Transcription
What's going on, YouTube? In today's video, I'm going to be pointing out three major things that I wish I would have known about before I got into cyber security.
[Music]
The first thing, for sure, is networking. When I first got into college, I was under the impression that I was just going to somehow sail through college and only learn cyber security. Well, that just was not the case. I repeatedly had networking classes that I had to take and learn about, but me being a little bit stubborn pushed off these classes. I didn't want to do them.
As college progressed, I started to realize a theme: it was becoming very important and crucial for me to understand the networking basics, at least at the CCNA level. I'm going to repeat that often because I think it's so vital—not necessarily that you get the shirt, but that you're at that level.
Even at the end of my educational career, I noticed that I was still kind of trying to push off networking. I got out of college, and I still had professors advising me to do some of the network certifications before the Security Plus. It paid out to my benefit that I did retain some of the knowledge that I was learning in college because I was able to take a security certification and pass it, even without actually getting a network certification.
But I'll explain to you why that even was not enough. I found out very quickly in my first job that my lack of networking knowledge needed to be sharpened and needed to be sharpened on the fly while I was learning this work. It's not recommended to do it this way, and this is one of the reasons I'm making this video: you don't want to get yourself in the position where you're stressed out with a new job and you're trying to learn things that you feel like you should already know.
Now, I'm that kind of guy; I like to have a challenge. So I did take on the challenge, and of course, within a month or two, I got myself to where I thought I should have been entering into cyber security, engaging in conversations about networking, actively participating, and also sharing some ideas on how to secure the network at the particular location that I was currently working for.
Now, number two is going to be financial compensation expectations. So what do I mean by that? I mean when we get into some type of educational career path, we begin to be told by universities as well as professors that maybe we're going to be getting a little bit higher compensation than really what is reality.
In today's world, the reality is you need a little bit of experience. Now, every job is going to prioritize this experience, so you need to have your expectations set at a level that is respectable for what you bring to the company. When you get out of college, just think about it: you're not somebody that has any type of real-life experience; you have some education.
Now, this even applies to those who are in certification paths that are going to try to get into security that way. Either way, you have no experience, and you're trying to get in. So do not set your expectations too high on what your salary is going to be getting into the field.
Now, I do want to tell you my estimate of what I think an entry-level security analyst, engineer, or technician should be making. I think you should be making out of college about anywhere from $50,000 to $60,000. That is a good starting point and a good pay scale for somebody with no experience.
I also would say that you should be expecting to get that kind of compensation, and if you aren't, I would recommend negotiating to get into that pay range. It doesn't matter that you don't have experience; the work that you do is still important enough to be in that range.
That being said, there are areas of the country, and I'm sure of the world, for instance, the Bay Area as well as New York, where you will see these pay scales a little bit higher because the cost of living is higher. So they just kind of go hand in hand. Just be understanding of that moving forward, and I think you'll be in a better predicament mentally with your expectations.
This is not to discourage anybody who wants to get into this field. We all need to make money; that's just the way of the world. It's one of the driving factors for the reason we pursue certain careers and paths.
That being said, I do want to point out that while the first couple of years you may be at a starting salary, which is still fairly well paid for the average person, you're going to see after a couple of years that that salary is going to start to go up pretty quickly. Then you will start to see what you have been told and what you may have read about the security field: the money's there, the jobs are there. You just have to get your experience in, and you have to stay willing to learn, be teachable, and continue to endeavor into new certifications.
Never stop learning, and as long as you do those things, the sky's the limit in cyber security. I think it's a great career path for anybody who is looking to make that kind of jump.
Number three: you don't need to know everything. This is one of the basics you need to understand before you get into cyber security, and I would even go further and say IT. Don't pressure yourself to the point where you think that you're not going to make it out there unless you have knowledge in every single area.
I've been in the field; I work in the field, and I'll tell you one thing: I have not met one person who knows everything. It just is not how IT works. Don't expect yourself to be like that. The typical path is that you gain a foundational knowledge of the network infrastructure and security, and as you gain experience, you find a niche of your own that you enjoy inside of cyber security.
Then you will be a subject matter expert on that subject, and that's how we all function in IT. This person knows firewalls, this person knows the VPN, this guy knows how to threat hunt, this one knows how to pen test. Everybody has their own part in the machine, so to speak, of cyber security.
So don't get down on yourself. With that being said, you do need to know the basics. You need to have a clear foundational understanding of networking, routing, and switching, and the network space that you're going to be playing on to defend against attackers from your company.
Okay, so understand that you need to know the basics, but you don't need to know everything.
Hey guys, I just want to jump in real quick while I have your attention. I want to point out that I am loving this Deity D4 microphone that I just purchased from Deity. I had a Rode before this video, and I did not like it at all. I'm really loving this microphone. I am not sponsored, but in case somebody else out there is looking for a microphone, I'll throw it down in the description on my Amazon.
I'm also going to start putting all of this setup that you see around me—everything that I buy—I'll throw it in that description so you can see it and buy it if you want to. Thanks, guys!
Also, I do want to mention I will be linking above my hacking video that I put out about eight days ago, nine days ago. I want you to check it out, tell me if you like it, if you enjoy it, if it helps you in any way. Let me know; I would love to hear your feedback.
So just a quick recap: let's go over the three things that we learned from today's video about what you should be doing before you go into cyber security and what I wish I would have known myself.
Number one: networking. Make sure you understand your networking and make sure you understand the playground on which you'll be playing.
Number two: the competition. Make sure you understand when you get out of school what your competition is going to be looking like. It's vital that you don't get your expectations caught up here and then shot down when you're trying to get into a new career.
Number three: you don't need to know everything. You can go into it comforted in the fact that while you may not know everything, you know the basics and that you're willing to learn. You will move forward in that mindset, and you're going to be A-Okay in security.
Hey guys, I hope that this video helped you. As always, that's the whole point of the channel. I always try to tell my subscribers and my new viewers that this is just tech content, hacking content, cyber security content, and it's all educational to bring education to other people to help folks out like people helped me.
Thanks for watching this video, guys, and thanks for always subscribing. To everybody who likes and comments, I love reading every day, and I try to get back to everybody I can.
So thanks, guys! I'll catch you in the next one. See you!
[Music]