Transcription
The reason you're not getting hired in cyber security is not because you don't have a degree or AI stealing your job. It's because you don't have experience. But here is the twist. We can manufacture experience. You can build it yourself without waiting for anyone to give you permission.
This is Jose. He landed his first cyber security analyst job at the age of 37 without any prior IT experience or technical degrees. and he did it in a very small and competitive market in South America using the exact same process that I'm about to show you in this video. But he's not alone. I get daily success stories from all over the world who followed advice on my videos and managed to land their first cyber security job without any prior experience.
And in this video, I'm going to show you the exact same process that Jose and others have used [music] in a step-by-step manner to land their first cyber security analyst job without waiting for anyone's permission and without having prior experience. I'm going to go over the foundation that you need, the training and certification, and more importantly, I'm going to go over how to work things in your resume in a way that meets that experience requirement without having a prior IT or cyber security job.
But before we start, what does a cyber security analyst do? And is it the same job as a sock analyst? Now, the first thing you need to know is that job titles in cyber security are so messy. So, the title cyber analyst can be given to so so many individuals within the cyber security world. However, more commonly when someone says cyber analyst, it's usually the same thing as a security operation center analyst. The individuals with that title usually specialize in detecting, analyzing, and responding to cyber attacks. They can work within a security operation center where they are part of a team that looks at security incidents and respond to them or sometimes in small to medium-sized organization. They can perform some security analysis but they'll be working alongside what we refer to as managed security service provider. This is an outsourced sock where perhaps they get some escalations or they do some investigations and then they escalate to that MSSP. These are the most common cyber analyst or sock analyst jobs.
Now just a caveat in some organization that sock analyst may be required to do more tasks such as vulnerability management or even risk management and GRC and all of that. I'm going to go over all of these generalist type tasks in part five of this video. But for now, I want us to focus on the tasks of the sock analyst.
Now, the challenge with the sock analyst job and the reason why companies want you to already have experience is because, as you may have guessed, it's a highly technical roles. You really need to know what cyber attacks are and how to analyze them. You also need to understand how networking works and how servers work. And hence why companies want you to already have some experience.
Now the way that many individuals who watch my videos have managed to land a sock analyst job without having experience is by building foundation. Now let me show you how to build that foundation in part two of this video.
Foundation. Now the word foundation in cyber security is very confusing especially for individuals who are not part of the industry. A lot of beginners believe that the foundation for cyber security is simply network engineering with the underlying false assumption that cyber security is simply advanced network engineering. No, this is simply not true. Network engineering and network security is one of many domains in cyber security. And therefore, when I say foundation, I mean cyber security foundation, which yes includes some networking. It includes operating system knowledge, but it also include knowledge of cyber security systems and processes and methodologies and framework. This is the foundation that you need to build skills that will enable you to become a cyber security analyst.
Now in the past the only foundational training available to us used to be Comptier A+ and Network Plus. However, nowadays we have so much better resources. The material in A+ and Network Plus are simply overpriced and outdated. Now some people get upset when I say skip those because they think I'm saying skip learning IT and networking. That's not what I'm saying. What I'm saying is their knowledge of IT and networking exist elsewhere in much better resources. In fact, all the hands-on practical platforms that I recommend throughout this video will have tons of foundational material that will teach you networking and operating systems and it in a much much better way.
Therefore, my recommendation for you as a starting point is simply the Google cyber security set and CompTIA security plus. However, [music] I want you to start with the Google cyber security set. And the reason is the Google cyber security set is really structured nicely in a very beginner friendly way that will ease you into cyber security. You'll get a broad introduction in all the domains of cyber security including things like networking, IT, operating system detection and response and some popular frameworks that we use in cyber security. The material is actually fairly comprehensive and it's quite normal to feel a little bit overwhelmed by the amount of definitions in the Google cyber security set. This is to be expected because this is a new field for you. But don't worry, we will be revisiting those definitions over and over as we go with our study plan. And the second reason why I want you to start with the Google Cyber Security set is because when you finish it, you get 30% discount to do the CompTIA security plus after. And there is a lot of crossover between the material in Google Cyber Security and CompTIA Security Plus. So it can be used as a nice prep for security plus, but it's not sufficient for Comptier Security Plus. you will need additional resources. I'll leave links in the description box under the video with all the links that you will need to access those resources. And finally, the Google cyber security set also includes practical hands-on lab that will introduce you to Linux, MySQL, and Python. Those are tools that you will need as a sock analyst. So, you'll get a nice taste early on in your learning journey.
Now, once you finish the Google cyber security set, you can do the CompTI Security Plus. However, I want you to wait a little bit. I want you to do more practical hands-on training so that when you come back to Comp Security Plus, it actually makes more sense. You don't need to memorize so many concepts because you have done them practically. So hold on for the Compare Security Plus. We will do it later. But before I move on from this section, a common question I get asked is what about the ISC2 certified in cyber security or ISC2C? I don't recommend that certificate simply because I feel the material is watered down and honestly it doesn't add any value. So please go ahead and skip it and don't make the common beginner mistake of spending way too much time in this introduction phase because really the Google cyber security set complete security plus ISC2CC ISC2CC all of those are simply introduction to cyber security. So all you're doing here is just getting introduced to some definitions and some concepts. The goal of this phase is for you to finish the Google cyber security search and move on to proper training that will actually build your stock analyst skills which is what we will cover in part three of this video.
The cyber security analyst skills. When you look at a typical sock analyst ro job job description they want you to have two to three experience in certain areas. And the reason is they really want you to know how to detect, analyze and respond to cyber attacks. Those are the three major tasks of a sock analyst. And therefore, we need to build those skills progressively. Luckily, today you have access to so many resources that I wish that I had access to when I was starting out in the early 2000. My life would have been so much easier.
Now, the starting point that I recommend for you to build your sock analyst skills is either try hackme s1 or let's defend sock analyst path. Both are absolutely great resources to build your sock analyst skills. The content is similar. There is a lot of crossover between the content. For example, if we look at try hackme s1, it starts off with foundational knowledge, which will be a review of what you've learned in the Google cyber security set. Then it covers cyber security fundamentals. You may be familiar with some of the concepts here, but it will introduce you to new stuff. And then it goes over common malicious behavior. This is an introduction to cyber attacks and common cyber attacks types. You go over social engineering, network attacks and web exploitations and other foundational concepts that you will use in a security operation center. So as a sock analyst, you'll usually receive tickets that one of those attacks have occurred and you need to perform the analysis on them. So here you get to learn about the different types of attacks and then you learn about the security tools that we use to analyze, detect and respond to those cyber attacks. When you work in a security operation center, there will be an abundance of tools in the environment and every environment will have a different set of tools. However, those tools work in pretty much the same way. So here you get to learn the concepts, how those tools act, why we need them, and how we utilize them as cyber security analysts. And in part five, you go over the workflows and the processes that we used in assault. As I said, as a cyber security analyst, you may be part of a big team and there are certain playbooks and processes that you need to follow that are industry standards. So, we don't go on randomly analyzing and responding to things and turning off production systems. It doesn't work that way. There are certain steps and methods that we use.
Now, the reason why I really like Try Hackme SA1 is because part of the exam and part of the training, you get to use their simulated sock environment. So you actually get to practice in a live real world security operation center where you actually analyze, detect and respond to cyber security incidents in a safe environment. This is how we manufacture experience. So when you go to an interview, you can actually talk about how you detected, analyzed and respond to cyber security incidents. This gives the hiring manager the confidence that you are in fact someone who knows what they're doing. you're serious about a career in cyber security and you didn't just memorize a bunch of multiplechoice exams to get a piece of paper at the end.
Now, if you look at let's defend sock analyst pathway, you will see that it covers pretty much similar concepts. There might be slight variations, but they pretty much talk about the same thing. Now, should you do one or both? In my opinion, I highly recommend you do both because as I said, this is something new to you. And even if it wasn't new to you, this is a lot of information and a lot of topics. And yes, this is a highly technical topic and therefore it's quite normal to forget things. Let's say you learned about the mitro attack framework, but 2 weeks later you forgot everything. So when you go and do the let's defend stock analyst pathway, you'll get exposed to the same concept. Perhaps you'll get asked about it in a different way. This will solidify your understanding and instead of trying to memorize things. This way you understand things but also you know where to look for things. Remember you're trying to get a long-term career in cyber security. So please don't try and cut corners and want to do the absolute minimum amount of work. Instead, you should use everything at your disposal to be the best cyber security analyst that you can be. And therefore, I highly recommend finishing also the let's defend sock analyst pathways.
Now, those two platforms would pretty much teach you how to work in a sock. However, if you remember at the beginning of this section, I said the sock analyst does detection, analysis, and respond to cyber attacks. Now the more experience you have the more depth you can have in all of these three areas. For example, there are individuals who specialize in just detecting cyber incidents. They are specialist in a seam. The seam is a tool where we ingest the logs from different locations and we perform the analysis using logs in that seam. So they create detection use cases and they create alerts for those cyber attacks. So that can be a specialty on its own. However, as you're learning to become a security analyst once you finish SAL1 and stock analyst pathway, I want you to go a bit deeper in one of those areas. And for that, my recommendation is to use let's defend seam engineer career pathway. This is similar to the sock pathway, but you specialize in seam engineering in detection. And this will give you so many keywords and so many talking points in your resume that will communicate to hiring managers and companies that you in fact have the knowledge and expertise in this area. You may not have done it in a company but you have the skills and you're more than capable. The seam engineer career pathway covers popular tools like Splunk and Waza and even IBM curator. As I said those seam tools work pretty much in a similar way. So once you learn one of them, your skills translate to the other. And the more depth and knowledge you have in this area, the more jobs you will qualify for. You will see job ads that say they want a seam engineer or a sock engineer, someone who specializes in detection. So now you have even more options.
Now, if you reach this point and you've done all of those trainings, I believe you've covered your bases when it comes to security analyst and you'll be pretty much ready for a sock analyst job. But if you really want to stand out, I'd like you to venture into more intermediate/advanced level skills. Now, for that, I want you to go deeper in the responding to cyber attacks. You see, it's one thing to respond to a fishing attacks or to reset a user password. Those are fine, nice tickets, usually low in severity. However, it's a completely different story to be called out to help a company that was completely hacked and you need to go and stop that hack, isolate the systems, contain the attacks, perform forensic analysis and help them go back online. This is advanced level work and we collectively refer to as incident response or digital forensics/inccident response usually short for DFIR. And that will be part four of this video intermediate level skills.
Now, if you look at my personal LinkedIn profile, which I'll leave a link to in the description box of this video, in 2017, I was actually leading a cyber defense team, which is essentially a team of individuals responsible for analyzing and responding to high severity cyber attacks. Now I can't give you details about what we dealt with but some of the attacks were quite serious that affected the entire company where we got a fishing attack that got one of the users infected and then that user's email address which is an internal company address used to send even more malicious emails to everyone in the company and the impact was really really high. Now my job as an experienced incident responder was a to manage the team that will do that work but the first thing we needed to do was to contain that incident to stop the damage from spreading further and that was hard. We needed skills to be able to understand the logs. We also needed to look at our cloud environment but we also needed some social engineering skills. We needed to know how was that user compromised to begin with and why was this email so convincing. So we analyzed that. Then we had to block that email from propagating further. And then we had to isolate all the infected machines and we had to perform forensic analysis on those infected machines to understand the extent of the damage. So suffice to say it was a week-l long job and we didn't get much sleep. But this is the world of digital forensic and incident response.
Now to gain those skills will give you a huge competitive advantage when you're applying for sock analyst job because trust me I don't see many candidates with that type of skill. All I see is usually comp security plus A+ and some CCNA and zero practical knowledge. So if you come to me with knowledge of how to analyze and respond to cyber attacks you will stand out. In fact that's what Jose told me. He said that his manager was even surprised that he had all this knowledge because most candidates simply don't have that.
Now to build that type of skill, luckily there are two platforms that offer you training with that type of skill. We have from hack the box we have CDSA and from cyber defenders we have CCD. Both are intermediate level to advanced certifications. You will gain security operation analyst skills but you will go really really deep into the analysis and the forensic analysis and respond to cyber attacks. Expect to be challenged. Those are not easy cyber security certifications. I'm not going to go through them in detail. I'll leave links to them in the description box below. And as far as which one to do first, I recommend Hack the Box CDSA, then Cyber Defender CCD, but it doesn't matter too much. You can switch them up. It's totally up to you. And if you're wondering about Comtia Security Plus, yes, you can do it after those thirds or before, but when you do it, you will have a much much easier time because you will be more than familiar with all the topics in CompTIA Security Plus. Alternatively, you can simply skip it. It's totally fine. Completely up to you.
But now the biggest question of this video is well let's say someone did all of this training yet they open the job ads and they see that the job wants them to have three years of experience. So what should they do? Well in part five of this video I will show you how to word your experience in a way that will give the hiring manager confidence that you can actually do this job. I'll also show you how to search for jobs and how to diversify your experience which is part five experience requirement.
Now before we start, I want to emphasize that yes, entry-level jobs do exist. That doesn't mean that every job advertised will be entry- level, but it also doesn't mean that every job advertised will require experience. Some jobs will want someone with 10 years of experience, whereas other jobs will want someone with one to two years of experience.
Now, what I want you to do is first update your resume. Go to unixguy.com/free and download my free cyber security resume because I've added a lot of those cyber security trainings to that template already. Now I'll show you an example of how to word try hackme s1 in a way that mentions all of these keywords. As you can see on the screen it's a paragraph with bullet points with each bullet point detailing what you've actually done in the certificate. So we mention the tools that you've used like splunk and elk. We also mention wireshark and pcap file analysis and the forensics tools that you've used and so on and so forth. this level of details and those tools is trust me as a hiring manager I don't see many candidates with those tools on their resume. So you will already stand out if you word things like this and if you've done something like cyber defender CCD then this is how I want you to word it. As you can see it's a long paragraph because cyber defender CCD covers so so many things. The worst mistake you can do is just have one line item and say I've passed cyber defender CCD expecting the hiring manager to go and Google it for you and look at the content. So here we cover all our tracks. Those bullet points contain a lot of the keywords that we're actually looking for when we're hiring for stock analyst jobs. Now if you want more examples of how to word things in your resume, I actually covered all of this in detail in this video. So please check it out.
Now the second thing that I want you to do is to start searching for jobs. But the way I want you to search for jobs is to simply type the word cyber and search. So don't type cyber analyst or sock analyst. I want you to just type one keyword because this will show you so so many jobs. And please apply to all the jobs that you think you can do. Don't care if they're asking for more things that you have or if they're asking for so many experience. It doesn't matter. Usually job descriptions are a wish list. They'll be asking for 10 things. If you feel like you need 20 to 30% of what they're asking for, apply. Let them reject you. Don't reject yourself. Like I said, it's extremely rare to see candidates who have done practical hands-on training apply to jobs. So, you will stand out.
Now, when I say practical hands-on training, I say the platforms that I outlined. I'm not referring to the free rooms from Try Hackme or just some random beginner CTF or some hacking tutorials. This is not education. The stuff that I mentioned, the full certification, the full sock analyst part, this is learning. Passing something like cyber defender CCD is a proof that you know what to do in a security operation center. This is completely different to things like capture the flag which is good for entertainment. You may learn something but it's not a structured plan.
Now the other keyword that I want you to use is just type sock. Some jobs will not mention the word cyber. They just type sock. So you will have to sift through and go through them one by one. Now as far as to where to search for jobs, LinkedIn should be your number one tool. So use LinkedIn in your country and then it depends on where you live there might be another job board that's relevant to you. For example in Australia we have seek.com.au. In the US there is dice and indeed and many more. So please look for what works for you locally.
And the third thing is you will see some jobs that are asking for so many things that are not really related to soap. For example they may want you to perform risk analysis or compliance or they want you to know ISO or NIST framework. Now those are GRC skills and you will find that usually small to medium-sized organization they want you to be more of a generalist. Then what you can do is actually build those GRC skills. I cover all of this in GRC. Go to grcmastery.com. I show you how to perform risk analysis, how to go through practical cases. It can be a good addition to a stock analyst if you want to work in an environment that wants you to do more than one thing. The other skill that I want you to consider adding is actually cloud skills. So doing certification from Amazon AWS or Microsoft Azure is an absolute great addition to any sock analyst because in most environment the data will be stored in the cloud. So the more knowledge in the cloud you have the better off you will be as a cyber security analyst. So combining sock analyst skills with some GRC and some cloud will make you stand out in a sea of candidates. Remember 99% of the candidates that I see applying to jobs have done the bare minimum. So, please give yourself a chance and treat this like a long-term career.
Now, as far as résumé is concerned, sometimes I see rums of candidates who have done a lot of things well, but their resume doesn't look good or they make common mistakes. I highly, highly recommend you check out this video where I go over the most common mistakes that candidates make in the resume just so you make sure that you're not making any of those mistakes. We don't want you to do all of this hard work and waste it because you made mistakes in your resume or you were a bit lazy with the resume. Please check it out and I'll see you