How to become a cybersecurity specialist from scratch

How to become a cybersecurity specialist from scratch

From our earlier articles it follows that cybersecurity is one of the most promising and sought-after fields in tech. If you still have doubts, we would suggest going back and reading everything you need to know about it. Now it is time to move from words to action and work out how someone actually becomes a specialist. In this article we set out a step-by-step plan for beginners that will help you learn the profession from nothing.

The skills a cybersecurity specialist needs

Success in a profession is decided first of all by confidence and by the wish to get better every day. But the industry does set certain rules about which abilities a given position requires. As in any field, a successful cybersecurity career combines technical knowledge, practical experience and strategic thinking. Let's look more closely at the skills that will help.

Hard skills:

  • Networking — TCP/IP, DNS, VPN, NAT, network protocols and firewalls
  • Operating systems — Linux and Windows administration, working on the command line (bash, PowerShell)
  • Cryptography — an understanding of encryption (AES, RSA), hashing (SHA, MD5) and how SSL/TLS certificates work
  • Programming and scripting — Python, Bash and PowerShell for automating work
  • Vulnerability management — analysing and exploiting vulnerabilities (CVE, Metasploit, Burp Suite, Nessus)
  • Forensics — the branch of cybersecurity concerned with investigating computer crime, analysing digital evidence and recovering data, known in full as digital forensics — and incident response: logging, investigating attacks, SIEM monitoring (Splunk, ELK)
  • Penetration testing — working with Kali Linux, Nmap, SQLMap, Wireshark
  • Application security — code analysis (SAST, DAST), protecting APIs, web vulnerabilities (the OWASP Top 10)

Soft skills:

  • Analytical thinking — the ability to find patterns and analyse threats
  • A capacity to learn — a readiness to keep developing in a fast-changing field
  • Communication — working with DevOps teams, developers and managers is an important part of the job. You will need to run training, take part in negotiations and decisions, and report to leadership
  • Resilience — the work involves not only documents but acting amid attacks and incidents, which demands quick reactions and structured, carefully planned action without panic

The road through cybersecurity can be hard and calls for a considered approach and a plan. For anyone wanting to take their first steps now, it can be difficult to concentrate and put the right sequence of actions together. We want to make that simpler, so here is a plan you can build on and start moving towards your goal in small steps.

Stage I — settle on a direction

We have written before about the directions within cybersecurity: penetration testing, threat intelligence, incident response, cloud security and others. Each has its own roles and professions. Read about each in more detail, weigh your own strengths and think about which direction they suit best. If you are at a loss and do not know what to choose, start with the general fundamentals and pick a specialism afterwards — you will not go wrong.

Stage II — learn the tech fundamentals in theory

Do not rush headlong into cybersecurity. At this stage it matters not to lose motivation but to build your interest in the field. We recommend starting with material on networking fundamentals, operating systems and programming, in theory. At this stage we would suggest not going deep into tooling but accumulating a sufficient base of knowledge:

  • Computer networks: study how TCP/IP, DNS and HTTP/HTTPS work
  • Operating systems: get to grips with Linux and Windows, the command line and log files
  • Programming: a basic knowledge of Python and Bash will help you automate work
  • Attacks and defences: study DDoS attacks, man-in-the-middle attacks, SQL injection, viruses and malicious software. Knowing these attacks and the defences against them helps you understand how systems are protected
  • Cryptography: get familiar with the principles of encryption, authentication and digital signatures, which play a key role in keeping data secure
  • Vulnerability and patch management: learn to analyse vulnerabilities and manage the patches that close them

Stage III — start using free learning resources

There is a genuinely large number of platforms with good material freely available. Which you choose depends only on how deep you want to go. If you want the fullest and most current information, we would suggest starting to look for a school with proper courses at this stage. To begin with you can look at the free resources to gauge how interested you actually are:

  • Coursera, Udemy, edX — courses on cybersecurity fundamentals
  • Cybrary — free courses on various aspects of security
  • TryHackMe, Hack The Box — practical labs for studying attacks and defences
  • OverTheWire, PicoCTF — games for learning to break in and to defend

This stage is in many ways decisive: how well your career goes depends on the school you choose. At PASV we take great care over what our students learn on the Cybersecurity Analyst course, and our instructors share practical, current experience. During the internship you work on a real project as close as possible to what awaits you once you are hired.

Stage IV — gain practical experience

Theory matters, but the profession is hard to learn without practice. That is exactly why we recommend choosing your school carefully at the previous stage, since many schools do not provide enough practice or experience on real projects. To go beyond project experience and broaden it, start taking part in competitions such as Capture the Flag. There are also bug bounty programmes — finding vulnerabilities for a reward, ethical hacking in other words — which you can join with minimal experience or as part of a team. Test labs on virtual machines with deliberately vulnerable systems are another good option; instructors often offer these as part of their own research or to a group of active students. Or try building your own test environment using VirtualBox or VMware.

Stage V — learn the tools

At this stage, applying the theory you gained and having worked through the training, you need to practise with the real tooling yourself. The wider the range of programs you can work with, the better your chances of being hired. The tools worth learning include:

  • Wireshark — a traffic analyser
  • Nmap — a port scanner and network reconnaissance tool
  • Burp Suite — a tool for testing web applications
  • Metasploit — a framework for exploiting vulnerabilities

Stage VI — get certified

Do not underestimate certification, particularly in information security. In the US market it is a substantial competitive advantage: in an HR specialist's eyes it confirms your knowledge and demonstrates that you hold the stack of knowledge and tools their position requires. Ultimately it improves your chances of being hired.

There are a great many certifications; we would suggest looking at these:

  • CompTIA Security+ — a foundational security certification
  • Certified Ethical Hacker (CEH) — for specialists doing penetration testing
  • OSCP (Offensive Security Certified Professional) — an advanced certification for ethical hackers
  • CISSP — a certification for more experienced specialists, confirming a knowledge of information security generally
  • Vendor certifications from Microsoft, Cisco and others, though we would suggest sticking to the market leaders

Stage VII — find an internship

The final stage before you are hired. But do not relax just yet. A good internship, alongside certifications, is your main card for standing out in the market. Be selective: it is worth spending more time at this stage searching and weighing what the market offers, because it will then take you less time to find a permanent position, since your resume will be strong. At PASV, internships are included in every tech course, so this stage is nothing to worry about.

Remember that what matters is starting, even in a small way — that is exactly what the art of small steps means. Be persistent in your effort and you will soon be a sought-after specialist in information security, reaping the rewards of hard work. And if you want support on that far from easy road, we at PASV will gladly lend you a shoulder and, with the professionalism we are known for, get you to the result you want.

Read next