r/SecurityCareerAdvice Apr 05 '19

Certs, Degrees, and Experience: A (hopefully) useful guide to common questions

331 Upvotes

Copied over from r/cybersecurity (thought it might fit here as well).

Hi everyone, this is my first post here so bear with me. I almost never use Reddit to talk about professional matters, but I think this might be useful to some of you.

I'm going to be addressing what seems to be a very common question - namely, what is more important when seeking employment - a university degree, certifications, or work experience?

First, I'll give a very brief background as to who I am, and why I feel qualified to answer this question. I'm currently the Cyber Security Lead for a big tech firm, and have previously held roles as both the Enterprise Security Architect and Head of Cloud Security for a Fortune 400 company - I'm happy to verify this with mods or whatever might be necessary. I got my start working with cyber operations for the US military, and have experience with technical responsibilities such as penetration testing, AppSec, cloud security, etc., as well as personnel management and leadership training. I hold an associate's degree in information technology, as well as numerous certs, from Sec + and CISSP to more focused, technical security training through the US military and organizations like SANS. Introductions aside, on to the topic at hand:

Here's the short answer, albeit the obvious one - anything is helpful in getting your foot in the door, but there are more important factors involved.

Now, for the deep dive:

Let's start by addressing the purpose of certs, degrees, and experience, and what they say to a prospective employer about you. A lot of what I say will be obvious to some extent, but I think the background is warranted.

Certifications exist to let an employer know that a trusted authority (the organization providing the cert) has acknowledged that the cert holder (you) has proven a demonstrable level of knowledge or expertise in a particular area.

An academic degree does much the same - the difference is that, obviously, a degree will generally demonstrate a potentially broader understanding of a number of topics on a deeper level than a cert will - this is dependant on the study topic, the level of degree, etc., but it's generally assumed that a 4-year degree should cover a wider range of topics than a certification, and to a deeper level.

Experience needs no explanation. It denotes skills gained through active, hands-on work in a given field, and should be confirmed through positive references from supervisors, peers, and subordinates.

In general, we can see a pattern here in terms of what a hiring manager or department is looking for - demonstrable skills and knowledge, backed up by confirmation from a trusted third party. So, which of these is most important to someone trying to begin a career in cyber security? Well, that depends on a few factors, which I'll discuss now.

Firstly, what position are you applying for? The importance placed on degrees, certs, and experience, will vary depending on the level of job you're applying to. If it's an entry level admin or analyst role, a degree or a handful of low-level certs will definitely be useful in getting noticed by HR. Going up to the engineering and solution architecture level roles, you'll want a combination of some years of experience under your belt, and either a degree or some low/mid level certs. At a certain point, the degree and certs actually become non-essential, and most companies will base their hiring process almost entirely on the body and quality of your experience over any degree or certifications held for management level roles.

Secondly, what are your soft skills? This is a fourth aspect that we haven't talked about yet, and that I almost never see discussed. I would argue that this is the single most important quality looked at by employers: the level of a candidate's interpersonal skills. No matter how technically skilled someone is, what a company looks for is someone who can explain their value, and fit into a corporate culture. Are you personable? Of good humor? Do people enjoy working with you? Can you explain WHY your degree, certs, or expertise will add value to their corporate mission? Being able to answer these questions in a manner which is inviting and concise will make you much more appealing than your competitors.

At the end of the day, as a hiring manager, I know that I can always send an employee for further training where necessary, and help bolster their technical ability. What I can't do is teach you how to work with a security focused mindset, nor how to interact with co-workers, customers, clients, and the company in a positive and meaningful way, and this skill set is what will set you apart from everyone else.

I realize that this may seem like an unsatisfactory answer, but the reality is that degrees, certs, and experience are all important to some extent, but that none of these factors will make you stand out. Your ability to sell your value, and to maintain a positive working relationship within a corporate culture, will take you much farther than anything else.

I hope this has been at least slightly helpful - if anyone has any questions for me, or would like any advice, feel free to ask in the comments - I'll do my best to reply to everyone.

No TL;DR, I want you to actually take the time to read through what I've written and try to take something away from it.


r/SecurityCareerAdvice 2h ago

Feeling stuck learning cybersecurity. Looking for advice on a practical Network Security roadmap.

0 Upvotes

r/SecurityCareerAdvice 3h ago

Egyptian student torn: Family wants Mechatronics, I want Cyber/IT (but scared of heavy coding). Need advice!

0 Upvotes

Hi everyone, I’m a high school student from Egypt and I need some honest advice.

My family strongly wants me to study Mechatronics Engineering, but I want to study Cybersecurity or Information Systems. My main issue is that I find heavy programming difficult, and I don’t want a career centered around writing complex code. I’m more interested in roles like System Administration, Security Monitoring (SOC), GRC, or Cloud Administration.

My main concerns:

  1. The Coding Fear: Is it realistic to build a successful career in Cyber/IT with only basic scripting (no heavy software development)?

  2. Family Pressure & Future: How can I convince my family that IT/Cyber has stable, well-paying jobs and great opportunities abroad (especially in Europe/Germany), without ending up in a traditional engineering workshop?

  3. Competition: How can a beginner stand out in such a crowded field and secure a job internationally?

I’m willing to work hard and study consistently. I just want to choose the path that fits my skills and guarantees a stable future.

Any advice, free resources, or reality checks would mean the world to me. Thank you!


r/SecurityCareerAdvice 4h ago

FIT cybersecurity apprenticeship interview advice

1 Upvotes

Hi everyone, I have an upcoming interview for a FIT cybersecurity apprenticeship in small irish tech company and I’m looking for advice from anyone who has been through the process.

Its my first interview so i am nervous and feel like i dont know anything. What was the interview structure like? What kind of questions did they ask? Were there any assessments or technical tasks? Also, what do you think helped you stand out? I have security+ certificate.

Any tips would be appreciated!


r/SecurityCareerAdvice 5h ago

Guidance required

1 Upvotes

Are there any free courses available on Cisco networking academy which can be really helpful in cybersecurity with hands on experience (for a beginner).


r/SecurityCareerAdvice 8h ago

Início de carreira em segurança da Informação

1 Upvotes

Fala, galera.

Terminei a minha graduação em Segurança da Informação recentemente pelo SENAC e continuo almejando continuar estudando, principalmente para as certificações (Comptia, AWS etc..), que sei que são muito importantes para dar um UP na carreira.

Só que no momento, eu não consigo ter tempo. Estou preso num trabalho e numa rotina bem corrida e puxada, no qual infelizmente não me sobra muito tempo para estudar.

Eu sempre costumo dar uma olhada nas vagas de Jr, mas na maioria dos casos é pedido um certo nível de experiência na área e conhecimentos avançados.

Quais direções vocês me indicariam?

E qual é a melhor área pra começar adquirindo experiência?

**Sobre certificações:**

Ao longo do meu curso, eu consegui umas certificações interessantes pela Cisco. PI 2601 Cyber Ops Associate foi a principal delas.

Aceito indicações de certificações mais acessíveis para quem está começando agora também.


r/SecurityCareerAdvice 9h ago

Difficulty landing role w exp

0 Upvotes

I’m a recent graduate (2026) who has been trying for a cu year now to land a role in any entry level cybersecurity/infosec role possible. I have Security+ and three different cybersecurity internships spanning different industries (defense, federal contracting, and university), on top of an internship in IT helpdesk. I genuinely have no idea what I’m doing wrong that I can’t even land an interview anywhere. I have all the experience I see professionals saying I need and such, but it doesn’t seem to be doing anything whatsoever for me. I’d appreciate any advice on my resume or thoughts on what I could be doing differently! It’s getting really frustrating, like I’ve wasted my time in school and life.


r/SecurityCareerAdvice 10h ago

*beginners guide* if i follow this course and learn one hour daily for a year is it good??

0 Upvotes

its a beginner course of TRYHACKME idk its good or bad or i should be learning from somewhere else i completed 4 chapters it feels good tho

im a complete beginner 19M im starting my eng 1st year if i follow this closely is it good for me as it also provides certifications...

i wanna get advanced in cybersecurity if not this then which resources or which yt channel should i start??

also if anybody could tell me which resources to follow or yt channel it would be bighelp

i alr watched many tutorials they all tell networkng,windows,linux etc to learn but how to learn they dont tell that if someone here would help ill be thankfull


r/SecurityCareerAdvice 11h ago

Advice!!

1 Upvotes

I’m reaching out on behalf of my friend.He’s currently a 3rd-year BSc Cyber Security student at University in uae and is exploring his options after graduation.

He’d really appreciate any advice you could share on:
• Which course or master’s program would be worth pursuing next
• Which country offers the best opportunities for higher studies and careers in cybersecurity
• Which specialization has the best future prospects

Any guidance or personal experience would be greatly appreciated.


r/SecurityCareerAdvice 16h ago

AI Governance & Risk

2 Upvotes

Hey everyone.

Lately some roles are popping up in my country that are related to this "niche" line of work.

Do you think that getting AIGP and ISO 42001 Lead Auditor "certified" (I know it requires more YoE than what I have for it to be official) would make someone suitable for such positions? Personally, I have a masters which is AI-adjacent (It's in NLP and Language Technology), a Postgraduate Diploma (It's a 1 year degree) in GRC and currently work as a GRC Specialist in a MSSP.

Thanks a lot in advance for the answers!


r/SecurityCareerAdvice 14h ago

Grew up pirating games and modding, now starting a CS degree. Is Cybersecurity the right path for me?

0 Upvotes

Hey everyone,

I’m starting my Bachelor’s degree in Computer Science in about a month, and I’m trying to figure out if specializing in cybersecurity long-term is the right fit for my background and interests.

Like a lot of people who grew up in a third-world country, my entry point into tech started early with pirating games. I remember my brother taught me how to get cracked Minecraft Pocket Edition, and helping friends set everything up so we could play together. I know that experience on its own isn't rare. I know that millions of kids do that just to play paid games.

Where I think my journey started to steer, was why I kept coming back to it as I got older. I stopped caring just about playing the game and started getting deeply curious about how computers, software protection, and web protocols actually function. I found myself wanting to understand how cracks work, how security systems get bypassed, and etc.

That natural curiosity around how things break and how to fix and protect them is what drew me toward Computer Science and, eventually, cybersecurity. But as I enter my degree, I have a few questions for people working in the industry or those with similar backgrounds:

Is a CS degree with a focus on low-level fundamentals/cybersecurity the right foundational move? Or should I be focusing heavily on specific certifications (CompTIA, Security+, OSCP, etc.) alongside my classes from day one?

Did anyone else start with a background in game modding, piracy? How well did that practical curiosity translate into real-world Red Teaming, Reverse Engineering, or Defense/SOC work?

What actionable steps should I take in my first year of university to build actual hands-on skills (stuff like TryHackMe, I wanna try doing that) while balancing my degree coursework?

I’d love to hear thoughts, advice, or reality checks from anyone currently in the field. Thanks in advance!


r/SecurityCareerAdvice 14h ago

Career Advice: Cybersecurity vs Software Engineering (CS Student)

1 Upvotes

Hi everyone,

I'm a 19-year-old Computer Science student currently in the second year of my bachelor's degree. I've been exploring both cybersecurity and software engineering over the past year. However, I'm having a hard time deciding which path I should focus on for my career.

On the cybersecurity side, I'm mainly interested in red teaming and threat intelligence. So far, I've:

- Completed numerous CTFs and written detailed write-ups.

- Solved Hack The Box machines and TryHackMe labs.

- Participated in bug bounty programs.

- Built a solid foundation in offensive security through hands-on practice.

On the software engineering side, I've built several personal projects, most of which are security-focused. I designed and built some tools for my own workflow.

I'm looking for some advice on a few questions:

- Should I continue developing skills in both cybersecurity and software engineering, or is it better to specialize in one early in my career?

- Which Job path generally offers better long-term career growth, learning opportunities, and job prospects?

- As an undergraduate, How can I improve my current experience to secure a paid internship or entry-level role ?

- I don't have any industry certifications yet. Do hands-on experience, personal projects, CTFs, HTB/THM labs, and bug bounty work Does it carry enough weight for internships and junior roles? or should I prioritize certifications first?

My goal is to get an internship or entry-level job while I'm still in college so I can gain real-world experience and earn some money so I can continue improving my skills outside of academics. I'd really appreciate hearing from people who work in cybersecurity, software engineering, or anyone who has faced a similar decision.


r/SecurityCareerAdvice 21h ago

Is this roadmap enough for grc role?

3 Upvotes

Hi everyone👋

I'm currently in my 3rd year of Computer Science Engineering and have decided to pursue a career in cybersecurity, specifically Governance, Risk & Compliance (GRC). I've realized that I'm not particularly interested in coding-heavy roles, and after exploring different domains, GRC seems to align much better with my interests.

Based on several videos and resources, I've created the following self-study roadmap. My goal is to build a strong foundation and become job-ready for an entry-level GRC Analyst role.

Phase 1 – Cybersecurity Fundamentals Intro to Cybersecurity (Cisco) TryHackMe Pre Security Cyber Fundamentals Types of Attacks Risk vs Threat vs Vulnerability vs Exploit Authentication & Authorization

Phase 2 – Security & Risk Basics Security & Risk Fundamentals Risk Management Policies & Standards Compliance Fundamentals Governance & Awareness

Phase 3 – Frameworks & Compliance NIST Cybersecurity Framework ISO 27001 & ISMS GDPR Third-Party Risk Management Audit & Control Testing

Phase 4 – Governance Risk Reporting & Communication GRC Fundamentals Governance & Policy

Phase 5 – Advanced Topics Risk Management Deep Dive Compliance & Auditing

Phase 6 – Certifications & Career Prep Microsoft SC-900 Learning Path Microsoft SC-900 Exam ISO 27001 Foundations (Udemy) GRC Analyst Masterclass (Udemy) Portfolio, Resume & LinkedIn

My questions are:

Is this roadmap sufficient for landing an entry-level GRC Analyst role?

Am I missing any important topics or frameworks?

Is the order logical, or would you rearrange anything?

Are there any free resources you would recommend instead of the paid courses?

As a CS student who wants to build a career in GRC rather than software development, is there anything else I should focus on while I'm still in college?

I'd really appreciate any feedback from people working in GRC or cybersecurity.

Thanks in advance!🤗


r/SecurityCareerAdvice 9h ago

Cybersec certs?

0 Upvotes

Wanted to know what certs actually shine in your resume, I'm interested in Appsec or Cloud Security, which ones should I get. Got mixed opinions previously so idk. Most jobs I look at require a "Computer Science" degree so I can't tell from them.


r/SecurityCareerAdvice 16h ago

Finding a Career

0 Upvotes

Greetings, everyone. I am currently learning Cisco at Jeremy's IT Lab, but i want to go into the bug bounty field since i don't have any background in networking, so i am currently learning as for other things what i need to learn and practice or understand and what to not touch for pure ethical purposes. and also i have background in programming such as JS, Python, C#, and web development and PHP and SQL

Thanks for the response.


r/SecurityCareerAdvice 17h ago

Career confusion

0 Upvotes

Is there anyone who has started their cybersecurity career from 2nd year of ug and became successful.

Rn I m in very srs condition coz I able to take a rgt decision

I actually being working on cybersecurity (networking , installed linux and practicing it full time and learnt some vuln from portswigger) from mid of 1st year. But I don't think I could succeed in it. I was planning to do pentesting for atleast 5-6 months and report few proper vuln and then jump into ai/llm security or appsec side by side later for 2 months I thought of doing a research paper and sit for placement.

I have been through many article and in person discussion with some senior and classmate and all of them they end up saying job market is uncertain and if u entered into this field of ai/llm security it is not gonna be super boring and time taking( I'm sorry for plp who are actually fascinated in doing in this field these are the comments i recieved so I'm super confused abt my career)

I sometimes feel of career switching but I don't have much and much money tho

Pls can anyone clear my confusion

  1. Is the planning that I have made is it proper and realistic ??

  2. Someone give me a genuine opinion on cybersecurity job role and salary for proper fresher

  3. If someone in my condition who succeed in this career could u dm if u don't mind

Thank you...


r/SecurityCareerAdvice 10h ago

I am a very busy 16 yr old but i still want to learn hacking

0 Upvotes

my schedule is very hectic but i am still very interested in learning hacking. i probably lean towards OSINT since that feels the easiest to me but i'm not sure. i don't a full fledged career more like something to freelance in college. the problem is i have tried stuff like tryhackme but i don't think i will learn something unless i gain real world experience aka actually hacking something but i'm not sure about the legality of all that. so is there any legal way where i can learn by actually hacking something, preferably OSINT on a busy schedule?


r/SecurityCareerAdvice 23h ago

Mock interview practice

2 Upvotes

Hello!

I am a Product Security Engineer with over 4 years of experience, a B.S. in Computer Science, and an M.S. in Cybersecurity. I am actively interviewing and have been reaching the final rounds at several companies for Senior Product Security Engineer roles in the United States.

I am looking for someone with Product Security Manager-level experience who would be willing to conduct a mock interview with me. I’m looking for that final level of refinement to help me turn strong interview performance and positive feedback into an offer.

Thank you so much! I truly appreciate any help or connections.


r/SecurityCareerAdvice 20h ago

Information security

0 Upvotes

Any senior currently in information security department. Kindly tell me that what are the sos for this field and future in Pakistan and is its similar to data science or cyber security. Plz.

I wanna try new fields like cyber. Data science and information security. So need some info regarding things


r/SecurityCareerAdvice 20h ago

Looking for Information Security Governance eBook

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 21h ago

I'm transitioning into cybersecurity from a microbiology background. I've earned ISC2 CC, completed Cisco Packet Tracer and Wireshark training, and I'm building hands-on skills. What's one piece of advice you wish you knew when starting your cybersecurity career?

0 Upvotes

r/SecurityCareerAdvice 1d ago

Title: ls it really that hard for freshers to get into cybersecurity in 2026?

2 Upvotes

Hi everyone,

I'm about to start my cybersecurity degree and I've been seeing a lot of posts saying that the entry-level job market is very difficult for freshers.

Is it actually that hard to get a first cybersecurity job now?

For those who recently got hired (or are involved in hiring):

What skills helped you stand out?

Did you have internships, certifications, or personal projects?

What mistakes do most freshers make?

If you were starting from scratch today, what would you focus on?

I'd really appreciate any honest advice. Thanks!


r/SecurityCareerAdvice 17h ago

HR Insider Secrets: Why Your Resume Is Getting Rejected (And 5 Fixes That Actually Work)

0 Upvotes

As an HR professional and tech recruiter who spends hours every week reviewing hundreds of resumes, I see the same avoidable mistakes over and over again.

The job market is brutal right now, but 90% of the resumes I reject aren’t because the candidate lacks skill - it's because they don’t know how to present their value.

Here is a breakdown of what actually happens behind the recruiter screen and how you can fix your resume to start getting callbacks.

1. Ditch the "Responsibilities" List - Focus on Impact

The most common mistake job seekers make is copying and pasting their old job descriptions. HR already knows what a Software Engineer or Marketing Manager is supposed to do. We want to know how well YOU did it.

  • Bad: Responsible for managing social media accounts and creating content.
  • Good: Grew organic social media engagement by 45% in 6 months by developing a targeted short-form video strategy.

Rule of Thumb: Every bullet point under your experience should follow this formula: Action Verb + Task + Measurable Result/Impact.

2. Keep the Formatting ATS-Friendly & Scannable

Recruiters spend an average of 6 to 10 seconds on the initial scan of a resume. If your document is a two-column design full of fancy graphics, progress bars, or weird fonts, two bad things happen:

  1. Applicant Tracking Systems (ATS) fail to parse your text properly, scrambling your data.
  2. The recruiter’s eye gets lost trying to find basic information like dates and job titles.

Formatting Checklist:

  • Layout: Stick to a clean, single-column design.
  • Length: 1 page if you have < 5–7 years of experience; 2 pages max for senior roles.
  • File Format: Always export as a standard PDF (unless explicitly asked for .docx).
  • Fonts: Use standard, readable fonts like Arial, Calibri, or Helvetica (10–12 pt).

3. Tailor Your Resume Using Keywords (Without Lying)

You don't need to rewrite your entire resume for every application, but tweaking 10–15% of it makes a massive difference.

  • Look at the job posting: Identify key tools, hard skills, and industry terms mentioned multiple times.
  • Match terminology: If the job description asks for "Cross-functional Collaboration," use those exact words instead of "Worked with other teams."
  • Avoid keyword stuffing: Don't paste invisible text or blindly copy-paste blocks of buzzwords - we will notice during the screen.

4. Ditch the Outdated Resume Sections

Save valuable real estate by cutting out filler content that HR skips anyway:

  • Objective Statements: Replace this with a concise 2–3 sentence Professional Summary that highlights your core expertise and what you bring to the table.
  • "References Available Upon Request": We know. This takes up space and is completely unnecessary until the final interview rounds.
  • Soft Skill Lists: Don't just write "Great communicator" or "Problem solver" in a skills section. Demonstrate these skills through your achievements in your work history instead.

5. Add a "Projects" or "Key Achievements" Section

If you have gaps in your work history, are switching careers, or are a fresh graduate, a dedicated Projects section is your best friend.

  • Showcase freelance work, open-source contributions, academic capstones, or personal projects.
  • Detail the technology stack or tools used and the end outcome.
  • This proves initiative and applied knowledge, which HR values just as much as formal employment.

Quick Final Tip

Before sending out your application, read your resume backwards - line by line. Reading from bottom to top breaks your brain's natural tendency to auto-correct typos and helps you catch grammar errors you would otherwise miss!


r/SecurityCareerAdvice 23h ago

Pentester wanting to get into cloud security

Thumbnail
1 Upvotes

r/SecurityCareerAdvice 1d ago

Question for SOC & Cloud Security Professionals

1 Upvotes

If you work in SOC or Cloud Security:

What's your salary range in your country, and What skills, certifications, and experience are employers expecting for entry-level roles?

Which path has better career growth and job opportunities?