Breaking into Cybersecurity from IT Support, Networking, or a Bootcamp
Security is hungry, and it is picky
Every year someone publishes a chart that says millions of unfilled cyber jobs. Then you apply and hear nothing. Both can be true. The unfilled jobs are often mid-level, cleared, cloud-security, or “be a whole team.” The junior jobs exist, and they fill with people who can show a queue: helpdesk, networking, a lab, a cert, a shift. They do not fill with people whose entire identity is a hoodie and a TryHackMe streak they cannot explain. If you are on a service desk now, you are not at the back of the line. You are in a line a lot of degree-only applicants are trying to cut into from the side.
This article is the on-ramp. The resume structure lives in the cybersecurity resume guide. Here is the career logic, the order of proof, and the mistakes that cost a year.
Keep the helpdesk on the page
Password resets are identity. Phish reports are awareness. Imaging laptops is endpoint. Permissions tickets are authorization. Write them with those nouns if they are true. You do not need to pretend you were a SOC analyst last year. You need to show you already sit next to the work. Hiring managers would rather train a calm ticket-writer than untrain a loud beginner who thinks nmap is a personality.
If you hate tickets, security will still be tickets, especially at L1. The tickets are about worse days. If you want less customer-facing work, GRC and some cloud-security roles are quieter and more document-heavy. Pick with your nervous system, not with a movie.
Networking and sysadmin are a gift
DNS, AD, firewalls, backups, VLANs — this is the physics of attacks and defenses. A CCNA or a few years of network ops is a better base than a random “ethical hacking” diploma with no packets. Put the environment size on the resume: how many users, which OS, which vendor firewall if you can name it. Then add the security tasks you already did: patching, MFA, disabling stale accounts. Then apply to SOC, to internal IT-security hybrid roles, and to junior network-security posts. You will beat bootcamp-only applicants on the fundamentals conversation, which still happens, because ransomware still travels on ordinary misconfig.
Bootcamps: use them, do not become them
A good bootcamp gives you a lab and a schedule. A bad one sells a job guarantee and a logo. If you already paid, extract the labs and write them as projects with what you practiced. Do not list the bootcamp as an employer. Do not replace your real jobs with it. Pair it with a cert the postings in your city mention. Then apply. The bootcamp is not a personality. It is a semester you bought. Treat it like a semester.
TryHackMe and Hack The Box are practice. They are not employment. “Top 2% on a CTF platform” can sit under Projects if you can talk about a box you finished. It should not replace work history. Banks do not staff SOCs from scoreboards alone. They staff from people who will show up for a night shift and write a sentence in a ticket.
Cert order that matches junior postings
Start with something that teaches breadth: Security+ or an equivalent vendor associate. Add a SIEM or cloud associate if your target posts repeat it. OSCP is a later flex for offensive roles; it is not the first move for a helpdesk person who has never read a log. CISSP is not a beginner cert. “In progress” after a weekend looks silly. Put dates and IDs for certs you hold. Recruiters do check, and faking a cert in this field is a career-limiting move because the field is smaller than it looks.
Labs you can describe in two minutes
A tiny AD lab. Sysmon to a local SIEM. One detection rule. A write-up with screenshots that do not include your real passwords. A phishing-analysis note on a public sample. That is enough to start. You do not need a rack that looks like a TV show. You need a story: what you saw, what you concluded, what you would do at work with a ticketing tool. Put the write-up in a repo or a PDF. Link it. If you cannot link it, you can still talk. The resume should mention the lab in one bullet so they ask.
Where to apply first
Internal mobility if your company has a security team — this is the highest-probability move and the most ignored. MSSP L1. SOC in a bank or BPO. GRC analyst if you can write. Vulnerability management coordinator if you can chase owners. Cloud security only if you already live in a cloud. Offensive roles later. “Junior pentester” ads that want OSCP, three years, and a blog are not junior. Read past the title.
Geography matters. Some cities have MSSPs. Some have none. Remote L1 exists and is competitive. Put your city and shift flexibility on the page if you can work nights. Night flexibility is a real skill in this market. Write it without drama.
The resume look
No skulls. No red-on-black. Classic headings, certs, tools you used, helpdesk bullets rewritten with security nouns, lab under Projects. One page if you are early. Export from MineResume and search the PDF for the SIEM and the cert. If you are applying to a government form that wants a photo and a declaration, that is a second file. Do not send the movie poster to a bank.
You will hear no a lot. The people who get in are repetitive: they keep the day job, they add one proof, they apply to L1, they write tickets like grown-ups. That is the in-demand path that still works in 2026. It is not cinematic. Cinematic is for after you have a queue of your own, and even then the work is mostly documentation. If you can live with that, start this month by rewriting three helpdesk bullets. Then open the guide and finish the page. Then send it to a posting that describes Tuesday, not a superhero.
A six-month version if you already have IT years
Month one: rewrite the resume with security nouns and a Classic template. Month two: Security+ or the cert your city repeats, studying on a schedule. Month three: one lab write-up. Month four: internal mobility conversation and ten external L1 applications. Month five: interviews and a second lab targeting the questions you missed. Month six: accept L1 or a hybrid IT-security role. This only works if the IT years are real. If they are not, use the twelve-month map instead and do not skip fundamentals.
Do not quit a stable helpdesk job on week two of a cert video. The helpdesk is your proof and your rent. Quit when you have an offer, or when the job is harming you for reasons that are not impatience.
Women, career returners, and the “culture” problem
Some security rooms are still rough. You do not have to perform a TV hacker to belong. GRC, identity, vendor risk, and some cloud-security teams are full of people who write well and do not post exploit memes. Target those postings if the SOC chat culture is a deal-breaker. Your resume should look like a professional document, which it should anyway. You do not owe anyone a hoodie in the headshot, and you probably should not include a headshot at all for private-sector ATS flows.
If you took a gap, use the gap guide and a cert/lab, not an apology paragraph. Security likes people who document. Document the gap like an incident: what happened, what you did, what you are doing now. Short. Then the lab.
Ethics you should already be practicing
Do not scan networks you do not own. Do not brag about breaking into a school Wi-Fi. Do not publish exploits against a former employer. Junior applications get rejected for that, and sometimes worse. Curiosity is not a legal defense. Put “home lab on isolated hardware” on the resume. Put “I only test systems I am allowed to test” in your mouth for the interview. If a bootcamp encouraged gray-area homework, leave that homework off the PDF.
The in-demand version of this career is trust. Your resume is the first trust document. Make it quiet, specific, and true. Then go do the shifts. The cinematic stuff, if it ever arrives, will not look like the poster. It will look like a long ticket and a phone tree. If you can want that, you are already more ready than the feed suggests.
Last practical note: set a weekly search for “SOC L1,” “GRC analyst,” and “security operations” in your city plus remote. Apply even if you match sixty percent. Wait for the posting that wants a unicorn if you want to wait a year. The people who get in send the quiet PDF on a Thursday and then go back to the helpdesk until someone replies. That rhythm is the job before the job. Start Thursday.