Transcription
Cyber analyst is one of the hottest jobs in the market, with high salaries and possibilities for remote work. However, there is a lot of confusion on how to actually get a job as a cyber analyst. Do you need a degree, CCMA, A+, Network+, and maybe spend two years as a help desk analyst before you even think about becoming a cyber analyst?
In this video, I'll give you a roadmap of the actual skills that you need to become a cyber analyst in the fastest and cheapest way possible. The video will be broken down into three main parts: General Foundation, Cyber Security Specialization, and finally, Becoming Unstoppable.
In each section, I will share the top mistake that I see people make at every stage of their journey into becoming a cyber analyst. So make sure you take some notes because this video is full of useful information. Let's get into it.
Part One: General Foundation
But before we get into the General Foundation, let's answer the most important question: Do you need a degree, or should you do certification, or should you just focus on practical skills and ignore degrees and certifications?
The truth is, things have changed a lot in the last few years. Companies used to reject candidates if they didn't have any degrees, but nowadays, more and more companies are hiring people without any degrees. Even companies like Google, which were notoriously strict about degree requirements, have been hiring people without degrees.
So if you're currently doing a degree or if you have a degree, great! Focus on it, do it. But if you don't have any degree at all, or you have a degree in something completely different and not IT-related, that's perfectly fine. You can still become a cyber analyst.
But the question is: Do you need certifications, or can you just learn the skills on your own? To be honest with you, certifications are not a must. However, I'm a big fan and a proponent of certifications because, yes, being a cybersecurity analyst is a practical skill. You can't theorize your way into becoming a cyber analyst.
However, certifications give you a nice structured way of learning a topic. You will also notice that every certification that I recommend has a lab component, which gives you a chance to practice things in a lab. Then you can build a portfolio and showcase your skills in an interview.
But I'm not saying you can't just learn things without certification; you absolutely can. The problem is it will take a lot longer, and you risk learning a bunch of random things that lead you nowhere.
So if you don't have any degree, experience, or knowledge in IT, let's buckle up because it's action time. The first certification that I want you to do is a foundation and a general introduction to cybersecurity. You have three options: CompTIA Security+, ISC2 Certified in Cybersecurity, or the Google Cybersecurity Certificate.
My personal preference is the Google Cybersecurity Certificate because I found it to be very beginner-friendly. But the most important thing is this certificate actually has a lab component where you get to practice on Linux, SQL, and Python, which are extremely important skills for you as a cyber analyst.
I reviewed the Google Cybersecurity Certificate in detail in this video. Once you finish the Google Cybersecurity Certificate, you have the option of either doing CompTIA Security+—which you get a discounted voucher for once you finish the Google Cybersecurity Certificate—or you can do the ISC2 Certified in Cybersecurity.
Now, which one would you do? I personally would skip both of them, but if you're hellbent on doing one of them, choose either one. It doesn't really matter which one you choose.
This brings me to the first biggest mistake that beginners make at this stage of their career, which is being too hung up on beginner certifications. I found that people get so obsessed with things like A+, Network+, CCNA. In fact, some of you have made a personality out of CCNA. It's absolutely crazy!
You really need to understand that this beginner introduction certification should only take 3 to 4 months of your entire life, and you should never build an attachment to those certificates. They are meant to introduce you to this field.
I found that this also comes from a place of fear because some of you are afraid to jump to the next certificate or jump to the next level because you're worried that maybe if you jump and you don't have enough foundation, for example, in networking, then you'll be stuck.
It's almost like you're trying to be 100% prepared so that you face no problems at the next stage. Well, I've got news for you: no one is ever 100% prepared. You will get into situations where you need to go back and review some networking stuff, read some documentation, or learn a new skill. This is part of the job; in fact, it's part of the fun.
This brings me to the next part: Part Two, Cyber Security Analyst Specializations. This is the part where you will learn the different tasks that a cyber analyst performs and the different specializations that you can get into as a cyber analyst. You will also get to practice all of them in a lab environment.
The certificate that I recommend at this stage is the Blue Team Level One Certificate. This certificate goes through almost every task that a cyber analyst will perform. Now, just keep in mind that in larger organizations, you're more likely to see these different tasks performed by a specialist analyst.
For example, you're more likely to see a cyber analyst who specializes in just one particular area, while in small to medium-sized companies, you will get to perform one or more of these tasks as a cyber analyst.
The first module will be basically a review of what you've already learned in the Google Cybersecurity Certificate, and lo and behold, there is a module about networking. So networking is repeated yet again, so stop stressing; you've got this!
Module two takes you through phishing. As a cyber analyst, your main duty is to protect the company from hackers and cyber attacks, and phishing is the most common cyber attack that you will have to deal with. It has labs where you get to learn and practice how to extract malicious load from an email and what to do to further block an attack.
Pro tip: This is something I ask about in interviews. Module three is about threat intelligence. Threat intelligence is where you collect intelligence about different cyber attacks externally so you can proactively protect against them.
For example, if there is a new malware in the wild, your job as a cyber analyst is to get that signature of the malware and block it before it even gets into your network. In this module, you will learn what an advanced persistent threat is, what an indicator of compromise is, but my absolute favorite part of this section is that you get to implement and practice with a tool called MISP.
MISP is an open-source tool used in threat intelligence. I've used it in the past; it's very popular in the industry and widely used. You will also learn about the different types of intelligence gathering and it will even take you through some popular recent malware campaigns that we had to deal with.
Module four is about digital forensics. Now, as I said, digital forensics can be its own specialization. You may be asked to perform some forensic analysis tasks on laptops, maybe to analyze and see if that laptop was infected with malware or even to investigate if the person who owns the laptop was stealing company data.
For example, in this module, you will learn some pretty cool tools like FTK Imager and some pretty advanced tools like Volatility and Autopsy. You'll even get to do some forensic practicals on both Windows and Linux, which is pretty awesome. This is where you can confidently start putting on a costume and go out at night and fight crimes.
Module five talks about SIEM. This is the central log server that we use to collect logs from all different sources where we, as cyber analysts, perform log analysis to detect cyber attacks. This course will teach you the most popular SIEM tool in the market, which is Splunk.
Pro tip: Some of the highest-paid cyber analysts are those with Splunk knowledge. Module seven will take you through incident response. This is where it all comes together. This is where, as a cyber analyst, you will respond to attacks.
The labs here will also get you to deploy Snort to detect unusual activities. You will also learn how to run and analyze network packet captures. This brings me to the second biggest mistake that I see people make at this stage, which is waiting too long to apply to jobs.
If you've reached this stage of your training, you should be adding all the practical skills that you learn into your CV, and you should already have started applying to jobs. Even if you meet 10% of what the job wants, still apply. You would be surprised, trust me.
If you've done the Google set, and you've done the Blue Team Level One set, and you've done all of these practicals, you are already ahead of so many candidates. I interview hundreds of people every year at that level, and trust me, I rarely, if ever, get candidates who actually have hands-on skills.
Some of you think that you need to be an absolute hacker with 500 certificates before you even think about applying. This is wrong. Start applying and apply to as many jobs as you can. Get rejected, get rejected quick and fast because that's how you will learn and get better at the skill of interviewing and applying for jobs. Trust me, it's a skill on its own.
Part Three: Becoming Unstoppable
This is where the fun begins. You've been taking action almost every day. You've been studying, you've done your Google search, and hopefully, you've done your Blue Team Level One SE. You've built that habit of studying, of practicing in a lab, of adding skills to your CV, and hopefully, you've done some interviews.
But right at this stage, you will realize something very important: you will realize how much you actually don't know about the subject. This is the part where we all learn to be humble. At this stage, you have an understanding of what a cyber analyst does. You also have an understanding of every specialization, and you've got a chance to practice each specialization.
But most importantly, you also have an idea of what you want to specialize in. So this is the time where you get to specialize and take the first step towards becoming a world-class expert in that particular area.
If you choose forensics, then you've got a couple of options. The first one is three courses offered by the FOSC Institute hosted on Coursera. They take you through digital forensic concepts, which may be a repetition of what you've already studied in the Blue Team Level One Certificate, and then it takes you into Windows forensics, and then you do a deep dive into Windows registry forensics.
Option number two is from TCM Security. They have a course called Practical Windows Forensics. It's fully practical and will give you an extra chance to practice Windows forensics. Now, I can't mention forensics without mentioning SANS GX certifications.
You have the SANS GX GCF and the GAK GCFA; both are incredible certificates. Unfortunately, they are quite expensive and pricey to get. If you can afford it, great! It will open so many doors. If you can't, I have three ways for you that can help you get them in a cheaper manner that I discussed in this video.
If you want to specialize in threat management, I really recommend that you pick Splunk and go deep in Splunk. Become a Splunk expert, and the great news is Splunk training is all available for free on their website.
Now, for threat intelligence, unfortunately, there isn't much in terms of certifications that I'm happy with, so I recommend that you pick the MISP platform that you've learned in your Blue Team Level One Certificate. You go to their website, read through their documentation, and try to practice a little bit more there.
There is another good certificate that I can recommend, which is from SANS GC. Again, the problem is the price. While you're studying, if you find that you have a passion for programming and you want to become the person who automates tasks in a cybersecurity operation center, you can definitely do that as a cyber analyst.
I recommend you pick Python and go a little bit deep in Python. Luckily, TCM Security has two courses: Python 101 and Python 102. They're quite cheap, and if you do them, you will get excellent practical skills.
If you're still not sure and you don't want to specialize in any one area, that's perfectly fine. You can always do the Blue Team Level Two Certificate, which will teach you more advanced skills.
Now, before we get into the third mistake that people tend to make at this stage, I just want you to take a step and acknowledge that at this stage in your journey, where you've finished some certifications, you've done interviews, you've got a good CV, hopefully, you've got employed, and even if you still sit there looking for a job, you are well on your way to becoming an expert.
It doesn't matter whether you're in university or not, or whether you think you're too old or too young for this. The process is the process. To become a world-class expert, you need to do the work. You need to be studying almost every day. You need to be constantly practicing and challenging yourself with higher-level certificates or higher-level projects.
But trust me, we live in an absolutely great time today because you can become a world-class expert using just your laptop. When I started, I wish I had the same courses that you all have at the moment.
This brings me to the third mistake that so many people make. Unfortunately, you will find in this industry, and in almost every other industry, that there are so many people who are beginners. Then there are less people who are intermediates, but then there are very, very few who are experts.
And you know why? It's because they make this very mistake, which is getting distracted. At this point, where people are starting to become intermediate, this is where they're going to get distracted and focus on silly things like, "Why is my colleague getting paid more than me?" "Why did she get promoted?" "Why did he get promoted?"
These kinds of silly things will distract you from doing the work because things will get harder. Like passing your Google Certificate and even the Blue Team Level One Certificate, yeah, they are challenging, but they're not as challenging as when you get to those higher-level stages where you will feel challenged.
You will feel a little bit lost, and it's really easy to start blaming others and thinking of silly things. It's a lot easier than facing the difficult problem that you're trying to solve. Trust me, if you cultivate this mindset, this is what will set you apart.
It's not the degrees; it's not the certifications. It is that mindset of focus, of continuous work, and continuous improvement. This is how people get those crazy salaries that you see. It's not because they went to a fancy school or they did a fancy certification; it's because they have their eyes on the prize.
Now, there is a lot more nuance to this type of mindset, which I discuss in detail in this video. I strongly recommend you watch it. It is important at every stage of your journey.