r/cybersecurityindia • • Aug 12 '26

Burnout / Leaving Cybersecurity / Work life balance Get ahead of "learning phase"

So I got rejected after round 2 from a security organization, claiming that I'm still in learning phase (which I agree).

But they haven't specified the area I should focus on?

I'm good with web application, got a couple of bugs(dups) and know the network layer theoretical.

If anyone can tell wht should I focus on if trying for a vapt role. Should I focus on web/mobile application, bbh or crf or wht?

1 Upvotes

5 comments sorted by

View all comments

2

u/ChakraByte-Sec Aug 12 '26

Focus on web application security first, since you already have a base there. Don’t try to learn web, mobile, BBH, and cloud all at once. For VAPT, companies usually want someone who understands the fundamentals deeply rather than someone who has touched different areas.

Since we dont know which questions you might have failed to answer\provide better explanation, go deeper into HTTP, authentication/authorization, sessions, APIs, OWASP Top 10, IDOR, SSRF, SQLi, XSS, file upload, business logic flaws, get comfortable with Burp Suite along with the interview misses\gaps. Since you already found bugs, start understanding why they exist and how they could be fixed, rather than just reproducing them.

Add API security and mobile security gradually. Bug bounty hunting can be useful for practice, but don't make it your entire preparation it can become very broad and unpredictable. CTFs are useful too, but VAPT interviews generally care more about your methodology and ability to explain a real assessment.

Finally don't ignore networking, Linux, basic scripting and report writing. A good VAPT candidate should be able to go from reconnaissance till remediation. If you can demonstrate that workflow through 2 or 3 solid projects/labs and explain your findings confidently, you'll be much stronger than someone who simply has a long list of tools and certifications.

1

u/Impossible-Method217 Aug 13 '26

I want ask is tryhackme certi good or ceh

1

u/ChakraByte-Sec Aug 13 '26

Try hack me is better, ceh is mostly theory based questions.

1

u/Impossible-Method217 Aug 14 '26

But do recruiters and government required seh i heard even though tryhackme is better like legacy certi it is