Can I land a cybersecurity job with weak academic percentages?
I'm a recent MCA graduate (6.72 CGPA) and currently building my career in cybersecurity, mainly focused on web security / offensive security.
My academics are probably the biggest weakness on my profile:
- 10th: 50%
- 12th: 55%
- MCA: 6.72 CGPA
But I've spent a lot of time building practical skills outside academics.
Current skills / experience
- Linux
- Networking
- Operating systems
- Cybersecurity fundamentals
- Python
- Bash
- Web security
- Burp Suite
- Caido
- Nmap
- Wireshark
- John the Ripper
- Metasploit
- Netcat
- Gobuster
- Subfinder
- Amass
- Katana
- DNSx
- AlterX
- HTTPx
- OSINT
I've completed 100+ TryHackMe labs, I'm currently around the top 5% on THM, and I've also completed roughly 100+ PortSwigger Web Security Academy labs.
I'm well beyond the absolute beginner stage at this point. I'd consider myself somewhere around intermediate, with a strong focus on networking, operating systems, cybersecurity fundamentals, and hands-on web security.
Right now I'm working on VDPs (Vulnerability Disclosure Programs) to gain experience dealing with real-world targets and vulnerability research. My longer-term goal is to move into bug bounty programs and continue building a track record of practical security work.
My concern
The biggest thing holding me back seems to be my academic record.
I'm worried that the 50% in 10th, 55% in 12th, and 6.72 CGPA in MCA will prevent me from getting into cybersecurity, regardless of my practical skills.
For people already working in cybersecurity:
Can someone with this academic background realistically land a cybersecurity job?
What kind of challenges should I expect during hiring?
Should I focus primarily on:
- Building a strong GitHub/portfolio
- Writing detailed vulnerability reports
- VDP/bug bounty experience
- CTFs/labs and certifications
- Networking with security professionals
- Applying to smaller companies/startups first
Or are there specific types of cybersecurity roles/companies that are likely to reject me automatically because of academic cutoffs?
I'm looking for honest advice from people who have actually gone through cybersecurity hiring. If academics were a weakness in your own career, how did you compensate for them?