如何找到入门级网络安全工作

这篇文章是回应一位朋友,他正在一个极具挑战的市场中寻找网络安全职位. 鉴于这是当今普遍存在的问题, 我决定写一篇文章,而不是简单地发表评论.
Various statistics from multiple sources suggest that there is a wide gap in cybersecurity roles, with millions of cybersecurity jobs waiting to be filled by new talent. Boot camps often use these numbers to promote their products. Although such a gap might exist, the talent shortage is usually most evident in specialized roles rather than among general candidates seeking entry level positions with limited experience.
Many applicants receive no response when applying for cybersecurity jobs even though there are supposedly millions of those opportunities available. Some may think they are not good enough or that something is inherently wrong with them for not receiving a callback. 然而, in many cases their applications are simply not reviewed.
If you are looking to enter cybersecurity, know that you are aiming at one of the more lucrative fields in technology and fierce competition typically awaits entry level positions at well-known companies. 例如, if you apply to reputable Fortune 500 companies for an entry-level role, each job opening might attract anywhere from 50 to 200 applications or even more. At this level even if you are highly capable and fully qualified, you might not be noticed.
Here are some key points you should consider before applying for these roles:
1. Be mindful of the location of your job search. The region where you reside may not have the largest cybersecurity job market. In contrast, areas such as the DMV (DC, Maryland, Virginia) have the highest number of job openings in cybersecurity. If there are not enough jobs available in your area, your chances of securing a position are reduced.
2. Visa sponsorship is limited. Most companies do not provide visa sponsorship. If you have a foreign sounding name (as I do) and require sponsorship, your opportunities may be even more limited. Conversely, if you do not need sponsorship, consider indicating your immigration status on your resume as clear as possible. I have been personally asked about my citizenship multiple times even though I clearly state that I am a U.S. citizen, implying that some candidates misrepresent their status only to later claim they need sponsorship. Be very clear about your immigration or citizenship status because obtaining sponsorship is not an easy task.
3. Watch out for fake job postings. Out of every 10 online job postings on platforms such as LinkedIn, around 4 may be fake, that is the jobs do not actually exist. You might apply for a posting for which you are fully qualified and receive no response, leaving you to wonder why you weren’t noticed when in fact the job was never real.
4. Many roles are not publicly advertised. For every 10 jobs posted online, there could be as many as 40 positions that are never publicly advertised. These opportunities are typically filled through networking or local channels. Look up local businesses in your area that hire for your role, reach out to them or check their websites. You might also consult lists like the Russell 2000 or Fortune 500 and leveraging AI tools may help you uncover positions that aren’t listed on LinkedIn.
5. Certifications matter but only if they are the right ones. 我有一个朋友,他通常先追求证书,然后抱怨这些证书的有效性. 重要的是要确定哪些证书是人力资源部门重视的,并优先追求这些证书,而不是仅仅积累证书然后抱怨人力资源不感兴趣. 即使最好的资格证书也无济于事,如果雇主不需要它们. 你持有或追求的证书可能不是最受欢迎的那些. 参考 这个链接 并选择你的州, 它显示了每个州按所需证书的职位空缺情况. 例如, 在密苏里州, 所有 30 SANS证书合计约占 500 空缺职位, 而CISSP证书单独拥有超过 1,200 空缺职位, Security+随后约为 1,100.
6. 注意偏见. There is a deep sense of distrust and bias against individuals from certain countries due to political tensions especially in sensitive industries. If you are originally from one of these countries, consider removing references to your foreign education or experience from your profile, although the final decision is yours. 例如, if you are seeking an internship at a pharmaceutical company, your foreign education might not add value to your cybersecurity credentials or national security expertise.
Below are some steps you can take to improve your chances:
1. You need to follow common job-hunting practices. Common practices such as networking, participating in cybersecurity communities, enhancing your online presence, tailoring your resume, following up on job applications, and even sending a handwritten thank you letter (even if your handwriting is as bad as mine).
2. Consider de-emphasizing your background on your resume. If you are a U.S. citizen or a permanent resident, consider de-emphasizing your background on your resume if you are from a country that does not have a strong relationship with the United States, as this might reduce the likelihood of being viewed unfavorably. First impressions matter, and you never know who will review your resume.
3. Craft your resume specifically for positions for which you are eligible. Read job descriptions carefully to ensure you meet or exceed all the qualifications listed in both your resume and cover letter. Merely being qualified does not guarantee you will secure an interview or the position.
4. Compile a list of job listings for the roles. Compile a list of the roles you desire, note their requirements and tailor your resume accordingly. By reviewing many listings from different companies for the same role, you will gain a better understanding of what the industry expects in an entry-level candidate.
5. Consider pursuing internships or volunteer opportunities. If you are unable to find a job immediately, consider pursuing internships or volunteer opportunities. Cybersecurity can be challenging to break into. If you cannot secure an internship at a high-profile company, look for opportunities at local libraries or community organizations. Adding more experience to your profile might prove more advantageous than emphasizing your background alone.
6. Start in IT and then switch to cybersecurity. If transitioning directly into cybersecurity proves difficult, consider starting in IT and then shifting into cybersecurity later. It might be best not to mention this strategy to recruiters; instead, work on your transition while holding a related IT role. After a couple of years, you may have a much better opportunity to break into cybersecurity.
7. Aim at the top. Finally, pursue a certification that distinguishes you. 例如, consider aiming for the CISSP certification if you also have a education background. Granted, CISSP is not an entry-level certification and you cannot achieve full CISSP status without five years of experience! But you can become an associate CISSP almost immediately if you pass the difficult exam. It is hard for recruiters to dismiss a candidate with a CISSP (or Associate CISSP) certification. Even if your application is ultimately rejected, 它至少会受到认真的考虑. 追求CISSP需要大量的投入, 但是如果你准备好发送几百份精心定制的申请和求职信,并与几百名其他候选人竞争, 这可能非常值得付出努力.
帖子免责声明
观点, 信息, 或表达的意见仅代表作者的意见,并不一定代表其雇主或他所属组织的意见.
本文中包含的信息仅供一般参考之用. 该信息由Farhad Mofidi提供,同时他努力保持信息的最新性和准确性, 他不作任何形式的陈述或保证, 明示或暗示, 关于完整性, 精度, 可靠性, 网站的适用性或可用性. 法哈德不作任何陈述或保证. 或任何信息, 出于任何目的包含在任何帖子中的产品或相关图形.
也, 人工智能可以用作提供建议和改进某些内容或句子的工具. 想法, 思潮, 意见, 最终产品是作者原创和人造的.