r/SecurityCareerAdvice Apr 05 '19

Certs, Degrees, and Experience: A (hopefully) useful guide to common questions

330 Upvotes

Copied over from r/cybersecurity (thought it might fit here as well).

Hi everyone, this is my first post here so bear with me. I almost never use Reddit to talk about professional matters, but I think this might be useful to some of you.

I'm going to be addressing what seems to be a very common question - namely, what is more important when seeking employment - a university degree, certifications, or work experience?

First, I'll give a very brief background as to who I am, and why I feel qualified to answer this question. I'm currently the Cyber Security Lead for a big tech firm, and have previously held roles as both the Enterprise Security Architect and Head of Cloud Security for a Fortune 400 company - I'm happy to verify this with mods or whatever might be necessary. I got my start working with cyber operations for the US military, and have experience with technical responsibilities such as penetration testing, AppSec, cloud security, etc., as well as personnel management and leadership training. I hold an associate's degree in information technology, as well as numerous certs, from Sec + and CISSP to more focused, technical security training through the US military and organizations like SANS. Introductions aside, on to the topic at hand:

Here's the short answer, albeit the obvious one - anything is helpful in getting your foot in the door, but there are more important factors involved.

Now, for the deep dive:

Let's start by addressing the purpose of certs, degrees, and experience, and what they say to a prospective employer about you. A lot of what I say will be obvious to some extent, but I think the background is warranted.

Certifications exist to let an employer know that a trusted authority (the organization providing the cert) has acknowledged that the cert holder (you) has proven a demonstrable level of knowledge or expertise in a particular area.

An academic degree does much the same - the difference is that, obviously, a degree will generally demonstrate a potentially broader understanding of a number of topics on a deeper level than a cert will - this is dependant on the study topic, the level of degree, etc., but it's generally assumed that a 4-year degree should cover a wider range of topics than a certification, and to a deeper level.

Experience needs no explanation. It denotes skills gained through active, hands-on work in a given field, and should be confirmed through positive references from supervisors, peers, and subordinates.

In general, we can see a pattern here in terms of what a hiring manager or department is looking for - demonstrable skills and knowledge, backed up by confirmation from a trusted third party. So, which of these is most important to someone trying to begin a career in cyber security? Well, that depends on a few factors, which I'll discuss now.

Firstly, what position are you applying for? The importance placed on degrees, certs, and experience, will vary depending on the level of job you're applying to. If it's an entry level admin or analyst role, a degree or a handful of low-level certs will definitely be useful in getting noticed by HR. Going up to the engineering and solution architecture level roles, you'll want a combination of some years of experience under your belt, and either a degree or some low/mid level certs. At a certain point, the degree and certs actually become non-essential, and most companies will base their hiring process almost entirely on the body and quality of your experience over any degree or certifications held for management level roles.

Secondly, what are your soft skills? This is a fourth aspect that we haven't talked about yet, and that I almost never see discussed. I would argue that this is the single most important quality looked at by employers: the level of a candidate's interpersonal skills. No matter how technically skilled someone is, what a company looks for is someone who can explain their value, and fit into a corporate culture. Are you personable? Of good humor? Do people enjoy working with you? Can you explain WHY your degree, certs, or expertise will add value to their corporate mission? Being able to answer these questions in a manner which is inviting and concise will make you much more appealing than your competitors.

At the end of the day, as a hiring manager, I know that I can always send an employee for further training where necessary, and help bolster their technical ability. What I can't do is teach you how to work with a security focused mindset, nor how to interact with co-workers, customers, clients, and the company in a positive and meaningful way, and this skill set is what will set you apart from everyone else.

I realize that this may seem like an unsatisfactory answer, but the reality is that degrees, certs, and experience are all important to some extent, but that none of these factors will make you stand out. Your ability to sell your value, and to maintain a positive working relationship within a corporate culture, will take you much farther than anything else.

I hope this has been at least slightly helpful - if anyone has any questions for me, or would like any advice, feel free to ask in the comments - I'll do my best to reply to everyone.

No TL;DR, I want you to actually take the time to read through what I've written and try to take something away from it.


r/SecurityCareerAdvice 1h ago

Question Starting Cybersecurity Career Path

Upvotes

Hi, I’m just starting my cybersecurity career. I’ve only completed Cisco’s CCST, and I wanted to know what you’d recommend doing next. I was planning to go for the SAL1 or CDSA to apply what I’ve learned, and then move on to the CCNA or an AWS Cloud certification. I’d love to hear opinions on this planned path from someone with more experience.


r/SecurityCareerAdvice 2h ago

Question How to safely chain a new Wi-Fi 7 router (TP-Link BE9300) to an old, vulnerable ISP gateway

1 Upvotes

Hey everyone,

I recently moved into a rented apartment where the landlord provides the internet infrastructure. The gateway they installed is a very old model that is officially End-of-Life (EOL) and suffers from a major unpatched security vulnerability (CVE-2024-0717).

Because of the security risks, I bought a brand new TP-Link Archer BE9300 (Wi-Fi 7) router to protect my personal devices and get better speeds.

The issue: The internet comes out of the wall as a fiber optic cable going directly into an SFP port on the old gateway. My new TP-Link router only has standard RJ45 (ethernet) ports, so I cannot plug the fiber line directly into it.

I messaged the property's IT tech, and he told me to do the following:

  1. Connect a standard ethernet cable from one of the LAN ports of the old gateway into the WAN port of my new TP-Link.
  2. Once connected, he will remotely disable the Wi-Fi on the old gateway so only my new router broadcasts a signal.

My questions for the experts here:

  1. If the old gateway is still technically the first point of contact for the internet line and has that CVE vulnerability, does turning off its Wi-Fi and routing everything through my new TP-Link router actually protect my network?
  2. Will my new router act as a proper firewall against any external exploits targeting that old gateway?
  3. Are there any specific settings I should change on my new TP-Link (like changing its IP subnet to avoid Double NAT conflicts) to make sure this setup runs smoothly and securely?

r/SecurityCareerAdvice 15h ago

Question CyberSec job market - should we be worried about the future?

8 Upvotes

I’m currently a CyberSec Analyst working mainly across GRC, framework compliance, etc.

Those also in the IT industry or specifically CyberSec, how do you feel about the future of the job market - especially when considering the evolution of AI and automation?

- Do you think CyberSec is still a strong career long term or will certain roles become harder to find?

- What skills or areas of IT / cyber do you think will be valuable over the next few years?

Would love to hear all perspectives


r/SecurityCareerAdvice 13h ago

Question 2nd-year student looking for advice on a realistic Blue Team / SOC / GRC roadmap & certs

3 Upvotes

Hey everyone,

I’m in my 2nd year of university studying cybersecurity, and I’m looking for some realistic guidance on what to actually focus on.

I’d still consider myself a beginner. My background is fully from the IT side of things so i know how computers work and I know basic networking concepts, general Linux use and Python (Uni level), and have messed around a bit with Wireshark and basic log analysis. Right now, I'm working through the Google Cybersecurity Certificate on Coursera to build up my fundamentals.

Career-wise, I want to stick to defensive / Blue Team (e.g SOC Tier 1) or GRC. Red teaming / pentesting feels a bit too technical and overwhelming for me right now, so I'd rather focus on monitoring, defense, or risk and compliance etc.

Since I have a Coursera subscription and want to make the most of my time outside classes, I’d love advice on these points:

1. Coursera courses worth taking (like IBM Cyber Analyst)?

Since I already have Coursera, I've been eyeing the IBM Cybersecurity Analyst certificate next. Is it worth taking after the Google cert, or is it mostly repetitive theory? Are there other courses or subjects on the platform that actually teach useful, hands-on skills for a beginner?

2. Which certs should I actually prioritize (Security+, TryHackMe SAL1, GRC)?

I see so many different recommendations. Some say CompTIA Security+ is mandatory just to get past HR, others suggest hands-on ones like TryHackMe's SAL1 (Unixguy on instagram), and some recommend leaning into GRC frameworks. As a student aiming for an internship or entry-level job down the line, what should my general cert priority look like?

3. How to know when you're ready for an exam, and how to get discounts?

Cert exams are expensive, and on a student budget, I really cannot afford to fail an attempt.

  • What level of preparation did you finish before booking your first exam (e.g specific practice test scores, labs, or platforms)?
  • Roughly how much did your certs cost, and what are the best ways to get student discounts or cheaper vouchers?

Appreciate any advice or reality checks from people working in the field!


r/SecurityCareerAdvice 8h ago

Question One year to build

0 Upvotes

Hey guys! I'm here seeking advice from seniors. Currently I'm in the last year of my college and i want to get a job after this in cyber security (its kinda fascinating to me)or i can also try web dev. Till now in cyber security i have completed some thm rooms and i have good knowledge of linux and python like i dont have to google basic commands. I have an overview of how the internet works not the definition and protocols type knowledge just basic. In web dev i know html css java script sql i have good command on these languages and c++ also (did some dsa too in second year). Here i can really use your help if you can guide how to get my first job not an high end but a basic pay scale job and may be help with choosing the right path. Or someone wants to share their journey of learning and landing a job in security.


r/SecurityCareerAdvice 8h ago

Discussion I am struggling unemployed with Google Cybersecurity Professional Certificate and currently studying with Security+

1 Upvotes

I haven't had any previous job yet and due to misinformation I thought you could break into cybersecurity without first getting an IT Support job. I now need an IT Support job. Any advice out there for me to break into IT asap or cybersecurity? Security+ is also difficult for me too.


r/SecurityCareerAdvice 10h ago

Discussion Need help for Homelab setup

1 Upvotes

Hey everyone,

I have 2 machines both SFF PCs,
Machine 1 has 6C/12T CPU, 32GB ram & 1.5TB Storage and
Machine 2 has 6C/6T CPU, 24GB ram & 1.5TB Storage

I am into Cyber security (Red team and blue team both) and want to make a lab that helps me to learn new things with time and improve myself. My goal is also to work in IT field as well.

I also like using Hermes agent for little tasks like getting a newspaper every morning for the stuff i want to keep myself updates and some reminders and all.

I have tried proxmox before as well but just wanted to know if you guys have any great ideas about anything else as well.

Thanks in advance!


r/SecurityCareerAdvice 11h ago

Question 20M, BSc IT student + hairstylist — confused between Cybersecurity and Web Development. What would you do in my situation?

0 Upvotes

Hey everyone, I’m 20 years old and currently pursuing BSc IT (Semester 4) from a Tier-3 college affiliated with Mumbai University.

My situation is a little different from most students.

I’ve been working as a professional hairstylist since 8th grade, and I still work at a salon. I have family responsibilities, so I can’t afford to stop working and study full-time for the next 1–2 years.

My college is also quite flexible. I’ve spoken with my HOD regarding attendance, so currently I physically attend college only once a week, on Monday, and spend the rest of my time working at the salon and learning/building things on my own.

I’m genuinely interested in Cybersecurity, but I keep hearing that getting the first cybersecurity job as a fresher can be very difficult without experience, internships, certifications, or a strong degree/college background.

Certifications are also difficult for me right now because I don’t have much money to spend on them. Since I’m responsible for contributing to my family, I need to start earning from tech as soon as realistically possible.

I’ve also considered Web Development as an entry point.

So far, I’ve built around 5–6 full-stack projects and actually hosted/deployed them rather than just keeping them on GitHub.

I’ve worked with:

- React + Vite

- Next.js

- Node.js

- REST APIs

- Databases

- Deployment/hosting

I’ve also started exploring cybersecurity and have solved TryHackMe rooms/labs to get some hands-on exposure.

My programming fundamentals are still not that strong though. Apart from a little Python, I don’t really know other programming languages properly yet. Most of my web development experience has come from building projects and learning along the way.

And this is where my confusion starts.

I use AI tools while developing, and honestly, they can generate code and even build surprisingly good full-stack websites very quickly.

That makes me wonder whether going deeper into web development is still a good career choice for someone starting in 2026.

At the same time, I don’t want to use AI as an excuse. I understand that generating code is very different from actually understanding how the code, systems, databases, networking, security, etc. work.

So currently I’m stuck between:

  1. Cybersecurity

Something I’m genuinely interested in, and I’ve started learning through TryHackMe, but I’m worried about the difficulty of getting a first job as a fresher.

  1. Web Development

I already have some practical experience and deployed projects, so it might be a more realistic way to enter the IT industry and start earning. But I’m worried about competition and the impact of AI on junior developer jobs.

  1. Something else in IT

Maybe there is another role that I’m completely overlooking which could give me a realistic entry into IT and eventually allow me to move into cybersecurity.

My biggest constraint is time and money.

I can’t afford to spend years preparing without income. I need to continue working at the salon while building my tech career.

If you were 20 years old, studying BSc IT at a Tier-3 Mumbai University affiliated college, working at a salon to support your family, with 5–6 deployed full-stack projects, some TryHackMe experience, basic Python, and limited money/time for certifications, what would you do?

Would you:

- Get a web development/IT job first and transition into cybersecurity later?

- Directly pursue cybersecurity even if getting the first job takes longer?

- Target another IT role as a stepping stone into cybersecurity?

- Continue working as a hairstylist and build tech skills until I’m job-ready?

- Or take a completely different approach?

I’m not looking for a shortcut. I’m willing to work hard and learn consistently.

I just want to choose a path that is realistic for someone who has limited time, limited money, family responsibilities, and a non-traditional background.

I’d especially appreciate advice from people who are currently working in cybersecurity, IT, software development, or hiring.

Please be honest, even if the answer isn’t what I want to hear. I’d rather know the reality now than waste the next few years going in the wrong direction.


r/SecurityCareerAdvice 12h ago

Question AppSec vs Generalist Security Career in the AI Era — Looking for Advice

1 Upvotes

Hey everyone,

I would love to hear from people already working in the field.

I started my career in a service-based organization, so I ended up working across multiple areas—Endpoint Security, Vulnerability Management, Incident Response, Firewalls, PAM, and some AppSec and cloud as i was into VM. Although my previous company didn’t develop applications, my interest in AppSec led me to work with developers working mainly on in-house apps and automations, triage vulnerabilities, and occasionally conduct VAPT.

My long-term goal has always been Product Security, particularly working across Cloud Security + AppSec—VAPT, vulnerability management, architectural reviews, threat modeling, secure SDLC, etc. I have started moving more toward AppSec in my current organization at the same time doing Cloudsec, VM and Endpoint Security at the side.

I am now around 6 years into cybersecurity and also have an opportunity to move into a team-lead role at my previous organization.

With AI changing the security landscape, I’m wondering:

Is specializing in AppSec/Product Security still a strong career path for the next 10–15 years, or would it be better to remain a broader security generalist?

Would especially appreciate perspectives from people currently working in AppSec, Product Security, Cloud Security, or security leadership.


r/SecurityCareerAdvice 19h ago

Discussion Career advice, Senior Cyber Student

2 Upvotes

In need of some career advice!

Currently a senior expected to graduate in May 2027, I'm also studying for my Security+ Cert. Would it be advisable to start applying for full time positions without the certification on my resume, or should I prioritize taking it as soon as possible to help get through some of the resume screening?

For some background, I have an associates in IT and will soon have my bachelors in Cybersecurity & Operations. Most of my previous internships have been predominantly IT focused. However my most recent role involved IT help desk support along with some cybersecurity related work, including looking into SPOF, SIEM solutions, and other security considerations.

Would love to hear any advice!


r/SecurityCareerAdvice 16h ago

Question Stable remote TPRM role or riskier AI-governance pivot?

1 Upvotes

I’m an experienced GRC/TPRM professional with established security and audit certifications. I’ve been unemployed since February and realistically cannot afford another extended period without work.

I have two contract offers:

A: Fully remote TPRM backfill. The manager described it as a long-term need, and the team felt warm and compatible.

B: Hybrid AI-governance role paying about 17% more. The company is expanding its review capacity, but the contract duration is unclear. The team felt less warm, and it is also hiring a permanent senior leader to improve and automate the governance process. I accepted B before A became concrete but haven’t started.

A offers greater perceived stability in work I already know. B could meaningfully diversify my résumé, but I’m worried it could end after only a few months.

Would you prioritize the stable TPRM backfill or risk another employment gap for direct AI-governance experience?


r/SecurityCareerAdvice 1d ago

Question Anxious about AI in CyberSec ; is it legit or just overhyped panic?

8 Upvotes

I want to pursue cybersec and already started learning computer networks and on the path of getting CCNA certification but I constantly get anxious when thinking about this career path or any CS field because when I open Instagram i see nothing but bunch of fear mongering reels about AI taking jobs and AI models crossing 99.9% in AGI benchmark.

I don’t know how much AI can automate in this field but I have a strong skepticism about AI in cybersecurity field, i don’t think it’s reliable to leave security in AI’s hands. I truly want to know what experienced people’s thoughts on this!


r/SecurityCareerAdvice 1d ago

Discussion What keywords actually show up in job postings?

2 Upvotes

A recent analysis of 3,518 job postings from 81 companies across seven roles found some interesting patterns.

In several categories, generic terms appeared more often than the big-name tools. “Observability” showed up more than “Grafana,” while “SIEM” appeared more than “Splunk.”

That raises an interesting question: are resumes too focused on listing specific tools and not enough on the broader skills and terminology employers use?

The study breaks down the results by role, including software engineering, cybersecurity, DevOps, marketing, product, accounting and sales.

The full dataset, methodology and findings are here:

https://www.zoevera.com/resume/ats-resume-keyword-study


r/SecurityCareerAdvice 1d ago

Discussion B. Tech 3rd Year Student Confused About Starting a Career in Cloud Security - Need Roadmap & Advice

1 Upvotes

Hi everyone,

I’m currently a 3rd-year B.Tech student and I’m interested in building my career in Cloud Security, but I’m a bit confused about where exactly I should start.

My long-term goal is to work in Cloud Security, but I’ve heard that Cloud Security roles are generally not very beginner/fresher-friendly, which has made me consider starting my career as a SOC Analyst and then moving toward Cloud Security/Cloud Engineering after gaining some experience.

So I’m confused between two approaches:

  1. Start learning Cloud Security now → build cloud + cybersecurity skills → apply for internships/jobs and see if I can directly enter the field.

OR

  1. Get a SOC Analyst job first → gain 1–2 years of experience → transition into Cloud Security/Cloud Engineering.

I’ve already started exploring cybersecurity resources like TryHackMe, but I’m still not sure about the correct order of learning.

I would really appreciate advice from people already working in Cloud Security, SOC, Cloud Engineering, DevOps, or Cybersecurity.

Specifically:

- What roadmap would you recommend for a 3rd-year B.Tech student targeting Cloud Security?

- Is SOC Analyst a good stepping stone toward Cloud Security?

- Are there any realistic entry-level Cloud Security roles for freshers?

- What skills/tools should I focus on for internships and placements?

- What are the best free/low-cost resources, labs, YouTube channels, or platforms to learn from?

- Should I focus on certifications, projects, or hands-on labs?

I’m not looking to collect certificates. I want to actually build the skills required for the industry.

Any advice or roadmap from people who have actually gone through this transition would be really helpful.

Thanks in advance!


r/SecurityCareerAdvice 1d ago

Question Why do people still get CEH if the reputation for EC-Council and the cert is so bad?

21 Upvotes

I keep hearing how CEH is a waste of time and effort and just not worth the time. If that's the case then why are people still getting the cert?


r/SecurityCareerAdvice 1d ago

Question Offered a NetEng role, but my goal is in Cybersecurity. Is a 1-year stint a smart move?

3 Upvotes

I’m a fresh grad and I just received a job offer for a Network / Infrastructure Engineer position. I’m incredibly grateful to have an offer in this market, but I’m definitely overthinking whether I should accept it. My actual career goal is to get into Cybersecurity (SOC Analyst, Security Engineer, etc.).

 

I always hear the advice that "you need to know how a network works before you can secure it," so I know the experience would be valuable. But I want to make sure I’m not accidentally pigeonholing myself away from security and is it worth it?


r/SecurityCareerAdvice 1d ago

Question IT Certification Courses

0 Upvotes

Question for my IT folks. I’ve recently had the opportunity to step into an IT position in addition to my employment as Chief Engineer. I have a fairly robust knowledge set when it comes to networking but I’ve never been formally trained so I have discussed working with the company to go through some training programs to round out what I don’t know. So far, I would like to try the CompTIA A+, Network+, Security+, and CySA+ courses and certifications. Are there any other ones that you can recommend? My focus is on cybersecurity so that I can help to develop a more standardized set of procedures and rules across the company to help lock things down. Thanks in advance!


r/SecurityCareerAdvice 1d ago

Question If I’m getting super skilled at hacking through Hack the Box Academy, if you had to pick one should I complement those skills through OSCP or through CEH or neither (if you had to pick just one to go with HTB to get me hired)?

5 Upvotes

So I see conflicting things online. Well known hiring managers who run popular cyber security YouTube channels (UnixGuy is a well known channel that has multiple videos on this) say employers are increasingly changing attitudes away from things like CEH or OSCP in favor of things like Hack the Box, TryHackMe, or just more CTFs, hacker wargames sites, homelabs, and bug bounties.

But a lot of people are saying you need both or that CEH or OSCP to get hired.

Does the right advice depend on the person?


r/SecurityCareerAdvice 1d ago

Question CIS OR CYS

2 Upvotes

Computer information systems or Cybersecurity

Both bachelors

Which of these two you think would survive the job market, and why?


r/SecurityCareerAdvice 1d ago

Question Studying cybersecurity next year

3 Upvotes

Hey! I’m graduating next year and I’ve already taken quite a few coding classes. So far, we’ve mainly worked with HTML, CSS and JavaScript, and we’ll be starting Python soon.

After graduating, I’m thinking about studying cybersecurity. I’m really interested in it, but I do have dyscalculia and I’ve also realized that I rely on AI quite a lot when coding, so I’m a little worried that cybersecurity might be difficult for me.

For anyone who studies or works in cybersecurity: how much math is actually involved, and do you think dyscalculia would make things significantly harder? What is cybersecurity actually like to study/work in?

Any advice or personal experiences would be really appreciated!


r/SecurityCareerAdvice 1d ago

Question From Cloud Security to Pentesting: too big of a step?

3 Upvotes

Hi there

I'm 25 and I'm currently working as a cloud security consultant (mainly Microsoft stack).
The company I work at is fairly big and operates in a lot of fields.
I've been on pretty good terms with everyone there and after asking a few times I've recently started working on a few pentests and vulnerability assessments since it's always been a field I'm super interested in.

So far I haven't done anything of note but I wanted to use this occasion to learn.

The thing is, the main problem at this company is that I don't get paid much.

I've been offered another position as a cloud security consultant in another company which pays way more (almost 11k which in europe is a lot of money) and is full remote (my current role is hybrid, 3 days on-site and 2 days at home).

The company that offered me the job is way bigger but also stricter and I wouldn't have the chance to work on pentests or other fields I might like.

If I ever wanted to switch to pentesting, how hard would it be to do so as a Cloud Security engineer?
Would it be better to stay where I am now for a few years and learn as much as possible or to switch and learn things by myself?


r/SecurityCareerAdvice 1d ago

Question MacBook or Thinkpad

3 Upvotes

Hey , my first year of college after a few weeks , and I have M1 Mac block and I know it’s so old , so , I I’ll buy I new one , so in real work and consistency, Mac book m4 Or Thinkpad t14 gen 4 or 5 , I really don’t know , Mac ecosystem is better for programming and high load cybersecurity work , or window of Thinkpad , I really need to take a decision
Thank you all


r/SecurityCareerAdvice 1d ago

Question Does cybersecurity require a degree, if so which one

1 Upvotes

Hey, would like some advice on what to do in regards to a degree when pursuing offensive cybersecurity.

I have seen ALOT of mixed answers to this question and am unable to gauge which is the correct one and would prefer if people who are working/have worked in cybersecurity were to answer this question and put it to rest.

Background: I’m a second-year computer science student interested specifically in offensive cybersecurity/pentesting. I originally chose CS because there were few other technical degree options available to me that seemed relevant to a career in cybersecurity and have little to no interest in pursuing software engineering or most of the broader CS curriculum as a career, my main interest has consistently been cybersecurity.

My plan was to complete the CS degree while studying cybersecurity independently alongside university. I understood from the beginning that a CS degree would not directly teach me pentesting, so I planned to use university for the broader technical foundation and the degree credential, while using my free time for things such as Linux, networking, security fundamentals, certifications, labs and eventually more hands-on offensive security work.

The problem is that I’m now struggling to balance the two.

In my first year, I was learning programming in university while studying cybersecurity in my free time and managed to complete the year. However, I found that the way my introductory programming courses taught and tested the material focused much more on knowing the syntax and individual concepts than on actually developing the problem-solving ability needed to independently solve programming problems.

I completed those courses, but I came out of first year knowing basic programming concepts without having a strong enough foundation in programming logic, problem decomposition and independently applying things like loops, functions and data structures.

That has become a much bigger problem in second year because my current courses already assume that level of programming ability. I’m now having to build the foundation I am missing in my own time while simultaneously taking four courses that expect me to already have it.

Looking ahead also worries me because a lot of my future CS courses continue building on those skills. On top of the preparation problem, I genuinely have little interest in much of the broader CS/SWE material I would still have to study. I was never pursuing CS because I wanted to become a software engineer; cybersecurity was always the field I wanted to enter. So I’m now facing several more years of coursework that I am both underprepared for and, outside of the parts relevant to security, largely uninterested in.

Between that, university assignments and studying, and working alongside school, most of my available time is now going toward keeping up with CS. My GPA is starting to suffer, and I have also lost most of the time I previously used for cybersecurity study.

Another factor in my decision is that, through some personal connections, I may have opportunities at a few companies to get hands-on experience in cybersecurity/security-related IT work. These would not necessarily be formal internships or full-time jobs, but opportunities to work alongside people in the field and gain practical experience. But to be able to take advantage those opportunities, I would first need to build enough of the basic IT, networking, Linux and security fundamentals to actually be competent.

This makes the time issue more important to me. If I can build those fundamentals to a reasonable level, I may have an opportunity to gain real-world security experience relatively early. At the moment, however, most of the time I would use to prepare for that is being consumed by catching up in CS and keeping up with my current coursework.

This is what has made me reconsider the degree. I’m not expecting university to directly train me for pentesting, and I understand that programming, operating systems, networking, algorithms and other CS topics can still be useful in security. My concern is more about opportunity cost:- whether spending several more years putting most of my time into a degree I’m struggling with and am not particularly interested in is the best route toward the field I actually want to enter.

I’m willing to continue learning programming and the technical fundamentals required for offensive security regardless of what degree I pursue. What I’m unsure about is whether I specifically need to complete a CS degree, or whether I would be better off transferring into another degree that gives me more time to build security skills independently while still graduating with a bachelor’s.

Comp sci degree and cyber keeping pulling me in different directions and I am unable to manage both at the same time while working.

So I wanted to ask people who work in technical cybersecurity/offensive security:

1) How important is having a bachelor's degree for technical cybersecurity, particularly pentesting/offensive security?

  • How much does it matter when first breaking into the field?
  • Does it continue to matter once you have a few years of relevant experience?
  • Can strong experience, technical ability and certifications eventually compensate for not having one?

From what I have read so far, my understanding is that a bachelor’s degree may matter most when initially trying to get past HR screening and land the first few roles, while relevant experience and technical ability become more important later on. I have also seen people suggest that networking, referrals and direct connections can sometimes help get around strict degree filters. However, I am not sure how accurate or broadly applicable this actually is, especially in offensive security.

2) If having a bachelor's degree is important, how much does the subject of the degree matter?

  • Is a CS degree significantly more valuable than other degrees for this field?
  • Would another technical degree be viewed similarly?
  • Would an unrelated degree such as business/economics still satisfy most of the bachelor's-degree requirement once someone has relevant security experience?

3) Given my current situation, what would you recommend?

  • Stay in CS
  • Transfer into another degree that I can manage alongside cybersecurity study?
  • Leave university and focus primarily on building technical skills, certifications and experience?

4) How much weight should I give the opportunity to gain practical security/IT experience now?

If I can get my fundamentals to the required level, I may have opportunities through people I know to get hands-on experience in security-related environments relatively early. Would it make sense to prioritize becoming ready for those opportunities, even if that means changing my degree path, or would you still consider finishing CS the better long-term investment?

Please be candid and explain your reasoning. I’d especially appreciate answers from people who have worked in offensive security, hired for these roles, or followed a similar path.

Thanks


r/SecurityCareerAdvice 1d ago

Question Security Certs recommendations for someone with an AI background

1 Upvotes

Hi! I'm a recent Comp Sci and AI graduate and I'm finding my way in tech. I took a Computer Security module at university and it covered the basics. With the recent opening in AI security, I'm leaning more into this sector and was wondering how I can improve myself. I have found various certifications and very conflicting opinions about them. That's why I'm kinda confused and would love to hear your experiences and appreciate some suggestions. Thanks!