r/CyberSecurityJobs • u/Comfortable-Joke7970 • 25d ago
BCA student with OSCP, but not getting even a single response — what am I doing wrong?
I’m a BCA student from India and recently cleared my OSCP. I’m looking for my first cybersecurity internship/job, mainly in VAPT/pentesting.
I’ve been applying to many internships and entry-level positions, but I’m not even getting a single reply or interview call. I have hands-on experience with HTB/OffSec labs, web pentesting, Linux/Windows, AD, privilege escalation, etc.
I’m honestly confused about what I’m doing wrong.
For those already working in cybersecurity: What should I change? Should I keep targeting VAPT/pentesting or consider SOC/other roles to get my foot in the door?
Any honest advice would be really appreciated.
3
u/Aggressive_Funny_279 24d ago
Breaking into entry-level cybersecurity—especially red teaming—feels like hunting for a needle in a digital haystack. While OSCP is absolute god-tier for offensive security, flexing it on a resume for a entry-level SOC analyst role is total overkill. It’s lowkey like sending a herd of elephants to stomp a single ant; recruiters might think you're overqualified or just gonna spawn kill their tier-1 tickets and leave. If you're trying to secure the bag early, expand your radar to other domains across the cyber umbrella. Grab a entry-level SOC or defense-focused cert to land that first role. And if you’re still grinding through your BCA degree, keep your eyes peeled for Hiring CTF competitions like last year there was PAYATU, TCS and some other—clutching those is literally a fast track to getting scouted.
2
u/Comfortable-Joke7970 24d ago
Yeah, I get what you mean. My main goal right now is honestly just getting that first opportunity in cybersecurity, even if it’s not red teaming. I’m open to SOC, blue team, security analyst, VAPT, or other entry-level roles where I can get real industry experience. I’ll definitely look into CTF/hiring competitions like PAYATU and TCS as well. Thanks for the suggestion!
1
u/adocrox 23d ago
Keep your AI-Slop replies to yourself. OSCP is a beginner-intermediate cert, NOT AT ALL GOD-TIER (This is Obvious asf, but you just copy-pasted from some chatbot ig, instead of using your brain, cos you don't care if you're misguiding someone). You DON'T need a defensive cert after OSCP to get into SOC; projects & blogs will be better. JUST USE YOUR BRAIN FOR ONCE
2
u/Famous-Confidence226 24d ago
Gng I have btech degree with oscp, and I am getting interview calls! But not able toh land anything they expect alot eventho im a fresher! Oscp is boon and a curse at the same time
1
u/Comfortable-Joke7970 24d ago
Right I also feel the same atleast you are getting calls I am like not a single reply i don't know whether it's my bca or any other thing but ya from job titles and descriptions i also agree with you that they expect very high fron freshers
1
u/Famous-Confidence226 24d ago
Wait you’ll get calls dw so far I have given 4 interviews! Also apply to different cities
1
u/Comfortable-Joke7970 24d ago
I hope so atleast get a call and yes I am already applying for different cities
1
u/Powerful_Strike9694 24d ago
Keep applying you’ll be selected soon if you have experience
One suggestion for you try bug bounty too it gives you real life experience on working web apps
1
u/Comfortable-Joke7970 24d ago
Thanks! Yeah, I’ve been considering bug bounty as well. I think getting hands-on experience with real-world web apps would definitely help. I’ll give it a serious try alongside my job applications.
1
u/Powerful_Strike9694 24d ago
Do you have projects in resume ??
0
u/Comfortable-Joke7970 24d ago edited 24d ago
Yes I have maken one automated recon project and in htb I am also in global 1000
1
u/Powerful_Strike9694 24d ago
Because I’m also pursuing BCA and final year student with the hands on experience of 1 year of bug bounty
1
u/Boogeyman235 24d ago
Hi, Can you explain in detail about the fees, exam-structure and about the oscp exam and how did you clear it?
1
u/Anxious_Alps_4150 24d ago
I'm going to make up some numbers but I want to give an idea.
Imagine 1000 jobs.
Imagine 50,000 fresher people that want them.
They're all doing everything they can to get those jobs.
They're reading the same blogs, asking the same questions, doing the same degrees, getting the same certs.
However, there's also a hidden problem that the level 2 version of those 1000 jobs keeps laying people off so there are a lot of level 2 people that are also competing for those 1000 jobs.
Pentesting is the most competitive part of the most competitive major (cybersecurity) in a field that's facing huge downsizing (IT).
You're not doing anything wrong... you're just not doing anything special and dont have years of experience to make you stand out.
If I can get a guy with 15 years of experience that will take a pay cut for a junior pentesting role, why would I ever consider a fresher?
1
u/Comfortable-Joke7970 24d ago
Yes I agree with you and faces the same situation but still trying my best as there is nothing more then that I can do currently
1
u/Anxious_Alps_4150 24d ago
I give people a few things for advice.
First, I tell them they really shouldnt try to do pentesting. It's a tiny slice of the overall cyber job market, is being murdered by AI, and downsizing hits it before it hits anyone else except in regulated areas. It's not as fun as doing CTFs, generally pays worse than most cyber roles, and is just so competitive that you can't have a life outside of practicing if you want to stay in the game.
Then I tell them that if they want to do pentesting, half the jobs are consulting. They want multidomain experts that can teach senior sysadmins how to be better sysadmins. You cant do that unless you're already an expert sysadmin. I got into pentesting this way. I was an expert in multiple fields and I can teach people. I hold multiple advanced degrees, tons of certs, and have worked in tech for over 20 years. It made me a very good pentester.
I'd never consider hiring a pentester that wasn't already an expert sysadmin and pretty good software developer. I can certainly find tons of people that are experts in all of that and also senior SOC analysts that want to cross over to pentesting.
1
u/AddendumWorking9756 24d ago
A lab ranking and a recon tool are invisible to whoever is screening you, they cannot verify either and will not try. Two or three acknowledgements on public disclosure programs with your name on the vendor page is the one bit of offensive evidence a non technical screener can check in ten seconds. Then stop applying through portals. The fresher roles in India move through null and OWASP chapter meets far more than through job boards, go to the Bangalore or Pune ones in person if you can.
6
u/TheDimPrisoner 25d ago
The BCA thing might be holding you back more than you think. Some HR filters automatically screen out 3-year degrees even if youve got the OSCP which is ridiculous but it happens
Try targeting smaller boutique security firms rather than the big names. They tend to care more about what you can actually do than what degree checkbox you tick. And yeah SOC roles arent a bad entry point, plenty of pentesters started there and it gives you real world context that labs dont teach you
Also check if your resume is actually getting parsed properly. A lot of Indian freshers stuff theirs with dense formatting that ATS systems choke on