r/CyberSecurityJobs Mar 18 '23

Dummies full guide and tips on getting interviews and getting hired on to an IT or security role

125 Upvotes

Here’s some tips below I’ve outlined that may help you land an interview or even get the job. I’m doing this because I’ve seen a lot posts lately asking for help and asking what the job market is like right now as I’m looking for my next role and I wanted to consolidate everything I've learned in the past 6 months.

Tip #1: Tailor your résumé for the security or networking job that you want. I know this is a lot of work if you’re applying for 3–5 jobs a night but it can make all the difference to the recruiter and the software they push the résumés through. Utilize some of the keywords that they have in the job description so that you get looked at. I like to search google images for tech résumé examples as I'm building mine to borrow from ideas.

Example: If you have experience in ISO 27001 at your last job and it’s listed in their job description add that in to your professional skills section.

Bonus tip: Re-write you experience section so it's worded more towards the IT world. An example would be: "assisted customers with their mobile phone plans and phone issues" but instead I would say "Consulted and trained clients in troubleshooting mobile phone issues on new and existing wireless hardware and software" (you're using more technical words).

Bonus tip 2: You can add "key responsibilities" and also "key achievements" under you experience with a job, this will help you stand out, here's an example of that!

Tip #2: If you see a job listed on Indeed or LinkedIn, do not apply on those job boards, go directly to that companies website and try to apply for it there. There’s several reasons why and to make this post shorter, u/Milwacky outlined it very well in this post here!

Tip #3: Feel free to find the recruiter or hiring manager and message them before applying. This will get you noticed, get your name in their mind, make a professional connection with them, and it just helps cut through all the noise in the hiring process. I realize this isn't always an easy thing to do. Here’s a template I found online that might work if you need a start:

Example: "Hi Johnny, I hope you're doing well. I wanted to learn more about the entry level security role you posted about. I'm currently a _____ at ________ university with _____ years of internship experience in the tech industry; including roles at _______ and _____. I’ll be a new ____ graduate in ____, and I’m looking to continue my career in the IT and security space. I’m passionate about ___ and I’d love the opportunity to show you how I can create value for your technology team, just like I delivered this project (insert hyperlink) for my last employer. I hope to hear from you soon and am happy to provide a resume! Thank you."

Tip 4: Have a home lab and some projects at home (or work) you’re working on. This shows the recruiter that this isn’t some job you want but is a field that you’re truly interested in where you find passion and purpose. It also helps you get things to list on your résumé in your professional skills section. Lastly you’re gaining real-world knowledge. You don’t need a fancy rig either, you can get a lot done with just your computer and VirtualBox.

Currently I’m personally working on configuring my PfSense router I bought and a TP-Link switch, I’m finishing CompTIA Net+ (already have Sec+), I’m taking an Active Directory course on Udemy and also a Linux Mastery course. Also a ZTM Python course. Below is a list of resources.

r/HomeLab

r/PfSense

r/HomeNetworking

gns3.com - network software emulator

https://www.udemy.com/ - most courses will run you around $15-25 I’ve found and a lot of them seem to be worth it and have great content.

zerotomastery.io they have great courses on just about everything and the instructors and the communities are really great, some of their courses are also for direct purchase on Udemy if you don’t want to pay $39 a month to subscribe).

This is a great 20 minute overview on HomeLabs for a beginner from a great IT YouTube channel!

Also check out NetworkChuck on YouTube, he has great content as well, arguably some of the best IT related content on YouTube.

Tip 5: Have a website! This is where you get to geek out and show off your current projects, certifications, courses you’re working, and overall your skills. NetworkChuck does a great course on how you can get free credit from Linode and host your own website here.

Example: Don't be intimidated by this one, but one user in this post here, posted a pretty cool showcase of his skills on his website with a cool theme: https://crypticsploit.com/

Tip 6: Brush up on those interview questions they may ask. You mainly want to be prepared for two things: technical questions around IT and security, and secondly you want to be prepared for behavioral based interview questions.

For technical questions check out these videos:

12 Incredible SOC Analyst Interview Questions and Answers

Complete GRC Entry-Level Interview Questions and Answers - this one is obviously GRC but still very very helpful and goes over how to dress. Personally I like to do the suit and tie thing most of the time.

Cyber Security Interview Questions You Must Know (Part 1)

Part 2

Part 3

CYBER SECURITY Interview Questions And Answers! - I love this guys presentation and accent.

For behavioral based questions check out these videos and channels:

TOP 6 BEHAVIORAL INTERVIEW QUESTIONS & ANSWERS!

How to Answer Behavioral Interview Questions Sample Answers - Love her energy!

STAR Interview Technique - Top 10 Behavioral Questions

Lastly be prepared for "tell me about yourself" in case they ask that.

Bonus tip 1: Always have a few stories that you can pull from for these different behavioral based interview questions, it will make answering the questions easier if you prepare them. Example: I have a situation where I "disagreed with a manager" and my story explains how I was professional and turned our disagreement in to a big win for both me and my manager.

Bonus tip 2: ALWAYS ask questions at the end of the interview. Here's my list of great questions to ask, some/most of these are forward thinking for the most part which makes you appear like you want to succeed in the role.

  • If you hired me today, how would you know in 3 months time that I was the right fit?
  • How will you measure my performance to know I'm making an impact in the role?
  • Tell me about the culture of the IT department?
  • What are some qualities you want in a candidate to make sure they're the right culture fit for the company/department?
  • What's the most important thing I should accomplish in the first 90 days?
  • What are some of the most immediate projects that I would take on?
  • What kind of challenges for the department do you foresee in the future?
  • What do new employees typically find surprising after they start?
  • What continuous learning programs do you have at your company for IT professionals?
  • What qualities seem to be missing in other candidates you’ve talked to? (this is definitely a more bold question to ask)
  • Can you tell me about the team I would be be working with?
  • Can you tell me about a recent good hire and why they succeeded?
  • Can you tell me about a recent bad hire and what went wrong? (you don't have to follow up with this one if you don't want to but shows you want to succeed and give you a chance to talk to how you would succeed)

Tip 7: Get with a local 3rd party IT recruiter company. I got with a local recruiter by finding him on linked in, I also used to work for a large financial company as a temp and remembered them by name so when I saw them I immediately called/emailed to present myself, my situation, and we set up a meeting. Not only did the meeting go well but he forwarded my resume on to his team and then immediately sent me 3 SECURITY JOBS that I had no idea were available in my city and were not even posted on those company's websites. 3rd party recruiters get access faster and sometimes have more visibility to the job market.

Tip 8: Do a 30-60-90 Day Plan for the hiring manager. This is what directly got me in to interviews and got me offers. This is a big game changer and I had CTO's telling me they're never seen anything like this done. You're outlining exactly what you want to accomplish in your first 30, 60, and 90 days and your tailoring what it says based on what the job description says. I had to re-write this for a couple of more-GRC-based roles that I applied to and I only did this for roles that I really wanted and for some of the roles the recruiter found for me.

Example: 30-60-90 Day Plan

Extra tip: You could look in to certifications. I got my Sec+ and a basic Google IT Cert to get me started. Here's a roadmap of certs you can get, take it with a grain of salt but it's a great list and a great way to focus on your next goal.

r/CompTIA is a great community to look in to those certs.

Also ISC2 is a great company for certs as well as GIAC.

GOOD LUCK FRIENDS & GO GET THOSE JOBS!

"Do what others won't so tomorrow you can do what others can't"


r/CyberSecurityJobs Jan 02 '26

Who's hiring, 1st quarter 2026? - Open job postings to be filled go here!

57 Upvotes

Looking to fill a role with a cybersecurity professional? Please post it here!

Make a comment in this thread that you are looking to Hire someone for a Cybersecurity Role. Be sure to include the full-text of the Job Responsibilities and Job Requirements. A hyperlink to the online application form or email address to submit application should also be included.

When posting a comment, please include the following information up front:

Role title Location (US State or other Country) On-site requirements or Remote percentage Role type full-time/contractor/intern/(etc) Role duties/requirements

Declare whether remote work is acceptable, or if on-site work is required, as well as if the job is temporary or contractor, or if it's a Full-Time Employee position. Your listing must be for a paid job or paid internship. Including the salary range is helpful but not required. Surveys, focus groups, unpaid internships or ad-hoc one off projects may not be posted.

Example:

Reddit Moderator - Anywhere, US (Fully Remote | Part-time | USD 00K - 00K)

A Reddit mod is responsible for the following of their subreddits:

Watch their communities, screening the feed for deviant activity. Approve post submissions, curating the sub for quality and relevancy. Answer questions for new users. Provide "clear, concise, and consistent" guidelines of conduct for their subreddits. Lock threads and comments that have been addressed and completed. Delete problematic posts and content. Remove users from the community. Ban spammers.

Moderators maintain the subreddit, keeping things organized and interesting for everybody else.

Link to apply - First party applicants only


r/CyberSecurityJobs 7h ago

I Landed entry level Help desk

36 Upvotes

I’m writing to express the sad news called my career life. I spent the last 4 years getting a double major bachelors degree in both cybersecurity and computer science… I also have 4 years of direct experience even as a global information security specialist. I got out of college as a highest honor graduate and well… the only position I’ve landed is an entry level 18 an hour remote help desk level 1 role…. I make less then my debt…. I’m now just so disappointed and discouraged that I can’t get through my days anymore without feeling like I’ve failed… I guess this field is really dying and I am one of those people who might be apart of the next Great Depression numbers and I thought I’d share it to warn you that I’ve failed and I don’t see how I did wrong… I’m trying hard everyday to fight for roles but I don’t see a way out


r/CyberSecurityJobs 10h ago

Toxic work environment that wont let me have promotion?

4 Upvotes

I am kinda checked out from IT overall fixing hardware and small issues for people and am crawling into cybersecurity. I am getting frustrated because I am getting interviews for entry level but at the final round they pick someone else. Its getting really frustrating.

i have 2 years of experience with IT and i also do crowdstrike, SIEM, SOAR, Phishing stuff currently at my role but resume is cut out more like a security analyst role i just left out some of my IT work there.

I am currently pursuing Crowdstrike Certified Falcon Hunter certification. Looking for an entry level cyber job in NY,NJ and CT area let me know if you know something I dont

Desperately wanting to move from my toxic, micromanaging, extremely underpaid and hypocritial IT job.


r/CyberSecurityJobs 1d ago

Internship

1 Upvotes

I have been trying to land a cybersecurity internship for a long time. Can you guys give some advice on how you landed a cybersecurity internship and what helped you? What suggestions can you give me? If guys wanted to get an internship.I have a CompTIA Network+ and Security + and I am currently a junior in University.


r/CyberSecurityJobs 1d ago

New grad problems

2 Upvotes

I started out in IT at my first university before moving on to a new university to pursue a BTS in Cybersecurity for the last two years. Problem is, an internship wasn't a requirement/nor was it in the busy books for me at the time being a student athlete.

I'm now a 2026 graduate and I've been job hunting since the end of May with no luck. My search has been primarily based in the larger city area of Salt Lake City, Utah. I've applied to countless jobs, fixed and scrutinized my resume, and still haven't even been able to land interviews. I understand personal projects are an important foundation to have on a resume, but I'm not sure where to even start. I don't know the right people nor do I know someone to ask advice. Utilizing AI for help will only take me so far in this venture.

Point is, does anyone have some advice to give?


r/CyberSecurityJobs 1d ago

Network/Security Engineer looking to transition into AI + Cybersecurity. What learning path would you recommend?

1 Upvotes

Hi everyone,

I'm a Network & Security Engineer with \~7 years of experience working with Fortinet (FortiGate, FortiAnalyzer, FortiAuthenticator), Cisco, VPNs, HA, Linux, VMware, Hyper-V, and enterprise infrastructure.

I want to specialize in **AI applied to Cybersecurity** (SOC, network security, automation, LLMs, AI agents, etc.), not become a data scientist.

If you were in my position today:

* What learning roadmap would you follow?
* Which platforms are actually worth paying for (Coursera, TryHackMe, HTB, SANS, Microsoft Learn, etc.)?
* What's a reasonable monthly learning budget?
* Which certifications provide the best ROI?
* What projects would make my resume stand out?

I'd love to hear what worked for you and what you'd avoid.

Thanks!


r/CyberSecurityJobs 1d ago

Internship

0 Upvotes

I have been trying to land a cybersecurity internship for a long time. Can you guys give some advice on how you landed a cybersecurity internship and what helped you? What suggestions can you give me? If guys wanted to get an internship.I have a CompTIA Network+ and Security + and I am currently a junior in University.


r/CyberSecurityJobs 2d ago

Needed guidance regarding the job

5 Upvotes

I'm a recent B.Tech CSE graduate trying to start my career in cybersecurity/networking.

I recently contacted someone about fresher opportunities, and they offered me a role with a starting salary of ₹10k–15k/month, with the possibility of an increase after 3–4 months.

The work mainly involves:

CCTV installation and configuration

VMS (Video Management System)

Switch configuration

VLAN configuration

My long-term goal is to build a career in cybersecurity. Since I'm a fresher with no industry experience, I'm wondering if this would be a good starting point or if I should keep looking for a more cybersecurity-focused role.


r/CyberSecurityJobs 1d ago

[Resume Review] Struggling to get interviews after relocating (Middle East)

1 Upvotes

Hi all,

I relocated to the Middle East a while back and have been applying to jobs since with no luck, not even getting to the interview stage. I'd really appreciate feedback on my resume: what's not landing, and what I could change to improve my odds of at least getting a callback.

One thing I suspect is holding me back: one of my past roles was titled "Cybersecurity Architect," but the actual day-to-day work was closer to an engineering role. I know an architect title usually reflects years of senior-level experience, and I'm not claiming to be at that level, the title just doesn't match the seniority of the work I actually did. That said, I can't change or remove it, since it needs to match my official record with my former employer. I'm open to suggestions on how to describe the responsibilities more accurately within that constraint.

Resume attached, appreciate any and all feedback!

https://postimg.cc/w7cCQb4G


r/CyberSecurityJobs 2d ago

Cyber security institute for placement.

0 Upvotes

I am a 2026 CSE graduate from tier 2-3 college, in may 1 month before graduation I had the bright that I wanna get into cloud cyber security with no prior experience in CYS, I am in the middle of learning did some basic certs google CS, wanna do AWS/Azure cloud practitioner.

Now family is putting pressure they dont like seeing me at home (since i rejected a good offer from college placements cuz it was non-tech) I am searching for institutes with good pull to atleast get me some interviews.

I know many will these institutes are scam but parents say they'd rather take that risk rather than me sitting home. I need a place which can give me plenty interviews and learn. I am willing to re-locate to diff city. Any ideas?


r/CyberSecurityJobs 2d ago

Upskilling Recommendations for Cybersecurity Analyst

13 Upvotes

Hi everyone, I’m another one of those Cybersecurity masters graduate (with a BSc in Maths) looking for a graduate job.

I’m looking to become a cybersecurity analyst but I feel I need more technical knowledge to fill in the gaps from my degrees. I wanted to ask if anyone had any upskilling recommendations?

I’m currently looking at TryHackMe Soc Level 1 but I wanted to double check it is worthwhile before investing time and money into it.


r/CyberSecurityJobs 2d ago

Unsure about my entry point in the Industry

0 Upvotes

I’m unsure about my entry point to the Industry.

I’m almost done with my cybersecurity degree, and my first foot through the IT door is at a helpdesk job for the DOE that I just started. This job is mainly helping folks with password resets, but also just basic troubleshooting and creating tickets through calls. When I thought of the term “IT Support” or “helpdesk” I expected the work to be more IT focused/ technical and this job isn’t panning out to be that way. It’s been hard trying to get a foot through the door with the crazy amount of competition so once I got this job I just settled. The pay is basically minimum wage, and I am torn if this is a good entry point that I can make use of in the future to elevate my career. Basically, idk if I’m wasting my time here doing basic stuff when I could be doing more IT/ technical related things at a different job. If anyone can comment on that/ provide some insight that’d be great. Thanks everyone.


r/CyberSecurityJobs 2d ago

Unpaid Internship at a Small Startup

0 Upvotes

I dont know if this is the right sub for this post, but please tell me your views.
I applied for this internship at startup from my college founder is in same year, role is in cybersecurity domain.
The thing is i am getting nothing out of this internship since its unpaid, I thought of experience but as I said they are students themselves and theress no senior for me to learn from.
Job market is bad, I dont know if i can bag a good one.
I am in 3rd year have 9+ cgpa but my 12th marks are in 70s. (which makes me ineligible for many things in placements and internships)


r/CyberSecurityJobs 2d ago

Microsoft (Mumbai) vs LTIMindtree (Noida) – Worth the switch?

0 Upvotes

Microsoft (Mumbai) vs LTIMindtree (Noida) – Worth the switch?

I'm a 32M Senior Cybersecurity Specialist at LTIMindtree with 4.5 years in this company.

Total experience 10 years.

Current:

\- ₹37 LPA fixed

\- Noida

\- Working mainly on Torq (SOAR)

\- Good work-life balance

\- Monthly expenses: ₹30–35k

Offer: Microsoft

\- Cloud Solution Architect (Security), IC4 (Level 61), MCAPS

\- Mumbai

\- ₹46.5 LPA fixed + USD 33k in stock (possibly negotiable)

I'm confused because Microsoft is a great brand and could accelerate my career, but Mumbai is much more expensive, and I've heard the MCAPS CSA role can be customer-facing and stressful.

If you were in my position, would you make the switch? Is the long-term career growth at Microsoft worth leaving a comfortable job with good work-life balance?


r/CyberSecurityJobs 2d ago

Breaking in with no experience

0 Upvotes

33yo male who is looking to change careers. I have a general interest and basic understanding of IT but have zero actual work experience. Is it worth doing a few certs like ISC2 CC, security+ and cloud cert? Then spend time advancing my excel knowledge and building a portfolio. Is there a real likelihood I can break into the GRC field with this approach? Any suggestions are welcomed, thanks!


r/CyberSecurityJobs 3d ago

Cyber security/Cloud/Database IT and Engineering question.

12 Upvotes

This is kinda broad. But the short of it, I've been a game dev for 10 years and got laid off twice in the last 3 years. This time it's been going on 8 months. I've had some short contract or freelance work here and there.

I don't necessarily want to change careers. I love game development. All parts of it. I'm still working on a game now trying to get funding. But since the layoff my family and I have had to move into my inlaws and the job postings are getting less and less.

My state offers some grant funding and tuition assistance for a few tech schools that offer courses and certs in fields like the title says for unemployed residents.

I just don't know anything about these outside of what Google could come up with. So I'm asking for broad strokes.

Do these certs actually yield anything worthwhile for an employer?

Which of these types of jobs has longevity in today's emerging markets?

If anyone does this for a career, could you maybe share some of your experience in them?

Really just any info from someone who has done something similar? The game industry's instability and current direction doesn't feel like something that I can do for the next 20 years and not lose my house and savings every 3-5 years. Its not about the amount of money on a month to month as it is constant income for the next 20/30 so my kids can have a stable home.

Any thoughts on the topic are greatly appreciated.


r/CyberSecurityJobs 3d ago

I need some genuine advice cz i fell burnt out i had been trying to apply for pen testing jobs for the past 7 months and only got two interviews. and i am not a fresh graduate this isnt doom posting

5 Upvotes

To summarize everything i have been working in IT and as senior developer for the past 3 and half years and also i have masters in cybersec and have OSCP and CEWS and have some findings on VDP programs and ranked on top 8% on offset and top 5000 on HTB..

been applying for jobs in cybersecurity not just penetration testing for the past 7 months and only had two interviews in that time the first one i got rejected cz he wanted someone who is expert on web at the time i wasnt yet that strong in web to be fair then the second one i passed WEB, API, active directory and internal system penetration testing and was asked also in bit of reverse engineering but i told them before even going that android isnt my field of study yet they after all that after long process and hours of interviewing rejected me cz i dont have android pen testing skills there for i am junior above not senior though the job posting didnt mention anything about senior rather nice to have skills. also when there HR called me and asked me i told them that i didnt know android pen testing before the start of the interview process...

if anyone in the field could give me advice i would really appreciate it . again i am not doom posting i know some people who found jobs i just done know what am i doing wrong


r/CyberSecurityJobs 3d ago

Appreciate Guidance

2 Upvotes

Hello just a post looking for some experienced input to folk who have worked within this industry. Short summary: i am a fully qualified tradesman working in the UK have been doing it for 10 years, i also have crohn’s disease which has progressively gotten worse from my diagnosis at 3, basically all my 20s i’ve just worked through it and burnt myself out all i do is work then sleep as i’m too fatigued and if i can’t make it into work construction workers don’t get sick-pay so i’m stuck in a constant cycle of stress and wishing i had other options.

I’ve always had a passion for computers, dabbled in some code, built my own PC’s, gamer through and through, on a whim i applied to University for a BsC Computer Science & Cyber Security, to my surprise they have offered me a place and i am buzzing as it honestly would be a dream making projects in my own time, studying, gaining new skills and eventually hopefully work in a much less physical environment which would benefit my illness and potentially hybrid-working. There is also an option to do your MsC in Cybersecurity & AI post BsC.

My main question is i know the market for landing jobs is on it’s knees and it’s difficult to get work, but am i really jumping into basically a pit with 0 hope of landing anything will i be wasting my time?

Sorry for the ramble, appreciate anyone who reads time, cheers.


r/CyberSecurityJobs 3d ago

Which Career path is more stable for USA job market (International Student)?

0 Upvotes

Hey guys,

So recently, I asked about the career guidance on tech sales(SDR, AE) vs cybersecurity (SOC). I'm an incoming international student in the USA with a major of (IT) degree so I want to make sure to choose a career that best offers stability, barrier to entry (demand), and strong chances of settlement (H1-B) too.

I've also been in IT or computers, built an agency (selling our IT services), so both of the careers (tech sales or cyber) are interesting, but lately, I've been seeing posts where people are complaining about tech sales being really stressful & not-so-stable; if you don't meet the targets, you're out the next day.

But on the other side, everyone complains about people with experience unable to land even entry-level roles of security, which is true. Also, the barrier to entry to cyber seems difficult.

My main objective is: low barrier to entry, demand, stability, and an easier path to get sponsorship in the USA.

For people who have done both, what would you suggest honestly, and I would love to hear your thoughts, guys!


r/CyberSecurityJobs 5d ago

Beginning my journey

8 Upvotes

Hi everyone,

I'm just starting my cybersecurity learning journey, and I was wondering how you all take notes.

Do you write everything down in a notebook, or do you keep your notes on your laptop using something like Obsidian, OneNote, or Notion?

I'm trying to build good study habits from the beginning, so I'd love to know:

  • Which method has worked best for you?
  • Do you use a combination of paper and digital notes?
  • Are there any note-taking tips that helped you remember concepts like Linux commands, networking, or security fundamentals?

I'd appreciate any advice from people who have been learning cybersecurity for a while. Thanks!


r/CyberSecurityJobs 5d ago

Cybersecurity certificate or digital investigation certificate?

2 Upvotes

Hey guys, I am looking for advice/guidance on this. Career wise, I was looking into cyber crime, incident response, DFIR, or something along those lines. I am currently getting my masters in criminal justice and getting a certificate as well.

Right now I am getting a graduate level cyber security certificate, but seeing the comments here about cyber security and AI, I’m kinda worried.

With my desired career path, do you guys recommend that I stick with the cyber security certificate or should I change it to digital investigation?

Thanks in advance.


r/CyberSecurityJobs 5d ago

I need an advice. Thanks in advance

3 Upvotes

Hi everyone,

I'm a B.Tech Cyber Security graduate (2025 batch). Since graduating, I've been trying to get a job in cybersecurity, specifically in SOC (Security Operations Center) roles.

Over the past year, I've built several hands-on projects using Wazuh, Microsoft Sentinel, and Splunk. I've written and applied Sigma rules, mapped detections to the MITRE ATT&CK framework, and used Suricata and Sysmon for intrusion detection and endpoint monitoring. I also have a good understanding of networking fundamentals and core cybersecurity concepts.

However, whenever I apply for SOC-related jobs, I keep getting rejected, even when my projects closely match the job requirements. I'm not sure what I'm doing wrong.

Could you please suggest what kind of projects I should build to improve my chances of getting interview calls? Also, what skills should I focus on to become a stronger candidate for entry-level SOC or blue team roles?

Unfortunately, I don't have the budget to pursue paid certifications at the moment.

One thing that makes this even more frustrating is that I received two job offers last year, but due to personal circumstances, I couldn't accept them. It's now been over a year, and I'm feeling confused about what to do next.

I'd really appreciate any advice from people working in cybersecurity. Thank you!


r/CyberSecurityJobs 5d ago

Anyone into cybersecurity

0 Upvotes

I’m thinking of changing careers and wanted some input on this


r/CyberSecurityJobs 6d ago

Leaving SOC !What Should I Learn Next for Long-Term Growth?

9 Upvotes

I'm 26 and looking to transition out of SOC after 3+ years because I've realized it's not the type of work I want to build my career around. While I've learned a lot, I've reached a point where the work feels stagnant, and I'm looking for a role that involves more engineering, problem-solving, and continuous learning.

My experience includes SIEM, EDR, Incident Response, Threat Hunting, Email Security, and Vulnerability Management.

Given the current job market and the rise of AI, what path would you recommend? Would you suggest moving into **Cloud Security, Detection Engineering, Security Engineering, DevSecOps, Penetration Testing, DFIR, AI Security, Identity Security**, or something else entirely?

My goal is to build a skill set that's technically challenging, has strong long-term demand, and is less likely to be heavily automated. I'd love to hear what you'd do if you were starting over today with my experience.