General Cybersecurity

What 125,336 People Had to Say About Breaking Into Cybersecurity

JRobertson Security graphic illustrating survey findings about breaking into cybersecurity, titled "What 125,336 People Had to Say About Breaking Into Cybersecurity."

I posted about breaking into cybersecurity and 125,336 people saw it.

That part surprised me. What surprised me more was what happened in the comments.

I expected encouragement. I got a conversation — a real one. Career changers, veterans, senior practitioners, CISOs, recruiters, and hiring managers. All of them talking past the same problem from different sides.

Here’s what I actually heard.


YOU’RE NOT STARTING FROM ZERO

The most common response wasn’t a question. It was relief.

People who had spent years in healthcare, military service, project management, construction, sales, and finance read the post and recognized themselves. Not as people who were behind, but as people who had been told the wrong story about where they stood.

A risk analyst who came up through construction forecasting said it clearly: the ability to quantify uncertainty for a non-technical decision-maker transferred into cyber risk reporting more directly than any certification he’d picked up. Three career pivots, and he walked in more prepared than people with five years of security-specific credentials.

A project manager said the same thing. Risk management, stakeholder communication, governance, change management. Those aren’t soft skills on the side. They’re what a security program actually runs on.

The pattern holds. People who have worked in regulated environments, high-stakes operations, or roles where explaining complex things to non-technical audiences was the job — they’re not starting from zero. They’re just starting from a position they don’t recognize yet.


THE GAP NOBODY TEACHES

One commenter framed it better than I did in the original post.

The issue isn’t just skill transferability. It’s context transferability. Security teams don’t only need people who understand tools. They need people who understand how systems fail in real organizations, under real constraints. That’s harder to teach than technical tooling.

That framing is exactly right.

A healthcare administrator who understands audit trails, chain of custody, and regulatory pressure is already thinking like a GRC analyst. They just don’t have the vocabulary to say it in an interview yet.

That translation is teachable. And it changes everything for people who already have the foundation but don’t know how to frame it.


THE HIRING SIGNAL PROBLEM

Here’s where the conversation got uncomfortable.

A former presidential security staff member — CISO, top-tier MBA, led offensive security teams on multi-billion dollar deals — said he reads current job postings and feels unqualified.

Someone else pointed out a job description requiring ten years of experience with Microsoft Sentinel. Sentinel launched in 2019.

This isn’t a one-off. It’s the system.

A recruiter who places CISOs and security leaders into regulated financial services said the strongest hires he’s made came from audit, operations, and military intelligence. People who’d never written a line of code. What they had was judgment — the ability to read a situation that isn’t in the playbook, make a call with incomplete information, and own the outcome.

He also said something worth sitting with: straight-line security careers can produce a fragility. No budget fights. No moment where the right answer and the politically possible answer aren’t the same thing. That experience builds something certifications can’t.

You can’t certify your way into judgment. And the current hiring system isn’t well-designed to find it.


BOTH PROBLEMS EXIST AT THE SAME TIME

Someone asked me directly: what’s the bigger bottleneck — candidate self-selection or employer signal design?

Both. But if I had to weight them, employer signal design is the larger problem.

Candidate confidence is solvable. You can coach someone to translate their experience. You can help them reframe a healthcare background as compliance and risk fluency, or a military career as decision-making under ambiguity.

What’s harder to fix is a job description written by someone who copied last year’s posting, filtered through an ATS trained on keywords, reviewed by a hiring manager who equates domain-specific tenure with capability. That system actively works against exactly the candidates this field needs. The candidate does everything right and still doesn’t clear the filter.

That doesn’t mean you stop trying. It means you stop playing the game the way the system expects you to.


WHAT ACTUALLY MOVES THE NEEDLE

Several people who have hired, trained, and mentored through this offered consistent advice.

Stop applying cold. Start making yourself findable.

Visible work beats a credential stack. Build something you can point to — a home lab write-up, a TryHackMe path, a short post explaining a concept you worked through. Put it where hiring managers look. The candidates who break through aren’t always the most qualified on paper. They’re the ones who made it easy for someone to say yes.

Cloud presence is increasingly non-negotiable. Most organizations live in AWS or Azure. Candidates who can demonstrate hands-on cloud experience have a real edge over those who only have it in theory.

Don’t skip the social media cleanup. Hiring managers look. Every time.

And the writing requirement catches almost everyone off guard. Security work involves more documentation, reporting, and communication than people expect. The ability to explain what happened, what you did about it, and what it means for the business — that’s a skill. Start developing it before someone needs it from you.


THE FIELD HAS MORE ROOM THAN IT LOOKS LIKE FROM THE OUTSIDE

The comment I keep thinking about is a short one.

Someone said she’s been following the advice — and still hearing “we went with someone with more experience.”

That’s real. I’m not going to pretend the market is fair or that doing the right things guarantees a fast outcome. It doesn’t.

What I will say is this: the conversation in those comments included CISOs, senior practitioners, vCISOs, and recruiters — all saying the same thing. The field needs people who came from somewhere else. The instincts, the judgment, the ability to operate under pressure and communicate across functions — those things matter more than the job postings suggest.

The door is harder to open than it should be.

It opens.


Haven’t read the original post yet? Start there: How to Get Into Cybersecurity With No Experience

The full video breakdown is on YouTube: youtu.be/8G1rnC8P_5w

← This Is What Happens When Analysts Rely on AI
← Back to Blog

Want to Go Deeper?

Browse online courses that cover these topics with the depth and clarity you need to apply them.