CareersInternationalTechnology Careers, Certifications & Hiring

How to Start a Career in Cyber Security

A practical entry roadmap for cyber security covering foundations, role selection, labs, evidence, applications and continuous learning.

MENTARA Editorial
On this page
Quick orientationTechnology Careers, Certifications & Hiring

A practical entry roadmap for cyber security covering foundations, role selection, labs, evidence, applications and continuous learning.

Cyber SecurityTechnology CareersSkillsCertifications

What the work actually involves

Cyber security is not one job. The popular image — a penetration tester breaking into systems — describes maybe a tenth of the roles that actually exist and hire. Most cyber security work is monitoring, investigating, documenting, advising and configuring.

Choosing a specific target role early is the single biggest accelerator, because it tells you what to learn and what to build.

Entry roleWhat you actually do all dayGood fit if youTypical entry route
SOC / security analystTriage alerts, investigate suspicious activity, escalate and document incidentsLike methodical investigation and can handle shift patternsMost common first job; IT support background transfers well
GRC analystMap controls to standards, chase evidence, support audits, assess suppliersWrite clearly, are organised, comfortable in meetingsBusiness, audit, legal or project backgrounds transfer well
Cloud security engineerReview and fix identity, network and workload configurationAlready know cloud or infrastructureUsually a second role, from cloud/sysadmin work
Penetration testerScoped testing of applications or infrastructure, then write it upPersistent, enjoy deep technical rabbit holesHardest direct entry; usually needs demonstrable lab work
Security engineerBuild and maintain security tooling and automationCan code and like buildingUsually from software or platform engineering

SOC analyst and GRC analyst are the two realistic direct-entry roles for most people. The others are typically second jobs.

The foundations you cannot skip

Nearly everyone who struggles to break in has skipped one of these. Security is applied knowledge — you cannot secure something you do not understand.

  1. Networking. TCP/IP, DNS, HTTP, routing, firewalls. If you cannot explain what happens when you type a URL and press enter, start here.
  2. Operating systems. Both Windows (including Active Directory) and Linux, at command-line comfort level. Most enterprise attacks involve Active Directory.
  3. Identity. Authentication, authorisation, MFA, SSO, privilege. This is where most real incidents actually begin.
  4. Cloud basics. At least one platform. Most environments you will defend are partly or fully cloud.
  5. A scripting language. Python or PowerShell, enough to parse a log file and automate something repetitive.

Budget three to six months on foundations if you are starting fresh. It is not wasted time — it is the difference between a candidate who can answer follow-up questions and one who cannot.

A realistic first-year plan

MonthsFocusOutput you should have
1–3Networking, OS and identity fundamentalsWorking home lab, notes you could teach from
3–5Security+ or ISC2 CC, plus hands-on platformsOne certification, 20+ completed practical rooms/boxes
5–8Pick a target role, go deeper in that directionA written investigation or audit-style report
8–12Apply, interview, iterate on feedbackTailored CV per application, interview practice

Where to learn — mostly free

Building evidence that works

The single most effective portfolio item is a documented investigation. Set up a small lab, generate some suspicious activity, detect it, investigate it and write it up the way an analyst would: what triggered, what you checked, what you concluded, what you would recommend.

That one document demonstrates technical skill, investigative reasoning and written communication simultaneously — which is exactly what a hiring manager is trying to assess and rarely gets evidence of.

Realistic expectations on pay and entry

Entry-level SOC and GRC roles typically sit meaningfully below the headline "average cyber security salary" figures you see quoted, which are skewed by senior and specialist roles. Expect a first role to pay in line with other entry technical positions in your market, with faster-than-average progression afterwards.

Also expect the first role to be genuinely hard to get. The industry has a shortage of experienced people, not of beginners. Service desk, IT support or junior systems administration for a year is a legitimate and common route in — it builds exactly the foundations listed above while being paid.

Frequently asked questions

Do I need a cyber security degree?

No. It is one route, and a good one, but employers in this field are unusually open to demonstrated capability, career changers and non-traditional backgrounds.

Is the skills shortage real?

Yes, but it is a shortage of experienced practitioners. That is why the first role is the hard one and the third is comparatively easy.

Should I learn hacking first?

It is the most fun entry point and the least employable one on its own. Offensive skills are valuable, but the volume of hiring is in defence, operations and governance.

Further reading

Technology careers

Connect skills development with real technology opportunities.

Professionals can explore MENTARA opportunities, while employers can request targeted workforce support.

Explore opportunitiesRequest workforce support ↗
Weekly briefing

Enterprise technology intelligence, delivered weekly.

AI, cyber security, cloud, enterprise software and technology workforce guidance.

New guides and comparisons, no more than weekly.