Transcription
If I had no prior experience and someone told me I had to find a job in cyber security in the next six months or my whole family would die, and the only thing I was allowed to spend money on was the Google cyber security program, I know exactly what I would do. After watching this video, you'll know what to do too.
So, if you're experiencing analysis paralysis about getting into IT or cyber security and you don't really have a lot of money to throw around, I made this video just for you. It can potentially change your life if you take advantage of it.
Also, in an effort to verify the claims of making this video and to gather feedback in general, I'm going to be giving away a thousand dollars worth of Amazon gift cards. Just check the pinned comment for details.
In this video, I'm going to give you a roadmap with a lot of actionable items on it, as well as some material that you can actually use. Then, I'm going to send you on your way knowing fully what you need to do in order to break into cyber security.
Just so you know what to expect, I'm going to give a brief overview of the Google cyber security program. I have actually gone through the program myself. I passed it, I got the certificate, and I even shared it on LinkedIn.
I'm also going to talk about and show some visuals of where you can expect to be immediately after finishing the program, as well as some visuals of where you can expect to be after implementing every single thing the program recommends you to do.
Remember, for this exercise, we're not allowed to spend any money other than on the Google cyber security program, which, by the way, is incredibly cheap. You can use the link in the description for a free 7-day trial, and after that, it's only $49.99 a month for as long as you need until you complete the program.
I will say, if you're interested in cyber security at all, I highly recommend you go through the program. I've taken tons of certifications in my career and been through a whole bunch of programs. I have five CompTIA certifications, I took Security Plus twice to get it expired, I have CCNA, TISP, and a bunch of other certifications.
I can say without a shadow of a doubt that the actual cyber security theory delivered in the Google cyber security program is the best you're going to find on the internet, especially for that price point. From the production quality to the topics to the lab environment where you practice stuff, even the instructors, who are security professionals from Google, the whole thing is just really well put together.
The whole program consists of different courses that cover a broad range of security topics, as well as some job hunt preparation material. I'm not going to cover every single course inside the program because there are a lot of YouTube channels already doing this.
What really stood out to me about the Google cyber security program is that it basically covers everything that Security Plus covers and then some on top of it. Specifically, the hands-on component around SIMs, which is a requirement for a lot of cyber security jobs.
There's also a whole course that teaches you how to code in Python and how it relates to cyber security. These two topics are huge in cyber security, and it's especially difficult to get hands-on experience using a SIM. The program does cover other important theoretical topics as well, such as cyber security frameworks and regulatory bodies, but we'll talk about those a bit later.
As far as how long it takes, Google reports that it takes about six hours per week, and it will take roughly six months to go through the entire program. I've never actually seen it take that long before. If you work a couple of hours a day consistently, you'll probably finish it within a couple of months.
Getting right into the roadmap, this is you and your personal stats as they relate to getting your first job in cyber security before you go through the program. Let's just assume all of your stats are zero. If you do the absolute bare minimum to pass the program and get the actual certification in your hands, this is kind of what you would expect your stats to look like.
Remember, this is just the bare minimum. You didn't do any of the other stuff the program recommends; you just passed the quizzes and then got the certificate. This is where your stats will look like in the program. Google actually acknowledges that you need to have a great resume, portfolio, interview ability, among other things, to really increase your chances of getting that first job.
But these things are not really required to get through the actual program and get the certification, if that makes sense. This video is going to hold your hand and guide you step by step on addressing these other areas that Google recommends, which will ultimately help you land that first cyber security job.
The good news is some of these areas are basically very easy to address. Consistency, job hunt execution, self-presentation, and written communication are all things that you can basically do on your own immediately. They just require a bit of execution and discipline on your part.
For consistency, for example, if you happen to actually dedicate two hours a day for the whole endeavor of breaking into cyber security, like all of the steps, at least two hours a day with no zero days, you can kind of consider your consistency stat close to being maxed out or maxed out.
When it comes to your self-presentation stat, when you're uploading your photo to LinkedIn or joining your Zoom interview, all you have to do is make sure you're wearing appropriate attire. Make sure you're groomed, and your clothes fit and everything's fine in that regard. You can consider this stat taken care of as well.
Very easy. Finally, the last easy thing that you can take care of is your written communication stat. You don't have to write that much. Maybe you're corresponding with a technical recruiter or in your interview, or you're sending emails to the hiring manager.
There's no reason that you shouldn't use ChatGPT or at least a grammar and spelling check before you send those correspondences. Like any of the other easy things, it's not like writing perfectly is going to get you a job, but writing poorly or misspelling HIPAA or something like that is definitely going to prevent you from getting a job.
Not wearing perfect clothes is not going to guarantee you a job, but wearing something weird like pajamas or a hat to your interview is possibly going to prevent you from getting a job. Yes, these stats that I just talked about are all easy gimmies that you can do to make sure that you're the best version of yourself possible.
Now, time to address the actual difficult things that you came to this video for. The first thing we're going to talk about is your resume. Your resume needs to be as good as it possibly can be for both humans and ATS, which stands for application tracking system. You can kind of think about it like the automated resume scanner.
The quality of your resume is basically a force amplifier when it comes to getting a job. What I mean by this is a really nice resume could yield 10 interviews if you apply to 100 places. But if you have a bad resume and you apply to a thousand places, it's possible to get zero interviews or none at all.
So, it's really important that we take care of this if you want to get a top-tier resume. Use this link in the description; it's a nice resume template that I use for the cyber security students in my course. Watch this video as well, and it will teach you how to construct a top-tier resume for zero dollars.
Basically, what you'll do is take this resume template, retrofit it with your own information, and make sure to do the actual stuff so the resume is telling the truth. Then you can kind of assume your resume stat is taken care of, maybe 90 to 100 relative to that entry-level job.
The next thing we need to worry about is our portfolio. If you don't have one or you don't know what one is, definitely watch this video. It will guide you through the process step by step on creating a nice, pretty portfolio using GitHub.
The lab that we do in my personal cyber security course is really good to go on your portfolio, and I have the students put it on theirs. But since this guide is supposed to cost zero dollars, I'm going to tell you how to emulate the lab in my course so that you can put it on your own portfolio for free.
Basically, the lab that we do in my course that you can emulate for free is we create a bunch of virtual machines in the cloud. We turn off the firewall for them and expose them to the raw public internet, letting all the virtual machines get attacked relentlessly by live bad actors and bots on the internet.
We enable logging and ingest all of those logs from the virtual machines into a central repository. We set up a cloud-native SIM, configure alerts, practice incident response, and then go through and secure the environment. We observe the reduction of attacks and security events, and then we document everything, make it look pretty, and put it on our portfolio in GitHub.
If this all sounds too complicated, you can definitely check out this video; it has some more simplistic security projects on it. I would recommend picking one or two of those, making them look really pretty using the portfolio video, and then just creating a really nice-looking portfolio.
The portfolio can then go on your resume, but also, more importantly, when you're in interviews and someone asks you about something, it's possible for you to say, "Oh, actually, I worked on a project with that. Do you mind if I share my screen with you and show you?" Then you can show them your portfolio, and that's going to really impress your interviewer.
Not only have I done this many times, but I've also told my students to do it, and they've done it as well. It worked, and they ended up getting hired, so I highly recommend making a really nice portfolio.
Next up is the experience stat, which is one of the hardest ones to raise in cyber security because we have this famous Catch-22 scenario where we need experience in order to get experience. But there's a way to deal with it.
The experience section that you see in the top-tier resume template is actually what the students in my course use who have gone through the internship program. But you can emulate this on your own for free with a little bit of effort. Remember, since we're not spending money, instead of actually going through the course, you can look at all the technology and stuff implemented in this experience section.
You can go and do that stuff yourself and make sure you really learn how to do it and learn it fully. Then, create a bunch of high-quality content around it. It could be shorts, like Instagram shorts, TikToks, or make some long-form YouTube content about it. Put it on your portfolio, make some blog posts or something like this.
On your resume, you could either open up your own company or just put "content creator" and then link to the stuff, maybe like a single link to a GitHub page that links to all of your other socials. Then talk about how you are a security professional, like a security educator or something like that—a cyber security content creator.
You can still list out those same technologies under your company name or content creator and put it on your resume. This is way better than having nothing at all. As someone who hires people, if I saw this, I would be super happy to see it, and it's a great conversation point as well.
Once you've taken care of this, you can at least consider your experience stat, as well as your social network stat, raised up a little bit, maybe like 50, depending on how well you implemented this step. Just for the record, I've provided references for several people using this resume template with this exact experience entry, and I know for a fact that many of them have been hired.
Getting into how to address your interview skill stat, the very first thing I would recommend doing is just start listening to the CyberWire Daily podcast right away, like every single day. This is a really highly produced, high-quality daily news cyber security broadcast that will help you keep up to date with the industry.
It's almost guaranteed that an interviewer is going to ask you something like, "How do you stay up to date with the industry?" or "What is your favorite breach?" or they'll say something like, "Name three breaches that happened in the last five years." I've been asked so many variations of these questions so many times; it's basically guaranteed that someone is going to ask you this.
Listening to this podcast is definitely going to help you answer that really well. I would also highly recommend listening to the Darknet Diaries podcast every single day, at least one episode until you've listened to all of them. Listening to these two podcasts over time is going to help you much more than you realize.
Even the ads that play in them are cyber security-centric. It's kind of magical, but listening to them enough and hearing cyber security professionals speak over a long period of time is going to improve your cyber security vernacular a lot. You'll be able to talk intelligently with interviewers, and you'll sound comfortable. It's just going to help you a lot.
I highly recommend listening to both of these going forward. You don't have to listen to all of the CyberWire episodes because it's daily news, so just listen to those. I do recommend listening to all of the Darknet Diaries episodes, however.
In addition to the podcasts, I recommend taking these 50 cyber security interview questions, which I'm about to make a video on pretty soon. Use ChatGPT to come up with really good answers to them, and then practice articulating your answers to these questions out loud continuously—maybe like 10 per day.
For these practice interview questions, I used a nice combination of behavioral questions, security frameworks, regulatory questions, and some security operations and technical questions as well. After you've mastered these 50 questions and you start applying to places, when you get an interview, take the job description for that interview that you got, as well as your resume.
Dump the description and the resume into ChatGPT and tell it, "Based off of this resume and this job description, please generate me 50 interview questions and answers." Before you go into the interview, just make sure you can answer those additional 50 questions relatively well.
If you do this properly, it's definitely going to fill enough gaps so that even if they ask you something you don't know the answer to, you'll be able to produce some kind of intelligent answer. At this point, you can kind of consider the interview skill stat taken care of, like 90 to 100.
Getting right into the knowledge and skill stat, if you've properly gone through the Google cyber security professional course, you've built your resume, done the lab, and practiced the whole interview process, your knowledge and skill set is going to be quite high already.
However, if you want to do some more exercises to really make sure you know everything you need to know, I included a free CompTIA Security Plus practice question deck. It has over a thousand questions in it; it's absolutely free to use. All you have to do is download Anki, which is free, and then import the deck into it.
It's really important that you know most of what's covered in the Google cyber security professional program and CompTIA Security Plus, at least like you don't want to be asked about the CIA Triad and then not be able to answer something basic like that. You really want to avoid those kinds of scenarios.
It's also really important that you understand some of the common frameworks used in cyber security, such as NIST 861, Computer Incident Handling Guide, 837 Risk Management Framework, 853 Security and Privacy Control Catalog, and the NIST Cyber Security Framework.
You don't need to know these things in and out, but you just need to know what they are and be able to converse about them a little bit. In addition, you should know about some of the more mainstream regulatory bodies, such as HIPAA, PCI DSS, and GDPR.
Again, you don't need to know these like in and out, but you just need to know what they are and be able to talk about them a bit. These topics can be quite boring; I delivered them in the most interesting way I could in my course.
But for you, for zero dollars, what I would recommend is take each one of these topics and just go to ChatGPT. Pretend like ChatGPT is a human and ask, "What is this? When would I use it? How do I use it? Who uses this? What is the difference between NIST 861 and NIST 837?"
It will produce a lot of answers for you. Just talk to it like it's a human; it will answer you exhaustively. Keep doing that until you have a good intuition on what all of these things are, and then you can answer questions and talk about them at least somewhat intelligently.
You can even go to ChatGPT and do something like, "Give me 10 high-quality questions about GDPR," and then answer the questions in the most perfect way possible. Just try to learn from it that way and get a good sense and intuition of what these things are.
If you do everything I described in this knowledge and skill section, your skill and knowledge stats are going to be up there, nearing 100, especially relative to that entry-level cyber security job.
Getting into the certification stat, this doesn't matter for everybody, but it's good to address it. In addition to your Google cyber security professional certification, there are a few other things that we can do for free.
Again, from the top-tier resume template, you'll notice a bunch of certifications in here. These are kind of certs that I recommend the students in my course to get because they are free. There's the NIMS ICS 100 certification by FEMA. ICS stands for Incident Command System.
It talks about how to run and conduct large-scale incidents, maybe like a city or a country having a large-scale incident. It discusses the chain of command and all those things. The Chief Information Security Officer at my previous job had all of us get the ICS 100 certification. It's just really useful, and there's a lot of overlap between incident response for computers and what's delivered in the ICS 100 program.
In addition, there's the Qualys Vulnerability Management training and certification, which is absolutely free. Vulnerability management is a huge part of security and security operations, so it's just great to have on your resume.
I'd also highly recommend putting CompTIA Security Plus with some kind of expected date sometime in the future on your resume. This will help quite a bit because it will flag your resume with ATS for potentially having CompTIA Security Plus, and it also lets any humans looking at your resume know that you're actively studying as well.
It's only going to help you. Not to mention, if you absorb everything there is to absorb in the Google cyber security program, you're going to be very close, if not ready, to take a CompTIA Security Plus. Completing Google's program gives you a $30 voucher for CompTIA Security Plus as well.
It's just really useful. Not to mention, there are these free CompTIA Security Plus practice questions in the description, so check those out. Doing all of this will undoubtedly make your certification stat as high as it can possibly be without spending any more money.
Finally, your education stat. If you don't have anything to put on here besides high school, or you don't even have high school (which I dropped out of, by the way), I highly recommend taking some free classes, perhaps from MITx, some free relevant classes, and then just putting them on your resume under the education section.
Again, as someone who's actually hired people, seeing this on a resume is infinitely better than not seeing anything at all or only high school. I would definitely consider putting these on your resume if you're really lacking in the formal education section.
Of course, having a bachelor's degree will effectively max out the stat, at least in terms of an entry-level job. But putting some kind of MITx course on here will at least elevate your stats somewhat.
If you're really diligent and go hard and do everything I talked about in this video, you're going to have a wonderful resume, a great portfolio, a lot of knowledge and skill, and great interview ability to tie everything together.
When you start applying to jobs, I recommend using this keyword list. It will help a bit because everyone else is searching for things like "SOC analyst," but this keyword list has a lot of keywords that you wouldn't expect to use when searching for jobs. It might yield results that not everyone is applying to.
For example, if you search "800-61" in Indeed, it will probably produce some kind of incident response jobs. If you search "SOC analyst" or something like this, these jobs might not have come out. So, I recommend using some kind of non-mainstream-ish words to search for jobs.
Lastly, this is super important: when you actually start applying, in addition to applying to cyber security jobs, apply to some nice, high-quality IT jobs as well. There's always going to be some kind of cyber security component in every single IT job.
Once you start working, you can kind of weasel your way into doing more security-centric work at your IT job. If you happen to get a cyber security job first, congratulations! That's super good.
But I wouldn't, for example, hold out for too long waiting for a cyber security job if a nice IT job comes your way. Again, there's a cyber security component to every single IT job.
After doing everything described in this video, with what you've become, it's going to be kind of easy for you to find a job in tech in general. Definitely sign up for the Google cyber security program free trial link in the description. You absolutely won't regret it.
Watch this video, re-watch it again, implement everything we talked about in this video, and then enjoy your new career. Thanks for watching!