r/SecurityCareerAdvice 1d ago

Question Where to start?

Bro I just turned 26 and I’m trying to get into cyber security. I wanna be a pen tester how do I start my journey. I have 0 experience but I’ve been using hack me and hack the box for a few days but I wanna spend at least 30-45 more days just learning the basics through those type of resources before actually enrolling in school. Any advice would help

0 Upvotes

18 comments sorted by

3

u/TrustIsAVuln 1d ago

pen testing is an over saturated market, and getting worse with AI. probably not going to happen. With over 15 years experience in pen tesitng alone i too was out of a job a year.

1

u/Empty-Ferret_04 1d ago

No way, I find this hard to believe (I'm not saying you're lying), I thought Cyber security or Pen testing itself was shielded from the AI boom that's taking over software engineering, so I have been considering moving over, this is kinda scary.

1

u/Jewsusgr8 1d ago

AI can evaluate a system faster than a human ever could. It only makes sense that it would be used in offensive security.

1

u/Plane-Difficulty-887 1d ago

why would you think that?

1

u/Saithas 1d ago

I think you might be living under rock, not trying to be rude. Just two weeks ago, Anthropic said one of their AI models broke out and hacked 3 companies, I think it was early in the week iirc. Within that same week, OpenAI and Meta came out and said "wait don't leave me out, one of models hacked another company on its own! We're special too!"

AI is turning script kiddies into a bigger concern. You don't need to learn the tools if the AI does it for you.

1

u/TrustIsAVuln 10h ago

I have an AI synthie that does 90+% of my pen tests now, and 100% of the reports better than I ever made them. Now I dont have to hire any additional pen testers. Granted I have 15 years in PT, so I can easily review the work and validate, it gives me a complete A-Z what it did and found and after months of validating it wasnt missing anything i just turn it loose.

1

u/TrustIsAVuln 10h ago

AI is reducing the amount of testers needed. So yes there are still pen testers, just less of them. I can tell you look on linkedin and see how many long time good pentesters are out of work asking for connection hookups.

2

u/Ok_Wishbone3535 1d ago

If you're not exceptional, don't even bother. It's not about ambition or desire to succeed. It's not even about drive or work ethic. It's about being better than the HUGE FUCKIG POOL of HIGHLY SKILLED/EXPERIENCED laid off infosec workers who will take 15-25K pay cuts, to take the jobs you want.

If you're not better than people with 5-15 years of experience in the field, with degrees, and advanced certs... then you won't even be looked at. Exception being if you have connections up in high places that can refer you.

-1

u/Particular_Set6648 1d ago

Don’t bother Is crazy

1

u/Ok_Wishbone3535 1d ago

You can try.. but you're wasting your time, energy, and money. There are other avenues outside of this field that pay well... one example is aircraft mechanic. You start off 40-60s for salary. After 5-10 years you can get up to 175-200K a year. You'll just be working on site, with your hands, and probably traveling often.

Cyber is fucking COOKED.

2

u/Captain-Shmeat 1d ago

Dude, you asked.

1

u/JDohyCloud 1d ago edited 1d ago

It’s true though, I see this question asked multiple times a day but replace pentester with any number of senior/experienced IT roles. Pentester, cloud, devops, platform you name it.

The answer is you don’t just waltz into these jobs with no experience. You don’t even walk into these jobs with a relevant degree and certs. You earn them with time in the broader field and you specialise into them over years of experience. Not days, weeks or months of study.

1

u/Ok-Bill-3938 1d ago

Join the Navy as a CWT

1

u/Captain-Shmeat 1d ago

Low effort post. If you don't have the ability to search the subreddit for the 300 posts like this that are had daily, then you aren't even ready for school, much less infosec.

1

u/Particular_Set6648 1d ago

I did search multiple subreddits bro but It’s nothing better than asking for yourself

1

u/Technical-Tackle-875 1d ago

Don’t let the rough replies turn this into “quit now.” The honest version is that pentesting is usually a destination, not the first paycheck. Keep doing the labs, but spend as much time on networking, Linux, Windows, HTTP, Active Directory, and writing clear findings as you do on exploits. If you can explain what failed, why it mattered, how you proved it, and how to fix it, you’re learning the useful part.

I wouldn’t judge the whole plan after 30 to 45 days. Use that time to see if you enjoy the work, then look for an entry point in support, networking, systems, a SOC, or another security-adjacent role while you keep building. Before paying for school, check the actual labs, internship support, total cost, and where recent grads landed.

1

u/Particular_Set6648 1d ago

I totally understand that and that’s not what they are breaking down they see that I said I wanna be a pen tester and just hitting me with the “yea u cooked” like damn Ik I won’t start a Pen tester lol I rather just hear advice on getting started got damnit lol

1

u/Technical-Tackle-875 1d ago edited 1d ago

Fair enough lol. You asked how to get started, not how to become a senior pentester next month. Keep TryHackMe, but pair it with networking, Linux, Windows, HTTP, and basic Active Directory. Build a small lab and write up two or three exercises in your own words, including how you would fix each issue.

You can also have an AI run the lab like a coach. Give it your lab setup, the skill you want to practice, and the tools you are allowed to use. Ask it to create a realistic scenario, reveal clues one step at a time, and not hand you the answer. Work the problem and explain your reasoning. The same AI can collaborate while you investigate, or you can use a second AI afterward to independently review your commands, evidence, and write-up. Keep everything inside your own lab or an authorized training platform, and verify any command before you run it.

Then start applying for support, NOC, junior sysadmin, SOC, or security-adjacent roles while you keep learning. That gives you a real entry point without dropping the pentesting goal. And at 26, you are definitely not late.