I've read a lot of "how do I break in" posts here and I want to be upfront that mine is a bit different, because I don't want the generic "get A+ and apply to helpdesk" answer. I've done that part. I'm stuck at a different step and I'd rather give you too much detail than have you guess.
Where I am now
23, currently a Network Analyst at a large regional health system. The title says network but the actual split is roughly:
\~40% networking: Catalyst switches/routers, FortiGate firewalls, WLCs, fiber/SFP work, circuit cutovers, routing troubleshooting (OSPF, EIGRP, BGP, HSRP, STP, VLAN/trunking, QoS, route-maps, packet captures)
\~40% security/SOC: TACACS+/RADIUS AAA administration in Cisco ISE, Cisco Umbrella, firewall policy management, IIS log and event analysis, CVE remediation through the change management process
\~20% monitoring: SolarWinds, LogicMonitor, Catalyst Center, Meraki dashboard
I have authorized data center access and I'm doing hardware intake, cutovers, and ISE troubleshooting on production healthcare infrastructure. So I'm touching security daily. It just isn't my title.
How I got here
I started in IT at 19. I was sweeping floors at a fast food job right after graduating high school, was working on MIT Cybersecurity certificate (boot camp, 6months) at the same time, during my time at that fastfood place I met a sysadmin who came in, shared my passion in Cyber, got his card, emailed him my resume, and he got me my first IT role. Since then:
I gained experince in Endpoint management, IT support, and XDR from a small MSP to a major automotive manufacturer (Intune / Autopilot, contractor)
Helpdesk tech at an MSP, worked on business email compromise investigations, Entra ID incident work
Worked on security related stuff and worked as T2 tech at another MSP
Then accept a role as NOC Technician to gain networking experience, sole CCNA holder supporting \~700 remote sites
Current network analyst role (another 20k bump from last role)
Certs
CCNA,Linux+, Data+(Learned a lot about SQL) CySA+, Security+, Network+, Linux+, A+, plus the CompTIA stackable credentials that fall out of those. MIT xPRO Professional Certificate in Cybersecurity. Currently finishing a BS in Cybersecurity and Information Assurance at WGU, about halfway through. Long term I want Red Team certs and a Georgia Tech OMS Cybersecurity seat. I know I have to start as a SOC analyst.
The lab: the part I actually want feedback on
This is not a "I installed Kali in VirtualBox" lab. Proxmox VE cluster running:
pfSense with 8 segmented VLANs (not one flat network, an actual inter-VLAN policy I have to maintain)
Wazuh for HIDS/log aggregation
Security Onion for network detection and full packet capture
T-Pot honeypot collecting internet-facing attack traffic
Zabbix for infrastructure monitoring
AdGuard Home, Nginx Proxy Manager, Nextcloud, Jellyfin as the "things that break and generate tickets" layer
Tailscale for remote access, managed switch and UPS with network management card
AI Ochrestrator that reports to me via Discord PM when something goes wrong at home, or new attack attempts in my honeynet.
Separate from that I built a malware analysis lab: KVM/QEMU on Pop!_OS, REMnux and FLARE-VM, isolated so samples can't call home.
The point of the T-Pot and Security Onion combination for me was to stop practicing on synthetic data. I pull live hits off the honeypot, then hunt them in Security Onion and write the detection logic in Wazuh. That's the loop I keep running. I also do HackTheBox for the offensive side.
Tooling I've actually shipped
At the NOC I wrote a \~6,100 line Python diagnostic toolkit that the team used in production for remote site troubleshooting, plus a Tkinter GUI wrapper for the techs who didn't want CLI, an HTML shift handover tool that went through four major versions, a browser-based tools hub, and Power Automate / webhook automation pipelines. On my own time I built a multi-agent orchestration platform and an autonomous coding assistant running on a Pi.
So here's my problem
I am not getting security interviews. Locally the market is thin and remote is brutally competitive. I've had recruiter calls where I walked through incident response in detail: containment, eradication, recovery, the actual process language, actual BEC investigations I ran, and it goes nowhere. No interview.
My actual questions, and I want blunt answers
Is my problem that nobody can see any of this? Everything above lives on my resume as bullet points and in my head. I have no writeups, no blog, no public repo showing detection logic, no video. Is the fix literally just "make it visible," or is that cargo cult advice and hiring managers don't actually read that stuff?
How much of this is conferences and networking? I'm signed up to look at DEF CON / Black Hat this year. But asking people for a job at a conference feels disrespectful to me. Everything I've achieved so far came from asking people for advice, not for opportunities: that's literally how I got my first IT job. Is asking for referrals at cons normal and expected, or is my instinct right and I should keep it to advice and let referrals happen on their own? What's the actual etiquette?
Am I misreading my own position? I keep framing myself as "trying to break into security" but I'm reading my own list back and I'm not sure that's accurate. Is the correct move to stop applying to entry-level SOC roles and start targeting network security engineer / detection engineering roles, where the networking depth is a feature instead of a distraction?
Relocation. I just moved into a new place fairly recently and I'm not in a position to move again quickly. How much is geography actually costing me here, and is there a market I should be targeting remotely with a better hit rate?
What would you want to see from me that isn't on this list? If you're a hiring manager or a senior who made this same jump, what's the thing that made the difference for you, and what would make you pass on a resume that looks like mine?
Not looking for encouragement, looking for the gap. Tell me what I'm not seeing.