SaveMyCert
Career paths

How to start a career in cybersecurity: an honest roadmap

Starting a career in cybersecurity usually means building core IT and networking fundamentals first, then adding security knowledge, an entry-level certification, and hands-on practice — most people enter security from an adjacent IT role rather than straight from zero. That sequencing is the single most important thing to understand about the field, and it is the part most heavily marketed courses skip: security work is the work of protecting systems, so employers strongly prefer people who understand systems before they trust them to defend any. The good news is that the path is legible and genuinely open to career changers — it just runs through fundamentals rather than around them. This article maps that path honestly: the skills to build, the certifications that help, the realistic entry routes and first roles, the hands-on evidence that separates candidates, and the growing cloud-security overlap worth aiming at.

The honest reality: security is rarely a first tech job

Cybersecurity is usually a second step in a technology career, not a first one. The reason is structural rather than gatekeeping: a security analyst triaging alerts needs to recognise what normal system behaviour looks like, which means having administered systems; an engineer hardening a network needs to understand how networks are built; someone reviewing access needs to grasp how authentication and permissions actually work in practice. That knowledge comes from doing IT work, and employers know it — which is why many adverts labelled “entry-level security” quietly assume a year or two of IT support, helpdesk, networking or sysadmin experience underneath.

None of this means the field is closed to you. It means the realistic plan is either to enter via an adjacent IT role and pivot — the most-travelled route — or, if you are targeting security directly, to build demonstrable fundamentals and hands-on evidence so convincing that they substitute for job history. Both work. What does not work is a certificate alone: anyone promising that a single course or badge lands a security job is selling, not advising.

The foundations to build first

Before security knowledge comes systems knowledge. The foundations that security hiring consistently assumes:

  • Networking — how traffic moves, what protocols do, how networks are segmented and where their weak points are. Most security work is unintelligible without this.
  • Operating systems — comfort administering both Windows and Linux: users, permissions, services, logs. Defenders live in system logs.
  • Identity and access — how authentication, authorisation and permissions work; our explainer on what identity and access management is covers why this has become security’s centre of gravity.
  • Basic scripting — enough Python or shell to automate a repetitive task and read someone else’s script. You do not need to be a developer; you do need not to fear code.
  • How systems fail — the attacker’s perspective on all of the above: common attack techniques, misconfigurations and the human factors behind most breaches.

The certification on-ramp

Entry-level certifications play a real but bounded role: they signal commitment, structure your study, and pass CV screens — they do not substitute for the fundamentals above. The two best-known are ISC2’s Certified in Cybersecurity (CC), a lighter and cheaper multiple-choice credential from the body behind the CISSP, and CompTIA Security+, the broader, longer-established option that many employers name explicitly. Our comparison of entry-level cybersecurity certifications weighs them properly; either is a defensible first badge, and our full guide to the ISC2 CC covers that route in depth.

Vendor certificates exist too — Google’s Cybersecurity Certificate is a structured beginner programme, and the cloud providers offer security-focused credentials at various levels. These can be useful study scaffolding, especially the hands-on ones. The rule that keeps you honest: pick one entry certification, pass it, and put the rest of your energy into fundamentals and practical evidence rather than collecting badges. Job adverts in your own market are the best guide to which credential carries local weight.

Entry routes and realistic first roles

The most common doorway into security is the SOC analyst role — monitoring alerts, triaging incidents and escalating what matters. The work can be repetitive, and shifts are common, but it is genuine security experience that compounds fast, and it is the field’s established first rung. The second classic route is the pivot: IT support, helpdesk, networking or sysadmin roles that you deliberately steer towards security — volunteering for access reviews, patching, log work — until a security title becomes the natural next step. This route is slower on paper and often faster in practice, because you accumulate exactly the systems experience security hiring wants.

Two further doors are worth knowing. Governance, risk and compliance (GRC) roles — audits, policies, risk assessments — sit closer to process than to terminals, and can suit career changers from business, legal or audit backgrounds who bring transferable skills. And junior security analyst or security operations roles at smaller companies can be broader than SOC work at large ones, trading structure for variety. Read live adverts for all of these in your market: the requirements listed there are the real syllabus.

Build evidence, not just credentials

What separates two candidates with the same certification is demonstrable work. A home lab is the classic move: a few virtual machines where you run a small network, break it, monitor it and write up what you found. Capture-the-flag platforms and structured labs give you guided attacking and defending practice with visible progress. Contributing write-ups — of labs completed, of a vulnerability class you studied, of how you configured logging in your lab — turns private learning into public evidence a hiring manager can actually read.

The habit underneath all of this is documentation. Security work is investigative and communicative — findings must be written up, incidents reported, risks explained to non-specialists — so a candidate who documents clearly is showing a job skill, not just study. A modest portfolio of honest write-ups beats a long list of course completions.

The cloud overlap, and a realistic word of encouragement

Security work is following the systems it protects into the cloud, and the overlap — cloud security — is one of the strongest destinations available: identity becomes the perimeter, misconfiguration becomes the classic breach cause, and detection runs on cloud-native logging. This cuts both ways for a newcomer: cloud experience is itself one of the best security entry routes, and security fundamentals make you a stronger cloud candidate. Our articles on cloud versus cybersecurity careers and the cloud security engineer career path map that ground; the short version is that learning some cloud alongside security keeps your best doors open.

The honest close: this career is genuinely accessible with sustained effort — the field is open to career changers, the learning materials are abundant and cheap, and the entry routes are well-trodden. But “get certified and walk into a six-figure job” claims are misleading, and we will not repeat salary figures here; live job adverts in your market are the evidence worth trusting. Expect the path to take real time, expect the first role to be unglamorous, and expect the compounding to be worth it.

Ready to start studying — free?

Original practice questions, timed mock exams and revision notes. No card, nothing to pay.

Jump straight into an exam
CLF-C02SCS-C03

Questions, answered

Yes, but rarely in one jump — most people enter from an adjacent IT role such as support, networking or system administration, because security work assumes you understand the systems you are protecting. The realistic zero-experience plan is fundamentals first (networking, operating systems, identity), an entry certification such as the ISC2 CC or Security+, and hands-on lab evidence, often via an IT role on the way.

Keep reading

Career paths
The Azure administrator career path, explained
Career paths
Cloud network engineer career path: skills, certs and how to start
Career paths
The cloud support engineer career path, explained
Career paths
Data engineering vs cloud engineering: which path fits you?