jobmarket.pro
All articles
Changing career

How do I move into cyber security analyst from another field?

What genuinely transfers, the certification route, what a career changer's CV has to overcome, and an honest timeline.

Published 20 Sept 2026 · 8 min read

What actually transfers, and what doesn't

If you're coming from IT support, sysadmin, network engineering, or software development, a fair amount transfers directly. Understanding how networks route traffic, how operating systems handle permissions, how applications talk to databases — that's the substrate cyber security analysis sits on. You can't analyse a suspicious login if you don't already know what a normal one looks like. Time served in a helpdesk or NOC counts for more than most career-change guides admit, because you've already seen the systems from the inside.

If you're coming from a genuinely unrelated field — teaching, law, retail management, marketing — the transferable material is thinner and more general: attention to detail, writing clear incident notes, working under pressure when something's actively going wrong, following a process without skipping steps because you're bored. Real, but not sufficient on their own. Security analysts spend a lot of time reading logs, and you cannot read a log you don't understand.

What doesn't transfer, whatever the field: familiarity with a SIEM (Splunk, Microsoft Sentinel, QRadar), with the MITRE ATT&CK framework as a working reference rather than something you've read about once, with how a SOC actually triages an alert queue, with the difference between a false positive and something that looks like one but isn't. None of that comes from adjacent experience. It comes from doing it, in a lab or in a job, and there's no shortcut round that.

The qualification route, and where it's actually a route

Entry-level: CompTIA Security+ is the closest thing to a recognised floor. It's referenced in a lot of junior job specs, partly because some organisations still map roles against the US DoD 8570 directive that named it, and partly because it signals baseline knowledge without requiring years of prior study. It is not a licence — nobody needs it by law — and it will not get you an interview by itself. Treat it as evidence you can learn the vocabulary, not as the qualification.

Beyond that, the field splits by specialism rather than following one ladder. If you're heading towards a SOC analyst role, GIAC's GSEC or GCIH and the SANS courses behind them are respected but expensive, and mostly paid for by employers rather than individuals — worth knowing before you commit your own money. If you're aiming at penetration testing, the practical, exam-in-a-lab certifications (OSCP is the one people ask about by name) carry more weight than multiple-choice ones, because they test whether you can actually do it. If you're aiming at governance, risk and compliance rather than technical analysis, CISM or CISSP matter, but CISSP specifically requires five years of paid experience in the field to hold the full certification — you can sit the exam earlier and hold "Associate of ISC2" status while you accrue the time, but you cannot use it to skip the time.

There's no licensing body for cyber security analyst the way there is for, say, an electrician or a financial adviser. Nobody can strike you off. That's a double-edged fact: it means the route isn't gatekept by a single exam, but it also means certificates alone don't prove much, because there's no shortage of people who've passed one and can't yet do the job. Employers know this, which is why certifications get you screened in for an interview more often than they get you hired outright.

A home lab counts more than most people expect. Standing up a small network in VirtualBox or Proxmox, deliberately misconfiguring it, then finding and logging what you broke — that's evidence of the actual habit of mind the job needs, and it's something you can point to in an application that a general IT background alone doesn't give you.

What your application has to overcome

The application from a career changer has two problems, and they're different problems requiring different fixes.

The first is the screening filter. A lot of junior security postings are written with "1-2 years SOC experience" or "security clearance eligible" in the first paragraph, and applicant tracking systems or a bored recruiter will screen on that literally. If your CV doesn't contain the words that match the advert — SIEM, incident response, vulnerability scanning, whatever the specific listing names — you may never reach a human who'd have read past it. This is a real mechanism, not a myth, though how strictly any given system applies it varies and nobody outside the vendor can tell you exactly how a specific tool weights a specific term.

The second is the actual doubt in the hiring manager's head: can this person tell a real incident from noise under time pressure. Nothing on a CV proves that except evidence of having done it, even in miniature. This is why the home lab, the Capture The Flag platforms (TryHackMe, HackTheBox), and any incident write-up you can produce matter more here than in most career changes — they're the closest thing to a work sample you can generate before anyone will give you the job to get the work sample from.

The practical fix: put your security-relevant experience and tools in the first third of the CV, not buried under your previous job titles. If you spent five years as a sysadmin, lead with the firewall rules you wrote and the access reviews you ran, not with "responsible for maintaining servers." Name the specific tools from the advert if you've genuinely used them, and don't claim ones you haven't — a technical interview for this role usually includes a scenario or a tool-specific question, and it surfaces gaps quickly.

Expect a technical screen even for junior roles: log excerpts to interpret, a scenario ("a user reports their laptop is running slowly and antivirus flagged something, what do you check first"), sometimes a written incident report exercise. This is one of the more testable entry-level tech jobs, and that cuts both ways — harder to fake, but also harder to be rejected from for reasons you'll never know, because the test is in front of you rather than hidden in a filter.

How long it actually takes, honestly

From a standing start with no IT background: expect a year or more before you're a credible junior candidate, and that's if you're studying and lab-building consistently alongside whatever you're doing now. Security+ typically takes a few months of part-time study to sit properly. Building enough hands-on evidence to survive a technical screen takes longer than passing the exam does — the certification is the fast part, the lab hours are the slow part.

From an IT background (helpdesk, sysadmin, network support): six months to a year is a more realistic range for becoming genuinely competitive for junior SOC or analyst roles, because you're not starting the underlying technical knowledge from zero. Some people move sideways into a security-adjacent role at their current employer, which is usually the shortest path of all, because it avoids the CV-screening problem entirely — you're already inside, and someone already trusts you with access.

From an unrelated field: be honest with yourself that a year is optimistic, and eighteen months to two years is common if you're building both the IT foundation and the security layer on top of it, part-time, around an existing job. This isn't a discouragement so much as a scheduling fact — the people who move fastest usually have a specific reason to (redundancy, a course with a fixed end date, a manager willing to sponsor a lateral move) rather than an open-ended "some day".

The route is not closed. It is genuinely open to career changers in a way some technical fields aren't, partly because the industry has a recognised shortage of junior-to-mid analysts and partly because there's no single licensing gate to pass through. But it is not fast, and nothing on this page will make it fast. What varies is whether you spend the year doing things that produce evidence — a lab, a write-up, a certification tied to a specific target role — or spend it reading about the field without building anything a hiring manager can look at.

What to do next

Pick one specialism to aim at first — SOC analyst, GRC, or pentest track — because the certifications, the language in your CV, and the interview questions differ by which one you're chasing, and "cyber security" as an undifferentiated target makes it harder to write a focused application. Sit Security+ if you haven't already, build a home lab you can describe in one paragraph and defend in an interview, and rewrite your CV so the security-relevant work is in the first third of the page, matched to the actual words in the advert you're applying to.

If the bottleneck for you right now is finding roles that genuinely fit what you already have rather than what the advert assumes a "cyber security analyst" background looks like, jobmarket.pro reads the full advert against your actual profile and tells you where the fit is real and where it isn't, before it prepares anything.

Or stop doing this by hand

An agent that reads each advert in full, tells you where you fit and where you do not, and prepares the application from a profile it cannot invent experience into. Free to start, no card.