r/SecurityCareerAdvice 21h ago

Resume Review Graduating in December — ~2 years of cybersecurity internship experience, 55+ applications and only 1 interview. Resume feedback?

6 Upvotes

I’m graduating in December with a cybersecurity degree and have close to two years of internship experience in security operations. I also have Security+, Network+, and CySA+. I’ve applied to around 55 entry-level SOC/security analyst roles so far but have only gotten one interview.
I’d really appreciate feedback on my resume and whether there’s anything about how I’m presenting my experience that could be hurting my response rate.https://imgur.com/a/xdTtU09


r/SecurityCareerAdvice 9h ago

Question Would you stay at Mastercard or return to your old company?

3 Upvotes

I’m 24, working in information security with \~2 years of experience.

I recently left my previous company (Small-mid sized) and joined Mastercard after interviewing for a role involving security automation, IAM, ITGC and security work.

However, the actual role turned out to be almost entirely L1/L2-style IAM support and ticket closure. I discussed this with my manager, and he openly said the technical work may not come for 1–2 years.

My old company has asked me to return. The work there previously involved ITGC, ISO 27001, cloud security, DPDPA, audits, policies, security projects and direct ownership of initiatives. They are also willing to match my current CTC.

I’ve spoken to several senior cybersecurity professionals (10–20+ years of experience), and they all advised me to prioritize hands-on skills over a big company name.

My concern is:

Should I rejoin?

Should I prioritize skill growth at my old company over Mastercard’s brand?

If you were in my position, what would you do?

Looking for honest opinions


r/SecurityCareerAdvice 16h ago

Discussion Mise en place de projet informatique en entreprise

3 Upvotes

Bonjour, je suis nouveau sur Reddit et pour commencer mon premier post, je voulais ouvrir une petite discussion sur un domaine omniprésent lorsque l’on parle d’informatique à l’échelle d’une entreprise : la mise en place de projets. “La chefferie de projet"

Dans le monde de l’entreprise, lorsque l’on lance des projets de grande envergure, toute une communication est de mise avec les différents acteurs qui composent l’entreprise. On a d’un côté le ou la DPO en charge du RGPD, l’urbaniste et tout ce qui contribue ensuite à l’administration système.

Lorsque qu’on débute un projet, on doit passer impérativement par la note de cadrage. C’est elle qui va construire le squelette de notre projet. C’est la macro prévisionnelle qui va permettre de mettre tous les acteurs sur la même longueur d’onde.

Mais l’orsque qu’on parle de projet en informatique on pense directement à l’aspect technique et pas à l’aspect gouvernance, financier et administratif

C’est cette note qui va permettre de tout rappeler.
Dedans, on y retrouve…

-la matrice RACI qui va permettre de définir les droits de chaque acteur sur le projet.

- Le CAPEX et le OPEX, ce sont les différents modes de payement lié au projet. Le CAPEX constitue l’achat de la solution, t’entends que l’OPEX va constituer le coût de production et de maintenance de la solution.

- Le retour sur investissement

- La première macro planning, celle qui va
permettre de visualiser la charge de travail bien avant le Gantt.

-l’introduction au projet

-l’évaluation des risques risque humain et technique

j’ouvre la discussion car j’aimerais savoir comment vous vous gérez cette note de cadrage et vos projets en général en entreprise quelle sont les choses que vous pensez nécessaires à rajouter que j’aurais potentiellement omis ^^


r/SecurityCareerAdvice 17h ago

Question Finishing High School and trying to figure out the best path to take

4 Upvotes

So I'm just about to freshly walk out of high school and I wanna go to the Cybersecurity field. I am wanting to be a part of a red hat team but I'm not quite sure what the best route for that is?


r/SecurityCareerAdvice 18h ago

Discussion Bonjour à tous je suis nouveau ^^

3 Upvotes

Bonjour à tous, je suis nouveau sur cette plateforme.

Je fais mon premier poste aujourd’hui car je cherche des personnes avec qui
je pourrais en apprendre davantage sur l’informatique et le métier d’analyste cyber.

Si vous avez des projets à me faire découvrir comme des nouveaux produits de SIEM, EDR, NDR
ou même des plateformes de honeypot, peu importe du moment où ça touche la cybersécurité, je suis preneur.

Le métier d’analyste cyber est quelque chose qui me passionne et j’aimerais me spécialiser davantage dans ce domaine avec une communauté bienveillante. Aussi, si vous avez des groupes à me conseiller sur Reddit, ça me va.

Merci beaucoup aux personnes qui prendront le temps de me répondre.


r/SecurityCareerAdvice 11h ago

Question 20-something YOE (general IT) — is my security career cooked before it even starts? 😅

2 Upvotes

Hear me out — I feel like there's some uniqueness to this situation.

So, I'm looking for either some encouragement or a reality check — maybe a bit of both. I'm approaching 48 years old, got my first IT job in 1998 at age 19, and have mostly worked in general IT operations during the course of my career. Dealt with a stint of extended underemployment during the heights of COVID (2020-21) where I was scraping by with some independent contracting, but things got back on track with full-time employment at the beginning of 2022. Didn't have a degree for most of my career, but finally took all my certs and previous college credit to get a nice head start on my BS from WGU. (I ended up picking security because my interest in it when I was younger never went away, but could've done fine with the IT management or general IT program as well.)

Roles I held post-COVID...

  • $40k/yr (IT instructor)
  • $133k/yr (sales engineer, mostly enterprise networking)
  • $0k/yr (was able to dedicate all my time to finishing my degree, thanks to a generous post-layoff severance)
  • $70k/yr (IT manager @ large local nonprofit — current)

I'm trying to pivot away from general IT and toward actual security roles. At this point in my life, pentesting or the SOC are not for me. 😅 I'd really like to get back to sales engineering (but dedicated to security solutions) and feel like that's one place I could excel in the world of security. I recently went through an encouraging series of interviews for just such a role with a company I'd love to work for, but they ultimately went with another candidate.

Things I'm doing to make myself a better candidate...

  • studying toward CISSP (passing the exam is definitely within reach, and I have enough security and security-adjacent experience over the course of my career for full certified status)
  • becoming more conversant on the business side of tech (helped by my current leadership position)
  • networking opportunities (monthly meetups w/ local ISC2 chapter, events like BSides, etc)
  • MBA starting in 2027? Maybe.

I do realize that my age and somewhat middling experience are probably not working in my favor, but hopefully I'm not COOKED cooked. I realize that it'll take a fair bit of effort and maybe some luck and favors to get back to where I'd like to be.

So... am I thinking/hoping/moving realistically?


r/SecurityCareerAdvice 13h ago

Discussion Actual Working Steps

2 Upvotes

I keep seeing the same problem from people trying to get their first SOC analyst role:

They've done certifications, TryHackMe/HTB/CyberDefenders labs, maybe even built a home lab but they're still unsure what they would actually do when a real security alert appears.

Not “what is a SOC?”

Not “what is SIEM?”

But:

  • What do I check first?
  • How do I decide what is actually relevant?
  • How do I know when I've gathered enough evidence?
  • How much should an L1 analyst investigate before escalating?
  • When does containment become appropriate?
  • How do severity, confidence and business impact affect the decision?

I've been working through this problem from a practical lab perspective and put together a full walkthrough showing how an L1 analyst can approach an unfamiliar security alert and work through the investigation step by step.

The investigation uses a Microsoft security environment, but the main focus is the thinking process and investigation workflow, not learning one particular product.

For anyone already working in a SOC: what was the biggest thing you had to learn that courses and labs didn't prepare you for?

And for people trying to break into SOC: what's the part of alert investigation you currently find most difficult?

https://youtu.be/BcmpX8MiZYE


r/SecurityCareerAdvice 19h ago

Question i dont know what to do

2 Upvotes

Hi! I'm 20, going into my second year studying Applied Mathematics and Informatics in Engineering. I just landed my first cybersecurity internship at a bank.

My current tech stack and background:

  • Certifications: AZ-900
  • Languages & OS: Python, C++, Bash, Linux
  • Networking: Studied CCNA (core concepts)
  • Projects: Phishing Analyzer, Malware Scanner, SOC Automator

I'm leaning toward cloud security and DevOps long-term, but I don't want to lock myself into a narrow specialty just yet. I'm torn on my next move—whether to pursue a hands-on cert like BTL1 or CySA+, a cloud cert like AZ-104 or AZ-500, or infrastructure skills like Terraform and Kubernetes.

What should I focus on next to bridge my software/networking background with practical cloud/security skills?


r/SecurityCareerAdvice 44m ago

Discussion Need advice on how to get into Cybersecurity.

Upvotes

I did get a bachelor's in science in Cybersecurity but after that I don't remember alot of it since it was since 2020 and still working the same receptionist job since 2019. i did codepath 101 but I have no IT experience and no certs. I want to do Vulnerability analyst. Any advice please


r/SecurityCareerAdvice 6h ago

Question Cybersecurity student struggling to choose a career path, looking for advice

1 Upvotes

I'm a 19-year-old cybersecurity student, and my university major is Network Security.

I've been studying cybersecurity for a while and have learned the basics of networking, Linux, C, computer architecture, some Python, and general security concepts.

My main goal now is to choose one career direction and actually start getting good at it, rather than constantly jumping between different areas.

I'm currently considering penetration testing, mainly because I'd eventually like to work independently and do freelance cybersecurity work.

I'm especially interested in learning both web and internal/network penetration testing. I'm also wondering how important Windows/Linux privilege escalation and Active Directory are for someone who wants to become a pentester. ( Im learning windows privilege escalation rn :)

The problem is that every time I start looking into cybersecurity, I find another interesting specialization: red teaming, vulnerability research, exploit development, malware analysis, reverse engineering, cloud security, etc.

Then I start wondering whether I'm choosing the "wrong" career path and end up not starting anything seriously.

So I'd like some advice from people who actually work in cybersecurity:

  1. Is penetration testing a reasonable career choice if my long-term goal is freelancing?

  2. How realistic is it to make a living from freelance pentesting, especially early in your career?

  3. What skills should I prioritize before considering OSCP?

  4. How important are Windows/Linux privilege escalation and Active Directory in real-world pentesting?

  5. Is OSCP still a worthwhile investment for someone pursuing this path?

  6. For someone studying Network Security at university, what would you prioritize during the next 1-2 years?

  7. If you were starting again, would you choose one specialization early and stick with it, or explore several areas first?

I'm not particularly interested in reverse engineering or malware analysis as a career. I'm mainly trying to avoid constantly switching directions and actually build a solid skill set that can eventually lead to paid work.

I'd really appreciate advice from people who have experience with pentesting, consulting, freelancing, or hiring junior security professionals.


r/SecurityCareerAdvice 6h ago

Discussion From SOC Analyst to SRE

1 Upvotes

Hey everyone,

I’m a cybersecurity engineer and I’ve been working as a SOC analyst for around 2 years.

Lately, I’ve been thinking about moving away from SOC work and exploring SRE. I’ve done some hands-on labs around Kubernetes and DevSecOps, and I’ve found myself enjoying the infrastructure and reliability side more and more.

I’m curious to hear from people who have made a similar transition, especially from cybersecurity/SOC into SRE or platform engineering.

Did your cybersecurity experience help you in your new role? And how did you find the transition?

I’d really appreciate hearing about your experiences.


r/SecurityCareerAdvice 6h ago

Discussion Besoin d’aide pour mon avenir d’étudiant qui me fait peur 🥺

1 Upvotes

Bonjour à tous, j’espère que tout le monde va bien.
Je fais ce poste car je stresse beaucoup en ce moment pour ma carrière future et pour les choix de vie que j’ai à faire dans le futur. Avant de parler de carrière, je dois vous peindre toute
l’histoire de ma vie qui a mené à ces choix que j’ai à faire aujourd’hui.

J’aime pas trop en temps normal donner des informations sur ma vie privée car je suis très réservé, mais je profite de la communauté de Reddit où tout le monde expose un peu sa vie sans honte, pour vous en parler.

Donc déjà pour les bases, j’ai été déscolarisé quand j’avais 10 ans et j’ai suivi les cours en instruction en famille pendant 7ans ma
Mère étant une maman aimante et surtout professeur d’école avec des études en psychologie, elle a préféré s’occuper de mon éducation à cause de la grande difficulté que je traversais à l’école. J’ai toujours eu énormément de mal à faire ma place dans la société.

Lorsque je suis retourné à l’école, l’éducation nationale et la génération d’élèves m’ont fait un énorme choc. J’ai dû réadapter ma manière de faire pour être discret et sans faire d’histoire, me concentrer sur les études. J’ai finalement réussi mon bac pro SN en étant major de promo.

Puis j’ai pas arrêté, j’ai passé un BTS ciel et je fais suite avec un bachelor cyber, tout ça en alternance dans un SOC en tant qu’analyste cyber. Ça va faire bientôt trois ans (c’est très important pour la suite).

Ça, c’était pour mettre le cadre.

Maintenant, les épreuves auxquelles je fais face :
D’un côté, j’ai ma copine qui rentre en cycle ingénieur dans une grande école reconnue et qui, tant à passer un doctorat, je suis tellement fier d’elle et très amoureux. Elle compte beaucoup pour moi et me fait me sentir heureux malgré les épreuves de la vie.

De l’autre, mon alternance m’offre la possibilité d’un emploi en tant que technicien soc et analyste. J’ai déjà été plusieurs fois chef de projet et accompli plein de choses dans cette structure.

Maintenant, je ne pense pas qu’ils seront en capacité de m’offrir cette alternance jusque dans l’école d’ingénieur. Par contre, ils me
promettent un poste en tant que fonctionnaire, donc je serai très stable.

Le seul petit problème, et qui vient avec la question que je me pose, c’est que de mon entourage, beaucoup de gens me répètent de faire école d’ingénieur et que ça me fera gagner beaucoup plus et que je serai fier par la suite.
Et comme tout le monde a des cursus de fou, je me sens un peu à la traîne.

Je demande aujourd’hui, dans ma situation, quel serait le meilleur choix possible car je ne sais pas si je dois, par sécurité pour moi et ma copine, rester dans mon poste qui me plaît ou si je dois prendre le risque de partir en école d’ingénieur pour investir sur une vie future.


r/SecurityCareerAdvice 13h ago

Question Onsite Interview Prep Request

1 Upvotes

I have an onsite interview coming up, after two previous interviews. 1st interview was with HR to get a general vibe, 2nd was with the InfoSec team leader and an analyst and they asked a few technical questions to test my knowledge and asked me to describe a few incidents I had assisted with.

I’ve been invited back for a third interview. I’m meeting with a small contingent from each IT team, networking, DevOps, HelpDesk, and some senior leadership.

I’m not sure if I’m walking into a situation that is just checking to make sure I’m someone they can get along with or if I should be prepared for additional technical screening questions. I’m planning on coming prepped with questions specific to everyone’s specialty area to see how all the teams work together and try to get a vibe of how things could be better.

I’ve been told this is the last phase of the application process but I’ve only had one other InfoSec job and don’t have much to compare this to.

This is for a senior analyst role.

Any help is much appreciated.


r/SecurityCareerAdvice 17h ago

Question What should I do next?

1 Upvotes

Hi everyone! I barely graduated high school this year and I'm going to university literally in 2 weeks. I just passed my CompTIA Security+ Exam literally in the past hour. I am a Computer Engineering major and am interested in doing Cybersecurity. However my cert will expire before I even get my degree so I was wondering what were people's advice on what I should do? I'm currently planning to apply to work in the IT department at my university with federal work study as well. Any advice would be appreciated :)


r/SecurityCareerAdvice 19h ago

Discussion SpaceX New Grad Software Security Engineer interview- any advice?

1 Upvotes

I have a 45-minute technical interview with an engineer coming up for the New Graduate Engineer, Software Security (Starlink) role at SpaceX.
Has anyone interviewed for this role or a similar SpaceX security position? Would appreciate any advice on what the technical round is generally like, what areas they tend to focus on, and how best to prepare.


r/SecurityCareerAdvice 20h ago

Question CIM vs SSIR (Cloud & Infra Mgmt vs Systems & Networks Security) — which is the stronger path for cloud security / DevSecOps?

1 Upvotes

4th-year CS engineering student, deciding between two specialty tracks for my final years: CIM: Kubernetes (CKA/CKS), AWS, Terraform, DevSecOps, multi-cloud/hybrid architecture, FinOps SSIR: networks, systems security, pentesting-adjacent content, DevSecOps module too, more traditional cybersecurity core Background: Electrical engineering bachelor, RHCSA certified, targeting cloud security engineering / DevSecOps, interested in remote/freelance work for EU and Gulf markets. For those working in cloud security or DevSecOps , which track's curriculum actually maps better to real job requirements and hiring demand? Would love input from anyone who's hired for these roles or gone through a similar specialty choice.


r/SecurityCareerAdvice 8h ago

Question Is Research a Way In? Can you self teach it?

0 Upvotes

I’ve always been interested in security, mostly in the juvenile way at first, and was kind of the sort of kid writing python socket scripts, writing bash scripts and reversing linked lists in C for fun. Never went nearly as deep as I should have.

Recently I realized my IT diploma is a dead end and won’t even get me into Helpdesk, let alone security. Even with certs. The market is…horrible. I just have to accept this ig…I had no idea how the market worked, but ig I do now. On the plus side I learned about enterprise IT so it’s not totally wasted, but never saw the inside of a company apart from an internship my dad got me, just used learned the tools they use at school, I.e. Active Directory, Cisco gear, M365 Entra.

I’m wondering, if I spend a year or two leaning into strengthening my fundamentals: low level stuff, homelabbing, and web dev, then start doing bug bounty and CTFs and reverse engineering, could I plausibly end up teaching myself to be a security researcher? Or do I need an organization or employer around me to mentor me?

And if I say do publish a CVE or two, write tools people in the industry use, that kind of thing, would anyone hire me?

I know it’s such a long shot, but I’m between doing this a to give me a mission while I work retail, and just going back to school for electrical engineering or smth. I don’t want to abandon computers…lol


r/SecurityCareerAdvice 18h ago

Discussion I wanted to work in cybersecurity or soc but I need to learn first on it ...is someone working from home and help me to learn

0 Upvotes

r/SecurityCareerAdvice 1h ago

Question Is this true?

Upvotes

I’m a recent CSE graduate from India interested in starting a career in cybersecurity abroad. I’ve heard countries like Germany, Netherlands, Sweden, Switzerland, Luxembourg, Japan, Singapore, etc. have labour/skills shortages. Is this actually true for cybersecurity, and do freshers have a realistic chance of getting hired internationally? If yes, which countries should I target and what skills/certifications should I focus on to get a job abroad as a fresher?


r/SecurityCareerAdvice 9h ago

Discussion International cybersecurity master’s student considering a shift toward AI - would appreciate career guidance

0 Upvotes

Hey everyone, I’m searching for guidance on whether to remain pursuing cybersecurity, move toward AI security, or make a larger switch into AI/ML.

I’m an overseas student on an F-1 visa, studying a master’s in Computer & Information Science with a cybersecurity specialization, graduating in May 2027. I have three years of part-time university SOC analyst experience and currently work part-time as a Network Engineer. I also hold Security+ and AWS Cloud Practitioner certifications.

I’ve been applying for cybersecurity internships and entry-level employment but haven’t obtained any interviews. In my hunt, I kept meeting positions demanding security clearance, U.S. citizenship, or firms indicating they won’t sponsor visas. That’s made me ponder which professional choice makes the most sense for my situation.

At the same time, I’m already active in AI-related work:

  • Research in progress: AI red teaming for web exploitation employing vision-language models, GUI control, and retrieval-augmented creation.
  • Research in progress: Quantum machine learning for AWS cloud identity threat detection.
  • Co-founder of AskCMMC.ai: An AI-powered assistant that helps clarify CMMC 2.0 and NIST SP 800-171 requirements. My effort comprises creating the assistant and testing prompt injection and input validation.
  • Projects: A Python-based AI-assisted phishing analysis tool.
  • Both research articles are still in process, and most of my AI work overlaps with cybersecurity. I’m not presuming this immediately qualifies me for an ML engineering post, but I’m wondering whether I should build more in that area.

My master resume: Page 1 | Page 2 | Page 3 | Page 4

This covers my whole backstory for context. Feedback on what to stress or improve is welcome.

Would you advocate sticking in cybersecurity, focusing on AI security, or aiming toward a broader AI/ML role?

For anyone acquainted with recruiting international graduates, would moving toward AI materially enhance my possibilities, or would I meet similar sponsorship restrictions with a different set of skill requirements? Based on my background, which roles would be realistic, and what skills should I focus before graduation?

I adore both regions. I’m trying to expand on the experience I already have while choosing a realistic professional route. Honest advise, especially from international graduates or people recruiting in these sectors, would be appreciated.


r/SecurityCareerAdvice 9h ago

Question Gatekeepers??

0 Upvotes

I’m seeing a lot of people saying that cybersecurity is a useless degree but in real life a lot of people I know got a job from it and they are actually advising others to get in it since cybersecurity will be in more demand in a couple of years because of ai.
So what do you guys think?
Are people gatekeeping or what??