These are practitioners I’ve connected with on my own journey. I asked them what they’d tell someone just starting out.

Path Into The Field: 

“I guess I’d have two thoughts. No, a Tier 1 SOC analyst is not the only or even best way in. 

In fact in the age of AI, those jobs are at risk. I’d say get any foot in the cyber door. 

Consider control testing and other GRC roles and even audit, training and awareness, etc. 

If you go back to school, make sure your program includes hands-on projects you can cite on your resume and has a solid pipeline with employers for internships and hiring.  

I see people getting low value  degrees that aren’t adding much to their prospects, just debt.”

- Jenny Menna, Chief Security Officer, Sallie Mae

“The fastest way to fail a career transition is trying to navigate it in isolation. Secure an active practitioner as a mentor to shorten your technical learning curve, and partner with a career coach to effectively translate your background into security value."

- T. Brad Kielinski, Founder of IT Pros and Philly Tech Exchange

Career Navigation:

“As you begin your cybersecurity journey, remind yourself we are all at different levels. Think of it as a book. We all start on page one, move to page two, all the way to the end of the book. You have to read every page, otherwise you may miss something really important. You also notice that everyone reads at a different pace. And everyone is on a different chapter of the book or a different book in the series. This is true with your cybersecurity experience as well. Enjoy the storyline, and keep turning the page." 

- Dara Gibson, CEO, Cyber Ready

“1. Take notes

2. Time management and breaks are key

3. Your attitude can make the problem better or it can make it worse. 

4. Pick jobs for growth if you can afford to 

5. This job can feel like you’re always at odds with everyone. Remember you’re on the same team.” 

- Leonardo Serrano, Security Architect and Community Organizer, Wawa, Inc. 

Technical Foundations: 

“1. Experience using SIEM tools. 

In my experience, cybersecurity training focuses heavily on teaching concepts and command line tools, with a lab or two devoted to using the SIEM. 

The SIEM is a tool I use every day as a security analyst. 

Some very important skills for my position include being able to create usable queries, assess collector health, and improve detection rules. 

2. Basic IT experience can be very helpful for breaking into Cyber. 

A hiring manager interviewing for a SOC role will want to see that you have a strong understanding of DNS, networking, and Active Directory. 

You can get exposure to all of this stuff and more by working in IT support.” 

- Nathan Elliot, Cybersecurity Analyst, ReliaQuest | Incident Response, Threat Detection, Security Engineering