Beginner roadmap
How to get into cyber security with no experience
A realistic 12-month plan for career changers — what to learn, in what order, what to build, and how to get the first interview. No bootcamp required, no six-figures-in-eight-weeks promises.
Set expectations first. For most people with no IT background, the honest timeline to a first security role is 9 to 18 months of consistent part-time effort. If you already work in IT, support or development, it is often 3 to 9 months. Anyone selling you a shorter path is selling you something.
The twelve-month plan
-
Months 1–2 — Fix the foundations
Security is applied IT. You cannot defend a network you do not understand. Before touching anything labelled “cyber”, get comfortable with: how TCP/IP, DNS, DHCP and HTTP actually work; the Windows and Linux command lines; what Active Directory is and does; and basic virtualisation.
Do this: work through free networking material (Professor Messer’s Network+ series is the standard free recommendation), install VirtualBox or VMware, and build a two-VM lab — one Windows, one Linux — that can talk to each other. Break it, fix it, repeat.
-
Months 2–4 — Earn one certification
Pick CompTIA Security+ unless budget is the binding constraint, in which case start with ISC2 CC at $199. One certification, not three. Its job is to get you past automated résumé filters and to force you through a structured syllabus.
Do this: book the exam date before you feel ready — a deadline you have paid for is the single most effective study technique there is. See the certification guide for costs and alternatives.
-
Months 3–8 — Build a lab you can talk about
This is the part that separates candidates. A home lab gives you the concrete stories that interviews are won with. Aim for something you could demonstrate in ten minutes on a screen share.
A good starter lab: a Windows domain controller and two clients, a Linux box, Security Onion or a free-tier SIEM ingesting the logs, and Sysmon deployed. Then attack it yourself with Atomic Red Team and see what your detections catch.
Do this: write up three investigations as short public posts — what you did, what you saw in the logs, what you concluded, what you would do differently. Three good write-ups beat a second certification.
-
Months 4–9 — Practise on structured platforms
Guided platforms fill the gaps a home lab leaves. TryHackMe is the gentlest on-ramp; Hack The Box and its Academy are harder and more respected; LetsDefend and Blue Team Labs Online simulate actual SOC work, which matters if defence is your target.
Do this: finish one complete learning path rather than dabbling in twenty rooms. Completion is the signal; a scattered profile is not.
-
Months 6–12 — Get near the work, even sideways
The fastest realistic entry is often not a security job at all. Help desk, NOC, IT support, sysadmin and junior developer roles all put you inside an organisation where security work exists — and internal moves face far less competition than external applications.
Do this: if you are already in IT, volunteer for anything security-adjacent — patching, access reviews, phishing triage, the annual audit. Six months of that on a résumé outweighs any certification.
-
Months 9–12 — Apply properly, and narrowly
Target three job titles, not fifteen. Rewrite your résumé for each application using the posting’s own vocabulary. Apply within 48 hours of a posting going live — application volume peaks fast and many reqs are effectively closed by week two.
Do this: build a list of 30 employers within commuting distance, check their careers pages fortnightly, and apply direct rather than through an aggregator. Then message one person on that team on LinkedIn with a specific, short, non-desperate note.
Where to aim
The realistic first roles
These are the titles that genuinely hire people without prior security experience. Note that “junior penetration tester” is not on this list for a reason.
SOC Analyst, Tier 1
The classic entry point. Shift-based, alert-driven, high volume — and the best broad education in the field. Look for teams with a documented escalation path and named mentors.
Typical: $60k–$85k
GRC / Compliance Analyst
The most accessible route for people coming from audit, legal, project management or operations. Rewards writing and organisation more than technical depth on day one.
Typical: $65k–$90k
IT Security Administrator
Half sysadmin, half security. You run the EDR console, handle access requests and patch things. Unglamorous, and it teaches you how organisations really work.
Typical: $65k–$95k
Help Desk with security duties
Not a security job, but the most common launchpad into one. Ask in the interview whether the team touches phishing triage, account lockouts or access reviews — then volunteer for all of it.
Typical: $45k–$65k
Security Awareness Coordinator
Ideal if you come from communications, training or marketing. You run phishing simulations and behaviour-change programmes, and you learn the threat landscape from the inside.
Typical: $60k–$95k
Federal / defence entry programmes
US agencies and defence contractors run structured entry pipelines, often with clearance sponsorship. Slower hiring, more paperwork, genuinely good training and a clearance at the end.
Typical: GS scale or contractor bands
Avoidable mistakes
Six things that waste beginners’ time
Collecting certifications
Three entry-level certifications and no hands-on work is a worse application than one certification and a documented lab. After your first, the return on the next drops sharply until you have experience to pair it with.
Aiming straight at pen testing
It is the smallest, most competitive slice of the field and the one that most assumes prior expertise. Wanting it is fine; making it your only target for a first job is how people spend two years applying and getting nowhere.
Waiting until you feel ready
You will not feel ready. Practitioners with ten years in the field routinely feel unready. Apply when you meet roughly 60% of the requirements, and let the employer decide the rest.
Ignoring the writing
Almost every security role produces documents someone else must act on. Practise writing a clear one-page incident summary. It is a rarer skill than knowing another tool, and it gets noticed immediately.
Learning tools instead of concepts
Tools change every three years; DNS, authentication, privilege and logging do not. Someone who understands why an attack works can learn any product. Someone who only knows one vendor’s console cannot.
Applying alone
Local security meetups, BSides conferences, ISSA and ISACA chapters, and Discord communities are where a large share of junior roles are actually filled. Referrals beat cold applications by a wide margin, everywhere.
FAQ
Starting out, answered
How long does it really take to get a first cyber security job?
With no IT background, plan for 9 to 18 months of consistent part-time study plus lab work, often via an adjacent IT role first. Coming from IT support, sysadmin or software development, 3 to 9 months is realistic because you already hold the foundations that security assumes.
Am I too old to switch into cyber security?
No, and career changers are common in this field. Prior professional experience — in finance, healthcare, law, the military, operations — is a genuine asset, because security work is fundamentally about understanding how a business functions and what would hurt it. GRC, risk and audit-adjacent roles in particular value domain knowledge highly.
Do I need to learn to code?
Not to start. SOC, GRC and IAM roles do not require it on day one. But scripting — Python and PowerShell — becomes a hard limiter around the mid-level, and it is the difference between doing a task and automating it away. Learn enough to automate your own work; that is sufficient for most defensive roles.
Is a cyber security bootcamp worth the money?
It depends entirely on the provider. The good ones give structure, hands-on labs and a cohort that keeps you accountable — genuinely valuable if you struggle to self-direct. The worst charge five figures for material available free and make placement claims they cannot evidence. Ask for verifiable outcomes data, talk to two recent graduates, and compare against the cost of one certification plus a home lab.
What should my home lab actually contain?
Start small and specific: a Windows domain controller, one or two Windows clients, a Linux server, Sysmon for logging, and a free SIEM collecting it all. Then attack it with Atomic Red Team and observe what your detections catch and miss. That single project gives you material for a dozen interview answers — far more than a sprawling lab you cannot explain.
What do I put on my résumé if I have no security experience?
Lead with the lab and the write-ups, described as projects with outcomes: what you built, what you detected, what you fixed. Then your certification. Then translate your existing work experience into security-relevant language — handling sensitive data, following procedure under pressure, investigating discrepancies, communicating with stakeholders. Never leave a résumé empty because the experience is not labelled “security”.
Start applying when you hit 60% of the requirements
Open entry-level and mid-level security roles, filterable by discipline and work setup.