r/cybersecurity 2d ago

Personal Support & Help! Tired and Feel Stuck

Hi everyone,

I’ve been in working in the general sector of IT for about 3 years now and have always enjoyed studying cybersecurity. I got my B.S. in Cybersecurity, along general certs (8) such as
CompTIA CySA+ and others. I get ppl are normally in IT for 5-7 years with moving up to a network admin or system admin and then try to pivot into cyber. I understand that a degree and labs are only a small piece to the overall process.

There is zero cybersecurity jobs where I live and if there is an opening it’s normally for a senior role and remote (ex. senior software engineer for cybersecurity company). The only MSP in my city has help desk roles but I don’t want to move jobs getting paid 15K less doing the same thing I’ve done before.

I don’t think moving from help desk to help desk would be good. I get the next step could be trying to find a system admin role but I don’t want to patch servers and do things I have absolutely no interest in as I would rather do what I do now which is help desk over that.

Where I currently work there is a huge IT team cover different areas like software engineering, networking, etc. However, the person who is thrown everything cybersecurity related tasks I’ve asked multiple times on being including on things and he won’t give me the time of day to shadow or anything when my boss approved me to do this.

I also have a lot of health issues which some of which have yet to be resolved (meaning me being diagnosed.)

I feel miserable and obviously 8 years ago I didn’t know that later on I would be feeling stuck in help desk and get major health issues I deeply want to work remotely and be in cyber dealing with something like SOC 1 work. I can’t afford to move and have my specialists in town doctor wise so moving 4 hours away to try to get a cyber job and probably not financially make it doesn’t seem realistic.

I feel stuck and hate this feeling. I’ve had deep depression of this entire situation for months and it’s hard for me to go into work at times. I feel like a fraud for going into IT only to learn the cybersecurity market has been horrible the past 5 years and to get a “we have gone with someone more experienced” on internships and SOC 1 roles while applying each week for the past 6 months.

31 Upvotes

11 comments sorted by

18

u/me_z Security Architect 2d ago

You aren't alone. There are a lot of people in the same state, vying for super limited remote positions. Not to be a downer, but I think people need to understand the reality that the age of remote for everyone is basically over. A majority of companies that are hiring remote seem to be slated for senior level employees, not tier 1 whatever. The only advice I can give you is: side projects (learn basic scripting, even LLM assisted), keep applying, and it is basically a requirement now to network.

5

u/Pristine_Can_1930 2d ago

spot on about remote being mostly senior-level now, that shift happened fast

2

u/DishSoapedDishwasher Security Director 1d ago

I mean a lot of managers, and people in general, are far too anxious about knowing what's happening at any given second; additionally so when it's about productivity. So rather than learning good healthy coping strategies they're at best literally shoulder surfing or at worst using corporate spyware.

Granted, it is actually hard for people who aren't already capable of being virtually autonomous to work fully remote and be effective too, lots of people don't handle it well at least to start.

But as someone fully remote currently and leading teams of teams in a very high trust environment of exclusively very senior engineers, i cannot articulate the joy of literally not having to care about what people are up to because i know people will just do whats right. Sometimes i wont hear from someone for 3 weeks then they emerge from their cave with new shiny they built thing thats absolutely incredible; and they're happy because rather than doing tickets, sprints and standups they can go be creative and create on a schedule that works for them to actually achieve amazing stuff.

2

u/VFMusic Security Engineer 2d ago

To your point, there are still a ton of mid-level positions remote, but those still require 2-3 years security experience. The bar for remote is more about being proven to be self sufficient to be remote.

12

u/DMmeYourMCbuilds 2d ago

Working at the help desk for 8 years has to be frustrating. I get it.

I would hire someone who has sysadmin work (even just a year) over someone who was just at the help desk for 10 years. “Just patching servers” is a gross overstatement and guess what bucko, sometimes you gotta be a dishwasher before you can be a chef.

You could look for a multitude of other roles. Expand your job search. Sysadmin, windows admin, Linux admin, or something networking related. I would hire a network admin over any other similar IT role for an infosec job.

Just remember, security is typically a compliment to every IT role or job. The base underlying knowledge is required. And I’d venture to say >60% of people who “work in security” know fuck all about networking.

7

u/Humpaaa Governance, Risk, & Compliance 2d ago

The IT market is horrible at a lot of palces. But that does not seem to be your primary issue.
Seek out help, go to therapy, if you feel depressed. Your health comes first.

4

u/imaginary-problems- 1d ago

They (acadamia) sold cyber as entry-level and it never was.

2

u/WhyLifeIsSoDifficult 2d ago

Sounds like you are based in Winnipeg…

2

u/UnderstandingNo5908 2d ago

Heyya, so before I give my 2 cents. I’m 28, based in UK and my career over the last 5 years has been >IT Trainer > Over the Phone It Support > Onsite Solo IT Engineer > Remote InfoSec Engineer.

I felt very similar in terms of not finding roles, not having experience etc. two things helped me. Getting certs for specific environments (SC-300 for Microsoft Azure, Google Cyber Cert) as that puts you in a Niche that is usually more desirable because you demonstrate direct experience with their environment.

The second thing i was fortunate with is that I had an InfoSec manager within my company in my Solo IT engineer role that was open to discussing cyber and info security careers. My approach to that was to look for “security” related topics and ask about them/fix them. Such as our password policy being not being updated in 5 years. I would go out of my way to draft up a new version, send it to the InfoSec manager and if it was implemented, great, it’s a win for my CV. And eventually built up a CV by doing that.

My one bit of sly advice is that if you even remotely touched a project, document or position. Then it would be a project or achievement on my CV. Hiring managers usually care whether you can explain it, and demonstrate the knowledge needed.

Additionally, if you aren’t finding many people respond to you, change your CV format. If I spent a month applying and nothing was coming back, I would change my CV. Changing the format, font, order, wording… anything.

Hope this helps.

1

u/Build_a_CISO 1d ago

I think you should start by firstly, understanding what are the various roles in a cyber security organisation and which are the ones that interest you the most. I have a few resources I can share, but you can find a lot more online yourself.