Start with the foundations both fields share: networking, Linux, and how systems fail. Then choose an entry role such as SOC analyst, IT support or junior cloud operations, and prove it with hands-on labs and one documented project rather than a stack of certificates.
What people tell me
I am finishing a software engineering or computer science degree and I am drawn to cybersecurity or operations rather than pure development. I do not know where to start, I have no one to guide me, and the first opportunities I found were unrelated and poorly paid. I am worried I am not good enough and job hunting feels overwhelming.
A composite of the messages behind this question, with personal details left out.
Key takeaways
- Cybersecurity and IT operations share the same foundation: networking, Linux, Windows and scripting.
- Most people enter security through an entry role such as SOC analyst, IT support or systems administration.
- Hands-on labs and a written project prove more than certificates alone.
- Pick one entry role and one certification that matches it, not several at once.
- A 12-week plan with weekly lab output is enough to start applying.
Start with the shared foundation
People who want "cybersecurity or operations" often feel they must choose immediately. You do not. Both fields sit on the same base: how networks move data, how operating systems work, how services are deployed, and how they break. Learn that base first and the choice becomes clearer, because you will notice whether you enjoy defending systems or keeping them running.
A software engineering degree is a solid starting point. You already understand code, which many people entering these fields do not.
Entry roles compared
| Entry role | Daily work | Core skills | Natural next step |
|---|---|---|---|
| SOC analyst (tier 1) | Monitoring alerts, triaging suspicious activity, escalating incidents | Networking, logs, SIEM basics, common attack patterns | Incident response, threat hunting |
| IT support or helpdesk | Resolving user and device issues, accounts, access | Windows, Active Directory basics, troubleshooting, communication | Systems administration, security operations |
| Junior systems administrator | Managing servers, users, patches, backups | Linux, Windows Server, scripting, networking | Cloud engineering, DevOps, security engineering |
| NOC or cloud operations | Keeping networks and cloud services healthy, responding to outages | Networking, monitoring tools, a cloud platform, scripting | Site reliability, platform engineering |
| Junior application security | Reviewing code and apps for vulnerabilities, supporting developers | Web technologies, OWASP Top 10, code reading | Penetration testing, security engineering |
If you enjoyed development, application security uses your coding background most directly. If you enjoy investigation, SOC work suits you. If you like building and fixing infrastructure, operations is the path.
Certifications: one at a time, matched to the role
Certifications help most at entry level when they match the role you are applying for. Common starting points include:
- CompTIA Network+ and Security+ for general networking and security fundamentals, widely recognised in job postings.
- ISC2 Certified in Cybersecurity (CC) as a foundational credential. Its free programme closed to new sign-ups in May 2026, so check the current cost before planning around it.
- Google Cybersecurity Professional Certificate on Coursera for a structured beginner course; Coursera offers financial aid on many programmes.
- A cloud fundamentals certificate from AWS, Microsoft Azure or Google Cloud if you lean towards cloud operations.
Pick the one that fits your chosen entry role. Collecting five beginner certificates without hands-on work does not make a candidate stronger.
A 12-week starter plan
Aim for about 10 to 15 hours a week, with something concrete produced every week.
| Week | Focus | Hands-on output |
|---|---|---|
| 1 | Networking basics: IP, subnets, DNS, HTTP, TCP versus UDP | Draw and explain your home network; capture traffic with Wireshark |
| 2 | Linux command line | Complete the OverTheWire Bandit levels you can; write notes on each command |
| 3 | Windows and Active Directory basics | Set up a small virtual lab with a Windows machine |
| 4 | Scripting for automation (Bash or Python) | A script that parses a log file and flags failed logins |
| 5 | Security fundamentals: CIA triad, authentication, common attacks | Summarise the OWASP Top 10 in your own words |
| 6 | Choose your entry role from the table | One paragraph explaining why, plus target job postings saved |
| 7 | Logs and monitoring | Install a free SIEM or log stack in your lab and send logs to it |
| 8 | Guided labs on a platform such as TryHackMe or Hack The Box | Complete a beginner learning path, keep a lab journal |
| 9 | Incident thinking | Simulate an attack in your lab and document detection step by step |
| 10 | Cloud basics | Deploy a small service on a cloud free tier and secure it |
| 11 | Project write-up | Publish your home lab project as a clear report on GitHub or a blog |
| 12 | Applications | Update resume and LinkedIn around labs and project, start applying and asking for referrals |
Start the certification study alongside weeks 5 to 12 if you choose one.
The project that makes you employable
A documented home lab beats almost anything else at entry level. For example: a small network of virtual machines, logs flowing into a monitoring tool, a simulated attack, and a report showing how you detected it, what the logs showed and how you would prevent it. That single write-up gives an interviewer twenty questions to ask you, all of which you can answer.
About low-paid, unrelated first offers
If the first opportunity you find is unrelated to security or operations and pays very little, weigh it carefully. Short-term income can be necessary, and any professional experience teaches communication and reliability. But do not let it consume the hours you need for the plan above. If you take it, protect a fixed block of study time every week.
Ethics and staying on the right side of the law
Only test systems you own or have explicit written permission to test. Practise on your own lab and on platforms built for training. Unauthorised scanning or access can be a criminal offence in many countries, and a reputation for integrity is the most valuable asset anyone in security has.
If you are still stuck
The full guide, getting into cybersecurity as a fresh graduate, goes deeper into roles, applications and common mistakes. If you are choosing between security, operations and development, book a free 1:1 session and we can work through it together.
Was this answer helpful?
Read next
- Getting Into Cybersecurity as a Fresh Graduate: Where to Actually StartA practical route into cybersecurity or IT operations for final year students and fresh graduates: whether to keep a low paid internship, SOC analyst versus operations versus application security, which certifications are worth it, hands on labs, a home lab, a portfolio of write ups, a six month roadmap and how to handle the fear of not being good enough.
- How to Start Your Career as a Software EngineerA practical route into the first software engineering job: pick one language and stop shopping, build things too big for a tutorial, learn the five fundamentals you cannot skip, get your code in front of a human, and apply earlier than you feel ready. Includes a twelve month shape to work to and an honest read on what the current entry level market has changed.
Your situation is not quite this one?
Members get written answers to their own questions, a roadmap built for them and feedback on their projects. Early access is open to X and Instagram followers and university students. Prefer to talk? A free call works too.