shellsharks
Infosec researcher | writes @ https://shellsharks.com
Mastodon: @shellsharks@infosec.exchange
Thereβs no one path in to be sure. But thereβs lots of ways to educate yourself and build a βhireableβ portfolio from home and without getting a typical 4-year degree. Learn to code, get some applicable certifications, start a website (as your digital portfolio), contribute to open source or spin up your own project(s), etcβ¦ The IT/software/cyber market is not at its peak (in terms of opportunity), but weβre definitely still here and there are openings. Itβs still a great field with a lot of perks if you can weather the challenges of βbreaking inβ. Itβs also not going anywhere, despite what some may lead you to believe given the advent of βAIβ. For those of us in tech, weβll be the first to tell you that our jobs are pretty safe.
If itβs infosec you might be interested in, you may find this guide I put together and typically share interesting - https://shellsharks.com/getting-into-information-security.
Good luck!
Overall, yes. Day to day yβknow it varies. Pure βsecurity workβ is, for me, genuinely interesting and I spend legit personal time learning and working on projects, for no other reason than they are kinda fun. What I do as a security engineer for a corporation day-to-day and week-to-week doesnβt always translate to the βfun stuffβ. So my answer is somewhat nuanced. Yes, I do like cybersecurity. But no, I donβt always like the work in terms of how it manifests in corporate life.
I just use an Osprey Comet daypack (https://www.amazon.com/gp/product/B072N2WY6S/ref=ppx_yo_dt_b_search_asin_title?ie=UTF8&psc=1), though if I had just random money to burn I might go for the βTechnonautβ https://www.tombihn.com/products/techonaut-30?variant=40265614753981
I wouldnβt worry about certs to start, especially not OSCP. Since you are in the software/dev space, I would consider security roles in the AppSec or CloudSec space as places to jump first. For that, consider going through PortSwiggerβs web security academy (free) training online to learn more about web vulns, their impact, how to mitigate, etcβ¦ If you want a cert, consider one from a cloud vendor and apply to jobs that use that vendor. If you can do even basic scripting, understand app-related vulns and use a few appsec tools then you should be an easy hire for a lot of places. (That said, Iβve been hearing the market for infosec is atrocious right now).