Forward:  I've seen many articles on breaking into the cybersecurity field from bloggers, journalists, and content creators, but I have yet to hear from hiring managers. This article seeks to change that.

 

Introduction to the Cybersecurity Job Market

 

Critical energy pipelines have shut down, stopping the essential flow of fuel. Distressed hospitals are forced to turn away patients from Emergency Rooms. Production on manufacturing lines has come to a halt. In all cases, people are scrambling about responding in panic. These aren't the scenes from an apocalyptic movie; they are real scenarios that play out daily due to cyber-attacks. However, with the proper training, you can help prevent these situations. Cybercrime has become a critical risk for every business, for you as a person who must protect your identity, credit, and medical records, and even for our nation. A cybersecurity report by govexec.com estimates that government agencies have seen a 40% increase in attacks in recent months.

 

Because of these larger-than-life events, cybersecurity has become an in-demand career field. It boasts exceptional pay, it may offer remote work possibilities, and it can be intellectually stimulating. Finally, considering lives are on the line because cyber attackers are targeting hospitals and critical infrastructure, a great deal of satisfaction can come from this line of work. 

 

However, the cybersecurity industry has an unfavorable reputation for being difficult to break into. In this article, we will explore those perceptions to see if they are reasonable. Evaluate the evolving cybersecurity landscape to see if changes in hiring practices are warranted. And explore why those perceptions have become so commonplace.

 

 

What is cybersecurity?  According to the Cybersecurity & Infrastructure Security Agency (CISA), cybersecurity is "the art of protecting networks, devices, and data from unauthorized access or criminal use and the practice of ensuring confidentiality, integrity, and availability of information." This definition, while accurate, fails to provide a clear view of the day-to-day activities of someone who works in the field. Cybersecurity professionals perform various tasks, including operating software such as vulnerability scanners, configuring network devices such as firewalls, and analyzing logs in security information and event management (SIEM) systems. Other cybersecurity-adjacent roles involve governance, risk, and compliance (GRC) tasks typically related to compliance or regulatory activities. GRC roles are commonly less technical and focus on the proper execution of I.T. or cybersecurity processes.

 

How is all this relevant to your job search? There are multiple areas within cybersecurity for both technical and process-oriented individuals. Cybersecurity is one of the most in-demand jobs today; statista.com reports over 750,000 unfilled cybersecurity jobs in the United States as of 2023. The Occupational Outlook Handbook by the U.S. Bureau of Labor and Statistics states that the job outlook for cybersecurity between 2021 and 2031 will increase by 35%, which is "much faster than average." The median pay for an "Information Security Analyst," according to the U.S. Bureau of Labor Statistics, is $102,600 annually. Cybersecurity does not require an advanced degree such as a Master's or PhD, and cybersecurity requires less than five years in a related occupation. All this information should bode well for cybersecurity job seekers in terms of job security and salaries within the field over the next decade. 

 

Common Cybersecurity Jobs

 

When individuals think about cybersecurity roles, several jobs come to mind. 

 

  1. hacker, aka penetration tester
  2. cybersecurity analyst 
  3. cybersecurity engineer
  4. governance, risk, and compliance specialist

 

The most common job people think about in cybersecurity is the "hacker" or penetration tester; there was a whole movie named Hackers.  According to Glassdoor.com, a penetration tester's median salary is $115,067, with a high-end earning potential of $194,000. The job definition provided by Glassdoor should be more accurate based on our experience. Penetration testers generally do not "implement systems and processes intended to keep electronic information private and secure," as Glassdoor states. Penetration testers commonly find weaknesses and vulnerabilities in information systems for their customers and generate a report of findings based on those weaknesses. 

 

Based on our experience working with almost 1,000 companies across the United States, the cybersecurity engineer is the most common cybersecurity job. The Glassdoor definition of a cybersecurity engineer job is reasonably accurate. Glassdoor states a cybersecurity engineer's role includes: "Information security engineers plan, design, build, and integrate tools and systems that are used to protect electronic information and devices." Glassdoor also stated that a cybersecurity engineer's median salary is $131,678 and can achieve a high end of $212,000 annually. To succeed in this role, a cybersecurity engineer must be competent in many systems engineering domains. Understanding networking principles, operating system configuration and hardening, protocol details, cloud operations, identity governance, and more are critical elements for the cybersecurity engineer. The cybersecurity engineer must be satisfied with something other than the fact that an information system is functioning; it must operate securely. Implementing security best practices across diverse information systems can be challenging due to the time and investment required by the engineers involved.

 

The cybersecurity analyst sits in between the penetration tester and the cybersecurity engineer. A cybersecurity analyst should understand the expected patterns of an information system designed by the cybersecurity engineer. For example, what processes should be allowed to open ports within the environment, the predicted network connections from one system to another, and what approved software, packages, and libraries can be installed on systems. Cybersecurity analysts should also understand how a penetration tester could exploit the systems within the environment. A vulnerability management analyst, for example, must understand the impact of a vulnerability within the environment and how it could be exploited to benefit an attacker. A SOC analyst should be able to identify when a protocol is being used in an unanticipated fashion, which could indicate an adversary being present in the environment, moving laterally from system to system. Again, according to glassdoor.com, a cybersecurity analysis's median salary is $106,568 and may reach a high end of $172,000.

 

A GRC specialist helps define the organization's risk posture and determines the policies guiding the information security program. The GRC specialist is commonly less technical than their cybersecurity counterparts. A GRC specialist should have a strong understanding of the laws and regulations that apply to the business in which they are employed. A GRC specialist also assists the organization in documenting risk tolerances defined by the company's leadership.  Glassdoor.com states a GRC specialist's median salary is $69,736 and may reach $107,000. 

 

Beyond these four common positions are numerous specialty areas within the cybersecurity job field.  The National Initiative for Cybersecurity Careers and Studies has identified fifty-two work roles within the cybersecurity space broken down into seven categories. The seven categories include:

 

  1. Analyze 
  2. Collect and Operate
  3. Investigate
  4. Operate and Maintain 
  5. Oversee and Govern
  6. Protect and Defend
  7. Securely Provision 

 

Some job roles may be more common in specific enterprises. For example, reviewing NICSS job categories, you will find the "Language Analysis" work role under the Analyze section. The language analysis work role is a highly specialized function commonly detecting nation-state threat actors. The language analysis work role is likely more common in the defense industry or military since they deal with national defense more frequently than industries not involved in national security.

 

Small to medium-sized organizations frequently have leaner cybersecurity staff; therefore, team members will probably assume multiple roles and responsibilities outlined in the NIST NICSS workforce framework. Working across numerous cybersecurity domains allows an individual to gain exposure to various cybersecurity disciplines and a more comprehensive breadth of knowledge. Having several domains of responsibility is valuable exposure early in a cybersecurity practitioner's career because cybersecurity roles vary. This exposure will allow a cybersecurity practitioner to select a specialization in the field. 

 

What we would like you to take away from this piece of the article is that many varieties of jobs are available within the cybersecurity field. Some jobs are more technical, others are analytical, and some are process focused. Each job requires different skills and personality traits, which are valuable in building a comprehensive cybersecurity program. 

 

How is the Cybersecurity Landscape Changing, and what is the Impact on Job Seekers?

 

It's not a matter of whether the cybersecurity landscape has changed; it's by how much. Business leaders are trying to determine how severely cybersecurity attacks will impact their organizations. A recent Forbes article stated, "During the past 12 months, 34.5% of polled executives report that their organizations' accounting and financial data were targeted by cyber adversaries." Over the last two decades, the complexity and impact of cybersecurity attacks has grown significantly.  Cybercrime Magazine reported, "Cybersecurity Ventures predicted ransomware damages would cost the world $5 billion in 2017, up from $325 million in 2015 — a 15X increase in just two years. The damages for 2018 were estimated at $8 billion, and for 2019 the figure rose to $11.5 billion." Because of these dire statistics, the cybersecurity job field is increasing at an astounding rate. However, this means businesses desire candidates who can immediately positively impact their organization's cybersecurity posture.

 

Having an immediate positive impact on an organization's cybersecurity posture can be challenging if you're new to the field. Twenty or even ten years ago, the cybersecurity landscape was more straightforward. An organization's typical cybersecurity stack would consist of firewalls to manage ingress and possibly egress traffic, an anti-virus solution that needed definition updates to be applied, and a logging solution that may have provided some baseline alerting and reporting. Operating system security involved administrators patching operating systems, primarily Windows, turning off unused services, and updating software when critical vulnerabilities were discovered. 

 

I.T. environments today are significantly more complex, so a greater breadth and depth of knowledge is required to secure these environments. Today's I.T. infrastructure still exists, but organizations are now using cloud-hosted infrastructure solutions as a service (IaaS); businesses are moving to Software as a Service (SaaS) solutions to reduce maintenance costs and operational complexity. Many organizations are writing custom software to enable a better customer experience. Those developers are likely writing insecure code and deploying that code to hosting solutions in the public cloud, commonly known as Platform as a Service (PaaS). Some businesses are trying to avoid being locked into any one cloud provider and, therefore, use an abstraction layer known as containers. Containers sit on top of an operating system and bring unique security challenges when selecting and securing base container images. Aside from the ever-expanding technical knowledge required to secure an organization, social engineering attacks leveraging phishing and business email compromise are highly effective in bypassing traditional technical security defenses.

 

Due to this evolving I.T. landscape, businesses are increasing their expectations of cybersecurity candidates. Individual cybersecurity candidates will only understand some areas required to protect an organization. Still, many companies have unrealistic expectations; therefore, candidates may feel breaking into the job field is impossible. It is possible to break into cybersecurity, but it requires careful planning, time investment, and determination to achieve the base skills needed. 

 

An Education Plan for Cybersecurity

 

Notice we did not title this section "The Education Plan for Cybersecurity"; there are many ways to break into this career field. Anyone who tells you there's only one way to do something is incorrect or has an ulterior motive. There are many ways to break into the cybersecurity job field; it's a matter of effort, the resources available, and your motivation for going into the field in the first place. When we think about individuals breaking into the occupation, we usually see a handful of scenarios. 

 

  1. Individuals early in their career, just out of high school, or currently taking college courses.
  2. Individuals working outside the I.T. field looking to make a career change, usually to earn more money. 
  3. Individuals already working in the I.T. field looking to make a career change, usually to earn more money. 

 

Each situation will present unique challenges, with option three likely the most straightforward transition into cybersecurity.  

 

Even though there are many right ways to break into the cybersecurity job field, we believe there are three critical criteria that most people would want to follow: 

 

  1. Take on the least amount of debt possible.
  2. Have the shortest time-to-income ratio possible.
  3. Build skills that maximize future opportunities and minimize risk.

 

Managing finances is an entirely different topic, but spending a penny more than necessary to break into a job field seems like an obvious no-no to us. Now that we've established our three guiding principles, we will focus on a path for individuals just getting out of high school or possibly just beginning college. Many of the steps outlined here directly apply to individuals already working in I.T. but looking to make a career change to earn more money.  

 

Note: We've interviewed many individuals who have been very senior in their careers as infrastructure I.T. engineers. It can be challenging to achieve the same salary when switching to a new field. As a seasoned I.T. engineer, you may be forced to accept a slightly lower wage initially to increase your long-term earning trajectory.

 

Individuals early in their career, just out of high school or college, may be in the most challenging position if they didn't secure any internships throughout college or work in high school. This situation is formidable because you need exposure to how a business operates. When onboarding a new group of college students in our company recently, the trainer commented that she had to spend hours teaching our intern group how to use Microsoft Outlook. This lack of "real world" experience can put a job candidate at a severe disadvantage.

 

However, suppose you're younger and don't have significant debt or responsibilities. In that case, you have the freedom to invest in your career. In this situation, we recommend looking at community colleges in your area and taking as many foundational information technology classes as possible. We do not recommend diving straight into a four-year university; the cost of the entry-level courses at a four-year university will be significantly higher than at a community college.

 

When evaluating community colleges, you should look for several types of core I.T. courses. We recommend investing in four topics as a foundation to build upon.

 

  1. Microsoft Windows Client and Server platforms.
  2. Linux (server) Red Hat based Distributions and Debian-based distributions.
  3. Networking courses, preferably from a college that is a Cisco Networking Academy.
  4. Introduction to computer science with Python, if available.

 

If your community colleges offer courses in cybersecurity, take them after you've taken these courses. These four topics above will give you context for what you're learning in your cybersecurity classes. It's much harder to understand how an exploit works for an Apache webserver running on a Linux operating system if you don't know what a Linux operating system is.

 

A strong indicator that these community college classes are good quality and will help you in your job ambitions is if they map back to industry certifications. The Cisco Networking Academy, maps to the Cisco CCNA certification, which many organizations value. Some colleges have Windows courses that map back to Microsoft certifications or Linux courses that map to the Linux+ certification. If the college has a course that maps to the Security+ certification, that would be a good choice since the Security+ is a solid entry-level certification. 

 

If you are fortunate enough to have multiple community colleges in your area, see if / what community colleges have articulation agreements with four-year universities. Even if you have no desire to attend a four-year university now, you may change your mind in the future, and it's good to have the option to transfer quickly. Also, if evaluating multiple community colleges, see if they have 3+1 articulation agreements with local four-year universities. We will touch more on 3+1 articulation agreements shortly. 

 

If you're looking for an associate degree, see if your college offers an associate in computer science. Many businesses view computer science as a "hard(er) science." In our experience, hiring managers view a generic technology management degree with a lower prestige than a degree in computer science. Take all the courses mentioned earlier as electives on your journey to your computer science degree.

 

Another reason we recommend computer science is that even though you're working towards a career in cybersecurity, the field is changing. We're beginning to transition into a phase where automation in cybersecurity is becoming the new normal. If you can write scripts to automate routine tasks, or work on security automation platforms, you set yourself apart from your peers. 

 

As we navigate our journey, we want to stay focused on the principles we spoke about above:

 

  1. Take on the least amount of debt possible.
  2. Have the shortest time-to-income ratio possible.

 

So, we recommend two additional things if you're fresh out of high school. This advice will not apply to college grads. 

 

  1. See if your community college has a 3+1 articulation agreement with a local university.
  2. After you have your associate degree, get a job in I.T.

 

After your associate degree, get a job in I.T. as soon as possible! I've taught at local colleges in my area and seen many people passed over in favor of another candidate with "experience." It can be challenging to break into the I.T. field; still, you can get your foot in the door at a company via a help desk, as a low-level network admin, or in a systems admin position. These jobs may allow you to start taking on cybersecurity responsibilities within that company. Taking on cybersecurity responsibilities is easier in smaller companies with zero security staff: start performing the security tasks in addition to your regular duties. First, this gets you a paycheck in an adjacent field you're trying to break into, and second, it allows you to start building your resume.

 

Principle 1: "Take on the least amount of debt possible."

 

Computer science is the preferred degree because it will increase your earning potential. Suppose you're in a help desk position; you will almost certainly have a lower salary than an entry-level software engineer. If you follow this plan, you will have two years of real-world job experience, a four-year degree, and minimal, if any, student loan debt.  Glassdoor.com says a software developer with 0-1 years’ experience earns $82,644 a year, a sharp increase from the reported helpdesk technician salary of $47,123.

 

Principle 2: "Have the shortest time-to-income ratio possible."

 

As you finish your courses at a community college, if you'd like to get your bachelor's degree, be very careful how you accomplish it. First, you can skip attending a big-name school to get a cybersecurity job. 99.9% of hiring managers will not care where you went to school or your GPA. This being said, look for what's referred to as a 3+1 articulation agreement. A 3+1 articulation agreement allows you to take three years of courses at a community college and transfer those credits to a four-year university. With the extreme costs of four-year universities, this can save you tens of thousands of dollars. If you can find a 3+1 articulation agreement for computer science, that is your best course of action in our opinion.

 

 

Principle 3: "Build skills that maximize future opportunities and minimize risk."

 

Life is good, and you've completed college with an in-demand degree. You'll likely be tempted to start spending that fat salary increase, but DO NOT! You're almost there, but you're not out of the woods yet when it comes to investing in your education and your future. 

 

Your After-College Plan for Cybersecurity

 

You should be in a strong position if you've stayed on track. Now that you have strong skills, and a solid paycheck comes the next phase. Start networking within your local geographic community. You can start networking at any point in your journey, but you will find many industry groups don't cater to students. You should locate your local ISC2 Chapter; ISC2 is well known for its CISSP certification. ISC2 has a chapter directory list to help you find your local community; you can locate the ISC2 chapter directory list here. Like the ISC2 organization, you'll also want to start networking with the ISACA chapters. ISACA tends to focus more on audit and governance risk and compliance, but hiring managers are frequently members. You can locate the ISACA local chapter directory list here. In addition to these well-known organizations, there are frequently local cybersecurity communities in major cities. You must be aware of the significance of networking in your job search. Cybersecurity is a tight-knit community, and building and establishing a good reputation is critical for your career.

 

Finally, it's time to look at the expensive certifications. SANS... When we started in cybersecurity, you could take a SANS course for roughly $4000. Back in my day, things were a lot cheaper; damn inflation! Today, for an in-person 5-day SANS course, you'll spend roughly $10,000, including the certification voucher. SANS certifications are expensive, but they are highly regarded.

 

However, there are ways to avoid paying such a high price. SANS has a program for In-Person Facilitators, which reduces the course cost to $2500. I want to avoid getting into the details of SANS, but you can locate details on the SANS work-study program here.  We recommend the SEC401: Security Essentials (GSEC) course on the SANS website. The SANS certification will establish a solid foundation built upon the technical knowledge you've developed up until now.  

 

 

At this point in your journey, you should be well-positioned to break into the cybersecurity field. You will have the trifecta of what organizations look for:

 

  1. A degree in a "hard" technology field (computer science),
  2. several certifications that are relevant to your career,
  3. and job experience in one or more I.T. domains. 

 

At this point, many people make what we believe is a mistake; they acquire their CISSP certification.  According to ISC2, the CISSP certification is intended to prove that you, as a cybersecurity practitioner, can "design, engineer, implement, and run an information security program." The CISSP certification is intended to validate a cybersecurity practitioner's experience. However, at this stage in your career, you need more experience to complement the CISSP certification. This combination of experience and credentials may lead to a situation where you are underqualified for a senior cybersecurity role but overqualified for junior positions due to your CISSP certification. Ensure that your resume is tailored for the cybersecurity positions you're applying for. You're not applying for a cybersecurity manager position when you have four years of experience. If you want to, and we recommend you do, keep investing in more certifications, we advise the SANS route. They offer many classes that can suit almost any interest in this space.

 

Now that you have the skills required for your cybersecurity career, you need to know getting your first job in cybersecurity is more than technical aptitude. Getting hired is just as much an art as a science, and you must hone your interview skills. There are enough interview topics to fill a volume, so we will not cover that here. We will publish a multi-part video interview series with recruiters and human resources executives to help you navigate that process. We will discuss how cybersecurity candidates can set themselves apart to stand out from the crowd during the interview process. You can sign up here for notifications to be informed when the interview series is published. Understanding what hiring managers and recruiters are looking for can be the difference between landing a job or having your resume in the trash pile.

 

Level of Effort vs. Reward: Is it Worth it?

 

As you can see, this is not a get-rich-quick scheme; this is a long-term approach to building a career. We are frequently frustrated with Six-Figure Career Coaches promising a fast path to a high-paying job. Is it possible? It is, but it's also possible to win the lottery. We don't promote career "hacks" or shortcuts; we encourage hard work, discipline, and diligence. How do the financials play out if we compare the earning potential of cybersecurity against another high-paying career, such as a medical doctor?

 

According to the U.S. Bureau of Labor Statistics, physicians and surgeons have a median pay of $208,000 a year. When comparing cybersecurity to the medical profession, you must remember that a doctor must take 12 to 20 years of schooling. A cybersecurity professional would take a fraction of that schooling. Because of the ability of individuals to start earning money earlier in their careers, there can be a significant difference in student loan debt. A Forbes magazine article made this astute observation, they stated: 

 

"A career as a physician can be a rewarding profession, but one that's generally mired with student loan debt. The Association of American Medical Colleges (AAMC) reported that the median medical school debt among the Class of 2021 was $200,000, not including their undergraduate debt."

 

The median cybersecurity salary is lower, but top-end salaries can approach this mark. Additionally, depending on what direction you'd like to take your career, you can find job postings for $230,000 as a cybersecurity pre-sales engineer. This career involves a cybersecurity engineer who assists an organization in sales campaigns for products or services. While the job postings we found on indeed.com peaked at $230,000 a year, we know many pre-sales engineers who are making much more, getting closer to $300,000 in base pay plus bonus. 

 

Cybersecurity jobs will not reach the high end of the physicians' and surgeons' pay range. However, cybersecurity professionals spend anywhere from 8 to 16 fewer years in college and will likely have significantly less student loan debt. This field provides exceptional earning potential when compared to the investment required.

 

Next Steps in Your Cybersecurity Career 

 

Don't believe people who say that breaking into the cybersecurity career field is easy because it's not. There may be a lucky few who accomplish the task quickly, but breaking into the field requires hard work, a non-trivial amount of knowledge in several domains of I.T., and a desire to continue learning throughout your career because the cybersecurity landscape is constantly changing. Please don't buy into get-rich-quick cybersecurity schemes; cybersecurity can provide a solid career field with longevity, but it takes time and effort.

 

If you've found this article helpful, download our eBook, which is full of knowledge from interviews with CISOs, cybersecurity hiring managers, directors, job recruiters, and more. These individuals share what makes a candidate stand out, the specific skill sets that are in demand in the field today, and what they are looking for in the future.