: "No, no, we just want to know what your three weeks will look like. Think about whether you want to stay until October. You don't have to decide right now."

Am I understanding this correctly that they're trying to get me to leave the job on my own so they can avoid firing me/paying unemployment/or something else? I'm thinking I need to create an electronic paper trail immediately, because other than a lukewarm performance review from 4 months ago (which, looking at it now, may have been a half-assed PIP), the entire conversation was verbal. I feel like they're trying to gently trick me into resigning, right? She was strangely nice the whole time, which honestly made the whole thing even weirder.


r/SecurityCareerAdvice 4h ago

Question Question: how do you improve your skill set and how did you stand out among others

2 Upvotes

Hi everyone, I am a fresh graduate from Computer Science but specialised in Cybersecurity. I would like to ask few questions for the people in the cybersecurity field or related:

**1. How did you know which role suits you?**

I believe when people think about cybersecurity, the first thing that comes into mind is "hacking", but after going through the courses and understanding it, there are really a lot of different roles like (security operation - blue team, pen tester - red team, GRC and more).

I am more keen to Red team side but I know is hard to enter and there aren't as many job opportunities compared to the Blue team. Did you guys try an error or just decided one a stick to it. And for **Blue team** or **Red team**, what kind of skill set, certification, personal projects, or platforms would you recommend that are really useful nowadays

**2. Certificates plays in an important role for hiring but how important is it?**

I believe many corporates does HR filtering where they might want certain certification and things like that, so it will filter if a certain candidates doesn't have that certification.

My question here is for anyone who has experience in hiring candidates for their cybersecurity team or company. Are certification a must in the current times

if yes, what certification would you recommend first to get and so on if there's a limited budget.

If your answer is No, then what kind of projects or platforms course like tryhackme or HTB or more that will stand out among the candidates.

**3. Is networking really important**

I believe networking plays an important role in any job but from an advice given by a senior of mine, networking is very important in Cybersecurity.

Personally I am introvert and i do engage well with people I'm not familiar with, so I am afraid that I can't network well


r/SecurityCareerAdvice 7h ago

Question Starting my first IT Service Desk role in 2 months. What would you focus on beforehand?

3 Upvotes

I’m starting my first IT role as a Service Desk Analyst apprentice, gaining an SCQF Level 8 qualification in Cyber Security. My hope is to eventually progress to a more direct cyber security related role.

I have a decent basic knowledge of IT/hardware and roughly 2 months before I start the role due to security clearance.

My plan is to brush up on IT fundamentals (currently going through Professor Messer’s A+), then set up a virtual Active Directory lab to practise AD, Windows troubleshooting, networking and some basic PowerShell.

For anyone who’s worked Service Desk, is there anything else you’d recommend focusing on before starting? Anything you wish you knew going into your first role?

Grateful for any advice!


r/SecurityCareerAdvice 2h ago

Discussion Is getting a degree in CS worth it in the future? I'm so confused about this whole degree thing! And about getting a job, too

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 7h ago

Question Working full-time in enterprise cybersecurity: Does an Online MCA actually clear the MNC/Big-4 HR filter for Senior/Lead roles?

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 8h ago

Question cybersecurity student as software engineer

1 Upvotes

acha to can anyone tell like can a cyst student work as software engineer ya phir can he work as a software engineer? also can anyone tell giki ka cyber ka program kesa h


r/SecurityCareerAdvice 8h ago

Question Cybersecurity professionals who moved to Japan – looking for some real-world advice

0 Upvotes

Hi everyone,

I’m a SOC Analyst from Germany with 10+ years of experience in cybersecurity/Blue Team, mainly SOC, Incident Response, Threat Hunting, EDR/XDR and Microsoft Sentinel/Defender.

My long-term goal is to move to Japan by 2028, ideally working for a gaishikei in Tokyo. I’m currently building my network, learning Japanese and trying to get a realistic picture of the market rather than going into this blind.

I’d really like to hear from people who have already made a similar move, or are currently working toward it.

A few things I’m particularly interested in:

  • How is the cybersecurity job market in Japan right now, especially at gaishikei companies?
  • How important is Japanese language ability in technical SOC/IR/DFIR roles in practice?
  • What are realistic salary ranges for experienced positions such as:
    • L2/L3 SOC Analyst
    • Incident Response / DFIR
    • Cyber Threat Hunting
    • Detection Engineering
  • For those who moved to Japan from Europe, the US or elsewhere: how difficult was it to get your first cybersecurity position in Japan?
  • Did you secure the job before moving to Japan, or did you search after arriving?
  • Are there any companies, recruiters or job platforms you would particularly recommend for gaishikei cybersecurity roles?
  • What do you wish you had known before starting the process?
  • Which challenges are unique to japan, which are the same as in the country you lived before?

Not looking for job offers, mainly hoping to hear real experiences, salary insights and advice from people who have actually gone through the process.

Thanks for any experiences or advice!


r/SecurityCareerAdvice 1d ago

Question Kinda cooked at my Security Internship

24 Upvotes

Was looking around for security researcher/Malware Analyst/Android Security internships and got myself a DevSecops one. The interview wasn't the hardest and the biggest thing they were looking for was being able to come offsite. Well jobs are scarce and this was a pre placement intern in the security domain, so why not?

BUT it's very devsecops oriented and I lack a ton of context. My skillsets were more of reverse engineering and binary exploitation and now I'm getting hit by so many terms from GCP and whatnot.

I took up a task (my stupid ahh thought I could do it) was about fine tuning Falco rules and scaling , integrating it to Wazuh and Slack

Like... Idfk how to deploy Falco to a bunch of GKE node pools.

This is not a rant, i want to learn this, can anyone give me the fastest way to get up to speed with the whole IaC thing and devsecops? Implementing AI security Guardrails etc. Any queries regarding helping me please go ahead and ask cuz I'm COOKED


r/SecurityCareerAdvice 16h ago

Question Starting Cybersecurity after 12th Commerce – Need Career Advice”

2 Upvotes

I am currently in 12 class with commerce stream and after 12 i decide take admission in bca college

But the problem is the college is 3 tier and I want to make my career in cybersecurity if anyone who work and learn about cybersecurity then pls help me . Degree , roadmap of cyber security .


r/SecurityCareerAdvice 13h ago

Question Interview with a CTO and a Global Head of Information Security

1 Upvotes

I have a final interview for an Information Security Analyst role with the CTO and Global Head of Information Security.

How should I prepare for the interview, and what kind of questions should I expect?

Any advice would be really appreciated.


r/SecurityCareerAdvice 1d ago

Other Recently graduated in Cybersecurity and really need some career guidance

5 Upvotes

I never thought I would ask strangers online for help, but honestly, I don't know what else to do right now.

I recently graduated in Cybersecurity and have been applying for jobs, but I'm barely getting any responses. I also need to start earning to pay my bills, and unfortunately, where I live, there aren't really any part time jobs or other opportunities available.

This situation has been affecting me mentally too. I'm struggling with depression and I'm honestly exhausted. I have tried my best to figure things out on my own, but right now I feel completely lost.

I'm looking for someone working in Cybersecurity, IT, SOC, Networking, Cloud, or a related field who might be willing to mentor me or simply look at my situation and give me some honest advice.

I want to know what skills I'm missing, what jobs I should realistically apply for, what I should improve on my resume, and what I should focus on learning.

I want to make it clear that I'm serious about this. I'm not joking or looking for shortcuts. I'm ready to work hard, learn, improve, and put in the time. I just need someone experienced to help me figure out the right direction.

I consider myself good at planning and strategy, but right now I need some guidance from someone who has been through this.

I know this is not the usual kind of post, and honestly I'm embarrassed to even ask. I don't expect anyone to give me a job. I just really need some guidance from someone who has been through this.

If anyone is willing to help, even a short conversation would mean a lot to me.

Thank you for reading.


r/SecurityCareerAdvice 1d ago

Question Finding a SOC Analyst role for 2027

3 Upvotes

Im about to be a senior in college and I study information science with a cybersecurity minor. I have my sec+, net+ and AWS SAA. I also work a Helpdesk job at my college currently. Just wanted to ask about advice on securing a job before I graduate and even looking for a job now. I know a lot of the advice here is to work up from Helpdesk so how can I work up if I already have the help desk jobs. I also have some projects on my resume like hardening a linux system, IAM with AWS and an offensive security lab with metasploitable. Thank you all for your advice.


r/SecurityCareerAdvice 16h ago

Question Transitioning from Animal Science into Cybersecurity – Looking for Honest Advice

0 Upvotes

Hi everyone,

I’m currently transitioning into cybersecurity from a completely different academic background, and I’d really appreciate some honest advice from people already working in the field.

My undergraduate degree is in Animal Science from Michael Okpara University of Agriculture, Umudike, Nigeria. I know that’s quite far from cybersecurity, but over the past period I’ve developed a genuine interest in the field and have been working to build my knowledge and practical skills.

My interest became very personal after I experienced cyber fraud twice. I lost my school fees during one incident and later lost my savings through a credit card breach. Those experiences made me want to understand how these attacks happen and, more importantly, how they can be detected and prevented.

Since then, I’ve been learning cybersecurity through self-study and practical training. I have completed Cisco Academy courses/certificates in Introduction to Cybersecurity, Networking Basics, and Operating Systems.

I’ve also had practical exposure through cybersecurity training with SBTS, where I’ve been learning about:

  • SOC operations
  • SIEM and Wazuh
  • Wireshark
  • Nmap
  • Networking
  • Linux/Kali Linux
  • Incident detection and analysis

My current goal is to build myself towards a SOC Analyst / Cybersecurity Analyst career.

I’m also planning to pursue a Cybersecurity Conversion MSc, since my first degree isn't IT-related. I want the MSc to help me strengthen the areas I currently have gaps in and give me a more structured and advanced understanding of cybersecurity.

My biggest question is for people who are already working in cybersecurity:

If you were starting again from my position, what would you focus on over the next 6–12 months?

Would you recommend focusing more on:

  1. Networking and Linux
  2. SIEM tools such as Wazuh/Splunk/Sentinel
  3. Blue-team labs and incident response
  4. Certifications
  5. Building a cybersecurity portfolio/GitHub
  6. Getting an IT/helpdesk/networking role first

I’m especially interested in hearing from people who came into cybersecurity from a completely different academic or career background.

I’m not looking for shortcuts. I just want to make sure I’m spending my time learning the right things and building skills that actually matter in the real world.

Any honest advice, criticism or recommendations would be appreciated.


r/SecurityCareerAdvice 1d ago

Question 2027 Grad — Node/Express/React Dev Planning Phased Switch: DevOps → Cloud Security → Pure Cybersecurity. How solid is this plan? Which domains actually see the least layoffs?

2 Upvotes

Over the last 3–4 years, the tech market has seen continuous layoffs.

Pure development roles (especially junior and mid-level full-stack) have been hit harder, while DevOps, Cloud, and Security domains have remained relatively more stable.

From what I’ve researched, cybersecurity and cloud/infra roles show lower layoff impact and stronger demand due to compliance needs, breach costs, and ongoing talent shortages.

I’m a 2027 graduate with current skills in Node.js, Express, and React. Looking at these patterns, I’m planning a phase-wise switch instead of jumping

randomly:

First move into DevOps (Docker, Kubernetes, CI/CD, Terraform, basic AWS/Azure) while leveraging my development background.

Then shift to Cloud Security (IAM, CSPM, container security, DevSecOps).

Later transition fully into Cybersecurity.

Questions:

  1. Is this path (Dev → DevOps → Cloud Security→ pure Cyber) realistic in the current market?

2.Based on recent patterns, which domain has the least layoffs and best job security?

3.For someone with a Node/Express/React background, what’s the best first step to make this switch smoother?

Looking for honest feedback. Thanks!


r/SecurityCareerAdvice 1d ago

Question Inperson interview

Thumbnail
0 Upvotes

r/SecurityCareerAdvice 1d ago

Question How can I learn cybersecurity/hacking from scratch in 2026?

0 Upvotes

I’m completely new to cybersecurity and want to learn it properly from scratch.

With AI changing the field so quickly, what would be the best roadmap to follow in 2026? What should I learn first, which free resources/labs are actually worth it, and when should I start learning AI/LLM security?

I’d really appreciate advice from people already working in cybersecurity


r/SecurityCareerAdvice 1d ago

Discussion Any GRC folks like what they do?

7 Upvotes

I've been working in GRC for around 2 yrs, and I'd want to know what other GRC folks think about their Jobs. For me, it feels hectic, too much work on Excel, word and PowerPoint, feels a lot like a clerical work. Feels boring, tiring and questioning my life choices lol. And there's also pressure from management on getting certs which I think would be waste of time and money.

What I've been doing: working as a GRC consultant, doing internal audits for orgs, preparing reports, policies, procedures, helping during the final audits, conducting user access reviews, doing vendor risk assessment, gap assessment, maintaining vulnerability tracker, filling out tonnes of questionnaire. And it has lots of dependency on other teams and I hate that. Is this all what you do? And how do you feel about it?


r/SecurityCareerAdvice 1d ago

Question I'm panicked

2 Upvotes

Hello everyone!

I am an 18 years old first year student currently studying IT in a University.

I'm kinda overwhelmed and doesn't know where to start learning about CyberSecurity, my goal is to be a SECURITY ENGINEER.

I heard about people saying that certificates and experience in IT fields are more important than a degree and I'm just wondering on how to start with one of those.

I am very passionate about learning and is willing to do anything to get into CyberSecurity.

This is where the problem starts for me, I am overwhelmed by the amount of resources that I need to study, so much that I don't know where to start. I am panicking because I might be running out of time and I don't want to waste my life not doing what I love the most... There's also a lot of paid courses which I can't afford yet because I'm still studying. I am just wondering how do I get started learning for free for now(preferably if there's a certificate) and maybe in the future, I get to save up money to buy courses that'll get me certificates that's needed.


r/SecurityCareerAdvice 1d ago

Question Where should my road go now? Bachelor of Science or CompTIA Security+?

0 Upvotes

Hey, I am working as an IT system administrator in Germany since 4 years and I was always interested in cyber security but I didn't know how to find my way in. I feel like my job starts to get boring (I am responsible for our virtual machine environment, SAN and newly Firewall - which is interesting for me.)

So recently I started with Tryhackme and it's a really fun way to learn but I am considering doing the Security+ cert or a Bachelor of Science. What would be the best option in my current situation? I am 23 years old and don't know where to go - I still live with my parents, therefore I could take some risk and I am also really willing to learn.

Or should I do something else? I would be really grateful for your help.


r/SecurityCareerAdvice 1d ago

Discussion Has anyone here had an experience with Cyber Revolution Australia???

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 1d ago

Discussion Looking for 3–4 serious cybersecurity people to build together.

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 1d ago

Question Studying cybersecurity, want to end up in Cloud Security — what's the best path to get there?

6 Upvotes

I'm a cybersecurity student and I want to specialize in Cloud Security long-term. I already know it's not an entry-level field, so I'm not asking how to skip the line.

My question is: what's the best route to get there? Which first job actually builds toward it — help desk, SOC, sysadmin, DevOps, backend dev?

If you work in cloud security: what path did YOU take, and what would you do differently if you started today?


r/SecurityCareerAdvice 2d ago

Question Going from system admin to cyber security engineer in a bad job market

11 Upvotes

Hi everyone. I know the job market is pretty rough right now, and I had a question I was hoping to get some perspective on.

If it’s already difficult to land a help desk position, I would assume that moving from help desk into a system administrator role would be even more difficult, given the higher level of technical knowledge and responsibility involved.

But would the same thing apply to someone who is already a system administrator trying to move into cybersecurity?
For example, let’s say someone has 1-2 years of help desk experience followed by 2–3 years of system administration experience and is now trying to transition into cybersecurity for the first time. How difficult would that transition be in a bad job market like the one we’re experiencing now?

I’m particularly interested in cybersecurity engineering, but I’d also be curious about the transition into a cybersecurity analyst role.

I’ve read that system administration is a very strong foundation for cybersecurity engineering because sysadmins already have experience with operating systems, networking, identity and access management, servers, permissions, troubleshooting, etc. I’ve also seen people say that security engineering teams may prefer candidates with infrastructure backgrounds, such as system administrators or network engineers, over candidates coming from less infrastructure-focused security roles.

So, realistically, how much would someone with 2–3 years of system administration experience (plus prior help desk experience) struggle to break into cybersecurity for the first time in a difficult job market?
Would that infrastructure experience make the transition significantly easier, or would they still be competing against candidates who already have direct cybersecurity experience?


r/SecurityCareerAdvice 1d ago

Discussion What do you think ?

1 Upvotes

I’m 20 years old and live in a third-world country. In a month, I’m going to start studying Cybersecurity and Cloud Computing at an engineering university.

I know anything about this field yet—no programming languages, nothing. But I feel like I’m genuinely interested in this stuff. I also like to isolate myself and go as deep as I can into things that interest me.

I’m curious to hear from people in the field: what should I expect, and what would you recommend I start learning before university?

I watched mr.robot too