Skip to content

If I wanted to land a Cybersecurity Job in 2026, This is What I’d Do [FULL ROADMAP]

A step-by-step 2026 roadmap to land a cybersecurity job without a degree or experience, focusing on practical skills and projects.

Ask about this video. Answers come from its transcript only — with the timestamp, so you can check them.

Generated from the transcript and can be wrong — check the timestamp.

Key Takeaways

  • Avoid certification hell by combining theory with hands-on practice immediately.
  • Choose a target cybersecurity role by researching real job adverts to tailor your learning.
  • Build practical projects to demonstrate your skills and create evidence for employers.
  • Optimize your CV to pass ATS filters and highlight relevant experience and projects.
  • Focus on quality applications and referrals to improve chances of landing interviews.

What the video covers

  • The video outlines a five-step system to land a cybersecurity job quickly in 2026 without prior experience or a degree.
  • Step one emphasizes learning cybersecurity fundamentals including networking, operating systems, and core security concepts with hands-on practice.
  • The presenter warns against 'certification hell' where beginners collect certifications without practical skills.
  • Step two focuses on building projects as practical work experience, such as home labs, SOC investigations, and vendor risk assessments.
  • Step three covers crafting an ATS-friendly CV that highlights relevant skills, projects, and reframes past job experience.
  • Step four discusses the importance of quality job applications and getting referrals to stand out in a competitive market.
  • Step five prepares viewers for interviews by practicing real-world scenarios and demonstrating project experience.
  • The presenter shares personal experience working as a senior cybersecurity consultant and landing a Big Four role after many rejections.
  • Resources like Professor Messer, TryHackMe, and Security+ certification are recommended for foundational learning.
  • The overall message is to combine theory with immediate practical application to build real skills that employers value.

Answers

Questions about this video

What is 'certification hell' and how can I avoid it?

'Certification hell' refers to collecting multiple cybersecurity certifications without gaining practical skills. To avoid it, immediately apply theoretical knowledge through hands-on exercises and projects.

Which cybersecurity roles are best for beginners?

Entry-level roles like SOC analyst and GRC analyst are realistic starting points for beginners, as they often require foundational skills in investigation, risk assessment, and documentation.

How important are projects for landing a cybersecurity job?

Projects are critical as they serve as practical work experience. They demonstrate your ability to perform real job tasks and provide evidence to employers before you have formal work experience.

Full Transcript — Download SRT & Markdown

00:00
Speaker A
If I wanted to land a cybersecurity job as fast as possible in 2026, this is exactly what I would do starting today.
00:07
Speaker A
What do you do for a living? I'm a cybersecurity specialist. And how much money do you make per year doing this?
00:11
Speaker A
So, I have multiple clients and multiple projects, but I think my best year was around 400,000.
00:16
Speaker A
I'm a cybersecurity analyst. How long have you been doing this? About 5 years now.
00:20
Speaker A
How much do you make? About 150 a year. In this video, I'm going to reveal to you the five steps to landing a cybersecurity job without a degree or any previous experience. And I want you guys to understand that
00:31
Speaker A
you need to go in order, right? Because each step builds on the one before, and each step kind of gets harder, so fewer and fewer people kind of make it through till the end. But the truth is, most
00:41
Speaker A
people never get past step one because there's something called certification hell, right? And I'd say 80% of beginners are probably in it right now.
00:49
Speaker A
What they're doing is kind of collecting certification after certification, spending thousands of pounds or dollars, and never actually getting closer to a job in the end because that's the end goal, right? So, what I'm going to do is
01:01
Speaker A
show you exactly how to escape that path and actually learn and work on things that matter and move you closer to your goal. And why am I the one to tell you this? I've been in the same position
01:12
Speaker A
you're in right now, where you're kind of confused on which courses to go for, which certifications are actually worth it, and not really having any direction to move forward in. And I've sent hundreds of applications to different companies, right? So, I've faced those
01:25
Speaker A
rejections, but I was finally able to land a role at a Big Four firm, and I currently work as a senior cybersecurity consultant for the past 4 years now. And I've helped hundreds of others kind of in the same position as a complete
01:38
Speaker A
beginner to eventually getting hired. So, this isn't theory, this is essentially the exact system you need to follow step-by-step to be able to break into the industry. So, let's get into it. Okay, firstly, we have step one, which is the fundamentals, and
01:52
Speaker A
everything else is built on this, and this is where the certification hell traps lives as well, which I mentioned earlier. And what that is is when you spend years and thousands of pounds collecting certifications, and you've never investigated a single alert, never
02:07
Speaker A
opened a terminal, or written a risk assessment. So, it's all just theory, and you might have something like the Security+ on your resume, but you might not be able to explain what happens when you, for example, type a website into a
02:22
Speaker A
browser. It essentially makes you feel like you're making progress because you're studying and passing exams, but the thing is certifications are checkpoints, not the goal. And the goal is obviously to eventually be able to land your first job. So, here's
02:39
Speaker A
how you're actually going to get through step one. First, you want to pick your target role because cybersecurity is not just one job, right? There's the SOC side, which is kind of like defending and investigating. There's GRC, which is
02:52
Speaker A
handling risk and compliance. There's cloud, there's identity, there's pen testing. So, what I want you to do is spend one weekend reading 20 or 30 real entry-level job adverts in your country.
03:04
Speaker A
Not things you see online or on TikTok or Instagram, right? But actual adverts, and write down which roles keep appearing and kind of see what they keep asking for, what kind of tools they list.
03:18
Speaker A
And that list is now going to be your syllabus. Because for most beginners, the realistic entries are going to be roles like SOC analyst and GRC analyst.
03:28
Speaker A
So, if you're kind of aiming for those roles or any other kind of entry-level roles, this is going to be the video that you want to kind of follow. Once you've picked your target role, you want to learn the fundamentals, and this is
03:39
Speaker A
going to be the same for any kind of cybersecurity role you go for. So, firstly, it will be networking, which is things like IPs, ports, DNS, what a firewall does. And if you go to a channel called Professor Messer online,
03:54
Speaker A
that covers everything you need to know for completely free. The next thing is operating system. So, this is things like Windows and Linux, especially Linux, right? Because half the security tooling lives in the terminal. So, making sure you understand that is going
04:10
Speaker A
to be essential for your career going forward. And if you go to TryHackMe's free intro path, that covers that from end to end. And the other thing is core security concepts. So, this is things like common attacks, how authentication
04:23
Speaker A
works, the basics of defense. And if you just go through the free Security+ material or something like the Google cybersecurity certificate, that covers everything you need to know. And here's a rule I want you to follow to
04:36
Speaker A
stay out of certification hell. What we need to do is make sure you're actually getting practical experience within 24 hours of learning any theoretical knowledge. For example, if you learned about ports today, scan your own home router with Nmap. If you learned about
04:52
Speaker A
logs, open Event Viewer on your own laptop and find your last five logins and understand what's going on behind that. These are five-minute exercises, but that's the difference between knowing about security and actually having done it. And if you want a
05:09
Speaker A
certification to kind of anchor this step, the Security+ is going to be the most recognized for entry-level. And you can't just get that certification, right? Make sure you're doing the hands-on work. So, for this step, a summary would be you kind of find your
05:23
Speaker A
target role, you learn about networking, you get comfortable with Linux, and you get the basic security concepts out of the way. Step two is projects. And this is the step that's going to separate people who actually get hired from
05:37
Speaker A
people who apply for a year and aren't hearing anything back and they say the job market's difficult.
05:43
Speaker A
I want you to kind of make this mindset shift. Projects are your work experience before anyone gives you work in the real world. Think about what an entry-level cyber job actually is. So, a SOC analyst would investigate things and
05:58
Speaker A
document them, right? And a GRC analyst would do something similar. They would assess things and then document them.
06:05
Speaker A
So, the play is simple, right? You need to do the job before anyone hires you to do it, and you need to have evidence to actually show you can do your work. So, let me give you some actionable advice
06:14
Speaker A
and give you three projects in order of difficulty that you can actually do this week going forward. So, a beginner project would be something like a home lab, which is documented. So, what you can do is set up a virtual machine, or
06:28
Speaker A
you can use Docker, for example, and then deploy something deliberately vulnerable. So, you can use something like DVWA or Juice Shop. And what you want to do is attack it, and then write up essentially what you did and what you
06:42
Speaker A
saw. That's going to be one project, and you've essentially touched virtualization, networking, web attacks, and also how to document a real-world attack. And that's going to be free for you to do as well. Okay, moving on to an intermediate project,
06:58
Speaker A
what you can do is a full SOC investigation. So, you would take a set of logs, for example, and then those can be from an SSH brute-force attack. That could be one. And you'd pull them into Splunk or Elastic. You would then find
07:13
Speaker A
the attacker, build the timeline, and write an actual incident report. So, in that report, you'd have the findings, impact, and recommendations, as well as screenshots of what you did. And this is something a manager could actually read.
07:27
Speaker A
Okay, finally, a more advanced project, right? You can do a vendor risk assessment. This is more GRC-related, and almost nobody goes for this role, right? Which is actually why it's going to help you stand out. But, what you
07:39
Speaker A
want to do is invent a company.
07:49
Speaker A
You'd produce a questionnaire, the risk register, and kind of like a one-page summary for management to read afterwards. I currently do this at my day job in cybersecurity, and I promise you, if you do this specific project, it's going to get you remembered when
08:05
Speaker A
you enter those interviews. Okay, now for the part that actually matters more than doing any of these projects, right?
08:11
Speaker A
And it's not about the tools you use, but it's more about the story behind it.
08:15
Speaker A
So, instead of writing something like Nmap, Wireshark, Splunk, and all these random tools on your CV, which just kind of shows that you've downloaded the softwares, what you want to do instead is write the story. So, for example, you
08:29
Speaker A
investigated a simulated brute-force attack across 3,000 login events. You then identified the source and then recommended two detection rules. This is going to tell me that you can actually do the job from end to end, and you don't just know certain tools. And the
08:44
Speaker A
final thing is you need a write-up, and this is going to go on your GitHub portfolio because if these projects aren't documented, no one's going to know what you've done, and there's no evidence of the tools that you've used, right? Next
08:59
Speaker A
up is step three, which is your CV. And what you might not know is most CVs kind of get rejected by the ATS filter before a human ever reads them. So, I'm going to show you how to actually get through
09:11
Speaker A
that. Firstly, you have your header, which needs your name, your email, phone, LinkedIn, and your GitHub.
09:18
Speaker A
In cybersecurity, your GitHub's going to do the heavy lifting, right? Because that's where the proof's going to live.
09:24
Speaker A
And if you have the right to work in the country you're applying in, make sure you have that kind of mentioned within that section as well. Next up, you have the headline, which is going to be around two lines max, and you don't want
09:35
Speaker A
to write something like passionate hardworking individual, It needs to be specific and have evidence and kind of aimed at one role. So, this can be SOC analyst. Uh you've documented investigations on your GitHub and you've done a home lab as well as completed the
09:51
Speaker A
Security Plus. Next up is the experience section and here's a move that a lot of people don't make, right? You want to reframe it. So, whatever job you've had in the past, whether that's, for example, IT support, you didn't just reset passwords, right?
10:07
Speaker A
What you want to say instead is you handled access management for 200-plus users and escalated suspicious activity on the accounts. For re- retail, for example, you dealt with fraud prevention and instant escalation. And this can be something for bank roles, warehouse,
10:23
Speaker A
customer service. There's always some sort of security touch somewhere. So, make sure you dig that out and write those as bullet points within your CV.
10:31
Speaker A
Then we have projects, which is going to be the most important, so it's going to be front and center. What you want to do here is, if you had no cyber experience in the past, right? This section is
10:42
Speaker A
going to go above the experience section and you want to avoid the two kind of classic fails I see a lot. The number one is a title with nothing under it.
10:51
Speaker A
So, you might just write home lab, but nobody kind of knows what you've done did with that, right? And then the other thing I see is a pile of tools with no context. So, instead you want one or two
11:02
Speaker A
lines per project with numbers and a proper GitHub link. And this is going to really set you apart from everyone else applying. Then we have the skills section, which is going to show you the tools you've used and the frameworks.
11:14
Speaker A
And don't write anything where you're kind of beginner level, right? Everything on here needs to be at a level where you can actually do the job. If you can't, then make sure to leave it out. Moving on to step four. So, we've done the
11:28
Speaker A
skills, we've done projects, we have have CV now. Now we need to get you interviews. And I don't need to explain to you how to apply for jobs, right? You know that part. You apply on LinkedIn, career pages, job boards. You're just
11:40
Speaker A
going to apply everywhere. But the hard part is actually getting the call back. Entry-level postings get hundreds of applicants within hours, and a chunk of those are pretty much AI tools auto applying the second the job goes live.
11:54
Speaker A
And if you see kind of a job around uploaded 20 minutes ago, there's probably around 150 applications on that. So, what I want you to understand is you don't win on volume. It's instead on quality applications, and how you can do
12:08
Speaker A
that is with referrals. And there are three tiers to referrals, right? And not all referrals are made equal, so I'll go through each of those right now. Firstly, we have referral tier one, which is the standard way. And
12:21
Speaker A
this is when you message someone at the company, you ask them to refer you, they drop your CV in the system, and this does help, but pretty much everyone does this right now. And a referral from someone who barely knows you carries
12:35
Speaker A
limited weight. Referral tier two, this is the decision maker. So, the hiring manager actually makes the decision of who gets hired, right? It's not the filter or HR at the end of the day. So, what you want to do is find team leads
12:49
Speaker A
or hiring managers in your target area. You then engage with their posts and ask genuine questions about their team, what kind of uh work they're up to.
12:59
Speaker A
And the aim is to get your GitHub in front of them. Because if they've seen the work before your application even lands, you're not going to be at the bottom of the application queue, right?
13:09
Speaker A
You're going to be the one that comes to the top of their mind when you're actually applying for a role that they have in their company. Referral tier three, which is inbound. This is going to be the most powerful one, right? And
13:20
Speaker A
if you do this correctly, you eventually never need to apply again. Every time you finish a project, post about it on LinkedIn. So, this can be what you built, what you found, what you learned, and then link your GitHub. If you do
13:34
Speaker A
that consistently for around two or three months, recruiters and managers will start appearing in your DMs. I pretty much watched this student of mine run this exact play for a few months. He reframed his experience, built the portfolio,
13:48
Speaker A
posted the journey, and landed a role at a major consultancy where the interview was practi- practically kind of like a formality because they'd already watched him work for months on LinkedIn. So, the question is why would anyone need to test you
14:03
Speaker A
from scratch when you've already been proving it in public. And now the final step, which is interviews. This is the one that the fewest people ever reach, and it's where you actually get the job, right?
14:14
Speaker A
The good news is entry-level cyber interviews are more predictable than you can think. They test three things, which I'll go over right now. First one is fundamentals. So, this is things like TCP versus UDP, uh the CIA triad, what
14:28
Speaker A
port HTTPS runs on, what happens when you type a website into a browser, for example. See, these are more pass or fail type questions, and the question banks are literally public. So, make sure you go through them. Um for
14:42
Speaker A
example, search SOC analyst interview questions and just drill them out loud. And you need to kind of practice literally just record yourself with your iPhone and answering these questions.
14:53
Speaker A
Number two is scenarios. Say you got an alert, for example, a suspicious login from another country at 3:00 a.m. Walk me through what you would do. They're not looking for a perfect answer here, right? They're looking for a process.
15:05
Speaker A
So, you just need to have these ready in your projects, for example. So, what you can say is you'd validate the alert, you'd gather context on the user and asset, uh you'd look kind of look for related activity, and you'd need to
15:18
Speaker A
contain it if necessary. And then you just document what you did and escalate it if needed. Number three is your story. So this is why cyber, why this is specific role, tell me about a project.
15:31
Speaker A
So what you would just want to do is prepare your best project stories in the kind of situation task action result format before you walk in. And when they ask you about a problem you solved, you could just bring up a brute force
15:43
Speaker A
investigation for example. And you don't need work experience to answer these, right? You just need documented projects. And one kind of small tip is research the company before you actually go into the interview. It's a obvious answer, but if you're kind of
15:57
Speaker A
interviewing at a bank, you need to mention things like regulation and resilience. If it's a startup for example, you need to kind of know about the cloud. And that's all the steps.
16:06
Speaker A
It's a simple system. It's just go through the fundamentals, build the projects, build out your CV, get those referrals, and you'll start seeing interviews come in. And if you watch this video and you're kind of motivated to get started and you're starting from
16:19
Speaker A
zero, I've linked the website to our community down below which has all the resources you need. So for example, the road maps, the beginner courses, the projects you need to do. It's just the link school.com/cyber. So just check it
16:31
Speaker A
out in the link in the description. There's around 90,000 people at the moment currently learning within that community. So you're not kind of doing it alone, right? You want to be in the same journey as other people so you're
16:43
Speaker A
on track and motivated to keep going even in those hard days. So yeah, thank you guys for watching. And if this was useful and you want more cybersecurity videos like this, then just leave a like and subscribe and I'll see you guys very
16:54
Speaker A
soon.
Topics:cybersecurity job 2026cybersecurity roadmapentry-level cybersecuritycertification hellSOC analystGRC analystcybersecurity projectscybersecurity CV tipsjob interview preparationhands-on cybersecurity learning

Get More with the SozAI App

Transcribe recordings, audio files, and YouTube videos — with AI summaries, speaker detection, and unlimited transcriptions.

Or transcribe another YouTube video here →