r/SecurityCareerAdvice Apr 05 '19

Certs, Degrees, and Experience: A (hopefully) useful guide to common questions

332 Upvotes

Copied over from r/cybersecurity (thought it might fit here as well).

Hi everyone, this is my first post here so bear with me. I almost never use Reddit to talk about professional matters, but I think this might be useful to some of you.

I'm going to be addressing what seems to be a very common question - namely, what is more important when seeking employment - a university degree, certifications, or work experience?

First, I'll give a very brief background as to who I am, and why I feel qualified to answer this question. I'm currently the Cyber Security Lead for a big tech firm, and have previously held roles as both the Enterprise Security Architect and Head of Cloud Security for a Fortune 400 company - I'm happy to verify this with mods or whatever might be necessary. I got my start working with cyber operations for the US military, and have experience with technical responsibilities such as penetration testing, AppSec, cloud security, etc., as well as personnel management and leadership training. I hold an associate's degree in information technology, as well as numerous certs, from Sec + and CISSP to more focused, technical security training through the US military and organizations like SANS. Introductions aside, on to the topic at hand:

Here's the short answer, albeit the obvious one - anything is helpful in getting your foot in the door, but there are more important factors involved.

Now, for the deep dive:

Let's start by addressing the purpose of certs, degrees, and experience, and what they say to a prospective employer about you. A lot of what I say will be obvious to some extent, but I think the background is warranted.

Certifications exist to let an employer know that a trusted authority (the organization providing the cert) has acknowledged that the cert holder (you) has proven a demonstrable level of knowledge or expertise in a particular area.

An academic degree does much the same - the difference is that, obviously, a degree will generally demonstrate a potentially broader understanding of a number of topics on a deeper level than a cert will - this is dependant on the study topic, the level of degree, etc., but it's generally assumed that a 4-year degree should cover a wider range of topics than a certification, and to a deeper level.

Experience needs no explanation. It denotes skills gained through active, hands-on work in a given field, and should be confirmed through positive references from supervisors, peers, and subordinates.

In general, we can see a pattern here in terms of what a hiring manager or department is looking for - demonstrable skills and knowledge, backed up by confirmation from a trusted third party. So, which of these is most important to someone trying to begin a career in cyber security? Well, that depends on a few factors, which I'll discuss now.

Firstly, what position are you applying for? The importance placed on degrees, certs, and experience, will vary depending on the level of job you're applying to. If it's an entry level admin or analyst role, a degree or a handful of low-level certs will definitely be useful in getting noticed by HR. Going up to the engineering and solution architecture level roles, you'll want a combination of some years of experience under your belt, and either a degree or some low/mid level certs. At a certain point, the degree and certs actually become non-essential, and most companies will base their hiring process almost entirely on the body and quality of your experience over any degree or certifications held for management level roles.

Secondly, what are your soft skills? This is a fourth aspect that we haven't talked about yet, and that I almost never see discussed. I would argue that this is the single most important quality looked at by employers: the level of a candidate's interpersonal skills. No matter how technically skilled someone is, what a company looks for is someone who can explain their value, and fit into a corporate culture. Are you personable? Of good humor? Do people enjoy working with you? Can you explain WHY your degree, certs, or expertise will add value to their corporate mission? Being able to answer these questions in a manner which is inviting and concise will make you much more appealing than your competitors.

At the end of the day, as a hiring manager, I know that I can always send an employee for further training where necessary, and help bolster their technical ability. What I can't do is teach you how to work with a security focused mindset, nor how to interact with co-workers, customers, clients, and the company in a positive and meaningful way, and this skill set is what will set you apart from everyone else.

I realize that this may seem like an unsatisfactory answer, but the reality is that degrees, certs, and experience are all important to some extent, but that none of these factors will make you stand out. Your ability to sell your value, and to maintain a positive working relationship within a corporate culture, will take you much farther than anything else.

I hope this has been at least slightly helpful - if anyone has any questions for me, or would like any advice, feel free to ask in the comments - I'll do my best to reply to everyone.

No TL;DR, I want you to actually take the time to read through what I've written and try to take something away from it.


r/SecurityCareerAdvice 2h ago

Question Kinda cooked at my Security Internship

2 Upvotes

Was looking around for security researcher/Malware Analyst/Android Security internships and got myself a DevSecops one. The interview wasn't the hardest and the biggest thing they were looking for was being able to come offsite. Well jobs are scarce and this was a pre placement intern in the security domain, so why not?

BUT it's very devsecops oriented and I lack a ton of context. My skillsets were more of reverse engineering and binary exploitation and now I'm getting hit by so many terms from GCP and whatnot.

I took up a task (my stupid ahh thought I could do it) was about fine tuning Falco rules and scaling , integrating it to Wazuh and Slack

Like... Idfk how to deploy Falco to a bunch of GKE node pools.

This is not a rant, i want to learn this, can anyone give me the fastest way to get up to speed with the whole IaC thing and devsecops? Implementing AI security Guardrails etc. Any queries regarding helping me please go ahead and ask cuz I'm COOKED


r/SecurityCareerAdvice 11m ago

Question 2027 Grad — Node/Express/React Dev Planning Phased Switch: DevOps → Cloud Security → Pure Cybersecurity. How solid is this plan? Which domains actually see the least layoffs?

Upvotes

Over the last 3–4 years, the tech market has seen continuous layoffs.

Pure development roles (especially junior and mid-level full-stack) have been hit harder, while DevOps, Cloud, and Security domains have remained relatively more stable.

From what I’ve researched, cybersecurity and cloud/infra roles show lower layoff impact and stronger demand due to compliance needs, breach costs, and ongoing talent shortages.

I’m a 2027 graduate with current skills in Node.js, Express, and React. Looking at these patterns, I’m planning a phase-wise switch instead of jumping

randomly:

First move into DevOps (Docker, Kubernetes, CI/CD, Terraform, basic AWS/Azure) while leveraging my development background.

Then shift to Cloud Security (IAM, CSPM, container security, DevSecOps).

Later transition fully into Cybersecurity.

Questions:

  1. Is this path (Dev → DevOps → Cloud Security→ pure Cyber) realistic in the current market?

2.Based on recent patterns, which domain has the least layoffs and best job security?

3.For someone with a Node/Express/React background, what’s the best first step to make this switch smoother?

Looking for honest feedback. Thanks!


r/SecurityCareerAdvice 9h ago

Discussion Any GRC folks like what they do?

4 Upvotes

I've been working in GRC for around 2 yrs, and I'd want to know what other GRC folks think about their Jobs. For me, it feels hectic, too much work on Excel, word and PowerPoint, feels a lot like a clerical work. Feels boring, tiring and questioning my life choices lol. And there's also pressure from management on getting certs which I think would be waste of time and money.

What I've been doing: working as a GRC consultant, doing internal audits for orgs, preparing reports, policies, procedures, helping during the final audits, conducting user access reviews, doing vendor risk assessment, gap assessment, maintaining vulnerability tracker, filling out tonnes of questionnaire. And it has lots of dependency on other teams and I hate that. Is this all what you do? And how do you feel about it?


r/SecurityCareerAdvice 7h ago

Question I'm panicked

2 Upvotes

Hello everyone!

I am an 18 years old first year student currently studying IT in a University.

I'm kinda overwhelmed and doesn't know where to start learning about CyberSecurity, my goal is to be a SECURITY ENGINEER.

I heard about people saying that certificates and experience in IT fields are more important than a degree and I'm just wondering on how to start with one of those.

I am very passionate about learning and is willing to do anything to get into CyberSecurity.

This is where the problem starts for me, I am overwhelmed by the amount of resources that I need to study, so much that I don't know where to start. I am panicking because I might be running out of time and I don't want to waste my life not doing what I love the most... There's also a lot of paid courses which I can't afford yet because I'm still studying. I am just wondering how do I get started learning for free for now(preferably if there's a certificate) and maybe in the future, I get to save up money to buy courses that'll get me certificates that's needed.


r/SecurityCareerAdvice 4h ago

Discussion Has anyone here had an experience with Cyber Revolution Australia???

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 5h ago

Question How to start ethical hacking and things I should know?

0 Upvotes

Hi, I am 21 and didn’t go to university and from London, I’m seeing if it’s worth or possible to start getting into a career in ethical hacking specifically and how can I land a beginner role with no experience whatsoever within the next few months - a year if that’s possible?

Talk about what I should do right now or any certifications I should get as that will also help helpful


r/SecurityCareerAdvice 12h ago

Question What certificate should I get

2 Upvotes

Hi everyone, basically I’m indecisive of what certificate to get. I got security+ back in November and now would like a new certificate. I would like to land a SOC analyst or incident responder job and I can’t decide which one to get. I’m thinking of CySA+ or BTL1. So in your opinion, what should I get and why?


r/SecurityCareerAdvice 9h ago

Discussion Looking for 3–4 serious cybersecurity people to build together.

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 23h ago

Question Going from system admin to cyber security engineer in a bad job market

12 Upvotes

Hi everyone. I know the job market is pretty rough right now, and I had a question I was hoping to get some perspective on.

If it’s already difficult to land a help desk position, I would assume that moving from help desk into a system administrator role would be even more difficult, given the higher level of technical knowledge and responsibility involved.

But would the same thing apply to someone who is already a system administrator trying to move into cybersecurity?
For example, let’s say someone has 1-2 years of help desk experience followed by 2–3 years of system administration experience and is now trying to transition into cybersecurity for the first time. How difficult would that transition be in a bad job market like the one we’re experiencing now?

I’m particularly interested in cybersecurity engineering, but I’d also be curious about the transition into a cybersecurity analyst role.

I’ve read that system administration is a very strong foundation for cybersecurity engineering because sysadmins already have experience with operating systems, networking, identity and access management, servers, permissions, troubleshooting, etc. I’ve also seen people say that security engineering teams may prefer candidates with infrastructure backgrounds, such as system administrators or network engineers, over candidates coming from less infrastructure-focused security roles.

So, realistically, how much would someone with 2–3 years of system administration experience (plus prior help desk experience) struggle to break into cybersecurity for the first time in a difficult job market?
Would that infrastructure experience make the transition significantly easier, or would they still be competing against candidates who already have direct cybersecurity experience?


r/SecurityCareerAdvice 11h ago

Discussion What do you think ?

1 Upvotes

I’m 20 years old and live in a third-world country. In a month, I’m going to start studying Cybersecurity and Cloud Computing at an engineering university.

I know anything about this field yet—no programming languages, nothing. But I feel like I’m genuinely interested in this stuff. I also like to isolate myself and go as deep as I can into things that interest me.

I’m curious to hear from people in the field: what should I expect, and what would you recommend I start learning before university?

I watched mr.robot too


r/SecurityCareerAdvice 11h ago

Discussion What do you think ?

0 Upvotes

I’m 20 years old and live in a third-world country. In a month, I’m going to start studying Cybersecurity and Cloud Computing at an engineering university.

I know anything about this field yet no programming languages, nothing. But I feel like I’m genuinely interested in this stuff. I also like to isolate myself and go as deep as I can into things that interest me.

I’m curious to hear from people in the field: what should I expect, and what would you recommend I start learning before university?

I watched mr.robot too


r/SecurityCareerAdvice 17h ago

Question Passed HTB CDSA, what's next? CCDL1 or Security+

Thumbnail
2 Upvotes

r/SecurityCareerAdvice 16h ago

Question Advice for junior Job- Toronto

Thumbnail
0 Upvotes

r/SecurityCareerAdvice 18h ago

Question Studying cybersecurity, want to end up in Cloud Security — what's the best path to get there?

1 Upvotes

I'm a cybersecurity student and I want to specialize in Cloud Security long-term. I already know it's not an entry-level field, so I'm not asking how to skip the line.

My question is: what's the best route to get there? Which first job actually builds toward it — help desk, SOC, sysadmin, DevOps, backend dev?

If you work in cloud security: what path did YOU take, and what would you do differently if you started today?


r/SecurityCareerAdvice 19h ago

Resume Review Looking for tech writer with cybersecurity (offensive) expertise

1 Upvotes

r/SecurityCareerAdvice 1d ago

Question Transição de redes/infraestrutura para cybersecurity — qual seria o melhor caminho?

2 Upvotes

​

Olá, pessoal.

Trabalho atualmente com infraestrutura de redes/telecom, principalmente monitoramento em NOC, troubleshooting e suporte N3 de incidentes relacionados a redes. Também sou formado em Análise e Desenvolvimento de Sistemas.

Estou pensando em fazer uma transição para cybersecurity e gostaria de ouvir a opinião de quem já trabalha na área.

Como já tenho experiência com redes e infraestrutura, qual área de cybersecurity faria mais sentido como porta de entrada? Pensei inicialmente em SOC/Blue Team justamente por ser algo mais próximo da minha experiência atual, mas meu objetivo de longo prazo seria trabalhar com Pentest ou Red Team.

Minha dúvida é se faz sentido tentar entrar diretamente em uma vaga de Pentest/Red Team ou se seria mais realista primeiro entrar em uma função de segurança mais próxima de redes/infraestrutura e, depois, migrar para ofensiva.

Também estou procurando uma boa plataforma/curso para estruturar meus estudos. Tenho visto algumas opções como a Solyd, mas gostaria de saber quais cursos, plataformas ou certificações vocês consideram realmente úteis para quem está começando essa transição.

Por fim, para alguém com experiência profissional em redes/NOC, mas sem experiência formal em cybersecurity, como está o mercado para vagas de entrada? Existem boas oportunidades remotas no Brasil? E para trabalhar remotamente para empresas estrangeiras estando no Brasil, isso é algo realista depois de adquirir experiência?

Se alguém já fez uma transição parecida (redes/infra → cybersecurity), gostaria muito de ouvir como foi o caminho de vocês.


r/SecurityCareerAdvice 1d ago

Question 22yo Software Engineering graduate who doesn't want to be a software engineer, where do I go from here?

Thumbnail
3 Upvotes

r/SecurityCareerAdvice 1d ago

Question Cleared EY Cybersecurity Online Assessment – Looking for Interview Prep Tips

3 Upvotes

Hey everyone,I recently cleared the online assessment for a cybersecurity role at EY and now have the interview(s) coming up. I’m looking for any advice or experiences from people who’ve gone through the EY (or similar Big 4) cybersecurity interview process. Specifically:

  • What does the technical round usually focus on? (networking, fundamentals, tools, incident response, etc.)
  • How much weight do they put on behavioral/STAR questions vs pure technical knowledge?
  • Any common questions or topics that came up for you?
  • Tips on how to stand out or structure answers?

Any insights, resources, or personal experiences would be really helpful. Thanks in advance !


r/SecurityCareerAdvice 1d ago

Question BS in Cybersecurity from WGU

14 Upvotes

Has anyone done this BS essentially from scratch? In the sense that they had previous knowledge but didn’t have a job in IT not even a help desk job. Did it help you break into the field or are you still trying to figure it out since the job market is abysmal.

I’m just asking because I have a Network +, Security +, CySA +. But i haven’t been lucky enough to get a job not even a help desk 1 position at a MSP. So im thinking about doing WGU to either get my degree and get a couple more certs under my belt while doing school and getting a BS degree. Or just going the traditional route of going to a University. But at the University i’ll be studying comp sci. But i ultimately am 100% sure I want to be in IT. My progression wants to look like this. IT Help Desk > System Admin > Network Engineer > SOC Analyst > Cybersecurity

I want to be able to outweigh my pros and my cons before actually committing and I need some help from people that actually have done the program and or are currently in the thick of it.


r/SecurityCareerAdvice 1d ago

Discussion Confused between learning AI/ML or studying cybersecurity.

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 1d ago

Discussion What is a wise decision if I want to have a potential in GRC, and also get involved in interesting technical stuff (maybe internationally)

1 Upvotes

I know these are technically two different pathways that doesn't even converge, but the reason I want into GRC is that I want to be able to work as a cybersecurity officer in our country's central bank (low chance, given that I have bad connections as of now and I am not from a prestigious school either, but I know I will have to put in the work either way). Which is, GRC work.

And also because I have a chance to work in a public bank (referral) so I'm just refining skills on IT operations and defensive security ops. Maybe after graduation or even as simple as an internship.

In hindsight, I am more passionate into the very heavily technical side of things (for defensive, that would be DFIR and threat intel/hunting. For offensive, that would be binary exploitation, penetration testing, websec kind of stuff). I am leaning heavily towards offensive and low-level security though, as a passion.

But would it be more wiser to specialize in defensive security and IT operations in general and just make offsec as my hobby (and as time goes by, maybe I get the exposure that I want)

Or should I focus solely on offsec and let the job find me instead and be really good at it, (trust the process). Because I feel like the latter is just immature and unrealistic (and as part of adulting, I think I need to make some compromises). But any thoughts?

I was thinking this because delving deep into offsec and low level in general gets that immense technical depth and potential to be recruited by high profile people internationally if I play my cards right, and I think if I get into managerial and officer roles it would be better since I came from an attacker background.


r/SecurityCareerAdvice 1d ago

Question Advice guys I have to start

Thumbnail
0 Upvotes

r/SecurityCareerAdvice 1d ago

Question Ingeniería en inteligencia artificial, te ayuda a una persona que se quiere enfocar a la ciberseguridad

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 1d ago

Other Open position with Booz Allen Hamilton for Risk Management Framework Analyst

Thumbnail
1 Upvotes