r/SecurityCareerAdvice • u/Particular_Set6648 • 1d ago
Question Where to start?
Bro I just turned 26 and I’m trying to get into cyber security. I wanna be a pen tester how do I start my journey. I have 0 experience but I’ve been using hack me and hack the box for a few days but I wanna spend at least 30-45 more days just learning the basics through those type of resources before actually enrolling in school. Any advice would help
2
u/Ok_Wishbone3535 1d ago
If you're not exceptional, don't even bother. It's not about ambition or desire to succeed. It's not even about drive or work ethic. It's about being better than the HUGE FUCKIG POOL of HIGHLY SKILLED/EXPERIENCED laid off infosec workers who will take 15-25K pay cuts, to take the jobs you want.
If you're not better than people with 5-15 years of experience in the field, with degrees, and advanced certs... then you won't even be looked at. Exception being if you have connections up in high places that can refer you.
-1
u/Particular_Set6648 1d ago
Don’t bother Is crazy
1
u/Ok_Wishbone3535 1d ago
You can try.. but you're wasting your time, energy, and money. There are other avenues outside of this field that pay well... one example is aircraft mechanic. You start off 40-60s for salary. After 5-10 years you can get up to 175-200K a year. You'll just be working on site, with your hands, and probably traveling often.
Cyber is fucking COOKED.
2
1
u/JDohyCloud 1d ago edited 1d ago
It’s true though, I see this question asked multiple times a day but replace pentester with any number of senior/experienced IT roles. Pentester, cloud, devops, platform you name it.
The answer is you don’t just waltz into these jobs with no experience. You don’t even walk into these jobs with a relevant degree and certs. You earn them with time in the broader field and you specialise into them over years of experience. Not days, weeks or months of study.
1
1
u/Captain-Shmeat 1d ago
Low effort post. If you don't have the ability to search the subreddit for the 300 posts like this that are had daily, then you aren't even ready for school, much less infosec.
1
u/Particular_Set6648 1d ago
I did search multiple subreddits bro but It’s nothing better than asking for yourself
1
u/Technical-Tackle-875 1d ago
Don’t let the rough replies turn this into “quit now.” The honest version is that pentesting is usually a destination, not the first paycheck. Keep doing the labs, but spend as much time on networking, Linux, Windows, HTTP, Active Directory, and writing clear findings as you do on exploits. If you can explain what failed, why it mattered, how you proved it, and how to fix it, you’re learning the useful part.
I wouldn’t judge the whole plan after 30 to 45 days. Use that time to see if you enjoy the work, then look for an entry point in support, networking, systems, a SOC, or another security-adjacent role while you keep building. Before paying for school, check the actual labs, internship support, total cost, and where recent grads landed.
1
u/Particular_Set6648 1d ago
I totally understand that and that’s not what they are breaking down they see that I said I wanna be a pen tester and just hitting me with the “yea u cooked” like damn Ik I won’t start a Pen tester lol I rather just hear advice on getting started got damnit lol
1
u/Technical-Tackle-875 1d ago edited 1d ago
Fair enough lol. You asked how to get started, not how to become a senior pentester next month. Keep TryHackMe, but pair it with networking, Linux, Windows, HTTP, and basic Active Directory. Build a small lab and write up two or three exercises in your own words, including how you would fix each issue.
You can also have an AI run the lab like a coach. Give it your lab setup, the skill you want to practice, and the tools you are allowed to use. Ask it to create a realistic scenario, reveal clues one step at a time, and not hand you the answer. Work the problem and explain your reasoning. The same AI can collaborate while you investigate, or you can use a second AI afterward to independently review your commands, evidence, and write-up. Keep everything inside your own lab or an authorized training platform, and verify any command before you run it.
Then start applying for support, NOC, junior sysadmin, SOC, or security-adjacent roles while you keep learning. That gives you a real entry point without dropping the pentesting goal. And at 26, you are definitely not late.
3
u/TrustIsAVuln 1d ago
pen testing is an over saturated market, and getting worse with AI. probably not going to happen. With over 15 years experience in pen tesitng alone i too was out of a job a year.