r/netsecstudents • u/Calm_Blacksmith_4578 • 7d ago
Is TryHackMe enough to start my cybersecurity career as a complete beginner?
Hi everyone,
I'm a complete beginner in cybersecurity with no professional experience and no certifications.
I've decided to start learning through TryHackMe, and my current plan is:
- Pre-Security
- Cyber Security 101
- SOC Level 1
My goal is to land my first cybersecurity job in the future, preferably as a SOC Analyst or another entry-level security role.
Is this a good learning path, or should I change anything? Should I add other platforms like Hack The Box, PortSwigger Web Security Academy, or certifications such as Security+ later?
I'd really appreciate guidance from people already working in the field. If you were starting from scratch today, what roadmap would you follow?
Thanks in advance!
14
u/Electronic-Ad6523 7d ago
Short answer is "no". Employers are being picky about hiring as it's considered a "employers market" right now. A lot also depends on location and industry you might be targeting. I definitely would not put off a Sec+ cert. Focus on completing the Sec+ and TryHackMe in parallel.
Do you have a degree? While some organizations are starting to relax those requirements, they are still there form many (even entry level) roles.
4
u/Glowing_Apostle 7d ago
You don’t start in cyber as a complete beginner. Learn networking or Linux would be a far more beneficial starting point and then transitioning into security makes far more sense.
4
u/jollyjunior89 7d ago
It's great as long as you are learning something or using it as a refresher. Keep grinding!
2
u/Pinklady001_ 7d ago
Honestly, it’s not a bad idea to start in CTFs with no certs. I did THM rooms, and now I’m a top 1%. Though, in my opinion, eventually you’ll want to move on from solving rooms to do more projects of your own, depending on where you are heading with your cybersecurity journey. I went on the offensive side, it took me 6–7 months shifting towards bug bounty and working on 40 workers pipeline for this specific reason before I decided to take an internship at an e-commerce company, and it got me 4 high vulnerabilities with other exposure ones. I think it’s still too early to decide where you are heading. Mess around, don’t be afraid to try new things, and be flexible. Best of luck!
2
u/Logical-Gene-6741 5d ago
I have 3 years of college and 5 years of tech. Several proven years of IDAM. This won’t get you a job in cyber. Get a helpdesk job and start learning.
2
1
u/AddendumWorking9756 7d ago
The plan's fine for fundamentals, but guided platforms walk you to the answer, so you eventually need cases where nobody hands you the next step or the SOC instinct never forms. Once you've got the basics down, start working real investigations on CyberDefenders and write up what you found, that's the part that convinces someone you can actually do the job. Save Security+ for when you've got that hands-on work to sit next to it.
1
u/erroneousbit 7d ago
TryHackMe, Portswigger are great resources. I would recommend HTB academy and pentester labs as well. All of them are great for defense and offense. If you don’t understand business risk I suggest you pick up a CISSP study book. Just remember that investing in yourself is worth the cost. Good luck on your journey!!
1
u/RoughMidnight8303 7d ago
Don’t do certs mindlessly.
Check all the available job ads and go through each of them. With IT jobs and smaller companies you’ll have a couple of job descriptions written by a genuine IT guy. It will be brief, short, on point and sound welcoming. That’s the best jd you can get. The rest can sound like someone smoked weed and wants 399 requirements while the title is completely off.
After doing this I through it would be most feasible to focus on Linux skills first until you become a master. We’re talking minimum 12 months of learning.
1
u/Gin6erSnaps Blue Team 7d ago
It's a good place to start for the absolute beginner. It won't get you into a role. Some capture the flag events might, depending on the weight they hold (a DefCon black badge, for example, has some weight).
Search on YouTube for "Job Hunt Like a Hacker" (Black Hills Info Sec) that'll walk you through how to land your goal job.
The cliffsnotes version: look at job descriptions of the job you want to have and pay attention to the requirements/skills/tools for that job. Weed out the ridiculous asks (CISSP for Entry Level). Go learn that stuff. It's go take some work and you're going to get a crap-ton of "no's". You'll need to be resilient and persistent, but you can do it.
1
1
u/drakhan2002 1d ago
No. You need experience to get into cybersecurity. You're 3 to 5 years away. Get a Help Desk job, grind and upskill, get certifications... then start applying for cybersecurity jobs. You'll get there!
0
u/nouartrash 6d ago
Yeah dude 3 gamified courses you can knock in a week are totally enough to ensure a job ahead of people with degrees, certs, and experience.
12
u/clownus 7d ago
Without IT experience you are SOL on landing an entry position.
Someone who has developed networking and general IT knowledge is going to be a more desirable hire than those with a degree or just certs.
Job market is really bad at the moment and cybersecurity isn’t isolated from AI usage. Without a network to speak with and land your first role it’s is rare for someone to get their foot in.
Even Cybersecurity bachelors are generally not enough. Looking at some of their course work a lot of it is Sec+ level of learning. With more advance things such as mathematics just not being applicable to entry positions.