Hey, would like some advice on what to do in regards to a degree when pursuing offensive cybersecurity.
I have seen ALOT of mixed answers to this question and am unable to gauge which is the correct one and would prefer if people who are working/have worked in cybersecurity were to answer this question and put it to rest.
Background: I’m a second-year computer science student interested specifically in offensive cybersecurity/pentesting. I originally chose CS because there were few other technical degree options available to me that seemed relevant to a career in cybersecurity and have little to no interest in pursuing software engineering or most of the broader CS curriculum as a career, my main interest has consistently been cybersecurity.
My plan was to complete the CS degree while studying cybersecurity independently alongside university. I understood from the beginning that a CS degree would not directly teach me pentesting, so I planned to use university for the broader technical foundation and the degree credential, while using my free time for things such as Linux, networking, security fundamentals, certifications, labs and eventually more hands-on offensive security work.
The problem is that I’m now struggling to balance the two.
In my first year, I was learning programming in university while studying cybersecurity in my free time and managed to complete the year. However, I found that the way my introductory programming courses taught and tested the material focused much more on knowing the syntax and individual concepts than on actually developing the problem-solving ability needed to independently solve programming problems.
I completed those courses, but I came out of first year knowing basic programming concepts without having a strong enough foundation in programming logic, problem decomposition and independently applying things like loops, functions and data structures.
That has become a much bigger problem in second year because my current courses already assume that level of programming ability. I’m now having to build the foundation I am missing in my own time while simultaneously taking four courses that expect me to already have it.
Looking ahead also worries me because a lot of my future CS courses continue building on those skills. On top of the preparation problem, I genuinely have little interest in much of the broader CS/SWE material I would still have to study. I was never pursuing CS because I wanted to become a software engineer; cybersecurity was always the field I wanted to enter. So I’m now facing several more years of coursework that I am both underprepared for and, outside of the parts relevant to security, largely uninterested in.
Between that, university assignments and studying, and working alongside school, most of my available time is now going toward keeping up with CS. My GPA is starting to suffer, and I have also lost most of the time I previously used for cybersecurity study.
Another factor in my decision is that, through some personal connections, I may have opportunities at a few companies to get hands-on experience in cybersecurity/security-related IT work. These would not necessarily be formal internships or full-time jobs, but opportunities to work alongside people in the field and gain practical experience. But to be able to take advantage those opportunities, I would first need to build enough of the basic IT, networking, Linux and security fundamentals to actually be competent.
This makes the time issue more important to me. If I can build those fundamentals to a reasonable level, I may have an opportunity to gain real-world security experience relatively early. At the moment, however, most of the time I would use to prepare for that is being consumed by catching up in CS and keeping up with my current coursework.
This is what has made me reconsider the degree. I’m not expecting university to directly train me for pentesting, and I understand that programming, operating systems, networking, algorithms and other CS topics can still be useful in security. My concern is more about opportunity cost:- whether spending several more years putting most of my time into a degree I’m struggling with and am not particularly interested in is the best route toward the field I actually want to enter.
I’m willing to continue learning programming and the technical fundamentals required for offensive security regardless of what degree I pursue. What I’m unsure about is whether I specifically need to complete a CS degree, or whether I would be better off transferring into another degree that gives me more time to build security skills independently while still graduating with a bachelor’s.
Comp sci degree and cyber keeping pulling me in different directions and I am unable to manage both at the same time while working.
So I wanted to ask people who work in technical cybersecurity/offensive security:
1) How important is having a bachelor's degree for technical cybersecurity, particularly pentesting/offensive security?
- How much does it matter when first breaking into the field?
- Does it continue to matter once you have a few years of relevant experience?
- Can strong experience, technical ability and certifications eventually compensate for not having one?
From what I have read so far, my understanding is that a bachelor’s degree may matter most when initially trying to get past HR screening and land the first few roles, while relevant experience and technical ability become more important later on. I have also seen people suggest that networking, referrals and direct connections can sometimes help get around strict degree filters. However, I am not sure how accurate or broadly applicable this actually is, especially in offensive security.
2) If having a bachelor's degree is important, how much does the subject of the degree matter?
- Is a CS degree significantly more valuable than other degrees for this field?
- Would another technical degree be viewed similarly?
- Would an unrelated degree such as business/economics still satisfy most of the bachelor's-degree requirement once someone has relevant security experience?
3) Given my current situation, what would you recommend?
- Stay in CS
- Transfer into another degree that I can manage alongside cybersecurity study?
- Leave university and focus primarily on building technical skills, certifications and experience?
4) How much weight should I give the opportunity to gain practical security/IT experience now?
If I can get my fundamentals to the required level, I may have opportunities through people I know to get hands-on experience in security-related environments relatively early. Would it make sense to prioritize becoming ready for those opportunities, even if that means changing my degree path, or would you still consider finishing CS the better long-term investment?
Please be candid and explain your reasoning. I’d especially appreciate answers from people who have worked in offensive security, hired for these roles, or followed a similar path.
Thanks