Cybersecurity Analyst
The route in from IT support, and how to reframe experience you already have.
The field is short of people and still hard to enter
Every year brings reports of a global shortfall of security professionals, and every year thousands of qualified-looking applicants cannot get a first role. Both things are true, and understanding why is the difference between a frustrating search and a successful one.
The shortage is real at the experienced end. Employers want people who have handled incidents, and they want them now. Almost nobody is short of entry-level applicants, because certifications and courses have made the on-ramp look accessible while the roles themselves have not multiplied.
So the honest position is this. Getting into security from scratch is hard and slow. Getting into security from an adjacent technical role is very achievable, and that is the route most people in the field actually took.
The route that works
The reliable path into security is sideways, not straight in.
Help desk or technical support, then system administration or network operations, then a security-adjacent responsibility, then a security role. Each step is a normal job change and each one is achievable. People who try to jump from a bootcamp straight to Security Analyst are competing against candidates who took that path, and losing to them.
If you are already in IT, the fastest move is to acquire security work inside your current job rather than applying out. Volunteer to run the vulnerability scans. Take the access review nobody wants. Ask to be the person who handles phishing reports. Get involved in the audit.
Six months of that turns you into an internal candidate for the security team, which is by a wide margin the easiest way into one. It also gives you something to say in an interview beyond what a course covered.
Certifications: what actually gates
There is more certification marketing in this field than in any other technical discipline, so be clear-eyed about what each one does.
Some genuinely function as filters. In government, defence and their contractors, specific certifications are mandated and no amount of ability substitutes. If you are targeting those employers, the requirement is not advice, it is a gate.
Elsewhere, a foundational certification helps a resume clear an automated filter and signals you have learned the vocabulary. It does not persuade anyone you can do the work, and interviewers will move past it within a minute.
The advanced certifications carry more weight because they require experience to obtain, which is a slower and better signal.
The realistic advice is to hold one recognised foundational certification, then stop and go and get hands-on evidence instead. Candidates with three certificates and no practical work are a recognised pattern, and it reads as someone who studied rather than someone who did.
Evidence that beats a certificate
Interviewers want to know whether you have looked at real data and made a judgment. There are ways to show this without a security job.
Build a home lab and actually run it. A small network with a firewall you configured, a log collector, and something deliberately vulnerable to attack and investigate. Then be able to describe what you saw, not just that you built it.
Do capture the flag competitions, and write up what you did. The writing matters more than the placing, because it demonstrates the thing the job needs: explaining a technical finding clearly to someone else.
Report something responsibly. A real bug bounty finding, however small, is worth more than any course, and the disclosure process itself teaches you how the industry communicates.
Each of these gives you a story with a specific technical detail in it. That is what gets you through an interview.
Writing a security resume before you have security experience
The hardest version of this resume is the one written by someone whose job title has never included the word. The instinct is to lead with certifications and courses, which is what every other applicant does.
Lead instead with the security-shaped work in the job you already have, described in the field's own language. Almost every technical role contains some.
Managing user accounts and permissions is identity and access management. Patching servers is vulnerability management. Configuring firewall rules is network security. Investigating why a machine behaved strangely is incident response. Writing the procedure for what happens when a laptop is lost is policy work.
None of this is exaggeration, provided you describe what you actually did. "Owned access reviews for 300 accounts across four systems, found and removed 40 accounts belonging to leavers" is a security bullet written by a system administrator, and it is more persuasive than a certificate.
Then be straightforward about where you are. A short line saying you are moving into security from infrastructure, with what you have done to prepare, reads better than a resume that pretends to a background you do not have. Hiring managers in this field are used to career changers and are mostly fine with them. What they are not fine with is overclaiming, in a discipline where overclaiming is a security risk in itself.
The tiers of a security operations role
Most first security jobs are in a security operations centre, and the postings do not always explain the structure.
The first tier monitors alerts and triages. It is shift work at many companies, often including nights, and the work is repetitive by design. It is also the single most reliable entry point in the entire field, and most senior people passed through it.
The second tier investigates what the first escalates, which is where the work becomes genuinely interesting. The third tier handles the serious incidents and does threat hunting.
Ask which tier a role sits in and what the shift pattern is. A posting that describes threat hunting and incident response but pays at entry level is usually a first-tier job with an aspirational description, and knowing that before you accept saves disappointment.
Be honest with yourself about the shift work. It is the most common reason people leave the field within two years, and it is entirely predictable in advance.
Blue, red, and where the jobs are
Security splits into defensive work, offensive work, and governance, and the attention is distributed almost exactly opposite to the hiring.
Offensive security, penetration testing and red teaming, attracts most of the interest and has the fewest roles. It is also usually not an entry point, because you cannot test defences well without understanding how they are built and operated.
Defensive work, monitoring, detection engineering, incident response, has most of the jobs.
Governance, risk and compliance has a great many jobs, minimal glamour, and a fast route to seniority. It is also more accessible to people from non-technical backgrounds, particularly anyone with audit or regulatory experience.
If your goal is to work in security, rather than specifically to do the version of it that appears in films, widening to defensive and governance roles will change your response rate immediately.
Clearances, certs and the pay ladder
We do not print salary figures, because a number from Washington means nothing in Toronto, Bangalore or Nairobi.
Three structural factors move pay in this field more than title or years.
Whether you hold a security clearance, in countries where those exist. It restricts who can hire you and how quickly, which raises what those employers pay.
Whether you are on-call for incidents. Carrying responsibility for a real response rota is compensated differently from monitoring during business hours.
Whether your work is regulated. Security roles attached to a compliance obligation, in finance, healthcare or critical infrastructure, sit above equivalent roles where security is discretionary spending.
The moves that reprice you: first tier to second, defensive operations to detection engineering or cloud security, and moving from a company where security is a cost centre to one where it is part of the product.
For what the role pays where you live, our salary calculator takes your city and your years of experience.
If you are trying to break in
Stop adding certifications and go and get one story. A home lab you actually broke into and investigated, a competition write-up, or a security task inside your current job. One of those changes an interview more than a third certificate will.
When you apply, our job search builder searches every board you trust at once, and the ATS scanner shows what a filter reads first.
Ready to apply? Tailor your resume to the role in a few minutes.
Open the resume builderRelated career guides
Roles close to Cybersecurity Analyst, and the same treatment for each: what the job involves, what employers screen for, and how to write for it.