r/SecurityCareerAdvice

▲ 1 r/SecurityCareerAdvice+1 crossposts

Is getting a degree in CS worth it in the future? I'm so confused about this whole degree thing! And about getting a job, too

So, next year I'm going to college, and I've always been interested in Cybersecurity. But for the last few weeks, I've been researching its job market, and it was awful to see how bad the market is; seriously, people with years of experience and technical skills are not getting jobs.

Because of this, I am genuinely scared to go into a CS major,

I really need help. What should I do?

reddit.com
u/SleepCareful404 — 1 day ago

Where to start?

Bro I just turned 26 and I’m trying to get into cyber security. I wanna be a pen tester how do I start my journey. I have 0 experience but I’ve been using hack me and hack the box for a few days but I wanna spend at least 30-45 more days just learning the basics through those type of resources before actually enrolling in school. Any advice would help

reddit.com
u/Particular_Set6648 — 1 day ago

What is the consensus on SANS/GIAC certs?

I’ve heard they are like the gold standard I have also heard they are overpriced as well. What’s the general consensus? Are they good at gauging if someone can do the work or are they better as a way to bypass a resume filter?

reddit.com
u/Many-Midnight-1972 — 1 day ago
▲ 98 r/SecurityCareerAdvice+103 crossposts

I Tried ChatGPT to Fix My Resume. Here’s Why It Missed the Point.

Comparing https://resume.zoevera.com against https://chatgpt.com

And what a purpose-built ATS checker caught that GPT-4 didn’t.

Let me be upfront: I use ChatGPT for everything. Code reviews, draft emails, explaining stack traces at 2am. It’s genuinely useful. So when I needed to tailor my resume for a senior backend role, my first instinct was to open a chat window.

That was three weeks ago. Here’s what I learned.

What ChatGPT actually does well

Ask ChatGPT to “improve my resume” and it will:

  • Clean up passive voice (“responsible for” → “led”)
  • Suggest stronger action verbs
  • Add structure and formatting consistency
  • Rewrite vague bullets into something that sounds more impressive

For general writing quality, it’s genuinely good. If your resume reads like it was written by someone who hasn’t slept in 48 hours, ChatGPT will fix that.

What ChatGPT fundamentally cannot do

Here’s the problem: ChatGPT doesn’t know what job you’re applying for.

You can paste the job description into the prompt, sure. But there’s no mechanism for it to:

  1. Score your resume against that specific JD — it has no concept of a match percentage
  2. Identify which keywords are present vs. missing — it will suggest improvements but won’t systematically audit keyword coverage
  3. Know how Applicant Tracking Systems parse text — it will rewrite content without knowing whether an ATS will ever see it

ATS filters work on keyword frequency and placement. A resume that reads beautifully to a human can score 40% on an ATS if the right terms aren’t in the right sections. ChatGPT optimizes for human readers. ATS systems are not human readers.

I ran a test. Same resume, same job description (Backend Engineer, Node.js/AWS stack). I gave ChatGPT the full JD and asked it to optimize my resume for ATS.

The output was well-written. It added “microservices” and “REST APIs” in a few places. But it missed:

  • “AWS Lambda” — mentioned 4 times in the JD, absent from my resume after the rewrite
  • “CI/CD pipeline” — appeared in the required skills section, never added
  • The Projects section — ChatGPT rewrote my experience bullets but left the Projects section untouched, which is where most of my relevant backend work lived

When I ran the same resume through resume.zoevera.com, it flagged all three gaps explicitly, with section-level attribution. The ATS match score went from 54% to 81% after applying the suggested changes.

The core difference: diagnostic vs. generative

ChatGPT is a generative tool. It produces new text. It’s very good at that.

An ATS checker is a diagnostic tool first. It measures the gap between your resume and a specific job description, then tells you exactly what’s missing. The rewrite comes second — and it’s grounded in what was actually identified as absent, not what the model thinks sounds better.

This distinction matters because:

ChatGPT hallucinates improvements. It will add metrics you never achieved (“improved system performance by 35%”), use terminology that
sounds right but wasn’t in the JD, and rewrite bullets that didn’t need rewriting while leaving critical gaps untouched. Every line needsfact-checking.

A purpose-built tool works from the actual gap. The keywords it adds are the ones the JD asked for. The sections it flags are the ones the ATS will score. The output is closer to submission-ready.

A practical workflow

These tools aren’t mutually exclusive. The best result I got came from using both in sequence:

  1. ATS checker first: identify the keyword gaps and get a scored rewrite that closes them
  2. ChatGPT second: use it to polish tone, tighten sentences, and clean up anything that sounds mechanical

The ATS checker handles precision. ChatGPT handles prose quality. Neither does both well alone.

The cost argument

ChatGPT Plus is $20/month. If you’re actively job searching, that’s a fixed overhead whether you use it or not.

Most people search for jobs in windows — a few weeks of active applications, then nothing for months. A per-session model makes more
sense: pay when you need it, nothing when you don’t. ZoeVera’s pricing works that way — free analysis, one-time payment for the full
rewrite, no subscription.

For a developer audience specifically: if you’re applying to 10–15 roles over two weeks, you’re not optimizing resumes 365 days a year. The math on a monthly subscription doesn’t work.

What I’d actually recommend

  • If you just need better writing: ChatGPT is fine and you already have it
  • If you’re applying to roles where ATS filtering is real (any company using Workday, Greenhouse, Lever, iCIMS): use a dedicated ATS checker first, then polish with ChatGPT
  • If you’re a developer and haven’t thought about this: your resume probably uses technical jargon that means something to you and nothing to an ATS keyword parser. “Built scalable backend” is not the same as “developed microservices architecture using Node.js and AWS ambda” — even if the underlying work is identical

The ATS doesn’t know what you meant. It only knows what you wrote.

Tested against a real Backend Engineer job description. Tools used: ChatGPT GPT-4o, https://resume.zoevera.com. June 2026.

u/Enough_Charge2845 — 2 days ago

I want to start a career in CS but don't know where to start.

As the title suggests i want to start to get into cybersecurity, and do a career change. Previously i've done some programming mainly python, and some JS. Thing is i don't really know where to start everyone has a different opinion on where to start, and some make it sound very complicated. I've found a couple of courses on udemy regarding the COMPTIA A+. But i don't think that would he enough to start a career. After a lot of searching as well they recommended that i should learn networking along the way, and forensics.

Any help would be very appreciated, and when should i start learning networking?

reddit.com
u/OGR3PEAR — 1 day ago

I was almost pushed into resigning this morning. What should I do to make sure they fire me and I don't hurt myself?

A few days ago, I accidentally overheard my Chair, who has a very loud voice, saying from behind the conference room door: "We're going to let her go early next year." I had a bad feeling she was talking about me, and it turned out she was. (For context: I basically don't have any coworkers. It's a very small nonprofit with 4 people above me, and then I'm at the bottom of the ladder.)

This morning I was called in, and the president told me, verbatim: "There's no easy way to say this, but we're going to have to let you go." Then she explained the reason: that I'm not the right fit. I asked her directly whether I had done something major or if there was any misconduct, and she confirmed no, there was nothing like that. Then she gave me some vague feedback that wasn't very useful, and asked me when I wanted my last day to be.

I was very surprised, because in my head I was thinking... You just told me I'm being let go?? So I asked her, but in a calmer and more professional way, to clarify. So I asked her honestly but politely: "Are you asking me to voluntarily resign?" She got flustered and said: "No, no, we just want to know what your three weeks will look like. Think about whether you want to stay until October. You don't have to decide right now."

Am I understanding this correctly that they're trying to get me to leave the job on my own so they can avoid firing me/paying unemployment/or something else? I'm thinking I need to create an electronic paper trail immediately, because other than a lukewarm performance review from 4 months ago (which, looking at it now, may have been a half-assed PIP), the entire conversation was verbal. I feel like they're trying to gently trick me into resigning, right? She was strangely nice the whole time, which honestly made the whole thing even weirder.

reddit.com
u/Financial-Ring-9118 — 1 day ago

Security Analyst job after diploma vs degree first — which would you choose?

I recently completed a Diploma in Network Security and have been offered a Security Analyst role.

At the same time, I’m considering pursuing a bachelor’s degree in Cybersecurity, Computer Science, or AI.

So I’m stuck between:

  1. Degree first — study full-time, then enter cybersecurity after graduating.

  2. Work first — accept the Security Analyst role now, gain experience, and complete a degree part-time while working

  3. Work for 1-2 years then quit and get a degree full time

I already have some SOC experience from my internship, including SIEM, EDR, alert triage, and incident investigation.

For those already working in cybersecurity, which route would you choose if the goal is to be in the strongest position 5–8 years from now in terms of salary, career progression, and job opportunities?

Also, how realistic is it to do a part-time degree while working in a SOC, especially with shift work?

reddit.com
u/Swimming-Beach616 — 1 day ago
▲ 5 r/SecurityCareerAdvice+1 crossposts

Recently graduated in Cybersecurity and really need some career guidance

I never thought I would ask strangers online for help, but honestly, I don't know what else to do right now.

I recently graduated in Cybersecurity and have been applying for jobs, but I'm barely getting any responses. I also need to start earning to pay my bills, and unfortunately, where I live, there aren't really any part time jobs or other opportunities available.

This situation has been affecting me mentally too. I'm struggling with depression and I'm honestly exhausted. I have tried my best to figure things out on my own, but right now I feel completely lost.

I'm looking for someone working in Cybersecurity, IT, SOC, Networking, Cloud, or a related field who might be willing to mentor me or simply look at my situation and give me some honest advice.

I want to know what skills I'm missing, what jobs I should realistically apply for, what I should improve on my resume, and what I should focus on learning.

I want to make it clear that I'm serious about this. I'm not joking or looking for shortcuts. I'm ready to work hard, learn, improve, and put in the time. I just need someone experienced to help me figure out the right direction.

I consider myself good at planning and strategy, but right now I need some guidance from someone who has been through this.

I know this is not the usual kind of post, and honestly I'm embarrassed to even ask. I don't expect anyone to give me a job. I just really need some guidance from someone who has been through this.

If anyone is willing to help, even a short conversation would mean a lot to me.

Thank you for reading.

reddit.com
u/ErenYeagerOn — 1 day ago

Starting my first IT Service Desk role in 2 months. What would you focus on beforehand?

I’m starting my first IT role as a Service Desk Analyst apprentice, gaining an SCQF Level 8 qualification in Cyber Security. My hope is to eventually progress to a more direct cyber security related role.

I have a decent basic knowledge of IT/hardware and roughly 2 months before I start the role due to security clearance.

My plan is to brush up on IT fundamentals (currently going through Professor Messer’s A+), then set up a virtual Active Directory lab to practise AD, Windows troubleshooting, networking and some basic PowerShell.

For anyone who’s worked Service Desk, is there anything else you’d recommend focusing on before starting? Anything you wish you knew going into your first role?

Grateful for any advice!

reddit.com
u/Pap4Chulo — 1 day ago
▲ 32 r/SecurityCareerAdvice+13 crossposts

Syscall monitor

I would like to share my Linux Syscall Monitor project with you. It's a Linux process monitoring tool written in C that uses "ptrace" to observe system calls and generate behavioral reports.

Repo .

I welcome any feedback or criticism—whether it's about the code .

github.com
u/cdtrmnbaell — 2 days ago
▲ 1 r/SecurityCareerAdvice+1 crossposts

Transitioning from Animal Science into Cybersecurity – Looking for Honest Advice

Hi everyone,

I’m currently transitioning into cybersecurity from a completely different academic background, and I’d really appreciate some honest advice from people already working in the field.

My undergraduate degree is in Animal Science from Michael Okpara University of Agriculture, Umudike, Nigeria. I know that’s quite far from cybersecurity, but over the past period I’ve developed a genuine interest in the field and have been working to build my knowledge and practical skills.

My interest became very personal after I experienced cyber fraud twice. I lost my school fees during one incident and later lost my savings through a credit card breach. Those experiences made me want to understand how these attacks happen and, more importantly, how they can be detected and prevented.

Since then, I’ve been learning cybersecurity through self-study and practical training. I have completed Cisco Academy courses/certificates in Introduction to Cybersecurity, Networking Basics, and Operating Systems.

I’ve also had practical exposure through cybersecurity training with SBTS, where I’ve been learning about:

  • SOC operations
  • SIEM and Wazuh
  • Wireshark
  • Nmap
  • Networking
  • Linux/Kali Linux
  • Incident detection and analysis

My current goal is to build myself towards a SOC Analyst / Cybersecurity Analyst career.

I’m also planning to pursue a Cybersecurity Conversion MSc, since my first degree isn't IT-related. I want the MSc to help me strengthen the areas I currently have gaps in and give me a more structured and advanced understanding of cybersecurity.

My biggest question is for people who are already working in cybersecurity:

If you were starting again from my position, what would you focus on over the next 6–12 months?

Would you recommend focusing more on:

  1. Networking and Linux
  2. SIEM tools such as Wazuh/Splunk/Sentinel
  3. Blue-team labs and incident response
  4. Certifications
  5. Building a cybersecurity portfolio/GitHub
  6. Getting an IT/helpdesk/networking role first

I’m especially interested in hearing from people who came into cybersecurity from a completely different academic or career background.

I’m not looking for shortcuts. I just want to make sure I’m spending my time learning the right things and building skills that actually matter in the real world.

Any honest advice, criticism or recommendations would be appreciated.

reddit.com
u/Big-Yoghurt8520 — 2 days ago
▲ 8 r/SecurityCareerAdvice+2 crossposts

Working full-time in enterprise cybersecurity: Does an Online MCA actually clear the MNC/Big-4 HR filter for Senior/Lead roles?

>TL;DR: 21yo working full-time in Cybersecurity Have production projects (custom Coraza-based WAF, Federated Learning IDS) and good trajectory, but holding a 3-year B.Sc CS. Need a Master’s on paper for long-term CISO/Lead filters and the 16-year education requirement without quitting my job. Looking for brutal truth on Online MCA vs BITS WILP.

Hey everyone,

Need some candid advice from folks who have actually broken into Senior/Lead/Management roles in Indian tech/MNCs.

Where I stand right now:

  • Background: 21, B.Sc Computer Science graduate (~8.0 CGPA, heavy upward trend in later sems).
  • Work: Currently working full-time in Enterprise Cybersecurity
  • Constraint: Shift work + full-time job. I cannot quit to sit in a physical MCA classroom for 2 years.

The Problem: I know skills beat degrees in the early game. But looking 5–10 years ahead toward Team Lead, Risk/Governance, and eventual Head of Security/CISO tracks, the lack of a formal Master's degree and the 15-year education barrier (3-yr B.Sc) frequently triggers automated HR rejection filters at enterprise MNCs and Big-4s.

What I'm evaluating:

  1. Reputed Online MCA (e.g., Manipal / Amity): UGC-DEB approved, proctored exams, purely to get the formal Master's checkbox ticked while I keep gaining enterprise YoE.
  2. BITS Pilani WILP (Work Integrated Learning): Heavy brand name, but higher workload and strict academic rigor alongside shift work.

What I want to know from hiring managers, leads, and people who took this route:

  1. In technical interviews and background checks for Mid/Senior roles, does anyone actually scrutinize whether the MCA was online vs regular, as long as it’s UGC-recognized and backed by solid real-world experience?
  2. Is the BITS WILP brand difference worth the extra grind compared to a standard online MCA when paired with continuous enterprise security experience?
  3. If you’ve done an Online MCA while working full-time, how was your experience managing shift/corporate hours with the exams?

Appreciate any no-BS insights from those who have navigated this.

Cybersecurity professionals who moved to Japan – looking for some real-world advice

Hi everyone,

I’m a SOC Analyst from Germany with 10+ years of experience in cybersecurity/Blue Team, mainly SOC, Incident Response, Threat Hunting, EDR/XDR and Microsoft Sentinel/Defender.

My long-term goal is to move to Japan by 2028, ideally working for a gaishikei in Tokyo. I’m currently building my network, learning Japanese and trying to get a realistic picture of the market rather than going into this blind.

I’d really like to hear from people who have already made a similar move, or are currently working toward it.

A few things I’m particularly interested in:

  • How is the cybersecurity job market in Japan right now, especially at gaishikei companies?
  • How important is Japanese language ability in technical SOC/IR/DFIR roles in practice?
  • What are realistic salary ranges for experienced positions such as:
    • L2/L3 SOC Analyst
    • Incident Response / DFIR
    • Cyber Threat Hunting
    • Detection Engineering
  • For those who moved to Japan from Europe, the US or elsewhere: how difficult was it to get your first cybersecurity position in Japan?
  • Did you secure the job before moving to Japan, or did you search after arriving?
  • Are there any companies, recruiters or job platforms you would particularly recommend for gaishikei cybersecurity roles?
  • What do you wish you had known before starting the process?
  • Which challenges are unique to japan, which are the same as in the country you lived before?

Not looking for job offers, mainly hoping to hear real experiences, salary insights and advice from people who have actually gone through the process.

Thanks for any experiences or advice!

reddit.com
u/m1L35dY50N — 1 day ago

Question: how do you improve your skill set and how did you stand out among others

Hi everyone, I am a fresh graduate from Computer Science but specialised in Cybersecurity. I would like to ask few questions for the people in the cybersecurity field or related:

**1. How did you know which role suits you?**

I believe when people think about cybersecurity, the first thing that comes into mind is "hacking", but after going through the courses and understanding it, there are really a lot of different roles like (security operation - blue team, pen tester - red team, GRC and more).

I am more keen to Red team side but I know is hard to enter and there aren't as many job opportunities compared to the Blue team. Did you guys try an error or just decided one a stick to it. And for **Blue team** or **Red team**, what kind of skill set, certification, personal projects, or platforms would you recommend that are really useful nowadays

**2. Certificates plays in an important role for hiring but how important is it?**

I believe many corporates does HR filtering where they might want certain certification and things like that, so it will filter if a certain candidates doesn't have that certification.

My question here is for anyone who has experience in hiring candidates for their cybersecurity team or company. Are certification a must in the current times

if yes, what certification would you recommend first to get and so on if there's a limited budget.

If your answer is No, then what kind of projects or platforms course like tryhackme or HTB or more that will stand out among the candidates.

**3. Is networking really important**

I believe networking plays an important role in any job but from an advice given by a senior of mine, networking is very important in Cybersecurity.

Personally I am introvert and i do engage well with people I'm not familiar with, so I am afraid that I can't network well

reddit.com
u/Poccoloco_ — 1 day ago

Interview with a CTO and a Global Head of Information Security

I have a final interview for an Information Security Analyst role with the CTO and Global Head of Information Security.

How should I prepare for the interview, and what kind of questions should I expect?

Any advice would be really appreciated.

reddit.com
u/BookkeeperFew1335 — 2 days ago

I claimed I had another job offer and now HR is asking for proof. What should I do?

For about the past four months, I've been doing my manager's work while he's been on a 5-month leave. I was handling everything, and at the beginning of this week I spoke with my manager about a promotion and a raise.

He basically brushed it off and said he might be able to try to get approval in November. I got a bit stressed and told him I needed a clear answer soon, because another company had offered me more money and I was considering accepting the offer.

He called me today and said that HR wants to see the offer letter from that company before they approve anything. Do they have the right to ask for that? Should I try to make some kind of fake letter, or is that a very bad idea?

Honestly, I'm already thinking about leaving, because this makes me feel like they can pay me more and give me the title, but they don't want to do it unless they're put under pressure. Any advice would be appreciated. Thanks.

reddit.com
u/Longjumping_Key_1552 — 2 days ago
▲ 26 r/SecurityCareerAdvice+1 crossposts

Looking for 3–4 serious cybersecurity people to build together.

I'm an engineering student focused on offensive security. Looking for people interested in:

  • Pentesting / Web Security
  • CTFs
  • Linux / low-level security
  • Malware / detection engineering
  • OSINT / DFIR
  • Security tooling

The idea isn't just to make a Discord group. I want us to learn together, build real security projects, publish them on GitHub, participate in CTFs and eventually compete as a team.

Beginners/intermediate people are welcome, but consistency matters more than skill level.

If you're genuinely interested, DM me with:
1. What you're learning
2. Your current level
3. What security area interests you
4. One thing you'd like to build

reddit.com
u/Worried_Mulberry_795 — 3 days ago

cybersecurity student as software engineer

acha to can anyone tell like can a cyst student work as software engineer ya phir can he work as a software engineer? also can anyone tell giki ka cyber ka program kesa h

reddit.com
u/Confident-Ice-4789 — 1 day ago

Where should my road go now? Bachelor of Science or CompTIA Security+?

Hey, I am working as an IT system administrator in Germany since 4 years and I was always interested in cyber security but I didn't know how to find my way in. I feel like my job starts to get boring (I am responsible for our virtual machine environment, SAN and newly Firewall - which is interesting for me.)

So recently I started with Tryhackme and it's a really fun way to learn but I am considering doing the Security+ cert or a Bachelor of Science. What would be the best option in my current situation? I am 23 years old and don't know where to go - I still live with my parents, therefore I could take some risk and I am also really willing to learn.

Or should I do something else? I would be really grateful for your help.

reddit.com
u/ulxtii — 2 days ago