Hook
Here are the top reasons why people don't get into cybersecurity. The first thing is because people will come to me and they'll say, I want to get into cybersecurity and I'm like, okay, well what type of cybersecurity do you want to do? And they'll have no idea that there's so many different genres of cybersecurity. There's incident response, there's GRC, there's threat hunting, there's cybersecurity engineering, there's identity and access management, and they don't know what's one it is that they want to do. And the problem with this is you have no way to inform your learning. If you want to do GRC, but you're taking a bootcamp that's preparing you for being a SOC analyst, you're not, you're not doing the right thing. The second thing is, people who come from non-technical backgrounds don't understand how their experience actually translates to cybersecurity experience and what cybersecurity domain their experience translates to. And the thing about this that I want you guys to realize is that cybersecurity is a part of every industry. So if you have a background in insurance, there is a technology company out there who makes software for insurance and that software company needs cybersecurity professionals. So like, when it comes to positioning yourself in the market, you want to be able to draw from the experience that you already have, even if it wasn't in the technology industry. Everything is the technology industry. The third reason and the biggest reason, honestly, is that you guys don't apply for roles. You guys will wait until you have this certification and that certification and did this boot camp and did that boot camp and bro, start applying to roles and start getting that feedback. Because that feedback, you're going to be able to iterate over it and once you iterate over that feedback, then you'll start actually seeing success over time. You guys will waste money on a boot camp or you guys will waste money on random certifications that don't have anything to do with what you actually want to do and you'll do everything but apply to roles. You'll do everything but reach out to recruiters or reach out to hiring managers because you have this feeling that, you know, you need to know more information. Once you have the Security+ certification and you have that direction of, you know, what type of cybersecurity it is you want to do, you need to only learn what is in line with whatever that track is, right? If you want to do identity and access management, then you need to learn Okta, you need to learn SailPoint, you need to learn these different technologies. If you want to learn and if you want to do GRC, then you need to learn a technology like Vanta or you need to learn a technology like Archer, you need to understand what does the IT risk management process look like. What are the skills that I need that are in congruence with governance, risk and compliance as a career field and not just cybersecurity overall. And then you need to network with the people who do that and you need to reach out to the hiring managers that are hiring. And even if you don't get the job, if you have good people skills, they'll be able to tell you why you didn't get the role and the type of experience that they're actually looking for, then you can iterate over that, improve yourself and have better chances at getting a role in the future.
More breakout videos from this creator.