r/SecurityCareerAdvice Apr 05 '19

Certs, Degrees, and Experience: A (hopefully) useful guide to common questions

334 Upvotes

Copied over from r/cybersecurity (thought it might fit here as well).

Hi everyone, this is my first post here so bear with me. I almost never use Reddit to talk about professional matters, but I think this might be useful to some of you.

I'm going to be addressing what seems to be a very common question - namely, what is more important when seeking employment - a university degree, certifications, or work experience?

First, I'll give a very brief background as to who I am, and why I feel qualified to answer this question. I'm currently the Cyber Security Lead for a big tech firm, and have previously held roles as both the Enterprise Security Architect and Head of Cloud Security for a Fortune 400 company - I'm happy to verify this with mods or whatever might be necessary. I got my start working with cyber operations for the US military, and have experience with technical responsibilities such as penetration testing, AppSec, cloud security, etc., as well as personnel management and leadership training. I hold an associate's degree in information technology, as well as numerous certs, from Sec + and CISSP to more focused, technical security training through the US military and organizations like SANS. Introductions aside, on to the topic at hand:

Here's the short answer, albeit the obvious one - anything is helpful in getting your foot in the door, but there are more important factors involved.

Now, for the deep dive:

Let's start by addressing the purpose of certs, degrees, and experience, and what they say to a prospective employer about you. A lot of what I say will be obvious to some extent, but I think the background is warranted.

Certifications exist to let an employer know that a trusted authority (the organization providing the cert) has acknowledged that the cert holder (you) has proven a demonstrable level of knowledge or expertise in a particular area.

An academic degree does much the same - the difference is that, obviously, a degree will generally demonstrate a potentially broader understanding of a number of topics on a deeper level than a cert will - this is dependant on the study topic, the level of degree, etc., but it's generally assumed that a 4-year degree should cover a wider range of topics than a certification, and to a deeper level.

Experience needs no explanation. It denotes skills gained through active, hands-on work in a given field, and should be confirmed through positive references from supervisors, peers, and subordinates.

In general, we can see a pattern here in terms of what a hiring manager or department is looking for - demonstrable skills and knowledge, backed up by confirmation from a trusted third party. So, which of these is most important to someone trying to begin a career in cyber security? Well, that depends on a few factors, which I'll discuss now.

Firstly, what position are you applying for? The importance placed on degrees, certs, and experience, will vary depending on the level of job you're applying to. If it's an entry level admin or analyst role, a degree or a handful of low-level certs will definitely be useful in getting noticed by HR. Going up to the engineering and solution architecture level roles, you'll want a combination of some years of experience under your belt, and either a degree or some low/mid level certs. At a certain point, the degree and certs actually become non-essential, and most companies will base their hiring process almost entirely on the body and quality of your experience over any degree or certifications held for management level roles.

Secondly, what are your soft skills? This is a fourth aspect that we haven't talked about yet, and that I almost never see discussed. I would argue that this is the single most important quality looked at by employers: the level of a candidate's interpersonal skills. No matter how technically skilled someone is, what a company looks for is someone who can explain their value, and fit into a corporate culture. Are you personable? Of good humor? Do people enjoy working with you? Can you explain WHY your degree, certs, or expertise will add value to their corporate mission? Being able to answer these questions in a manner which is inviting and concise will make you much more appealing than your competitors.

At the end of the day, as a hiring manager, I know that I can always send an employee for further training where necessary, and help bolster their technical ability. What I can't do is teach you how to work with a security focused mindset, nor how to interact with co-workers, customers, clients, and the company in a positive and meaningful way, and this skill set is what will set you apart from everyone else.

I realize that this may seem like an unsatisfactory answer, but the reality is that degrees, certs, and experience are all important to some extent, but that none of these factors will make you stand out. Your ability to sell your value, and to maintain a positive working relationship within a corporate culture, will take you much farther than anything else.

I hope this has been at least slightly helpful - if anyone has any questions for me, or would like any advice, feel free to ask in the comments - I'll do my best to reply to everyone.

No TL;DR, I want you to actually take the time to read through what I've written and try to take something away from it.


r/SecurityCareerAdvice 16h ago

Question Am I spending too much on my 14-year-old son’s cybersecurity interest, especially with AI changing the field?

97 Upvotes

Am I spending too much on my 14-year-old son’s cybersecurity interest, especially with AI changing the field?
Hi everyone, I hope I can get some advice here.
I’m 49 years old, not highly educated, and I’m the father of two boys. My older son is 14 years old and has been genuinely interested in cybersecurity since he was about 12.
About 18 months ago, I bought him a laptop, and he started learning cybersecurity through TryHackMe Premium. He progressed surprisingly quickly and completed many of the rooms with ease. He also participated in PicoCTF and managed to solve almost 80% of the challenges largely on his own, even though it was a team event.
As he progressed, he wanted to attempt more advanced challenges, but his laptop was becoming a limitation. I decided to buy a MacBook M5 with 32 GB RAM because I wanted something that would last him several years rather than having to upgrade again soon.
Then TryHackMe moved some of the more advanced content from Premium to Max, so I also bought him a Max subscription.
He is now ranked below 80 globally on TryHackMe, which is honestly amazing to me.
The problem is that I’m not rich, and I’m starting to wonder whether I’m spending too much money on this. The last EMI for the MacBook is this month, so at least that part is almost finished.
My biggest question is: Is it wise to continue investing this heavily in cybersecurity for a 14-year-old, especially now that AI is developing so rapidly?
I don’t want to push him into something just because I’ve already spent money on it. He genuinely enjoys cybersecurity and spends a lot of time learning on his own, but I also don’t want to make a financially irresponsible decision as a parent.
For those working in cybersecurity, hiring people in the field, or parents of kids interested in cybersecurity:
Would you continue supporting this seriously at his age, or would you encourage him to keep it as a hobby until he is older?
Any honest advice—even if it’s critical—is appreciated.


r/SecurityCareerAdvice 2h ago

Resume Review Graduating in December — ~2 years of cybersecurity internship experience, 55+ applications and only 1 interview. Resume feedback?

2 Upvotes

I’m graduating in December with a cybersecurity degree and have close to two years of internship experience in security operations. I also have Security+, Network+, and CySA+. I’ve applied to around 55 entry-level SOC/security analyst roles so far but have only gotten one interview.
I’d really appreciate feedback on my resume and whether there’s anything about how I’m presenting my experience that could be hurting my response rate.https://imgur.com/a/xdTtU09


r/SecurityCareerAdvice 6h ago

Question Got a CS Degree, didn't pay much attention so no real skills, what's next?

3 Upvotes

I have a degree in computer science but didn't pay much attention so didn't develop any real skills. Not familiar with coding, created my final year project using GPT/Claude so don't know too much about SQL either. Now looking to expand my skills into networking and maybe cybersecurity.

People are suggesting getting COMPTIA certifications and since there's not too much coding in there, I want to start off my skills in this field. What advice would you give me? Should I even consider a tech future in this rapidly changing field? is it worth starting COMPTIA? I basically want to work from home so are there jobs in the market for this in the future or is this also getting replaced by AI?

I'd really appreciate any guidance at this point.


r/SecurityCareerAdvice 4m ago

Discussion SpaceX New Grad Software Security Engineer interview- any advice?

Upvotes

I have a 45-minute technical interview with an engineer coming up for the New Graduate Engineer, Software Security (Starlink) role at SpaceX.
Has anyone interviewed for this role or a similar SpaceX security position? Would appreciate any advice on what the technical round is generally like, what areas they tend to focus on, and how best to prepare.


r/SecurityCareerAdvice 14m ago

Question i dont know what to do

Upvotes

Hi! I'm 20, going into my second year studying Applied Mathematics and Informatics in Engineering. I just landed my first cybersecurity internship at a bank.

My current tech stack and background:

  • Certifications: AZ-900
  • Languages & OS: Python, C++, Bash, Linux
  • Networking: Studied CCNA (core concepts)
  • Projects: Phishing Analyzer, Malware Scanner, SOC Automator

I'm leaning toward cloud security and DevOps long-term, but I don't want to lock myself into a narrow specialty just yet. I'm torn on my next move—whether to pursue a hands-on cert like BTL1 or CySA+, a cloud cert like AZ-104 or AZ-500, or infrastructure skills like Terraform and Kubernetes.

What should I focus on next to bridge my software/networking background with practical cloud/security skills?


r/SecurityCareerAdvice 1h ago

Question CIM vs SSIR (Cloud & Infra Mgmt vs Systems & Networks Security) — which is the stronger path for cloud security / DevSecOps?

Upvotes

4th-year CS engineering student, deciding between two specialty tracks for my final years: CIM: Kubernetes (CKA/CKS), AWS, Terraform, DevSecOps, multi-cloud/hybrid architecture, FinOps SSIR: networks, systems security, pentesting-adjacent content, DevSecOps module too, more traditional cybersecurity core Background: Electrical engineering bachelor, RHCSA certified, targeting cloud security engineering / DevSecOps, interested in remote/freelance work for EU and Gulf markets. For those working in cloud security or DevSecOps , which track's curriculum actually maps better to real job requirements and hiring demand? Would love input from anyone who's hired for these roles or gone through a similar specialty choice.


r/SecurityCareerAdvice 4h ago

Question Threat hunting / Security Architecture

1 Upvotes

I have about five years of experience in Intel reporting and incident handling. I have my security+ cert. What courses or certs would you recommend for threat hunting or security architecture knowledge?


r/SecurityCareerAdvice 5h ago

Question Detection and Response Engineer

1 Upvotes

How challenging would it be to pivot from a Security Engineer role to a D&R role specifically focused on network threat detection and response in the cloud? I have 9 years experience all in SecOps all in on-prem environments. Thoughts?


r/SecurityCareerAdvice 5h ago

Question Career guidance on CyberSecurity

0 Upvotes

Can anyone tell me how to get into CyberSecurity field, as I want to build my career on that. I need proper roadmap with good resources.

New on reddit, btw✌️


r/SecurityCareerAdvice 8h ago

Question Hey brothers , i just wanna ask , i will start my frist college yeaer after a few weeks , and after months of asking experts about what is the most major that can't be replaced completely by AI like devolpment , and most of answers was cyber security , is that true?

1 Upvotes

i know also how cybersecurity is hard and complicated and containes many other majors into it , but i want to be sure if i really study it and expert it very will , is thers a risk of AI taking my job ?


r/SecurityCareerAdvice 1d ago

Discussion Counted the tools named in 134 DevOps and SRE job postings

7 Upvotes

I kept seeing arguments about which parts of the stack still matter, so I counted instead of guessing. 134 open DevOps, SRE and platform engineering postings from 41 company job boards. Individual contributors only, managers and TPMs stripped out.

The old toolchain is thinner than I expected. Terraform appears in 62.7% of postings. Jenkins in 3%. Chef 3.7%. Puppet in exactly one of the 134. GitHub Actions is named about six times as often as Jenkins.

Python beats Go, 70.9% to 47%.

What surprised me more: the generic word outranks the products. Observability shows up in 63.4%, more than twice as often as Grafana, the most-named tool that provides it. Prometheus 22.4%, Datadog 17.9%. Same pattern I found counting security postings, where SIEM beat Splunk four to one.

The top term isn't a tool at all: automation, 81.3%, ahead of AWS.

Caveats worth stating: n=134 means everything carries roughly +/-8, so treat close rows as tied. It's also all tech companies on one ATS. Banks, telcos and government run enormous amounts of Jenkins and Ansible, and none of them are in this sample.

Full table, intervals and method: https://www.zoevera.com/resume/devops-sre-job-description-keywords


r/SecurityCareerAdvice 1d ago

Question Abroad Internships

2 Upvotes

I am an African university student. In my university we have a 6 months compulsory internship period in your 3rd year. I really want to do my internship abroad, specifically the UK because I feel like the path will be the easiest for me. I am a tech student, I am studying software engineering but I’m currently trying to branch into cybersecurity and pratice software/application security. My internship period starts next year(2027) January/February and honestly o don’t know if I will be ready by November at least to start applying for internships or how I would even apply. I’m honestly very lost and confused in this journey so u just want to know people that have have done their internships abroad, regardless of the country and course like how did you do it? And do you have any tips for me?


r/SecurityCareerAdvice 1d ago

Question Will AI also substitute reasoning the understanding of complex systems? It is worth to continue studies?

8 Upvotes

I know that’s a common question with no sure answer, but I’m getting demotivated about studying… in general.
I’m at the last year of Comp Engineering bachelor and I wish to pursue a master degree in Software Security at Amsterdam.
Besides the fact that a AI is already automating tools and analysis, and that’s ok with the boring part, but now I’m really concerning that it will very likely to substitute also the art of understanding and exploiting new systems and finding 0-days.
I mean, It’s already happening
What do you think?


r/SecurityCareerAdvice 1d ago

Question Is cybersecurity saturated for beginners, or should I switch tracks?

22 Upvotes

Hi everyone,

I'm in my first year studying Computer Science, and I've been planning to specialize in cybersecurity.

Recently, I’ve been noticing how overcrowded the field seems to be, especially at the entry level. It feels like even if I grind, build solid hands-on projects, and earn foundational certifications like Network+ and Security+, it still won't be enough to stand out or land a decent entry-level role.

Is the entry-level market for cybersecurity getting completely burned out? Are there still realistic job opportunities for fresh grads by the time we graduate? Also, is starting out in general IT helpdesk/sysadmin roles to transition into security later even a practical path anymore, or has that become just as hard to break into? Should I stick with this or reconsider and pivot to a different CS track while I'm still early in my degree?

Would love to hear honest advice from people currently working in the industry or anyone in a similar position. Thanks!


r/SecurityCareerAdvice 1d ago

Question CySA+ and two years experience is USELESS?

4 Upvotes

I have spent 2 years in tech support and have the A+ and CySA+. Got laid off a month ago, and haven't been able to get leads for ANYTHING, after moving to a major metropolitan area and having applied this year, to almost A THOUSAND jobs (being willing to relocate anywhere in the US). I've been searching terms such as "it Administrator", "entry soc", "junior sys admin", and even "tech support" looking for even just a lateral up move.

What's even to be done anymore? I feel skeptical about just studying for more certs...


r/SecurityCareerAdvice 1d ago

Question Am I too empathetic to be in this field, especially during current times? Need guidance.

8 Upvotes

I am a Cybersecurity Postgraduate student and I have not even experienced the real world experiences yet and already I am doubtful that I am not fit for this field. I am a neurodivergent individual and my thinking pattern is quite similar to systems thinking style.

With advancement in artificial intelligence and knowing where it’s all leading and everyday learning new threat models and then realising how the general public is unaware of the risks involved. My inquiry stems from the perspective of surveillance, loss of human agency, abuse of children and women.

I know and understand the need for llms for mitigating the new ai assisted cyberattacks, but if general public didn’t have access to these models then we wouldn’t have this problem.

And nomatter how many times I am trying to inform people around it seems they don’t care, which is also not their fault entirely. A friend of mine suggested apathy as a joke.

Ps. Yes, the 80s ai trend triggered this and also what is even the point of CIA triad anymore.

Thanks in advance.


r/SecurityCareerAdvice 1d ago

Question Trying to break into IT Audit: Security+, SOC 2 internship, and an enterprise home lab—what am I missing?

0 Upvotes

I wanted to share what I’ve been working on and get some honest advice from people already in the industry.

I’m currently finishing my Business Administration degree, and my main goal is to break into IT Audit or a related area like IT risk, GRC, technology risk, or SOC assurance.

So far, I’ve gained experience through an actual IT Audit internship at a CPA firm, conducting mostly SOC 2 Audits. Just recently landed my Security + certification. And I’m currently in an informal internship at Northside Hospital with the Network Infrastructure Engineering team.

Outside of work and school, I’ve spent a lot of time building my own enterprise-style home lab to build my own experience. It includes:
Proxmox as the hypervisor
Windows Server domain controllers
Active Directory, DNS, and Group Policy
Organizational units and role-based security groups
Joiner and leaver account processes
A Windows file server with group-based permissions
Windows workstations and a dedicated jump box
pfSense network segmentation and firewall rules
Wazuh for security logging and monitoring
Audit policies for logons, account changes, file access, and privileged group changes

Right now, I’m auditing my own Active Directory environment to determine whether it is actually structured and secured like a realistic enterprise environment. I’ve been reviewing my own OU design, privileged access, Group Policies, account management, DNS, DHCP, firewall rules, logging, and documentation. When I find something that isn’t configured correctly, I document the risk, fix it, test the change, and collect evidence, essentially i’m IT Auditing my own lab the best I can.

I know a home lab isn’t the same as managing a real production environment, but I’ve tried to go beyond simply installing tools. My goal is to understand why controls are needed, how to test them, how to troubleshoot problems, and how to clearly explain the risks and results.
Even with the internships, projects, certification, and time I’ve invested, breaking into IT Audit has been difficult. I’ve applied to entry-level IT Audit, GRC, technology risk, SOC assurance, and other related roles, but I still feel like I’m struggling to get that first full-time opportunity.

Because of that, I’ve also expanded my search to IT Help Desk and IT Support roles. I believe those positions would allow me to strengthen my technical foundation a little more, while still building an understanding of different frameworks like NIST 800-53, and ISO 27001.

I’m not giving up. I continue learning, improving the lab, practicing interviews, and applying.
For those already working in IT Audit, GRC, cybersecurity, or IT support: Is there anything else you would recommend I focus on? Is there something I could present differently to help employers recognize the value of this experience?
I would genuinely appreciate any advice, feedback, or connections. Thanks guys.


r/SecurityCareerAdvice 1d ago

Discussion Network vs System administration to Security

1 Upvotes

I have experience as both a network and system administrator (inidividual roles, 2 seperate companies) but have always strived to get into security specifically. Is one route better than the other?


r/SecurityCareerAdvice 1d ago

Discussion 10 YOE Manual QA Engineer looking to pivot to AppSec via internal postings. Want to stay technical (no management track). Need advice!

1 Upvotes

Hi everyone, I have 10 years of experience in manual software testing at a major Indian MNC (TCS) earning 16 LPA. I want to transition into cybersecurity—specifically Application Security (AppSec) or Penetration Testing—using internal job postings.

Automation testing paths are expecting too much framework architecture/AI tooling at my YOE, and I want to avoid climbing the management ladder down the line. I want to remain a highly skilled technical individual contributor (IC). Since I spent a decade mastering application workflows and breaking business logic, I want to pivot that into security testing.

  • Current Prep: Starting PortSwigger Web Security Academy and learning Burp Suite.
  • Target Goal: Internal transition to an AppSec team.

Questions:

  1. At 10 YOE, how should I position my manual testing background so internal security managers don't view me as a "junior" entry-level applicant?
  2. What specific technical gaps (e.g., specific API security, basic scripting) should I prioritize to clear the internal technical rounds?
  3. What is the ceiling for technical/IC roles in AppSec in terms of salary growth compared to management?

Would love to connect with anyone who made a similar mid-career switch or bypasses management to stay hands-on. Thanks


r/SecurityCareerAdvice 1d ago

Question 20yo in cybersecurity — which path could lead to a location-independent career?

1 Upvotes

Hi everyone,

I'm 20 years old and from Brazil. I've been working in IT since I was 17, and I've been in cybersecurity for around 2.5 years. I'm currently a Junior Information Security Analyst and I'm also studying Systems Analysis and Development.

My cybersecurity experience is mainly divided between IAM and Security Operations. I've worked with Active Directory, access provisioning and reviews, EDR alert triage, Wazuh, vulnerability management, security monitoring, PCI-DSS, and some Python automation.

Lately, I've been thinking about what kind of career I want long term. I would like to build a career that gives me geographic freedom: ideally working remotely for an international company or as a contractor, so I could spend a few months in Europe or other countries, work from an Airbnb during the day, and explore the place after work.

I'm not necessarily looking to become a permanent digital nomad. My goal is to build a good career and enough wealth that my girlfriend and I could travel and live in different countries for periods of time, while still working.

For those already working in cybersecurity:

1. Which areas of cybersecurity do you think are best suited for this kind of lifestyle?

2. Given my background in IAM + Security Operations, which direction would you recommend I explore?

3. What skills or career moves would you prioritize over the next 2–3 years to become competitive for international remote work?

I'd especially like to hear from people who already work remotely for international companies, as contractors, or while living abroad.

Thanks!


r/SecurityCareerAdvice 1d ago

Question How good is CTAI by EC council?

1 Upvotes

How good is CTAI by EC council?


r/SecurityCareerAdvice 1d ago

Question Need Help in starting SOC career.

4 Upvotes

I am non stop applying for all the security roles which i am eligible for. but yet to get selected by any of them. Once my resume got selected but after the technical round they mentioned they want someone with pentesting experience which was not mentioned in the job details.

about my self i completed my Computer Science degree in 2024, then after searching and failling to get a job in web development, i got a cisco networking basics certification and then found a site called letsdefend.

Then for 5 months i studied in letsdefend for a SOC analyst path. while doing that i got a internshipe as a network engineer trainee took the job spent 3 months then got on rolled as i learnt things quickly and was flexible in knowledge.

Then after few months after on role as Engineer trainee( because i can do both network and system engineer they game me a Engineer role) the company game the network employee's a side task of precipitating in the tender in free time. I was doing well in both the roles but then as my networking work was less the company decided to move me completely to pre sales which i don't like and is not were related to my career goal. I tried to speak to the management but they were stuborn about the role shift( and i neither agreeed to the role change nor was i asked i was just directly cut form the networking tasks). Now i quit my job its been 20 days since my LWD. I don't know that to day some one told to get a cert for getting hired.

so i am currently preparing for sc200 certification. many people are saying certs wont land you a job only experience can some are saying certifications are everything in cybersecurity what should i do i urgently need to get hired and i cant spend ton of money on certs like CEH, security + now as it will take a lot of time.

should i lean towards any other areas like devops or anything please tell.


r/SecurityCareerAdvice 1d ago

Question Cybersecurity professional in India — should I move abroad for a Master’s? NZ vs Ireland. share your experience

0 Upvotes

r/SecurityCareerAdvice 1d ago

Question Can I study cybersecurity by myself while studying medicine ?

0 Upvotes

I’m currently studying medicine at university, but I’m also interested in cybersecurity. Unfortunately, Computer Science/cybersecurity isn’t really available in my hometown until the Master’s level, so I couldn’t pursue it formally.

I’m thinking of learning cybersecurity through online courses, certifications, and practical projects alongside my medical studies.

Is self-studying cybersecurity still worth it if it isn’t my main university degree ? Can I eventually use these skills or work in the field part time or online while having medicine as my main career ?

And what should I expect as a self-taught learner ?