Underrated Cyber Security Certs that WILL get you HIRED

UnixGuy | Cyber Security
18 Mar 202412:18

Summary

TLDRThe video script discusses the outdated advice of pursuing traditional certifications like CompTIA and CCNA for a career in cybersecurity. Instead, the speaker advocates for hands-on, lab-based training, sharing the story of Josh, an electrician with a cybersecurity degree, who sought career mentorship. The speaker recommends platforms like Let's Defend for defensive technical skills and GC Mastery for non-technical GRC skills to broaden employability. The emphasis is on gaining practical experience and applying for jobs to build confidence and skills, rather than solely focusing on recognized certifications.

Takeaways

  • 🚫 Outdated Advice - The conventional path of CompTIA, Network+, Security+, and CCNA before entering cybersecurity is considered outdated.
  • 🌐 Global Success Stories - The YouTube channel shares success stories of individuals who achieved success in cybersecurity through alternative paths and trainings.
  • 📋 Foundation Over Certifications - Emphasizing the importance of foundational skills and hands-on experience over traditional certifications.
  • 🔍 Confidence Through Application - Gaining confidence in cybersecurity through real-world applications and interview experiences rather than just studying.
  • 🛠️ Hands-On Training - Recommending lab-based, hands-on cybersecurity training as a more effective approach to learning and skill development.
  • 🔧 Career Mentorship - Utilizing career mentorship calls to guide individuals in their cybersecurity career path and address specific concerns.
  • 🔄 Broad Skillset - Advising beginners to focus on a broad skillset to maximize job opportunities rather than specializing too early.
  • 🎯 Job Application Strategy - Encouraging job applications as soon as possible to gain experience and improve interview skills.
  • 🔄 Continuous Learning and Applying - Emphasizing the importance of continuous learning and job application to increase the chances of landing a cybersecurity job.
  • 🔎 Misconceptions About Hiring - Clarifying that hiring managers in cybersecurity are not solely focused on certifications but rather on practical skills and experience.
  • 🌟 Specialization vs. General Skills - While specialization is important, having a general skillset that applies to a wide range of cybersecurity jobs is more beneficial for beginners.

Q & A

  • What is the speaker's opinion on the traditional advice of pursuing CompTIA, Network+, Security+, and CCNA before entering cybersecurity?

    -The speaker believes that following this traditional advice is outdated, comparing it to advice given 20 years ago. They argue that many successful cybersecurity professionals have achieved their goals without these certifications by following alternative paths and training.

  • What was Josh's background and why did he book a career mentorship call with the speaker?

    -Josh is a 32-year-old electrician living in the US who also holds a cybersecurity degree from WGU University, which includes many CompTIA certifications. Despite this, he felt unprepared and lacked confidence to apply for cybersecurity jobs, leading him to seek guidance from the speaker.

  • What was the speaker's first recommendation for Josh to improve his cybersecurity skills?

    -The speaker recommended a platform called Let's Defend, specifically its Security Analyst pathway, which focuses on the defensive technical side of cybersecurity and can qualify Josh to work in a Security Operations Center (SOC).

  • Why did the speaker suggest Josh pursue a broad range of skills rather than focusing on a specific specialization early in his career?

    -The speaker advised Josh to be as generic as possible to qualify for a larger number of jobs, maximizing his chances of landing a cybersecurity position. Specialization is less important initially, and a broad skill set is more marketable, especially for someone new to the field.

  • What is the speaker's stance on the importance of recognized training and certifications in the cybersecurity job market?

    -The speaker emphasizes that hiring managers are not just looking for recognized training or certifications. They value the skills listed in job descriptions more, and candidates should focus on acquiring practical skills that match the job requirements rather than chasing after recognized certifications.

  • What is GC Mastery and why was it recommended to Josh?

    -GC Mastery is a training program focused on the non-technical side of cybersecurity, known as GRC (Governance, Risk, and Compliance). It was recommended to Josh to broaden his skill set and increase his chances of landing a cybersecurity job, even if it's not directly related to his ultimate goal of digital forensics.

  • What are the other Hands-On training options mentioned by the speaker for someone looking to enter cybersecurity?

    -The speaker mentions Blue Team Level One, Hack The Box, and Try Hack Me as other practical, hands-on training options that can help individuals gain the necessary skills for a cybersecurity career.

  • What advice does the speaker give regarding the selection of a training course?

    -The speaker advises that the specific training course chosen is less important than the commitment to completing a hands-on, practical cybersecurity training. The goal is to gain skills and experience, not to collect certifications.

  • What is the speaker's strategy for job hunting in cybersecurity?

    -The speaker suggests starting with a basic foundational certification, then immediately engaging in hands-on cybersecurity training while simultaneously applying for jobs. This approach involves continuous learning and applying to gain experience and confidence, increasing the chances of landing a job.

  • What mistake did Josh make that is common among beginners looking for their first cybersecurity job?

    -Josh made the mistake of only searching for digital forensics jobs, limiting his opportunities. The speaker advises against this narrow approach and encourages job seekers to apply for a broader range of cybersecurity positions.

  • How does the speaker suggest improving one's chances of landing a cybersecurity job?

    -The speaker recommends a combination of completing hands-on cybersecurity training, gaining practical experience through labs, and applying to a variety of cybersecurity jobs to build confidence and interview experience. Persistence and a willingness to learn from rejections are key to success.

Outlines

00:00

🚀 Challenging Traditional Cybersecurity Career Advice

The speaker shares an alternative approach to entering the cybersecurity field, emphasizing the importance of hands-on experience over traditional certifications like CompTIA and CCNA. The story of Josh, a cybersecurity degree holder, is used to illustrate the limitations of conventional wisdom. The speaker recommends lab-based, practical training and highlights the value of broad, marketable skills to increase job opportunities. The focus is on gaining real skills that can lead to a rewarding career, rather than just collecting certifications.

05:01

🎯 Prioritizing Job Acquisition Over Specialization

The speaker advises that the primary goal for beginners should be to secure a cybersecurity job, regardless of specialization. They should aim to acquire a wide range of skills to qualify for various positions, especially generalist roles. The speaker introduces GRC Mastery as a valuable training for the non-technical side of cybersecurity, despite Josh's interest in digital forensics. The recommendation is to combine technical and GRC skills to enhance employability and to focus on the first job as a stepping stone to further opportunities.

10:03

📈 Maximizing Job Prospects Through Continuous Learning and Application

The speaker emphasizes the importance of continuous learning and applying for jobs concurrently to gain experience and confidence. They suggest that after completing a foundational certification, one should immediately start a hands-on cybersecurity training and begin job applications. The speaker encourages persistence and a growth mindset, advising to keep learning and applying until the desired job is achieved. They also address common misconceptions about job hunting in cybersecurity and the overemphasis on specific certifications.

Mindmap

Keywords

💡CompTIA Security+

CompTIA Security+ is a certification that demonstrates foundational knowledge in cybersecurity. In the video, it is mentioned as part of the conventional wisdom for entering cybersecurity, but the speaker suggests that it may not be as necessary as it once was for career advancement in the field.

💡CCNA

CCNA, or Cisco Certified Network Associate, is a certification program focused on networking skills. In the context of the video, the speaker implies that pursuing CCNA might not be the most effective path for everyone looking to break into cybersecurity, as there are other, less traditional paths that could be more beneficial.

💡Career Mentorship

Career mentorship refers to guidance or advice given by an experienced professional to help someone in their career development. In the video, the speaker offers career mentorship to Josh, providing him with a list of hands-on cybersecurity training to help him gain practical skills and confidence for job applications.

💡Hands-On Training

Hands-On Training refers to practical, experiential learning where individuals directly engage with the material or tools related to a specific field. The video emphasizes the importance of hands-on cybersecurity training over traditional certification exams, suggesting that real-world practice is more valuable for career development.

💡Security Operations Center (SOC)

A Security Operations Center (SOC) is a centralized unit that monitors and manages an organization's security risks and incidents. In the video, the speaker suggests that the skills learned from the recommended training can qualify someone to work in a SOC, which is a key entry point for many cybersecurity careers.

💡Digital Forensics

Digital Forensics is the process of collecting, preserving, and analyzing digital evidence in order to investigate and prevent cybercrime. In the video, Josh expresses his ultimate goal of working in digital forensics, which is a specialized area within cybersecurity.

💡GRC Mastery

GRC Mastery is a training program focused on Governance, Risk Management, and Compliance (GRC), which is the non-technical side of cybersecurity. The video highlights the demand for skills in this area and how the training provides practical labs and assessments to prepare individuals for GRC roles.

💡Job Application Strategy

Job Application Strategy refers to the approach one takes when applying for jobs, including when to start applying and how to present oneself to potential employers. In the video, the speaker advises starting to apply for jobs immediately after completing a foundational certification and continuing to apply while further training to gain experience and confidence.

💡Blue Team Level One

Blue Team Level One is a certification that focuses on the defensive side of cybersecurity, providing practical training for roles in security operations. The video mentions it as one of the recommended trainings for someone looking to enter the cybersecurity field, emphasizing hands-on experience over traditional exams.

💡Hack The Box

Hack The Box is a platform that provides hands-on cybersecurity training and challenges, allowing users to test their skills in a safe and legal environment. In the video, it is recommended as a practical training resource for aspiring cybersecurity professionals to gain experience and enhance their skills.

💡Cybersecurity Job Market

The Cybersecurity Job Market refers to the demand and supply of cybersecurity professionals in the job market. The video discusses the importance of having a broad skillset to maximize job opportunities and the misconceptions about hiring in the cybersecurity field.

Highlights

The conventional advice of obtaining CompTIA, Network+, Security+, and CCNA before entering cybersecurity is outdated.

Success stories are shared weekly on the YouTube channel, showcasing alternative paths to cybersecurity without traditional certifications.

Josh, a 32-year-old electrician with a cybersecurity degree from WGU University, felt unprepared for cybersecurity jobs despite having multiple CompTIA certificates.

Josh's lack of confidence in applying for cybersecurity jobs is a common issue among those who follow conventional wisdom and certification paths.

The importance of applying for cybersecurity jobs to gain experience and confidence, rather than waiting for perfection from foundational certificates.

A list of lab-based, hands-on cybersecurity training is recommended for practical application of learned concepts.

Let's Defend is recommended for its focus on the defensive technical side of cybersecurity and its potential to qualify for work in a Security Operations Center.

Josh's ultimate goal of working in digital forensics, a cybersecurity specialization, is acknowledged, but broad skills are advised for initial job applications.

The myth that hiring in cybersecurity is solely based on recognized certifications and ticking boxes is debunked.

The importance of focusing on the skills listed in job descriptions rather than just the certifications.

GRC Mastery is recommended for its practical approach to the non-technical side of cybersecurity, despite Josh's desire for a technical role.

The necessity of being well-rounded in cybersecurity to maximize job opportunities, especially for beginners.

Blue Team Level One and Hack The Box certifications are mentioned as valuable, but the emphasis is on hands-on skills over specific course names.

The strategy of combining technical Security Operations Center skills with GRC skills to enhance employability in cybersecurity.

The advice to apply for cybersecurity jobs as soon as possible, even with the risk of rejection, to gain experience and confidence.

Josh's mistake of only searching for digital forensics jobs, illustrating a common beginner's approach that limits job opportunities.

The importance of a winner's mindset and continuous learning and applying to secure a cybersecurity job.

Transcripts

play00:00

if you are told you must do the comp A

play00:02

Plus network plus Security Plus and CCNA

play00:05

before you get into cyber security then

play00:07

you're listening to the same stupid

play00:09

advice that was given to me 20 years ago

play00:12

but what if I told you that every week

play00:14

on this YouTube channel I post weekly

play00:17

success stories from all over the world

play00:19

by following advice from this YouTube

play00:21

channel without even doing any compa or

play00:24

CCNA instead they do other Sears and

play00:26

training that you may not have even

play00:28

heard of like the ones that I recommend

play00:30

it to Josh so Josh who's 32 years old

play00:33

booked a career mentorship call with me

play00:35

last week he is an electrician he lives

play00:37

in the US and he also did a cyber

play00:40

security degree from WGU University

play00:42

which comes with a lot of compa

play00:45

certificates yet he was confused because

play00:47

he followed the conventional wisdom of

play00:49

getting those foundational certificates

play00:51

yet he felt like he learned nothing he

play00:54

didn't feel confident enough to even

play00:56

apply to cyber security jobs but the

play00:58

problem is if he doesn't apply to cyber

play01:00

security jobs he will not gain that

play01:02

confidence that he's after he needs to

play01:05

be in interviews he needs to learn how

play01:07

to answer questions on the spot this is

play01:10

how we gain confidence so he booked a

play01:12

career mentorship call with me to know

play01:14

what his next move should be so in order

play01:16

for me to give him the skills and the

play01:18

confidence that he needs to start

play01:20

applying to cyber security job I

play01:22

compiled the list of lab based Hands-On

play01:24

cyber security training where he can

play01:26

actually practice the concepts that he

play01:28

learned instead of just scking boxes

play01:30

cramming and passing multiple choice

play01:33

exams this way he can learn a concept

play01:35

apply it in a lab remember those

play01:37

Concepts that he learned the training

play01:39

and certification list that I provided

play01:41

him with are challenging they will take

play01:43

time but this is the only way to gain

play01:46

real skill that will open so many doors

play01:49

and lead to a very lucrative and

play01:51

rewarding career my first recommendation

play01:54

to him was a platform called let's

play01:56

defend it's full of labs that focus on

play01:59

the defensive technical side of cyber

play02:01

security their website is a little bit

play02:03

confusing but what I asked Josh to do

play02:06

was their sock analyst pathway because

play02:09

the skills that he will learn there can

play02:11

qualify him to work in a security

play02:13

Operation Center which will open so many

play02:15

doors but Josh told me that his ultimate

play02:17

goal was to work in digital forensics

play02:20

which is a cyber security specialization

play02:22

where you perform cyber forensic

play02:24

examination as part of an investigation

play02:27

yet I still advised him to follow let's

play02:29

defend the stock analyst pathway so he

play02:31

can have broad skills that will maximize

play02:34

his chances of Landing a sa security job

play02:37

even if the job is not directly influenc

play02:39

the idea is to give him as many broad

play02:41

marketable skills as possible to

play02:44

maximize his chances of Landing a job

play02:46

the specialization itself is not really

play02:48

that important in the beginning so I

play02:50

advised him to be as generic as possible

play02:53

so he can qualify for a larger number of

play02:56

jobs but then the next question he asked

play02:58

me is this training recog recognized

play03:00

this one drives me crazy there seem to

play03:02

be this myth circulating around that

play03:05

hiring in cyber security is based on

play03:07

ticking boxes beginners seem to think

play03:10

that we as hiring manager we only look

play03:12

at the name of the training or the piece

play03:14

of paper they think if they show us a

play03:16

piece of paper then that's all we need

play03:18

to qualify for a job which couldn't be

play03:20

further from the truth they also seem to

play03:22

think that the reason why they can't

play03:24

plan the cyber security job is because

play03:26

they don't have this magical recognized

play03:29

piece of paper I have no idea who

play03:31

started this idea but please please get

play03:33

it out of your head we most definitely

play03:35

don't look for certain keywords you are

play03:38

not going to trick a hiring manager by

play03:40

showing them the word comp in your CV

play03:42

that is not what we look for sure in

play03:44

some job descriptions we might list some

play03:47

certifications that are nice to have but

play03:49

please don't ignore the rest of the job

play03:51

description where we list the skills

play03:53

that we need for this job the skills

play03:55

part of the job description is the most

play03:57

important part this is what you you need

play04:00

to focus on so yes lit's defend is not

play04:03

widely known however the skills that you

play04:05

will learn in that training are

play04:07

Universal they apply to every situation

play04:10

and every country your situation is not

play04:13

special you are not a special snowflake

play04:15

now the next training that I recommended

play04:18

for Josh surprised him it was GC Mastery

play04:22

there is a huge area in cyber security

play04:24

called GRC which is the non-technical

play04:26

side of cyber security there is so much

play04:28

demand in this area and there was simply

play04:30

no training that can cover Your Tracks

play04:32

when it comes to GC so I created GC

play04:35

Mastery which is fully practical full of

play04:37

Hands-On labs and practical assessments

play04:39

that will give you the skills that we

play04:41

need for GRC jobs but Josh wasn't after

play04:45

a untechnical cyber security job in fact

play04:47

he wanted the complete opposite he

play04:49

wanted to work in digital forensic which

play04:51

is one of the most technical parts of

play04:53

saba security so why did I recommend GC

play04:56

Mastery well Josh is an electrician he

play04:59

has never never worked in it before so

play05:01

he has zero it experience so in his case

play05:04

getting any cyber security job should be

play05:07

his number one priority he shouldn't

play05:09

Focus too much on the specialization in

play05:11

the beginning instead he needs to have

play05:13

the maximum number of skills that will

play05:15

qualify him for the largest numbers of

play05:17

cyber security jobs out there he simply

play05:19

needs to get his foot in the door now

play05:21

there are a lot of cyber security jobs

play05:24

that are generalist in nature so they

play05:26

want you to have more than one skill

play05:28

this is really for small and

play05:31

medium-sized organizations they will

play05:33

usually want someone with the title

play05:34

information security officer or a cyber

play05:37

analyst where they want you to work with

play05:39

their security service provider they

play05:41

want you to respond to some incidents

play05:43

but they also want you to run some

play05:45

vulnerability scans conduct risk

play05:47

management work with auditor and even

play05:49

run security education awareness

play05:51

campaign so that's a large number of

play05:53

skills now they don't want you to have

play05:55

deep knowledge in all of these areas but

play05:57

they want you to touch on all of these

play05:59

areas so so in order to maximize Josh's

play06:01

chance of Landing any cyber security job

play06:04

is for him to be a little bit more

play06:06

well-rounded so combining technical

play06:08

Security operation Center skills and GRC

play06:11

skills will put him at an advantageous

play06:13

point this will make him a lot more

play06:16

attractive to an employer than someone

play06:17

who simply just did one track or one

play06:20

pathway this is key especially if you're

play06:22

trying to land your first cyber security

play06:24

job and you don't have any experience

play06:27

now I talked about GRC Mastery in detail

play06:29

in this video so please check it out now

play06:31

Josh's next question was what about Blue

play06:33

Team level one what about hack the Box

play06:35

cdsa both are certifications that I've

play06:38

personally recommended in previous

play06:40

videos are they good should he do these

play06:42

instead well the answer isn't what you

play06:44

think but before we get to that I want

play06:46

to thank the sponsor of this video n

play06:48

pass business n pass business is a

play06:51

password manager ideal for businesses

play06:53

that want to maximize productivity did

play06:55

you know that 50% of development teams

play06:58

have missed de de lines due to issues

play07:01

with accessing it infrastructure well n

play07:03

pass makes managing passwords a lot more

play07:06

efficient with easy to configure

play07:09

password policies in fact 81% of data

play07:12

breaches are caused by poor passwords

play07:15

but the good news is with not pass you

play07:17

can create strong passwords by default

play07:20

the other big security problems that

play07:22

businesses struggle with is sharing

play07:24

sensitive data like passwords PIN codes

play07:27

and even credit card information over

play07:29

email but with not pass you can share

play07:32

credential payment information and other

play07:35

sensitive information safely and without

play07:38

sacrificing convenience among your

play07:40

teammates with full and limited rights

play07:43

to ensure members only have access to

play07:46

what they need but my favorite feature

play07:48

is still the data breach notification

play07:50

feature this allows you to change any

play07:53

passwords that were compromised in a

play07:55

breach before any damage is done but

play07:58

best of all secure your business

play08:00

effortlessly with a 3mon not pass trial

play08:03

use the code Unix guy at notp pass.com

play08:07

Unix guy it's a limited time offer and

play08:09

back to the video so to answer the

play08:11

question which training course is the

play08:13

best you may not like the answer but it

play08:16

is the truth which is it doesn't really

play08:19

matter the reason why I recommend

play08:20

courses like let's defend or hack the

play08:22

box or try hack me is to Simply get you

play08:25

out of the mindset of chasing multiple

play08:27

choice based exams and keywords and

play08:29

other stupid courses that don't teach

play08:31

you anything I'm trying to get you to

play08:33

focus on the skills on the Hands-On Labs

play08:36

that will actually lead you to a job the

play08:38

goal is to maximize your chances of

play08:40

Landing a cyber security job it's not to

play08:42

collect trophies and keywords and

play08:44

certifications so the skills that you

play08:46

learn in in Blue Team level one or hack

play08:49

the box or let's defend they're all very

play08:51

similar so it honestly doesn't matter

play08:53

which one you choose pick one and go

play08:55

with it till the end now for Josh I gave

play08:57

him four options to do after he finishes

play09:00

let's defend and GRC Mastery the first

play09:03

one is try hack me sock one which is a

play09:05

fantastic training it's a great chance

play09:07

to practice everything that you've

play09:09

learned and strengthen the knowledge

play09:11

that you already have in a practical way

play09:13

the second one is called cyber Defenders

play09:15

they have a fantastic security analyst

play09:18

certification that's fully lab based

play09:20

that covers everything that you need to

play09:22

work in a security Operation Center it's

play09:24

really ideal for someone who want to be

play09:26

a sock analyst or even a digital

play09:28

forensic analyst the third option was

play09:30

hack the Box cdsa again it's another

play09:33

phenomenal handsome practical

play09:35

certification that takes all the boxes

play09:37

for what I look for in a good training

play09:39

and the fourth one was blue Team level

play09:42

one which is a phenomenal Hands-On

play09:44

training that again teaches you

play09:45

everything you need to work as a cyber

play09:47

security analyst now the biggest

play09:49

question that Josh had that we ended up

play09:51

spending the majority of the Consulting

play09:53

call on was at what point should he

play09:56

start applying to cyber security job and

play09:58

how many set should he do should he do

play10:00

all of them should he pick one should he

play10:03

pick two which one should he do first

play10:06

well this is what I told Josh and this

play10:08

is the mindset that I want you to have

play10:10

as well once you finish one basic

play10:12

foundational certification like let's

play10:14

say the Google cyber security SE or even

play10:16

comp Security Plus then the plan is to

play10:19

start doing two things first immediately

play10:23

pick a Hands-On practical cyber security

play10:25

training and certification don't wait

play10:27

start right away start start whilst

play10:29

you're fresh pick any of the trainings

play10:31

that I recommended it doesn't matter

play10:33

which one if you're not sure which one

play10:35

to pick then do them in the order that I

play10:36

specified but the second thing that you

play10:39

need to do is to start applying to cyber

play10:41

security jobs as soon as possible yes

play10:44

you will get rejected but you also might

play10:46

plan the job you never know but the idea

play10:49

is as you continue to study as you do

play10:51

more and more practical Hands-On

play10:53

training and as you apply to more and

play10:56

more jobs you will have more confidence

play10:58

you will get more experience in

play11:00

interview settings you will start to

play11:02

know which companies are hiring this way

play11:04

your chances of Landing a job will go

play11:06

way up for example let's say you did

play11:09

let's defend and GC Mastery and now

play11:11

you're doing try hack me so one and as

play11:14

you apply to jobs you might get an

play11:15

interview maybe you'll get a job but

play11:18

let's say you get rejected that's fine

play11:20

keep studying pick hack the Box this way

play11:22

you will get to go over the same concept

play11:24

that you learned you might learn

play11:26

something new but more importantly you

play11:28

get to have more projects on your CV the

play11:31

idea is to continue studying and

play11:33

continue applying until you land your

play11:35

dream job I want you to have the winnner

play11:38

mindset don't stop until you get to your

play11:40

goal and it can happen really fast it

play11:43

depends on how much time are you willing

play11:44

to dedicate to it but it also comes down

play11:47

to how bad do you want it how invested

play11:49

are you now Josh actually made the

play11:51

classic mistake that I see all beginners

play11:53

make when they chy to land their first

play11:55

cyber security job which is he was only

play11:58

searching for digital forensics job and

play12:00

he was complaining that there aren't

play12:02

many digital forensics jobs advertised

play12:04

this is not the correct way to look for

play12:06

jobs in fact this is one of the five

play12:09

mistakes that every beginner makes when

play12:11

they try to land their first cyber

play12:13

security job I talked about them in

play12:15

detail in this video so please check it

play12:17

out and I'll see you there

Rate This

5.0 / 5 (0 votes)

相关标签
Cybersecurity CareersHands-On TrainingUnconventional AdviceSuccess StoriesJob Market InsightsSkill DevelopmentCareer MentorshipDigital ForensicsGRC MasteryJob Search Strategies
您是否需要英文摘要?