How to Get into Cyber Security: The Honest Route
Getting into cyber security is a sequence of moves, and most of the advice online gets the order wrong by putting a certification first. Here is the route, with the part about entry level hiring that the ads leave out.

Search this question and you get two answers that contradict each other. One says the field is desperate for people, hundreds of thousands of jobs are unfilled, and a twelve week course will get you hired. The other, usually from someone six months into applying, says nobody answers, every posting wants three years of experience, and the whole thing is a scam.
Both are describing the same field from different points on the route. The demand is real and the wages are real. The first rung is also genuinely hard, and no amount of certification collecting fixes it on its own. What follows is the sequence that works, in order, with the government's own numbers where a number is needed.
How to Get into Cyber Security
The route has six moves and the order matters more than the contents of any single one. People who stall are almost always doing them out of sequence: a certification before any hands on the keyboard, or applications before anything to point at.
- Pick a directionOne of the five NICE work role categories, not a job title yet
- Build the baseNetworking, Windows, Linux, a scripting language, how identity works
- Build something you brokeA home lab, a capture the flag write-up, a script that does one useful thing
- Add one certificationThe entry credential that matches your direction, after the lab, not before
- Get hired near the workHelp desk, systems administration, cloud support, an internal transfer
- Move sideways into securityUsually 12 to 24 months later, usually at the same employer
Step one exists because "cyber security" is not one job. The National Initiative for Cybersecurity Education runs the map, and it is free: the NICE Workforce Framework for Cybersecurity, developed by NIST, establishes a common lexicon that describes cyber security work and workers regardless of where or for whom the work is performed. Its five work role categories are Oversight and Governance, Design and Development, Implementation and Operation, Protection and Defense, and Investigation. Reading those five definitions takes ten minutes and it tells you whether you are aiming at policy, engineering, operations, defense or forensics, which changes every decision after it. CISA's own advice to beginners puts the framework first, before any course, for exactly that reason.
Step two is where most of the calendar goes. The technical base under every security role is the same: how a network moves a packet, how Windows and Linux handle users and permissions, how identity and authentication work, and enough scripting to automate something boring. Security is applied knowledge of systems, so the field itself is unreachable without them.
Step three is what turns a resume from a claim into evidence. Nobody can verify that you studied. Anyone can look at a lab you built, a write-up of a challenge you solved, or a small tool you published.
What Qualifications Do You Need for Cyber Security?
The honest answer has two halves that the marketing keeps separate. The formal qualification employers name and the informal one they actually screen on.
For the formal half, the Bureau of Labor Statistics Occupational Outlook Handbook page for information security analysts, read on September 7, 2026 and last modified on August 27, 2026, lists a bachelor's degree as the typical entry-level education and adds that some workers enter the occupation with a high school diploma and relevant industry training and certifications. Its own summary states that these analysts typically need a bachelor's degree in a computer science field, along with related work experience.
Read that last clause twice, because it is the whole problem with the standard advice. The government's occupational profile lists prior work experience in a related occupation in its Quick Facts table, defined there as what employers usually consider necessary, not as a bonus. The same page notes that many analysts have experience in an information technology department, often as a network and computer systems administrator.
The informal half is the certification question, and it is genuinely useful for getting through an applicant tracking system. It is also the most oversold part of the route, and it is a whole subject on its own: which certifications employers name in job ads, what each demands before you can hold it, and what each one actually costs.
Do You Need a Degree to Get into Cyber Security?
No, and yes, depending on which door you are walking through.
You do not need one for most private sector operations roles. Analyst, support, junior engineering and consulting jobs are filled on demonstrated skill and prior IT work every day, and the BLS acknowledges the high school diploma plus certifications route as a real entry path into the occupation.
You are at a serious disadvantage without one in three places: cleared defense work, large regulated employers whose HR filters cannot be argued with, and any role you want to enter directly as a graduate rather than sideways from IT. Federal civil service is not one of them, which surprises people: OPM's qualification standard for the 2210 information technology series allows eligibility through either the education requirements or the experience requirements, and says that experience may be demonstrated by paid or unpaid work or by completing specific intensive training such as an IT certification. A degree still compounds. The BLS lists it as the typical entry-level education, which means a hiring manager reading a hundred resumes uses it as a first cut without any hostility toward you personally.
If the degree route is the one you want, CISA's beginner page is the cheapest place to start looking, because it lists more than 500 colleges and universities with nationally recognized cyber security degree programs, many of which offer scholarships up to $27,000 for undergraduates and $37,000 for graduate students. Those scholarships change the arithmetic of the decision considerably, and almost nobody comparing bootcamps against degrees has looked at them.
Which Cyber Security Job Should You Aim for First?
Aim at a category before you aim at a title. The NICE Framework groups the work into five categories, and the realistic first jobs are concentrated in two of them.
| Work role category | What the work is | Realistic as a first job? |
|---|---|---|
| Protection and Defense | Protects against, identifies and analyzes risks to technology systems or networks | Yes. The SOC analyst seat is the standard entry point |
| Implementation and Operation | Provides implementation, administration, configuration, operation and maintenance of technology systems | Yes, and it is the usual side door from IT |
| Investigation | Collects, processes, analyzes and disseminates information from all sources of intelligence on foreign actors' cyberspace programs and operations | Rarely. Its two work roles are cybercrime investigation and digital evidence analysis |
| Design and Development | Researches, conceptualizes, designs, develops and tests secure technology | No. Needs software or systems engineering experience first |
| Oversight and Governance | Provides leadership, management, direction and advocacy for the security program | No. These are the roles other roles lead to |
The Cyberspace Intelligence and Cyberspace Effects categories moved out of the NICE Framework and now live in the Department of Defense Cyber Workforce Framework, which is worth knowing if military or intelligence work is the target.
The default first seat is the security operations center analyst, and the honest description of it is triage on a shift rota. Alerts arrive, you decide which are real, you escalate the ones that are, you write up what happened. It is repetitive, some of it is at three in the morning, and it is the single best place to learn what an attack looks like from the inside, because you see hundreds of them. How a security operations center runs and what a SIEM console actually shows an analyst are the two things worth understanding before an interview for one of these jobs, because you will be asked about both.
How to Get into Cyber Security with No Experience
Nobody starts with experience. The question is which cheap forms of it a hiring manager counts, and the answer is narrower than the internet suggests: anything you can show, anything someone else can vouch for, and anything you were paid for.

Two things worth doing alongside the list: learn the vocabulary properly, because interviews are largely a test of whether you use the words correctly, and work through the basics a beginner needs first so the lab work has something to attach to.
How Hard Is It to Get an Entry Level Cyber Security Job?
Harder than the advertising says, and the mismatch is arithmetic rather than opinion.
The widely repeated figures about hundreds of thousands of unfilled cyber security jobs come from industry workforce studies, not from a government count of vacancies. The government count is narrower and much less flattering. The BLS projects employment of information security analysts to grow 21 percent from 2025 to 2035, against 3 percent for all occupations, an increase of 40,600 positions, with about 14,100 openings projected each year on average over the decade. That is a fast growing occupation. It is not an occupation with a quarter of a million empty desks waiting for a bootcamp graduate.
That last line is the one that explains the experience of everyone shouting into the void on career forums. In the government's own occupational profile, prior experience in a related occupation sits in the Quick Facts table alongside the degree. It is described as an occupation you move into from a related one, not one you start in. The postings asking for two or three years of experience are not being unreasonable; they are describing the occupation accurately.
The traditional side door has narrowed too, which is worth knowing rather than being surprised by. Computer support specialist roles, the classic help desk starting point, had 903,100 jobs in 2025 and the BLS projects that number to decline by 3 percent through 2035, with a median wage of $62,890 in May 2025. It is still the highest volume entry point into IT by a wide margin, with about 48,700 openings a year, and it is still the advice. It is simply not a growing door.
Can I Make $200,000 a Year in Cyber Security?
Yes, and the BLS data lets you see exactly how far out on the curve that sits.
The median annual wage for information security analysts was $129,180 in May 2025. The lowest 10 percent earned less than $75,090, and the highest 10 percent earned more than $199,850.
| Where you sit | Annual wage, May 2025 |
|---|---|
| Lowest 10 percent | Less than $75,090 |
| Median | $129,180 |
| Highest 10 percent | More than $199,850 |
So $200,000 is roughly the ninetieth percentile of the occupation. It is a real number that real people are paid, and it is not what anybody earns in year one. Industry moves it a little: the same page puts the median at $138,650 in information, $132,410 in computer systems design and related services, and $130,630 in finance and insurance.
Getting to the top decile generally means one of four things: a senior individual contributor role in security engineering or architecture, management of a security function, consulting or offensive testing at a firm that bills for it, or a specialization with a thin supply of people such as cloud security, detection engineering or industrial control systems. Every one of those is five to ten years in from the first job. Treat $200,000 as a ceiling that exists, not a starting salary that was promised.
Is 30 Too Old to Learn Cyber Security?
No, and the occupational data explains why the question has the answer backwards.
If security were an entry level occupation filled straight from graduation, being thirty would be a disadvantage. It is not one. The BLS describes an occupation entered with prior work experience, and notes that many analysts came from an information technology department, often as a network and computer systems administrator. An occupation whose normal entry path is a lateral move out of a previous career is an occupation structurally friendly to people who have had a previous career.
The specific advantage is domain knowledge, and it is worth more than most thirty-year-olds think. Someone who spent eight years in hospital administration understands clinical workflows and where patient data actually moves, which is exactly what a healthcare security team cannot hire for. The same is true of anyone who has worked in finance, manufacturing, logistics or retail. Security is a business problem before it is a technical one, and the person who already understands the business is halfway to being useful.
What a career changer should do differently: aim at the industry you already know rather than starting over in a new one, be direct about the transition rather than hiding the previous career, and take the internal transfer route seriously, because moving into your current employer's security team is far easier than convincing a stranger. Forty is not too old either, for the same reasons.
How Long Does It Take to Get into Cyber Security?
There is no single number, but there are honest ranges by starting point, and they assume real study time rather than a course watched at double speed.
- Already in IT, in a systems or network role. Six to eighteen months. You have the base and the employment history; you need the security-specific knowledge, one certification and an internal move.
- Already technical but not in IT, for example a developer or a data analyst. One to two years. The systems fundamentals are the gap, particularly networking and identity.
- Non-technical, working full time. Two to four years, with the first job being IT rather than security. This is the range the route above is built for, and it is the one most guides quietly avoid printing.
- Full time student. The degree length, plus an internship, plus the same lab and certification work as everyone else. The degree is not a substitute for the portfolio.
The variable that moves those ranges most is not intelligence or study hours. It is whether you get paid to touch systems early. Everything speeds up once someone is paying you to be near the work.
What Does a Cyber Security Career Path Look Like?
The first job is a branch point, not a destination. From an operations seat, the common paths are detection and response engineering, incident response, penetration testing, cloud security, governance and risk, and eventually security leadership, which is the Oversight and Governance category in the NICE Framework.
The people who move fastest tend to specialize deliberately about two years in, once they have seen enough to know what they want, and generalize again later when they are managing. The people who stall tend to stay in the same triage seat for five years collecting certifications instead of scope.
Key takeaways
- Pick a direction from the NICE Framework's five work role categories before picking a course or a certification. It is free and it is the map employers use.
- The technical base is networking, Windows, Linux, identity and a scripting language. Nothing in security is reachable without it.
- Build a lab and write up what you broke. It is the only evidence a hiring manager can verify.
- BLS lists prior work experience in a related occupation as what employers usually consider necessary for the analyst role, which is why entry level hiring is genuinely hard and why an IT job first is the standard route.
- The occupation is growing 21 percent through 2035 with about 14,100 openings a year, which is fast growth but not the limitless demand the ads describe.
- $200,000 is roughly the top decile of the occupation, five to ten years in, not a starting salary.
- Thirty and forty are not too old. The occupation recruits laterally, and your previous industry is the asset.
- Realistic timeline from a non-technical standing start is two to four years, with the first paid job in IT rather than security.
Common questions
How do I get into cyber security with no experience?
Build a home lab on hardware you already own, document what you broke and how you found it, take one entry certification, and get hired into any paid role that touches systems: help desk, desktop support, cloud support. Then move sideways into security, usually at the same employer, twelve to twenty-four months later.
What qualifications do I need to do cyber security?
The BLS lists a bachelor's degree as the typical entry-level education for information security analysts, along with related work experience, while noting some workers enter with a high school diploma plus industry training and certifications. In practice most private sector employers screen on demonstrated skill and prior IT work first, and the degree matters most for cleared defense roles and large regulated employers.
Is a 2 year cyber security degree worth it?
An associate degree is worth it if it is cheap, if it comes with an internship or a lab component, and if you treat it as a route into an IT job rather than directly into security. It is not worth taking on significant debt for, because employers weigh the portfolio and the work history more heavily at that level.
Can I get into cyber security without a degree?
Yes, and plenty of people do. The route is longer and depends more on your work history: an IT role, demonstrable hands-on skill, one or two certifications to get through automated screening, and an internal move. The doors that narrow without a degree are cleared defense work and some large regulated employers. Federal civil service is not one of them, because OPM's IT qualification standard accepts experience in place of the education requirements.
Can I make $200,000 a year in cyber security?
Yes, at roughly the top ten percent of the occupation. BLS reported that the highest 10 percent of information security analysts earned more than $199,850 in May 2025, against a median of $129,180. Reaching it usually takes five to ten years and a senior engineering, leadership, consulting or scarce specialization role.
Is 30 too old to learn cyber security?
No. The occupation is normally entered laterally, with prior work experience in a related field, so a career changer at thirty is closer to the standard profile than a new graduate is. The industry you already worked in is the asset rather than the liability.
Is 40 too old for cyber security?
No, for the same reason. What matters is the ability to show current technical skill and the domain knowledge you already carry. The realistic adjustment at forty is targeting roles where your existing experience is worth something, such as risk, compliance, or security for the industry you spent two decades in.
Is cyber security hard to learn?
The fundamentals are no harder than any other technical discipline, and the tools are learnable. What makes it feel hard is breadth: you need working knowledge of networks, operating systems, identity, cloud and scripting before the security layer makes sense. Depth in one area beats a shallow pass over all of them.
How long does it take to get into cyber security?
Six to eighteen months if you are already in an IT systems role, one to two years if you are technical in another field, and two to four years from a non-technical standing start, with the first paid job being IT rather than security. Getting paid to work near systems early is what compresses every one of those ranges.
What is the best first job in cyber security?
The security operations center analyst seat, because you see a high volume of real alerts and learn what attacks look like from the inside. The realistic step before it, for most people, is help desk, desktop support or systems administration, which is where the occupational data says many analysts come from.
Is cyber security a good career?
By the numbers, yes: BLS projects 21 percent growth for information security analysts from 2025 to 2035 against 3 percent for all occupations, with a median wage of $129,180 in May 2025. The caveat is the entry point rather than the career. Growth is strong once you are in, and getting in takes longer than the advertising suggests.
On this page
- How to Get into Cyber Security
- What Qualifications Do You Need for Cyber Security?
- Do You Need a Degree to Get into Cyber Security?
- Which Cyber Security Job Should You Aim for First?
- How to Get into Cyber Security with No Experience
- How Hard Is It to Get an Entry Level Cyber Security Job?
- Can I Make $200,000 a Year in Cyber Security?
- Is 30 Too Old to Learn Cyber Security?
- How Long Does It Take to Get into Cyber Security?
- What Does a Cyber Security Career Path Look Like?

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.