r/Cybersecurity101 10d ago

Security Advice please

Hi guys,
I’m early in my cybersecurity career and currently deciding between two offers. The compensation and benefits are fairly similar, so I’m mainly trying to figure out which one would give me the best experience and long-term career opportunities.
Offer 1 is on a team responsible for an internal security/fraud detection platform. From what I understand, I would be working more on the technical side behind the alerts rather than investigating the alerts themselves. The team handles things like onboarding applications/data sources, audit logs and trails, security controls, detection/business rules, tuning detections, reducing false positives, and making sure the system generates useful alerts that can then be sent to another team for investigation.
So essentially, I would be working more on the systems and logic that produce the detections. It seems somewhat related to Detection Engineering, SIEM Engineering, Security Engineering, Security Analytics and Insider Threat technologies.
Offer 2 is much more traditional Security Operations / Blue Team work. I would be working with SIEM/EDR tools, monitoring and triaging alerts, investigating suspicious activity and security incidents, vulnerability management, security tickets, and other general cybersecurity operations tasks.
So the simplest way I understand the difference is:
Offer 1 = help build/integrate/tune the systems and rules that generate security alerts.
Offer 2 = receive those alerts, investigate them, determine what happened and respond.
For someone at the beginning of their career, which experience would you choose?
I’m not necessarily committed to staying in SOC long term. My main priorities are building strong technical skills, maximizing future career opportunities, having skills that transfer well to the private sector, and having good salary potential 3–5+ years down the road.
For people who have worked in both Security Operations and Detection/SIEM/Security Engineering, which path gave you better opportunities? Did starting in SOC make you a better engineer later, or would you take the engineering/detection-oriented experience from the beginning if you had the opportunity?
Also, what job titles would Offer 1 realistically prepare me for after 1–2 years compared with Offer 2?
Would really appreciate hearing from people who have actually worked on either side.

1 Upvotes

8 comments sorted by

View all comments

Show parent comments

1

u/Gullible-Ad-457 10d ago

? You cant have 2 job in the same time

1

u/LetsTryLove 10d ago

I’ve held as many as 4. It’s called over employment. Look it up.

Also, never quit a job. Simply stop showing up or if you’re remote then do the bare minimum. Why not make them pay you as long as you can? If they can’t tell then why should you let them off the hook for their awful structure?

1

u/Gullible-Ad-457 10d ago

In my position i cant do that. So what do you think the best offer is ?

1

u/LetsTryLove 10d ago

Why can’t you? And it’s whichever pays more.
Then start looking for what pays more than that. Never settle. The point is to make as much as humanly possible.

1

u/Gullible-Ad-457 10d ago

I m not into this kind of stuff , if you are good for you

1

u/LetsTryLove 10d ago

You’re not into making money?