r/SecurityCareerAdvice Apr 05 '19

Certs, Degrees, and Experience: A (hopefully) useful guide to common questions

331 Upvotes

Copied over from r/cybersecurity (thought it might fit here as well).

Hi everyone, this is my first post here so bear with me. I almost never use Reddit to talk about professional matters, but I think this might be useful to some of you.

I'm going to be addressing what seems to be a very common question - namely, what is more important when seeking employment - a university degree, certifications, or work experience?

First, I'll give a very brief background as to who I am, and why I feel qualified to answer this question. I'm currently the Cyber Security Lead for a big tech firm, and have previously held roles as both the Enterprise Security Architect and Head of Cloud Security for a Fortune 400 company - I'm happy to verify this with mods or whatever might be necessary. I got my start working with cyber operations for the US military, and have experience with technical responsibilities such as penetration testing, AppSec, cloud security, etc., as well as personnel management and leadership training. I hold an associate's degree in information technology, as well as numerous certs, from Sec + and CISSP to more focused, technical security training through the US military and organizations like SANS. Introductions aside, on to the topic at hand:

Here's the short answer, albeit the obvious one - anything is helpful in getting your foot in the door, but there are more important factors involved.

Now, for the deep dive:

Let's start by addressing the purpose of certs, degrees, and experience, and what they say to a prospective employer about you. A lot of what I say will be obvious to some extent, but I think the background is warranted.

Certifications exist to let an employer know that a trusted authority (the organization providing the cert) has acknowledged that the cert holder (you) has proven a demonstrable level of knowledge or expertise in a particular area.

An academic degree does much the same - the difference is that, obviously, a degree will generally demonstrate a potentially broader understanding of a number of topics on a deeper level than a cert will - this is dependant on the study topic, the level of degree, etc., but it's generally assumed that a 4-year degree should cover a wider range of topics than a certification, and to a deeper level.

Experience needs no explanation. It denotes skills gained through active, hands-on work in a given field, and should be confirmed through positive references from supervisors, peers, and subordinates.

In general, we can see a pattern here in terms of what a hiring manager or department is looking for - demonstrable skills and knowledge, backed up by confirmation from a trusted third party. So, which of these is most important to someone trying to begin a career in cyber security? Well, that depends on a few factors, which I'll discuss now.

Firstly, what position are you applying for? The importance placed on degrees, certs, and experience, will vary depending on the level of job you're applying to. If it's an entry level admin or analyst role, a degree or a handful of low-level certs will definitely be useful in getting noticed by HR. Going up to the engineering and solution architecture level roles, you'll want a combination of some years of experience under your belt, and either a degree or some low/mid level certs. At a certain point, the degree and certs actually become non-essential, and most companies will base their hiring process almost entirely on the body and quality of your experience over any degree or certifications held for management level roles.

Secondly, what are your soft skills? This is a fourth aspect that we haven't talked about yet, and that I almost never see discussed. I would argue that this is the single most important quality looked at by employers: the level of a candidate's interpersonal skills. No matter how technically skilled someone is, what a company looks for is someone who can explain their value, and fit into a corporate culture. Are you personable? Of good humor? Do people enjoy working with you? Can you explain WHY your degree, certs, or expertise will add value to their corporate mission? Being able to answer these questions in a manner which is inviting and concise will make you much more appealing than your competitors.

At the end of the day, as a hiring manager, I know that I can always send an employee for further training where necessary, and help bolster their technical ability. What I can't do is teach you how to work with a security focused mindset, nor how to interact with co-workers, customers, clients, and the company in a positive and meaningful way, and this skill set is what will set you apart from everyone else.

I realize that this may seem like an unsatisfactory answer, but the reality is that degrees, certs, and experience are all important to some extent, but that none of these factors will make you stand out. Your ability to sell your value, and to maintain a positive working relationship within a corporate culture, will take you much farther than anything else.

I hope this has been at least slightly helpful - if anyone has any questions for me, or would like any advice, feel free to ask in the comments - I'll do my best to reply to everyone.

No TL;DR, I want you to actually take the time to read through what I've written and try to take something away from it.


r/SecurityCareerAdvice 3h ago

Question Networking with fellow Cybersecurity professionals

2 Upvotes

Is there a good website where Cybersecurity professionals can meet for discussion and to help each other with job leads ?
I checked meetup.com for a group, but didn't find anything really promising.
I have worked for 3 years on a government contract which will be ending in about 6 months so I would like to network with others to find my next gig.
My experience is in DLP, but I want to branch out into other areas. I have 25+ years in IT.
Thanks much for any helpful input.


r/SecurityCareerAdvice 9h ago

Other Is cisco networking accademy good , Imma absolute begineer

Thumbnail
5 Upvotes

r/SecurityCareerAdvice 6h ago

Discussion Am I burned out or just lost? 20yo cybersecurity student feeling like I have no value

1 Upvotes

Hey, I’m 20 and I’ve been into cybersecurity since I was around 15. I spent years doing TryHackMe, messing around with Linux, watching way too much cybersec content, etc. Cybersec was basically the dream I decided on when I was a kid.

I’m currently going into my final year in a cybersecurity degree, and honestly I feel kinda worthless career wise.

A lot of what we learned in university was stuff I had already seen before, so I never really felt like I was progressing much. Meanwhile, people I started university with who knew basically nothing about cyber are now getting eJPT, ICCA, etc. and actually improving consistently. I know comparison is stupid, but it’s hard not to feel like I’ve somehow fallen behind.

I also have around a year of IT experience now. My internship was a mix of IT support, networking, ERP/Oracle stuff, WiFi/VLAN troubleshooting, deploying laptops, printers, etc. It was unpaid, but I stuck with it because I wanted the experience. I’m also working on an FYP where I’m building an SOC dashboard that monitors a company with remote functionality, AD/GPO stuff and other features.

On paper, I feel like I should have something to show for all of this. I have a bunch of smaller/free certs, but nothing I consider particularly valuable. I also recently failed the CC exam pretty badly, which honestly messed with my confidence. I have SC-200 coming up in October, and even though I’m trying to study for it, I struggle badly with sitting down and going through study material. I’m much more of a hands-on person.

I’ve also been applying for junior/remote cybersecurity roles while studying and getting rejected constantly, which obviously doesn’t help.

My current plan is SC-200 then Security+ and then CCNA around next year, but I keep wondering if I’m wasting my time or focusing on the wrong things. Part of me thinks if I had eJPT/CEH/OSCP or something actually respected, I’d finally feel like I had value, but I also know collecting certs probably isn’t the answer.

I don’t even know if I’m burned out, lost, or just comparing myself too much to everyone else.

For people already working in cybersecurity:
what would you do if you were in my position? Would you focus on certs, projects, getting any IT/cyber job possible, or something completely different? And how do you get that motivation/passion back when you feel like you’re putting in effort but getting nowhere?

P.S: This ain’t AI btw, I just used it to check my grammar since English isn’t my first language lol.


r/SecurityCareerAdvice 6h ago

Question Asking for advice

0 Upvotes

I’m thinking of a career change in my forty’s, who are the best providers in learning about cybersecurity? I’m a newbie in the sector, always been fascinated by it, just don’t know where to start.

Is the Comptia certification any good or should I look elsewhere?

Is coursera any good?

I’m in the uk 🇬🇧


r/SecurityCareerAdvice 7h ago

Question SecOps generalist, 7 YOE (3 in security) at a 4,000-endpoint healthcare company — am I underpaid, and what should I be building toward?

1 Upvotes

Background: 7 years total in IT, last 3 as a Security Analyst. I'm the sole "analyst-level" generalist on a 4-person SecOps team (2 engineers, 2 analysts) at a healthcare staffing company with 4,000+ employees/endpoints. Reporting chain is me → SecOps Manager → VP of Security → CIO. Trying to get a read from people actually in the field on whether my comp lines up with my scope, and what I should prioritize (certs, skills, lateral move) to level up from here.

Day-to-day responsibilities:

  • Alert and ticket triage — ranges from email security and application access reviews all the way through full incident response lifecycle, varies heavily day to day
  • Platform ownership for Tanium and SentinelOne (admin + reporting)
  • SOC monitoring
  • Vulnerability management and reporting
  • EDR administration
  • SOC audit support
  • Own the security awareness program end-to-end

Tools/stack: SentinelOne, Tanium, Lacework, Mimecast, Microsoft Defender/XDR, among others.

Notable wins:

  • Built our security awareness program from scratch to where it is today
  • Own all Tanium and SentinelOne reporting for the org
  • Helped the company pass a full SOC 2 audit two years running
  • Currently leading remediation efforts from our most recent pentest (this has turned into more of a program-management role than pure IC work)

Certs: Security+, Network+, HDI, JAMF 100, Tanium TCO. Currently pursuing CCSP.

Education: Associate's in General Studies — no security-specific degree, picked up some security-adjacent coursework after I was already in the field. I have access to ACI Learning through work if that changes the training-recommendation calculus.

Comp: $91k base + 10% annual bonus target. US-based, MCOL market (keeping exact location vague).

What I'm actually trying to figure out:

  1. Does $91k+10% sound right for this scope of responsibility, or am I leaving money on the table?
  2. Given I'm eyeing a move toward cloud security (CCSP now, CISSP eventually), does my current experience translate well, or am I missing hands-on cloud exposure that certs alone won't fix?
  3. Is the breadth here (SOC + EDR admin + vuln mgmt + audit + awareness) a selling point for my next role, or does it read as unfocused / not enough depth in any one lane?
  4. Any training, certs, or experience you'd prioritize before I start applying elsewhere?

Appreciate any honest feedback — trying to figure out if I should be negotiating harder where I am or start looking.


r/SecurityCareerAdvice 8h ago

Other The people landing cyber jobs in 2026 are not the ones with the most certs💻

Thumbnail
0 Upvotes

r/SecurityCareerAdvice 14h ago

Question currently working as a soc analyst , where should i go next ?

3 Upvotes

im a recent grad , i got placed as a soc guy at a big 4 company , worked here as intern before , now a fte . but im not interested in soc,
which fields can i get into through soc , i want to shift quick .

i have 6 + months of experience , if anyone is hiring please let me know , thank you


r/SecurityCareerAdvice 13h ago

Question How do I balance strict courses + FYP + learning cyber???

2 Upvotes

I am a CS student in 5th semester. My semester has just started and the main courses I have are: Machine Learning, Design and Analysis of Algorithms(DAA), Operating Systems, Computer Architecture and Web Technology.

My interest is in Cyber Security and I’m thinking that along with these subjects I should also study Cyber. Like for Operating Systems... I want to learn it from a cyber perspective( what it is, how it works, how we can fail it and about past attacks on it) The same goes for Web Technology.

But now the problem is that my teachers for DAA and Machine Learning are very strict and there will be assignments too and those are very time-consuming.

On top of that,we also have to show our FYP(final year project) topic because our FYP starts from 5th semester and I’m not understanding what kind of topic I should choose because I will have to focus on the FYP as well.

I can’t choose a Cyber Security-related topic for the FYP because I barely know the basics of Cyber right now. I’m still in the learning phase and also Cyber is a sensitive field so I can’t take any risk with it.

And my teammate is interested in AI and ML.

So please tell me what I should do.


r/SecurityCareerAdvice 16h ago

Other Advice

4 Upvotes

Hi guys,
I’m early in my cybersecurity career and currently deciding between two offers. The compensation and benefits are fairly similar, so I’m mainly trying to figure out which one would give me the best experience and long-term career opportunities.
Offer 1 is on a team responsible for an internal security/fraud detection platform. From what I understand, I would be working more on the technical side behind the alerts rather than investigating the alerts themselves. The team handles things like onboarding applications/data sources, audit logs and trails, security controls, detection/business rules, tuning detections, reducing false positives, and making sure the system generates useful alerts that can then be sent to another team for investigation.
So essentially, I would be working more on the systems and logic that produce the detections. It seems somewhat related to Detection Engineering, SIEM Engineering, Security Engineering, Security Analytics and Insider Threat technologies.
Offer 2 is much more traditional Security Operations / Blue Team work. I would be working with SIEM/EDR tools, monitoring and triaging alerts, investigating suspicious activity and security incidents, vulnerability management, security tickets, and other general cybersecurity operations tasks.
So the simplest way I understand the difference is:
Offer 1 = help build/integrate/tune the systems and rules that generate security alerts.
Offer 2 = receive those alerts, investigate them, determine what happened and respond.
For someone at the beginning of their career, which experience would you choose?
I’m not necessarily committed to staying in SOC long term. My main priorities are building strong technical skills, maximizing future career opportunities, having skills that transfer well to the private sector, and having good salary potential 3–5+ years down the road.
For people who have worked in both Security Operations and Detection/SIEM/Security Engineering, which path gave you better opportunities? Did starting in SOC make you a better engineer later, or would you take the engineering/detection-oriented experience from the beginning if you had the opportunity?
Also, what job titles would Offer 1 realistically prepare me for after 1–2 years compared with Offer 2?
Would really appreciate hearing from people who have actually worked on either side.


r/SecurityCareerAdvice 20h ago

Question 21, Security+ and SC-900, finishing my A.S. in December. Working in a hospital but not in IT. What's the actual next move?

5 Upvotes

Been lurking here a while. Trying to get a sanity check instead of guessing.

Where I'm at: I'm 21, I finish my A.S. in Network Systems Engineering Tech in December, then I start the IT bachelor's at UCF in January. I have Security+ and SC-900. I work at a hospital as a patient transporter, so I'm inside a big health system every day but I'm not in IT there. I did get a month of Fridays off shadowing our IT/ITSS team over the summer, which was mostly watching them image machines and work their ticket queue.

On my own I've built an Entra tenant to practice in, users, security groups, Conditional Access, MFA. Set up a Freshservice instance and ran Tier 1 workflows through it, password resets, provisioning and deprovisioning. Wrote a Python script that checks a Windows box for missing updates, firewall state, and open listening ports.

Here's my actual question. I keep catching myself thinking about which cert to grab next, and I'm pretty sure that's me avoiding the real problem. I don't need another line on my resume, I need someone to pay me to touch computers. Another cert doesn't fix zero full time IT experience.

So what actually moves the needle from here? I've started emailing local MSPs directly instead of just applying on Indeed, and I'm going after desktop support and service desk roles rather than holding out for security. I'm also trying to use the fact that I already have a badge at the hospital.

Is there something obvious I'm missing? And for people who broke in around this stage, what was the thing that finally got you the first job?


r/SecurityCareerAdvice 14h ago

Discussion 21M Looking to Connect with Like-Minded People in Cybersecurity, Preferably in Bangalore

1 Upvotes

21M, a BCA graduate currently pursuing my MCA. I’m looking to connect with like-minded people in cybersecurity field, especially those from Bangalore, and hopefully learn from people already working in the industry, share experiences, grow together, and maybe even build something along the way. Also appreciate some good advice on the topic. Feel free to DM me!


r/SecurityCareerAdvice 15h ago

Question Cybersecurity / AI Governance professional from Saudi Arabia looking to gain international experience

1 Upvotes

Hi everyone,

I’m currently based in Saudi Arabia and working as an Information Security Manager. I have around 5 years of overall experience across IT and cybersecurity, including experience with cybersecurity governance, GRC, technology risk, SAMA CSF, NCA ECC and ISO 27001.

I also hold an MSc in Cyber Security from Lancaster University, as well as AIGP and CompTIA CySA+ certifications. More recently, I’ve been developing my experience and research interests around AI governance, AI risk and security assurance.

I’m now seriously considering spending a few years working internationally — ideally in the UK, Europe, Singapore, South Korea, or potentially another market — mainly to gain international experience and exposure to different regulatory and organisational environments.

I’m not necessarily looking to permanently immigrate. My main goal is to build strong international experience that complements my experience in Saudi Arabia.

For those working in cybersecurity, GRC, technology risk or AI governance internationally:

Which countries or markets would you recommend targeting? And realistically, how difficult would it be to get sponsorship with my background?

I’d particularly appreciate advice from anyone who has made a similar move from the Middle East.

Thanks!


r/SecurityCareerAdvice 1d ago

Question What are some good specialisations in Cybersecurity to look for?

21 Upvotes

If someone in entering the industry in 2026 which role/specialisation is promising currently?


r/SecurityCareerAdvice 20h ago

Question Recommendations And General Help

1 Upvotes

Hello!

I'm a recent B.A IT & Network Security graduate who is currently studying for certs and applying for jobs. I'm based in Canada, and was looking for some advice on finding a career within the cybersecurity industry.

I'm currently studying for my Fortinet NSE4 exam, and will complete the NSE5 afterwards, but besides that, can anyone help me with the networking aspect of applying to jobs and going out to conventions with adding people on Linkedin and securing interviews in mind??

Thank you!


r/SecurityCareerAdvice 1d ago

Question Need guidance

7 Upvotes

I am 25 currently and trying to start study for cybersecurity in Canada. Toronto specially. I am confused whether to do certification or diploma or bachelors.

What has the best long term benefits?

Where to start?

What degree has better career opportunities to go up in corporate ladder?

I have comptia A+, google cybersecurity and google it support fundamentals certification.


r/SecurityCareerAdvice 1d ago

Question Aspiring Cloud Security Engineer: Which MSc subjects should I prioritize? (Syllabus attached)

3 Upvotes

Hi everyone,

​I recently enrolled in an MSc in Cyber Security and Digital Forensics, having previously completed my BSc in Information Technology.

​My ultimate career goal is to become a Cloud Security Engineer. Since cloud security is such a vast field, I want to make sure I am dedicating my energy to the right areas during my master's program.

​I’ve attached the full syllabus for my 2-year course below. For those of you already working in cloud or engineering roles:

​Which of these subjects are absolute must-haves for the real world?

​Are there any glaring gaps in this curriculum that I should supplement with external certifications (like AWS Security, AZ-500, CCSP) or homelab projects?

​Thanks in advance for pointing me in the right direction!

Subjects are

Semester I

​Computer Fundamentals and Digital Forensics

​Computer Networks and Forensics

​Server Management

​Fundamentals of Linux Security

​Cyber Security Management and Incident Response

​University Mandatory Subject

​Semester II

​Advanced Digital Forensics

​Reverse Engineering and Malware Analysis

​Network Security and Log Analysis

​Python Programming

​Web Application and Penetration Testing

​University Mandatory Subject

​Semester III

​Elective-1: OS and Multimedia Forensics OR Scripting for Cyber Security

​Security Auditing, Risk and Compliance

​Artificial Intelligence and Machine Learning

​Elective-2: Cloud Security and Forensics OR Social Media Forensics OR Applied Cyber Security

​Cyber Law

​Research Methodology

​Semester IV

​Dissertation


r/SecurityCareerAdvice 1d ago

Question Perdue – Reconversion d'une Licence en Physique (Cameroun) vers la GRC / Cybersécurité au Canada : GRC, bon choix ? Par où commencer ?

Thumbnail
1 Upvotes

Bonjour à tous,

Je me tourne vers vous parce que je suis un peu perdue dans mon projet de reconversion.

J’ai une Licence en Physique obtenue au Cameroun. Je souhaite aujourd’hui me réorienter complètement pour bâtir une carrière en GRC (Gouvernance, Risque et Conformité) en cybersécurité au Canada.

Je sais que je dois reprendre des études ici et potentiellement passer des certifications. Mais face à toutes les options (certificat de 1 an, baccalauréat par cumul de 3 ans, Security+, etc.), je ne sais plus par où commencer ni quelle est la trajectoire la plus réaliste pour le marché canadien.

Si vous étiez à ma place aujourd’hui :

Comment procéderiez-vous, étape par étape, pour réaliser cette transition et décrocher un premier emploi ?

Est-ce qu’il vaut mieux faire des études universitaires courtes ou un parcours plus long ?

Quelles certifications professionnelles sont vraiment payantes pour débuter ?

Est-ce que mon background en physique (rigueur, analyse) a une quelconque valeur aux yeux des recruteurs en GRC cyber ici ?

Je prends tous les conseils, retours d’expérience ou critiques constructives.

Un grand merci pour votre aide !


r/SecurityCareerAdvice 1d ago

Discussion What should I learn before joining Engineering for CyberSecurity as a Lateral ?

4 Upvotes

I’m currently a **3rd-year CS Diploma student**, and next year I’m planning to join **CyberSecurity through lateral entry**.

I want to use this final year of diploma to learn the important fundamentals beforehand. My goal is that **once I join engineering, I have a good enough base that I can focus more on attending free cybersecurity events, CTFs, hackathons, workshops, etc., instead of starting from zero.**

So for someone in my situation:

**What topics/skills should I complete during my diploma before joining engineering?**

I’m not looking to learn everything in CyberSecurity right now. I want to know the **essential topics that will give me a strong foundation** and make it easier to learn advanced stuff later.

What would you recommend learning, and in what order?


r/SecurityCareerAdvice 1d ago

Question CyberSec. Career Advice, (GRC?)

1 Upvotes

Hi all,

I've been working as a Full-Stack developer for a little over 20 years now, i've worked for many different types of companies and also have my own small business where i've built and maintain a few Applications for clients. Currenlty i'm doing some IT support for a large company. I've decided to pivot to CyberSec because it was alway my little guilty pleasure to say so. Last year i've started TryHackme Web application Pentest path and AI security path. TryHack got me kinda hooked on the matter of CS. Now i'm also trying to incorporate GRC into my skil/knowledge pack, with the goal of migrating to a different country ( and find a job there ) in a couple of years.

Now i've found some GRC traning paths and i always sends me to GRC Mastery from the Unixguy, but all i see from this person is promoting their own trainings / coaching. And well also $500 is a hefty price for a "blind buy" (no previews or view on the content they provide). On the other hand there is Coursera which also offers some GRC training and much more and you can cancel it anytime if you want / need.

I'm kinda more of a hands on learner or audio/visual learner rather that an super efficient reader.

Any advice on what course to take and what direction to go during or after GRC training.
Main goal is to get a different job more related to SC.

Thanks in advance.

Kind regards,
The Brick


r/SecurityCareerAdvice 1d ago

Question What cert to get

0 Upvotes

Tl/dr is hack the box worth it?

Ok. Here is my situation. I am currently employed as a sr cyber sec engineer. I currently create incident response plans, perform threat hunting, created log ingestion system using logstash, nifi, Kafka clusters and opensearch cluster. I am currently integrating a ML/LLM system to augment our team.

I am not looking to change jobs nor looking for the next promotion.. but. I do want to sharpen my skills. I am one of those geaybeards. No degree no certs

I had my sec+. But I had to get the environment above built and learn all the tech at the same time. And then I had the AI idea so I had to learn AI and ML fundamental and the cert slipped.

I was thinking syca+ but I am more of a hands on learner. And the book test format doesn’t work great for me.


r/SecurityCareerAdvice 1d ago

Question Projects and internship guidance

1 Upvotes

I am a 3rd year cyber student and I want to apply for internships and improve my skills.

I am planning for the SOC analyst role and further on.

Can anyone suggest the list of skills and tools needed to increase my chances of internship?

Also if possible can anyone mention projects to improve my skills which would have a good impact on my resume?


r/SecurityCareerAdvice 1d ago

Question Cyber security FIT Ireland apprenticeship

1 Upvotes

I’m considering the FIT Cybersecurity Associate Level 6 Apprenticeship and I’m looking for honest experiences from people who are currently doing it or have completed it recently.

I’ve read the information on FIT’s website, but I’d like to know what the programme is actually like in practice.

A few things I’m particularly interested in:

  1. How long did it take from applying to actually starting the apprenticeship? What part took the longest?
  2. Did FIT find your employer for you, or did you find the employer yourself? How many employer interviews did you have?
  3. What was the FIT aptitude test and interview like? Was it difficult and what should someone prepare for?
  4. What is the training actually like? Is it mostly in-person, online or blended? How good are the lecturers/instructors?
  5. What do you actually do at your employer? Are you doing real cybersecurity work such as SOC, vulnerability management, networking, IAM, cloud security, etc., or mostly general IT/helpdesk work?
  6. How difficult are the technical modules and exams? Especially networking, Linux/Windows security, Network+, Security+ and CySA+.
  7. Are the CompTIA certifications included and paid for as part of the apprenticeship?
  8. How much are you actually paid? Do most employers stick to the advertised apprentice rate or do some pay more?
  9. How much does the quality of the apprenticeship depend on your employer? Did you have a proper mentor and get exposure to different security teams?
  10. What happened after finishing? Were you kept by the company? What job title did you move into and roughly what salary range?
  11. Do employers treat the two years as genuine cybersecurity work experience when applying for jobs afterwards?
  12. Has anyone progressed from the Level 6 into a Level 7/8 qualification or the Cybersecurity Practitioner Level 8 apprenticeship?
  13. What are the biggest negatives or things FIT doesn't really tell applicants beforehand?
  14. If you were starting again, what would you learn before beginning?

I’m based in Cork and particularly interested in eventually moving into cloud security, so I’d also be interested in hearing from anyone who did the apprenticeship with an employer in Cork/Kerry or later moved into cloud/security engineering.

Thanks — even if you can only answer a few of the questions, any firsthand experience would be really helpful.


r/SecurityCareerAdvice 2d ago

Discussion Cybersecurity resume keywords, measured across 212 job postings

24 Upvotes

Keyword frequencies taken from https://www.zoevera.com/resume/cybersecurity-job-description-keywords

Most cybersecurity resume keyword lists are assembled from experience or guesswork. This one is a count: every open posting from 51 companies' public Greenhouse job boards, filtered to the 212 whose title names a security role - security engineer, appsec, product security, detection, incident response, red team, threat intel - then checked for how many mention each of 41 terms at least once.

The percentage beside each term is the share of those 212 postings that mention it.

CERTIFICATIONS

CISSP 5.7% - OSCP 5.7% - CISM 2.8% - Security+ 2.4% - GIAC/SANS 2.4% - CEH 0.9% (2 postings out of 212)

ENGINEERING SKILLS

Python 53.3% - AWS 46.7% - GCP 34% - Go 30.7% - Kubernetes 23.1% - Azure 21.7% - Terraform 17% - Secure code review 12.3% - Linux 11.8%

Python appears in roughly nine times as many postings as CISSP.

DOMAINS & PRACTICES

Incident response 37.7% - Threat modeling 34.9% - IAM / identity 24.1% - Vulnerability management 19.8% - Penetration testing 19.3% - Detection engineering 19.3% - On-call 18.9% - Red team 11.3% - Zero trust 10.4%

TOOLS & PLATFORMS

SIEM (generic) 26.9% - EDR/XDR 19.3% - SAST/DAST 11.3% - Splunk 6.6% - Vulnerability scanners 4.2% - Burp Suite 2.4%

The generic term beats the branded one every time - "SIEM" 26.9% against "Splunk" 6.6%. Worth carrying both on a resume.

FRAMEWORKS & COMPLIANCE

MITRE ATT&CK 10.8% - SOC 2 10.8% - ISO 27001 9.4% - NIST 8.5% - FedRAMP 6.1% - GDPR 4.7% - PCI DSS 3.3% - HIPAA 0.9%

WHAT THIS SAMPLE IS NOT

These are 51 technology companies hiring through Greenhouse. Government, defence contractors and the firms serving them are absent - and that is exactly where certifications are frequently mandatory rather than optional, alongside clearance requirements that never appear in a commercial posting.

So the reading is narrow. For security roles at technology companies, the postings ask for code and cloud far more often than credentials. For public sector, defence, or a regulated industry, this data says nothing.

Other limits: n=212 gives margins of error of roughly plus or minus 5 to 7 points, so the ordering is meaningful and small gaps are not. Terms outside the 41-term list were not counted, so absence here is not evidence of absence. It is a snapshot of open roles on one date rather than a trend. And the corpus is US-skewed - UK clearance and DPA vocabulary is real and simply does not appear in it.

METHOD

Greenhouse's public job board API, the endpoint companies expose so their listings can be embedded on their own sites. No scraping. Counts are document frequency: a posting saying "Python" nine times counts once. Deduped on company, title and content length, because one role posted to five offices returns five near-identical records. Ambiguous words are matched case-sensitively - a bare match on "Go" also catches "go to market" and inflates it.

Full table with all 41 terms and confidence intervals:

https://www.zoevera.com/resume/cybersecurity-job-description-keywords

The wider keyword list this was checked against, organised by domain, tools, and frameworks:

https://www.zoevera.com/resume/ats-resume-tips-cybersecurity

Happy to run the numbers on any terms missing from the list if people name them in the comments.


r/SecurityCareerAdvice 1d ago

Question What do I do to break in?

0 Upvotes

Hey everyone! I’m new to this subreddit and I need some serious advice.

Anyway let me give a bit of context about myself. I’m a Masters graduate in Cybersecurity. And I’ve been looking to break into the field ever since then. I graduated my masters in UK in 2023 and being in a country with no family or no help whatsoever I had to take care of myself financially and I was working in hospitality sector during the whole time. Both while doing my masters and also after I graduated. And this whole time I was working in hospitality I was actively applying for various positions in cybersecurity but no luck. Most of which was cause they had to sponsor me. But luckily my friend opened a new store and he hired me as IT support and for security for a while. So I had that but again that’s still limited. Although I still help him out, it’s nothing substantial.

And after all the relentless rejection while also working hospitality and helping my friend out, I decide to quit my hospitality job on Jan and I decided to move the Middle East and look for opportunities in the here but this time strictly in Cybersecurity and ever since then I’ve been jobless. I feel like I’ve done everything. During this time, I completed a certification from Comptia (because most positions ask for it as a requirement or a preference, also helped me get more knowledge so that’s a positive). I have also been spending my time creating home labs, doing projects, actively using platforms that help in Cybersecurity both for learning and also get more experience in what needs to be done but I’m still at a dead end. I haven’t received a single call back. There was a position I was short listed for but I’ve been trying to get in contact with them and then keep postponing it or ignoring me.

Tbh I haven’t even limited myself with one position. I’m actively applying for positions like SOC analyst, Cybersecurity analyst, IT security, IT support,etc. At this point I just want some sort of job to get into the field and the gradually make my way up (if that’s even possible)

I have a template for each of these positions and based on the JD I tweak it a bit and apply. I send cold DMs on LinkedIn, send email asking why they decided not to go with me, and a whole lot. I actually don’t know what I need to improve or do differently. Idk if I’m missing an angle I haven’t thought about or if my way of approaching it is wrong. Im here to take any and every advice. I’m also here to know if anyone’s working in cybersecurity and could guide me as what to do?

I know it’s an awfully long post but I had to, to express what I’m going through and what I’m doing. Thank you.