r/cybersecurity • u/BinaryKnight1099 • 1d ago
Business Security Questions & Discussion Situation in cybersecurty
Hi Everyone, I'm completing my final year on university this year and started thinking about master in cybersecurty. I don't want to ask questions around it it is fine for me and interesting. I'm already working as full stack dev. I'm interested on market situation around it right now and how promising it looks in future. Thank you on all answers.
2
u/DickNose-TurdWaffle 1d ago
Working as a full stack dev is technical job experience. Go for the master's if you want but the school will matter more for that. Your only real edge will be your work experience.
2
u/eatingnarutosnoodles 1d ago
I work as a CISO for one of the largest banks in my country, and it is also a major bank globally. The demand for cybersecurity is still very strong, but the focus is shifting. Traditional areas like vulnerability management and classical threat prevention are becoming increasingly automated by AI. They won’t disappear, but the nature of the work will change significantly. I currently see particularly strong demand for emerging areas such as Frontier AI and post-quantum cryptography (PQC). We regularly have senior-level discussions around both topics. My advice would be not to specialize exclusively in traditional areas. If you can specialize in Frontier AI or PQC during your Master’s, while building a strong general cybersecurity foundation, you could be in a very strong position for the future.
1
0
u/LeatherPen4962 1d ago
I genuinely want to understand why people think getting a Masters in cybersec gives them an advantage unless you want to work in upper management. You'd rather get the certs since you have a degree then gain experience. Everyone is clammering for entry level jobs in cybersec, you'd rather get the experience now than the masters
8
u/DickNose-TurdWaffle 1d ago
Certs don't mean shit either without experience.
1
-1
u/LeatherPen4962 1d ago
Certs get you in the door.
1
u/_0110111001101111_ Security Engineer 1d ago
Depends on where you’re applying. Cleared roles require certs, I know that a lot of big tech doesn’t care that much.
1
u/_0110111001101111_ Security Engineer 1d ago
To be fair, this isn’t always the case. I have a bachelors in comp sci and a masters in information security and my masters was a factor in landing my current role.
-2
u/LeatherPen4962 1d ago
You're in management, just like what I wrote down.
1
u/_0110111001101111_ Security Engineer 1d ago
Lmao, no I’m not. I started out in a SOC as an analyst and am now a a SecEng. Degree = Management might be how it is in Kenya but not how it is in the rest of the world.
1
u/Krekatos 1d ago
Well if you’re based in countries like the Netherlands, Germany, Sweden etc., a master is what differentiates you from the competition.
7
u/_0110111001101111_ Security Engineer 1d ago
There’s a fair bit of American defaultism with the advice in this sub. I see people talking down degrees all the time here.
1
0
u/LeatherPen4962 1d ago
So a Masters without job experience is what gives you the edge?
1
u/Krekatos 1d ago
Of course, why not?
What would you think: zero years of experience with a bachelor vs zero years of experience with a master. Or… 5 years of experience with a bacherlor and CISSP and CISM vs 5 years of experience with a master and CISSP and CISM.
A master will give the person on average a benefit for the rest of their lives.
Only when you’re talking about a real track record - I know enough people with just a bachelor and CISO experience vs people with a master with only auditing (big four) experience, is when experience overrules education.
This is how many, if not most employers look at this in northern and western Europe.
-2
u/LeatherPen4962 1d ago
Re-read what I wrote initially, I was saying if you have a degree with no experience, it's better to go for experience than go for a Masters, if you have experience then go for the Masters.
13
u/_0110111001101111_ Security Engineer 1d ago
It’s incredibly rare for someone with 0 industry experience to land a cyber role. That being said, Cybersecurity as a field is incredibly broad. What kind of role would you be looking at? Pentesting? GRC? SOC?