Skip to content
Oluma Cyber Security Awareness
Resume Lab

Turn your CV into a cyber CV.

Answer three questions and get an instant report: the security path that fits you, the skills you already have but aren’t claiming, and exactly what to fix next. Then run your resume through our 24-point scorecard.

6–8sFirst recruiter scan
24Point scorecard
5Career paths mapped
$0Free, no sign-up
Your instant report

Three questions. One tailored plan.

Nothing is uploaded, stored or sent anywhere — this runs entirely in your browser. Pick an answer for each step and your report builds itself below.

1 Where are you coming from?
2 What kind of work pulls you in?
3 How far along are you?
📄

Your report appears here

Answer all three steps above and you’ll get your transferable skills, best-fit role, and a 90-day plan — instantly.

What you already bring

IT / helpdesk / sysadmin

You have the single strongest on-ramp into security. Most SOC analysts came from exactly this seat. Your problem is not capability — it’s that your resume reads like a support ticket log instead of a security story.

Claim these on paper

  • Incident triage — every escalated ticket was a mini incident-response cycle: detect, contain, resolve, document.
  • Identity & access — if you touched Active Directory, resets, onboarding or offboarding, that is IAM experience.
  • Endpoint hygiene — patching, imaging, antivirus and MDM are endpoint security work.
  • Log reading — you’ve already read event logs to chase a fault. Same muscle a SIEM uses.
  • User behaviour — you know how people actually break rules, which most security teams badly need.
Rewrite like this →
“Resolved 40+ escalations/week including malware and account-lockout events; documented root cause and reduced repeat incidents 25% by proposing an MFA rollout.”
What you already bring

Audit, finance or accounting

You are closer to a GRC role than most computer-science graduates. Security governance is auditing — the subject matter is just systems instead of ledgers. Do not undersell this.

Claim these on paper

  • Control testing — design vs operating effectiveness is the exact language of SOC 2 and ISO 27001.
  • Evidence handling — sampling, workpapers and audit trails transfer one-to-one.
  • Risk rating — likelihood × impact is the same maths in a risk register.
  • Regulatory literacy — SOX, segregation of duties and materiality all have direct security equivalents.
  • Stakeholder pushback — you already know how to tell a business owner something they don’t want to hear.
Rewrite like this →
“Tested 30+ ITGC control activities across access management and change control; drafted remediation plans adopted by process owners, closing 12 findings ahead of deadline.”
What you already bring

Military or veteran

Security culture borrows its vocabulary from yours — posture, threat, operations, chain of custody. Your challenge is translation: civilian recruiters can’t decode ranks, unit names or MOS codes. Translate everything.

Claim these on paper

  • Operating under pressure — incident response is triage with a clock running.
  • Clearance — if you hold or held one, put it near the top. It is a hiring accelerant for defence contractors.
  • Procedure discipline — following and improving SOPs is exactly what playbook-driven SOC work is.
  • Briefing skills — writing a clear situation report is the same skill as writing an incident report.
  • Team leadership — supervising people at a young age reads very well for future team leads.
Rewrite like this →
“Led a 6-person team maintaining secure communications equipment across a 24/7 operation; authored SOPs adopted unit-wide and briefed leadership on operational status daily.”
What you already bring

Student or recent graduate

You have the one thing working professionals don’t: time and cheap access to labs, societies and internships. Your resume will be judged on evidence of initiative, not employment history — so manufacture that evidence.

Claim these on paper

  • Coursework as projects — name the module, the tools and the outcome, not the grade.
  • Home lab — a virtual machine setup with a domain controller and a SIEM beats a fourth certification.
  • CTFs and challenges — list platforms and rank, and link a write-up.
  • Society or club roles — treasurer, event organiser and committee work are genuine soft-skill proof.
  • Any job at all — retail, tutoring, bar work. It proves reliability. Never leave the page empty.
Rewrite like this →
“Built a home lab (pfSense, Windows AD, Splunk Free) simulating a 5-host network; generated and detected simulated brute-force attacks, documenting detections in a public write-up.”
What you already bring

Customer service, retail or hospitality

Every hiring manager says the same thing: technical skills can be taught, communication cannot. You already have the part most technical applicants lack. Lead with it, then prove you can learn the tools.

Claim these on paper

  • De-escalation — invaluable when you’re telling someone their account was compromised.
  • Social engineering awareness — you’ve seen manipulation attempts in person; that instinct is real.
  • Cash and data handling — following strict loss-prevention or PCI rules is compliance experience.
  • Working the queue — prioritising under pressure is precisely what alert triage is.
  • Training new starters — you’ve delivered security awareness training without calling it that.
Rewrite like this →
“Handled 100+ customer interactions daily under PCI-compliant card-handling procedures; trained 8 new starters on loss-prevention and fraud-identification protocols.”
What you already bring

Healthcare, teaching or public sector

You’ve worked inside strict data-protection rules your whole career — you just called it confidentiality rather than compliance. Privacy and GRC roles are an unusually natural fit.

Claim these on paper

  • Regulated data — patient or student records mean real exposure to HIPAA, FERPA or GDPR-style rules.
  • Confidentiality judgement — you’ve made need-to-know calls under pressure, with consequences.
  • Explaining hard things simply — the core skill of security awareness and stakeholder reporting.
  • Documentation discipline — if it wasn’t written down it didn’t happen. Auditors think identically.
  • Safeguarding and incident reporting — you’ve followed formal escalation procedures already.
Rewrite like this →
“Managed confidential records for 200+ individuals under GDPR and internal safeguarding policy; delivered annual data-handling training to 25 staff with 100% completion.”
What you already bring

Developer or engineer

You can skip the entry rung entirely. Application security, cloud security and detection engineering all pay a premium for people who can actually read and write code — and there aren’t many.

Claim these on paper

  • Code review — reframe as identifying insecure patterns: injection, secrets in source, weak validation.
  • CI/CD — pipeline work is where SAST, DAST and dependency scanning live.
  • Cloud & IAM — if you’ve written policies or managed roles, that’s cloud security experience.
  • Automation — scripting toil away is exactly what detection and SOAR engineering is.
  • Threat modelling — if you’ve ever asked “how could this be abused?”, name that skill explicitly.
Rewrite like this →
“Introduced dependency scanning and secrets detection into the CI pipeline, cutting exposed-credential incidents to zero and reducing critical-vulnerability backlog 60%.”
What you already bring

Career changer

Coming from an unexpected field is an advantage more often than a handicap — security teams are full of musicians, lawyers, chefs and mechanics. What you must do is close the credibility gap with visible, verifiable proof.

Claim these on paper

  • Domain knowledge — you understand an industry security teams struggle to protect. Say which one.
  • Pattern recognition — most trades are diagnostic work; frame it that way.
  • Process ownership — if you ran anything end to end, that’s operational maturity.
  • Self-directed learning — your career change is itself the evidence. Show the receipts.
  • Projects over history — put a Projects section above Experience. It’s the exception that works.
Rewrite like this →
“Completed 120+ hours of hands-on security labs (TryHackMe, PortSwigger) while working full-time; published 6 technical write-ups documenting methodology and remediation advice.”
Your best-fit path

SOC Analyst / Detection & Response

You’d spend your day asking “is this real, and what happened next?” — reading alerts, pulling logs, and deciding what matters. It’s the most common first cyber job in the world, and the widest door in.

Hard skills to build, in order

Networking · TCP/IP · DNSWindows & Linux logsSIEM (Splunk, Sentinel, ELK)MITRE ATT&CKPhishing analysisEDR toolingRegexPython or PowerShell

Certifications that move the needle

CompTIA Security+ISC2 CCCompTIA CySA+BTL1Microsoft SC-200

Titles to search for

SOC Analyst I · Security Analyst · Threat Detection Analyst · Cyber Defence Analyst · Incident Response Analyst · Security Operations Associate

Your best-fit path

Security Engineer / Cloud Security

You’d rather prevent the incident than investigate it. This path builds the controls — identity, network segmentation, cloud guardrails — and it pays well because it demands real engineering ability.

Hard skills to build, in order

Networking & firewallsLinux administrationOne cloud, deeply (AWS or Azure)IAM & least privilegeInfrastructure as codePython / BashZero Trust architectureCIS Benchmarks

Certifications that move the needle

CompTIA Security+AWS Security SpecialtyMicrosoft SC-300 / AZ-500CompTIA Network+

Titles to search for

Security Engineer · Cloud Security Engineer · IAM Analyst · Infrastructure Security Engineer · Platform Security Associate

Your best-fit path

GRC Analyst / Risk & Compliance

Governance, risk and compliance is the most underrated entry point in the industry — and the friendliest to career changers, because it rewards writing, organisation and judgement over command-line ability. Frameworks are learnable; good judgement is not.

Hard skills to build, in order

NIST CSFISO 27001Risk registers & assessmentSOC 2 & audit evidencePolicy writingThird-party / vendor riskPrivacy (GDPR, CCPA)Excel to a high standard

Certifications that move the needle

ISC2 CCCompTIA Security+ISACA CRISCISC2 CGRCIAPP CIPP/E

Titles to search for

GRC Analyst · IT Risk Analyst · Compliance Analyst · Third-Party Risk Analyst · Security Governance Associate · IT Auditor

Your best-fit path

Penetration Tester / Application Security

The most glamorised path and the hardest to enter cold — almost nobody starts here. Treat it as a destination two or three years out, and take a SOC, IT or development role on the way. That’s not a compromise; it’s the standard route.

Hard skills to build, in order

Networking fundamentalsLinux command lineWeb application flaws (OWASP Top 10)Burp SuiteNmap & enumerationPython scriptingReport writingActive Directory attacks

Certifications that move the needle

CompTIA Security+eJPTCompTIA PenTest+OSCP (later)Burp Suite Certified Practitioner

Titles to search for

Junior Penetration Tester · Security Consultant · Application Security Analyst · Vulnerability Analyst · Red Team Associate

Your best-fit path

Security Awareness / Human Risk

Most breaches begin with a person, not a firewall — yet almost nobody applies for these roles, so the competition is thin. If you can write clearly and hold a room, this is a genuinely open door with a fast route into wider GRC work.

Hard skills to build, in order

Phishing & social engineeringSecurity fundamentalsTraining designPhishing simulation platformsMetrics & reportingPolicy communicationBehavioural science basics

Certifications that move the needle

ISC2 CCCompTIA Security+SANS SSAPIAPP CIPP

Titles to search for

Security Awareness Analyst · Human Risk Analyst · Security Culture Coordinator · Security Communications Specialist · GRC Analyst (awareness focus)

Your next 90 days

Starting from zero

Do not apply yet. Ninety days of focused work will change your outcomes far more than ninety applications sent now. Resist the urge to collect certifications — build understanding first.

  1. Weeks 1–4 · FoundationsNetworking and operating systems before anything security-specific. Free: Cisco “Introduction to Cybersecurity”, Professor Messer’s Network+ series. Aim for one hour a day, every day.
  2. Weeks 5–8 · Get hands dirtyTryHackMe’s beginner path. You want to be comfortable in a terminal and unafraid of breaking things. Write down what you learn each week.
  3. Weeks 9–12 · Prove itStart Security+ or the free ISC2 CC. Simultaneously build one small project you can describe in an interview. Publish one write-up.
  4. Throughout · Build the paper trailCreate a LinkedIn profile now and post what you’re learning weekly. In three months you’ll have a visible track record, which beats a bare profile with a certificate.
Your next 90 days

Learning, nothing finished yet

Your risk is drifting — endlessly consuming courses without producing anything an employer can verify. The next 90 days should be about finishing things and making them visible.

  1. Weeks 1–2 · Pick one lane and commitUse your best-fit path above. Breadth feels productive but reads as unfocused on a resume.
  2. Weeks 3–6 · Finish one certificationBook the exam now and let the deadline force the pace. An unbooked exam slips forever.
  3. Weeks 7–10 · Build one substantial projectA home lab with a SIEM, a documented phishing analysis, or a full risk assessment of a fictional company. Document it properly — the write-up matters as much as the build.
  4. Weeks 11–12 · Package and launchRewrite your resume against the scorecard below, rebuild your LinkedIn, and start applying to 5 tailored roles a week. Quality beats volume.
Your next 90 days

Certified and applying

You have the credentials. If applications aren’t converting, the problem is almost always one of three things: the resume isn’t ATS-readable, you’re applying to the wrong level, or you’re relying on the “apply” button alone.

  1. Weeks 1–2 · Fix the documentRun the 24-point scorecard below. Most rejections at this stage are formatting and keyword failures, not capability failures.
  2. Weeks 3–4 · Widen your titlesSearch IT Auditor, Risk Analyst, IAM Analyst, Compliance Analyst, Security Operations Associate — not just “Cyber Security Analyst”. Adjacent titles have far less competition.
  3. Weeks 5–8 · Work the networkRoughly half of roles are filled through referral. Attend two events or chapter meetings a month. Message people who hold the job you want and ask about their route, not for a job.
  4. Weeks 9–12 · Track and iterateLog every application in a spreadsheet. If 30 applications produce zero screens, the resume is the problem. If screens produce no offers, practise interviewing out loud.
Live scorecard

Score your resume out of 24.

Open your resume beside this page and tick honestly. Your score updates as you go, and each group unlocks a badge when it’s complete. Anything you can’t tick is your to-do list.


of 24

Your resume score

Under 12 means the document is holding you back more than your experience is. 12–18 is workable but leaking opportunities. 19+ and you’re competitive — focus your energy on networking instead.

Basics ATS-safe Evidence Polish

A · The basics

Get these wrong and nothing else matters.

Why

Recruiters need to know your region for right-to-work and hybrid logistics, not your doorstep. A full address is a privacy risk on a document you email to strangers.

Why

Most recruiters check LinkedIn before replying. A default URL full of random digits looks unfinished; customising it takes two minutes.

Why

The first pass is a scan of a few seconds. Length doesn’t buy attention — it dilutes it. Cut the oldest and least relevant first.

Why

PDF preserves your layout everywhere. Some older applicant systems prefer .docx — if the posting says so, follow the posting, not the internet.

Why

In the US, UK and much of Europe these invite bias claims and many recruiters must discard such resumes. Norms differ by country — follow your local convention.

Why

“resume_final_v3(2).pdf” lands in a folder of hundreds. Your name in the filename makes you findable and looks deliberate.

B · Machine-readable

Most resumes are filtered before a human sees them.

Why

If the posting says “vulnerability management” and you wrote “patching”, a keyword filter may miss you. Mirror their language where it’s honestly true of you.

Why

Parsers look for conventional headings. “My Journey” and “What I Bring” may not be recognised as sections at all.

Why

These are the single most common reason a well-qualified resume parses as gibberish. A simple single-column layout is safest.

Why

You don’t know which form the recruiter searched. Writing both once covers you for either.

Why

Decorative fonts can render as unreadable characters after parsing. Save the creativity for your portfolio site.

Why

Named tools — Splunk, Wireshark, NIST CSF, ISO 27001 — are what searches actually match. “Strong technical ability” matches nothing.

C · Evidence, not adjectives

Claims are free. Proof is what gets interviews.

Why

“Responsible for” describes a job description. “Investigated”, “Reduced”, “Automated”, “Implemented” describe a person who did something.

Why

Volume, percentage, time saved, people trained, systems covered. Numbers create the impression of a person who measures their own work.

Why

For a first cyber role this is the most important section on the page. It’s the only place you can show security work if your job title isn’t security.

Why

“Security+” is ambiguous; “CompTIA Security+ (SY0-701), 2026” is verifiable. If one’s in progress, say so with an exam date.

Why

One working link showing how you think beats a paragraph claiming you think well. Check it opens in a private browser window.

Why

“Monitored alerts” is a task. “Monitored alerts and escalated 15 confirmed incidents, cutting mean response time by a third” is an outcome.

D · Final polish

The difference between competent and hired.

Why

Ten tailored applications outperform a hundred generic ones. Adjust the summary and reorder your skills to match each posting.

Why

Career changers especially need this — it explains the pivot before the reader has to guess. Name the target role explicitly.

Why

Security work is detail work. A typo on a security resume carries more weight than it would elsewhere, fairly or not.

Why

Past tense for previous roles, present for current. Either end every bullet with a full stop or none of them. Just be consistent.

Why

Gaps are fine and common. Unexplained gaps invite worse assumptions than the truth. A single line covering study or caring is enough.

Why

Both are assumed and waste prime space. Everyone knows you’ll provide references. Use the room for a project instead.

🌟 All 24 checked. Your resume is doing its job — now put your energy into referrals and interview practice, because the document is no longer what’s holding you back.
Rewrite clinic

The same job, written two ways.

Nothing here is exaggerated — every “after” describes identical work. The difference is specificity, ownership and outcome.

Before

Responsible for helping users with computer issues.

After

Resolved 45+ weekly support tickets across Windows and Active Directory, including account lockouts, malware alerts and access requests.

Volume, named technologies, and the security-relevant subset made explicit.

Before

Familiar with cyber security concepts and tools.

After

Completed 120+ hours of hands-on labs across TryHackMe and PortSwigger Academy; published 6 write-ups covering SQL injection, privilege escalation and log analysis.

“Familiar” is unverifiable. Hours, platforms and published output are all checkable.

Before

Helped with the company’s compliance audit.

After

Gathered and validated evidence for 30+ ITGC controls during the annual SOX audit; built a tracker that cut evidence-collection time by roughly 40%.

Names the framework, quantifies scope, and shows initiative beyond the task given.

Before

Good communication skills and works well in a team.

After

Delivered monthly security-awareness briefings to 40 non-technical staff; phishing simulation click rate fell from 22% to 6% over two quarters.

Never claim a soft skill — describe the situation where you demonstrably used it.

Before

Set up a home lab to learn about security.

After

Built a 5-host virtual lab (Windows Server AD, pfSense, Ubuntu, Splunk Free); simulated brute-force and lateral-movement attacks and wrote the detection rules that caught them.

Named components and a defined outcome turn a hobby into demonstrable engineering.

Before

Worked in retail dealing with customers and cash.

After

Handled 100+ daily transactions under PCI-DSS card-handling procedures; identified and escalated 3 attempted fraud incidents and trained 8 new starters on loss-prevention protocol.

The same job — now visibly relevant to a security reader without a word of exaggeration.

Hard skills

The technical foundation, in priority order.

You do not need all of this to be hired. The first three are non-negotiable for almost every security role; the rest depend on your path.

🌐

Networking

TCP/IP, DNS, HTTP/S, ports, subnetting, firewalls, VPNs, proxies. How traffic moves and where it can be intercepted.

The most common reason candidates fail technical screens. Learn it first, properly.

🖥️

Operating systems

Windows internals, Active Directory, Group Policy, the Linux command line, file permissions, processes and services.

Prove it: build a domain controller in a VM and break it deliberately.

🛡️

Security fundamentals

CIA triad, defence in depth, least privilege, zero trust, encryption basics, hashing, authentication vs authorisation.

This is what Security+ and ISC2 CC actually certify. Start here.

📊

Logging & SIEM

Reading Windows Event Logs and syslog, writing queries, building alerts. Splunk, Microsoft Sentinel or the ELK stack.

Splunk Free and Sentinel’s trial cost nothing. Ingest your own lab logs.

☁️

Cloud

One provider deeply beats three shallowly. Identity, storage permissions, network controls, logging, shared responsibility.

AWS and Azure both have free tiers. Misconfigure something on purpose, then find it.

🔑

Identity & access

Authentication, MFA, SSO, SAML, OAuth, joiners-movers-leavers, privileged access and access reviews.

The fastest-growing entry area, and the least contested by other applicants.

🐍

Scripting

Python or PowerShell — enough to parse a log file, call an API and automate a repetitive task. Plus regex.

You don’t need to be a developer. You need to stop doing things by hand.

📐

Frameworks

NIST CSF, ISO 27001, CIS Controls, MITRE ATT&CK, OWASP Top 10. The shared language of the profession.

Free to read. Mapping a control to a real system is a legitimate portfolio project.

⚖️

Risk & compliance

Risk registers, likelihood × impact, SOC 2, PCI DSS, HIPAA, GDPR, SOX ITGC, third-party risk assessment.

Essential for GRC, valuable everywhere. Very learnable without a technical background.

🔎

Vulnerability management

Scanning, CVE and CVSS, prioritisation, patch cycles, remediation tracking and reporting to owners.

Nessus Essentials scans 16 hosts free. Scan your own lab and write the report.

🚨

Incident response

The lifecycle: preparation, detection, containment, eradication, recovery, lessons learned. Evidence handling.

Know the order cold — it’s the most predictable interview question in security.

🧰

Core tooling

Wireshark, Nmap, Burp Suite, Nessus, and for GRC: ServiceNow, OneTrust, Archer, BitSight, SecurityScorecard.

Name the tools you’ve actually touched. Recruiters search by tool name constantly.

Soft skills

What actually separates two equal candidates.

Hiring managers say it constantly: they can teach the tools, not the temperament. But never claim a soft skill — each card below shows how to evidence it instead.

✍️

Written communication

Security runs on writing: incident reports, risk assessments, policies, findings. Unclear writing means the risk doesn’t get fixed.

Evidence it: link a technical write-up. Nothing proves writing like writing.

🗣️

Translating for non-technical people

Explaining why a finding matters to someone who controls the budget but doesn’t know what a subnet is.

Evidence it: “Presented quarterly risk summary to non-technical department heads.”

🧐

Healthy scepticism

The instinct to verify rather than assume. Not paranoia — a habit of asking how you’d know if something were false.

Evidence it: describe a time you questioned something everyone else accepted.

🔬

Attention to detail

The difference between spotting the anomalous login and scrolling past it. Also the reason typos matter here.

Evidence it: a flawless document is itself the proof. So is a caught error.

🧠

Curiosity & self-teaching

The field changes faster than any syllabus. Employers hire people who will still be useful in three years.

Evidence it: labs completed, write-ups published, a consistent learning trail.

⏱️

Prioritisation under pressure

Fifty alerts, two matter. Choosing well and calmly is the daily reality of security operations.

Evidence it: any high-volume triage role — support, nursing, hospitality, dispatch.

🤝

Collaboration across teams

Security can’t fix anything alone. You persuade engineering, legal, HR and finance to act.

Evidence it: “Partnered with IT and HR to redesign the offboarding process.”

🔐

Discretion & ethics

You’ll see salary data, private messages, and colleagues’ mistakes. Employers must trust you completely.

Evidence it: prior handling of confidential records, clearances, regulated data.

📋

Documentation habit

Undocumented work is invisible work — and in audit terms, work that never happened.

Evidence it: “Authored SOPs adopted across the team.” Auditors love this line.

🧩

Problem decomposition

Breaking a vague alarm into checkable questions. The core mental move of investigation.

Evidence it: describe your method in a write-up, not just the answer you reached.

💬

Receiving criticism well

Your first reports will be marked up heavily. People who take that well improve fastest.

Evidence it: mention iterating on feedback in a project description.

🪨

Persistence

The first cyber job is genuinely hard to get. Most people who succeed simply outlasted the rejections.

Evidence it: a career change completed while working full-time speaks for itself.

Skills translator

You’ve done more security work than you think.

Everything on the left is ordinary work from ordinary jobs. Everything on the right is the same thing, in the language a security recruiter is scanning for. Only use a line if it’s genuinely true of you.

What you didWhat to call it
Reset passwords and unlocked accountsIdentity and access management support; account lifecycle administration
Set up new starters’ laptops and loginsEndpoint provisioning and joiner-mover-leaver process execution
Told a colleague an email looked fakePhishing identification and user-reported threat escalation
Kept a spreadsheet of what needed fixingRemediation tracking and issue management
Checked staff followed the cash-handling rulesControl monitoring and compliance verification
Wrote the guide for how to do a taskStandard operating procedure documentation
Chased people for missing paperworkEvidence collection and audit readiness support
Decided which problem to handle firstRisk-based prioritisation and triage
Trained the new personSecurity awareness and process training delivery
Kept patient or student records confidentialSensitive data handling under regulatory obligation
Noticed the numbers didn’t add upAnomaly detection and investigative analysis
Ran the monthly software updatesPatch management and vulnerability remediation
Reported a safety concern up the chainIncident reporting and escalation procedure adherence
Managed who had keys to whatPhysical access control and least-privilege administration
The experience paradox

Eight ways to have experience before anyone hires you.

“Entry level, 3 years required” is the industry’s oldest cruelty. The answer is to manufacture verifiable experience yourself — all eight of these are free or nearly free.

  1. Build a home labVirtual machines on your own laptop: a Windows domain, a Linux box, a firewall, a free SIEM. Attack it, detect the attack, document both. This is the single highest-value thing on this list.
  2. Publish write-upsEvery lab you complete becomes a short post explaining your method. Ten posts is a portfolio. It proves you can write, which half of applicants can’t.
  3. Volunteer your skillsCharities, community groups and places of worship all have data to protect and no budget. Offer a basic security review. It’s real work with a real stakeholder.
  4. Compete in CTFsPicoCTF, CyberDefenders, Blue Team Labs. Free, gamified, and a ranked profile you can link to.
  5. Take on security tasks in your current jobThe fastest route of all. Ask to help with the access review, the audit, the phishing training. Now it’s on your resume with a company name attached.
  6. Contribute to open sourceDocumentation counts. Fixing a confusing README for a security tool is a genuine, citable contribution.
  7. Run a risk assessment on a fictional companyInvent a 50-person business, assess it against NIST CSF, write the report. Ideal for GRC applicants and requires zero infrastructure.
  8. Attend and speakLocal chapters — ISACA, ISC2, OWASP, BSides — are free or cheap. Present a five-minute lightning talk on something you learned. Instant credibility and instant network.
Avoid these

Ten mistakes that quietly cost interviews.

Listing every certification you started

Unfinished courses look like a pattern of not finishing. List what you completed, plus one in progress with a booked exam date.

A skills bar chart showing “Python 70%”

It means nothing to a reader and parses as nothing to a machine. Replace with named tools and a project that shows the level.

Applying to senior roles hoping for the best

Wastes your time and burns recruiter goodwill. Target roles where you match roughly 60% of requirements.

The same resume sent to fifty jobs

The single biggest cause of silence. Ten tailored applications will outperform fifty generic ones every time.

Hiding a career gap

Gaps are normal and rarely disqualifying. Unexplained gaps invite worse assumptions than the reality. One line is enough.

Only using the “Easy Apply” button

Highest-volume, lowest-conversion route in existence. Apply on the company’s own careers page, then find a human on LinkedIn.

Claiming tools you can’t discuss

Anything on your resume is fair interview game. If you can’t describe what you did in Splunk for five minutes, take it off.

Burying the certification

If you hold Security+ and the posting asks for it, it belongs in the top third of page one — not at the bottom.

Writing for yourself, not the reader

Your resume isn’t your autobiography. It’s an argument that you can do one specific job. Cut everything that doesn’t serve it.

Giving up at forty applications

A first cyber role commonly takes six to twelve months of consistent effort. Sustained, targeted effort is what works.

Straight answers

The questions everyone asks.

Do I need a degree to work in cyber security?
No. Plenty of practitioners have no degree, and many have one in something unrelated. Some employers — particularly government, defence and large enterprises — still filter on it, so it opens doors rather than being a requirement. Certifications, demonstrable projects and adjacent experience substitute effectively almost everywhere else.
Which certification should I get first?
ISC2’s Certified in Cybersecurity (CC) if cost matters — the training and exam have been offered free through their One Million Certified initiative. Otherwise CompTIA Security+, which appears in more job postings than any other entry credential. Don’t collect certifications; get one, then build something with what you learned.
How long does it realistically take to land the first role?
For someone starting from zero and working at it consistently, six to twelve months is a realistic range. Coming from IT or audit it can be considerably faster. Anyone promising you a job in eight weeks is selling something.
Should I put my home lab on my resume?
Yes — and prominently, if you don’t have security job titles yet. Describe it like an engineering project: what you built, which technologies, what you demonstrated. “Set up a home lab” is weak; naming the components and what you detected with them is strong.
Is GRC really easier to enter than technical roles?
Less contested, rather than easier. It demands strong writing, organisation and judgement instead of deep technical skill, which suits career changers from audit, law, healthcare and administration. It’s also excellent leverage — GRC people who later learn the technical side become very valuable.
Should I write a cover letter?
If there’s a field for it, yes — most applicants skip it, so it’s cheap differentiation. Keep it under 200 words: why this company specifically, the one thing that makes you a fit, and what you’re currently learning. Never repeat your resume in paragraph form.
How do I explain switching careers?
In two or three lines at the top, positively and without apology. Name the target role, connect one genuine thread from your past work, and point at your evidence. “Audit professional moving into IT risk, bringing five years of controls testing and a completed Security+” does the whole job.
What if I get no response at all?
Diagnose by stage. Applications with no screening calls means the resume or targeting is wrong — run the scorecard and widen your job titles. Screens but no interviews means how you talk about your experience needs work. Interviews but no offers means practise answering out loud, and ask for feedback every time.
Next step

Now go and build the evidence.

A stronger resume gets you seen — real skills get you hired. Start with the free Learning Hub, find your role in the Cyber Roles guide, then take your prepared resume straight to the boards.