§ TECH · 3 MIN READ
The Security Job Starts at the Help Desk
Cybersecurity has the loudest shortage in tech and the most gatekept entry, and the actual route in is a job most people looking at the field refuse to take.
By Culture

THE SHORT VERSION
Entry into cybersecurity typically runs through an IT support or help desk role rather than directly into a security title, because security work assumes fluency with networks, operating systems and identity that support work builds daily. The common certification ladder is CompTIA A plus, then Network plus, then Security plus, paired with a home lab, which together substitute for a degree at most employers.
Every year the industry announces a shortage of hundreds of thousands of security workers, and every year people who want in cannot find a first job. Both things are true and they are not a contradiction.
The shortage is of people who can do the work. The bottleneck is that nobody hires for the job you are picturing at entry level.
Security work assumes fluency. To notice an unusual login you have to know what a normal one looks like. To spot bad network traffic you have to know what the normal traffic is. To decide whether a change is dangerous you need to know how the system was built.
That knowledge comes from operating the systems, and the job where you operate systems all day, badly, under pressure, for many different people, is support.
This is why the ladder is real and why skipping it usually fails. A bootcamp graduate with no operational background is applying for a job that presumes two years of context.
Help desk or IT support. Twelve to eighteen months. Resets, imaging, tickets, networking problems, users doing inventive things. Unglamorous and enormously educational.
Certifications while you work. A plus establishes the hardware and operating system floor. Network plus is the one that actually matters, because security is mostly networking with consequences. Security plus is the one that appears in job postings and clears automated filters.
Do them in that order. People skip to Security plus, pass it, and then cannot answer a basic routing question in the interview.
Operations centre analyst. The first real security title. Alerts, triage, escalation, shift work. From there the field opens into incident response, detection engineering, cloud security, identity, governance, testing.
Certifications prove you can pass a test. The lab proves you can do the thing.
Old hardware or free virtualisation software. Build a small network. Stand up a domain. Break it deliberately. Install logging, generate the events yourself, then hunt for what you did. Run the free tiers of the cloud providers and lock down your own account.
Then write down what you did. Not polished, just a public record of the work: what you built, what went wrong, what you learned. A hiring manager who sees three of those is looking at somebody who works on this when nobody is paying them, which is the entire signal they are trying to find.
“Certifications get the interview. The lab gets the job.”
Support pays modestly. The operations analyst step is the meaningful jump, and the specialisations after it are where the numbers people quote actually live. Plan for two to three years to the real salary rather than six months, and the plan will work.
Check whether an employer will pay for the certifications, because a great many will and almost nobody asks.
Pick the first certification and book the exam date before you feel ready. An unbooked exam is a hobby.
Build the lab this weekend with hardware you already own. Shipping something small in a weekend is a habit, not a talent.
And put the work somewhere public, because a repository is a resume that cannot be exaggerated.
- Can I get a cybersecurity job without a degree?
- Yes, and it is common. Most employers substitute certifications plus demonstrable operational experience for a degree, but they rarely substitute either for the support background that teaches you what normal systems look like.
- What order should I take the certifications in?
- A plus for the hardware and operating system floor, then Network plus because security is largely networking with consequences, then Security plus because it is the one job postings filter on.
- What is a home lab and why does it matter?
- A small network you build yourself on old hardware or free virtualisation software, then break and investigate deliberately. It demonstrates you can do the work rather than pass a test, which is what hiring managers are looking for.
