Sefism early access is open for X and Instagram followers and university students.Get early access
Starting out

Where do I start if I want a career in cybersecurity or IT operations?

Tauseef Fayyaz

Answered by Tauseef Fayyaz

Asked 2 timesUpdated 15 Sept 2026
Short answer

Start with the foundations both fields share: networking, Linux, and how systems fail. Then choose an entry role such as SOC analyst, IT support or junior cloud operations, and prove it with hands-on labs and one documented project rather than a stack of certificates.

What people tell me

I am finishing a software engineering or computer science degree and I am drawn to cybersecurity or operations rather than pure development. I do not know where to start, I have no one to guide me, and the first opportunities I found were unrelated and poorly paid. I am worried I am not good enough and job hunting feels overwhelming.

A composite of the messages behind this question, with personal details left out.

Key takeaways

  • Cybersecurity and IT operations share the same foundation: networking, Linux, Windows and scripting.
  • Most people enter security through an entry role such as SOC analyst, IT support or systems administration.
  • Hands-on labs and a written project prove more than certificates alone.
  • Pick one entry role and one certification that matches it, not several at once.
  • A 12-week plan with weekly lab output is enough to start applying.

Start with the shared foundation

People who want "cybersecurity or operations" often feel they must choose immediately. You do not. Both fields sit on the same base: how networks move data, how operating systems work, how services are deployed, and how they break. Learn that base first and the choice becomes clearer, because you will notice whether you enjoy defending systems or keeping them running.

A software engineering degree is a solid starting point. You already understand code, which many people entering these fields do not.

Entry roles compared

Entry roleDaily workCore skillsNatural next step
SOC analyst (tier 1)Monitoring alerts, triaging suspicious activity, escalating incidentsNetworking, logs, SIEM basics, common attack patternsIncident response, threat hunting
IT support or helpdeskResolving user and device issues, accounts, accessWindows, Active Directory basics, troubleshooting, communicationSystems administration, security operations
Junior systems administratorManaging servers, users, patches, backupsLinux, Windows Server, scripting, networkingCloud engineering, DevOps, security engineering
NOC or cloud operationsKeeping networks and cloud services healthy, responding to outagesNetworking, monitoring tools, a cloud platform, scriptingSite reliability, platform engineering
Junior application securityReviewing code and apps for vulnerabilities, supporting developersWeb technologies, OWASP Top 10, code readingPenetration testing, security engineering

If you enjoyed development, application security uses your coding background most directly. If you enjoy investigation, SOC work suits you. If you like building and fixing infrastructure, operations is the path.

Certifications: one at a time, matched to the role

Certifications help most at entry level when they match the role you are applying for. Common starting points include:

  • CompTIA Network+ and Security+ for general networking and security fundamentals, widely recognised in job postings.
  • ISC2 Certified in Cybersecurity (CC) as a foundational credential. Its free programme closed to new sign-ups in May 2026, so check the current cost before planning around it.
  • Google Cybersecurity Professional Certificate on Coursera for a structured beginner course; Coursera offers financial aid on many programmes.
  • A cloud fundamentals certificate from AWS, Microsoft Azure or Google Cloud if you lean towards cloud operations.

Pick the one that fits your chosen entry role. Collecting five beginner certificates without hands-on work does not make a candidate stronger.

A 12-week starter plan

Aim for about 10 to 15 hours a week, with something concrete produced every week.

WeekFocusHands-on output
1Networking basics: IP, subnets, DNS, HTTP, TCP versus UDPDraw and explain your home network; capture traffic with Wireshark
2Linux command lineComplete the OverTheWire Bandit levels you can; write notes on each command
3Windows and Active Directory basicsSet up a small virtual lab with a Windows machine
4Scripting for automation (Bash or Python)A script that parses a log file and flags failed logins
5Security fundamentals: CIA triad, authentication, common attacksSummarise the OWASP Top 10 in your own words
6Choose your entry role from the tableOne paragraph explaining why, plus target job postings saved
7Logs and monitoringInstall a free SIEM or log stack in your lab and send logs to it
8Guided labs on a platform such as TryHackMe or Hack The BoxComplete a beginner learning path, keep a lab journal
9Incident thinkingSimulate an attack in your lab and document detection step by step
10Cloud basicsDeploy a small service on a cloud free tier and secure it
11Project write-upPublish your home lab project as a clear report on GitHub or a blog
12ApplicationsUpdate resume and LinkedIn around labs and project, start applying and asking for referrals

Start the certification study alongside weeks 5 to 12 if you choose one.

The project that makes you employable

A documented home lab beats almost anything else at entry level. For example: a small network of virtual machines, logs flowing into a monitoring tool, a simulated attack, and a report showing how you detected it, what the logs showed and how you would prevent it. That single write-up gives an interviewer twenty questions to ask you, all of which you can answer.

About low-paid, unrelated first offers

If the first opportunity you find is unrelated to security or operations and pays very little, weigh it carefully. Short-term income can be necessary, and any professional experience teaches communication and reliability. But do not let it consume the hours you need for the plan above. If you take it, protect a fixed block of study time every week.

Ethics and staying on the right side of the law

Only test systems you own or have explicit written permission to test. Practise on your own lab and on platforms built for training. Unauthorised scanning or access can be a criminal offence in many countries, and a reputation for integrity is the most valuable asset anyone in security has.

If you are still stuck

The full guide, getting into cybersecurity as a fresh graduate, goes deeper into roles, applications and common mistakes. If you are choosing between security, operations and development, book a free 1:1 session and we can work through it together.

Was this answer helpful?

Ask your own

Your situation is not quite this one?

Members get written answers to their own questions, a roadmap built for them and feedback on their projects. Early access is open to X and Instagram followers and university students. Prefer to talk? A free call works too.

Work with me

Stuck on something specific?

Writing only gets you so far. If you want an answer to your situation rather than the general case, book a session and we will work through it together. Sessions are free for approved Sefism members, and a few slots open each week.

Follow along

New writing, resources and project ideas land here first.

More questions people ask

All questions