Featured Jobs
Latest Blogs & Articles

Cybersecurity is one of the most exciting, fast-moving and potentially rewarding areas of IT right now. It’s also one of the most misunderstood when it comes to actually building a career. There’s a huge amount of messaging suggesting that if you complete the right certification, finish a cyber degree, build a home lab and learn a few security tools, you can walk straight into a cybersecurity role. And sometimes you can. Some people land that SOC Analyst opportunity straight out of university. Others meet the right employer at exactly the right time, secure a junior security position and never look back. But for many people, the journey looks very different. And that’s perfectly OK. In fact, some of the best cybersecurity careers start somewhere far less glamorous. The service desk. You spend time troubleshooting Microsoft 365, resetting accounts, learning Active Directory and Entra ID, understanding permissions, networking, endpoints, servers and cloud infrastructure. You also discover the mysterious ability users have to break things nobody previously thought were breakable. 😄 It might not feel like cybersecurity at the time, but you’re building something incredibly important – context . You’re learning how technology actually works inside a business. You see how users behave, how identities are managed, where permissions go wrong, why systems fail, how networks communicate and how seemingly small configuration mistakes can create much bigger problems. Then perhaps you progress into L2 support, infrastructure, systems administration, networking or cloud. Gradually, security becomes part of almost everything you do. Identity, MFA, Conditional Access, endpoint security, firewalls, vulnerability management, email security, privileged access, patching and incident response. Suddenly, you’re not just studying cybersecurity. You understand the technology you’re trying to secure. And that foundation can be incredibly valuable. Another misconception is that "getting into cyber" means getting one particular job, usually a SOC Analyst role. But cybersecurity is enormous. There are careers in security operations, security engineering, IAM, cloud security, governance and risk, penetration testing, vulnerability management, security architecture, incident response, threat intelligence and many other areas. You don’t necessarily need to teleport from the service desk into a SOC. You can level up into cybersecurity. A systems engineer working heavily with Entra ID, Conditional Access and privileged access might eventually specialise in IAM. A cloud engineer might move into cloud security. A network engineer could move towards network security. An infrastructure engineer who becomes increasingly involved in security projects could transition into security engineering. Cybersecurity doesn’t always have to be a dramatic career change. Sometimes it’s simply the next stage of your technical career. Certifications, degrees, home labs and courses absolutely have value. They demonstrate learning and show employers you’re serious about developing your skills. But they become far more powerful when combined with genuine hands-on experience. If you’re trying to build a cybersecurity career and the direct route isn’t opening up yet, focus on a few things: Build strong IT foundations – networking, infrastructure, identity, cloud and endpoints. Find security inside your current role – volunteer for security projects, audits, migrations and remediation work. Combine certifications with practical experience – learn the theory, then find ways to actually use it. Build relationships with people already working in cyber – understand how they got there and what employers actually value. Look sideways as well as upwards – IAM, cloud security, security engineering and other areas can provide excellent transition points. Most importantly, don’t think of time spent in support, infrastructure, networking or cloud as time wasted because you haven’t officially "made it into cyber" yet. It could be exactly what makes you better when you do. Cybersecurity needs people who understand security, but it also needs people who understand systems, infrastructure, cloud, networks, users and businesses. The more you understand how all those pieces fit together, the better equipped you can become to protect them. There are multiple ways into cybersecurity. Occasionally somebody gets to skip a few steps. For everyone else, those steps aren’t necessarily obstacles. They can become the foundations of a fantastic career. So don’t become obsessed with getting into cybersecurity as quickly as possible. Become obsessed with building a cybersecurity career that will last. 🔐 Want more FREE content around building culture and hiring? 👉 https://jmp.sh/Blgq4f8A Want more FREE content around career development and job seeking? 👉 https://jmp.sh/gla70YWp Some great videos here as well 👉 https://www.youtube.com/playlist?list=PLWCIjFeFwvnmiULvInFNx2IkTuwtYxqsy

One of the questions I get asked most often by engineers is, "Which certification should I do next?" The answer is usually the same. It depends on where you are in your career. Too many people collect certifications because they look impressive on LinkedIn. The best engineers use certifications to build practical skills that solve real business problems. MSPs and MSSPs are evolving rapidly. Cloud, identity, automation, cybersecurity and AI are reshaping the services clients expect. The engineers who continue investing in the right skills will have the greatest opportunities over the next five years. Here's where I believe your focus should be. Junior Engineers (0–2 Years) At this stage, the goal isn't to become an expert. It's to build a solid technical foundation while demonstrating that you're committed to learning. Some of the most valuable certifications include: Microsoft Certified: Azure Fundamentals (AZ-900) Microsoft 365 Fundamentals (MS-900) Microsoft Security, Compliance & Identity Fundamentals (SC-900) CompTIA Network+ ITIL Foundation Cisco Certified Support Technician (CCST) Networking These certifications introduce cloud computing, networking, Microsoft technologies and IT service management. More importantly, they help junior engineers understand how modern MSPs operate. Intermediate Engineers (2–5 Years) This is where careers often accelerate. Clients expect engineers to solve problems independently, deliver projects and provide technical advice. Certifications should now deepen technical capability rather than simply demonstrate awareness. I'd recommend focusing on: Microsoft Azure Administrator (AZ-104) Microsoft Endpoint Administrator (MD-102) Microsoft Identity and Access Administrator (SC-300) Microsoft Information Protection Administrator (SC-400) Cisco CCNA CompTIA Security+ VMware VCP Fortinet NSE certifications Veeam VMCE These certifications align closely with what many MSPs and MSSPs are delivering every day, including Microsoft 365, Azure, networking, endpoint management, backup and cybersecurity. Senior Engineers & Technical Leaders (5+ Years) Senior engineers are expected to design solutions, mentor teams and advise clients strategically. At this level, certifications should reflect architecture, security and leadership. Some of the strongest options include: Microsoft Azure Solutions Architect Expert (AZ-305) Microsoft Cybersecurity Architect Expert (SC-100) Microsoft DevOps Engineer Expert (AZ-400) Certified Information Systems Security Professional (CISSP) Certified Cloud Security Professional (CCSP) Palo Alto Networks Certified Network Security Engineer Cisco CCNP Enterprise AWS Solutions Architect Professional Microsoft Fabric Analytics Engineer (where data projects are becoming part of managed services) These certifications prepare engineers to lead complex cloud migrations, security transformations and strategic client engagements. Don't Chase Every Badge One mistake I see regularly is engineers collecting certifications that don't align with the work they actually want to do. Instead, ask yourself: What problems do I want to solve? What projects do I want to lead? What role do I want in three years? Your certification roadmap should support those answers. The Skills That Matter Most The best engineers I've placed don't always have all the certifications. And my clients still fight over them. They hire people who can communicate with customers, simplify complex technology, document their work, collaborate with teammates and genuinely enjoy solving problems. Technical certifications might get you the interview. Your attitude, curiosity and ability to deliver outcomes are what build a long-term career. Invest in both, and you'll always be in demand. Want more FREE content around building culture and hiring? 👉 https://jmp.sh/Blgq4f8A Want more FREE content around career development and job seeking? 👉 https://jmp.sh/gla70YWp Some great videos here as well 👉 https://www.youtube.com/playlist?list=PLWCIjFeFwvnmiULvInFNx2IkTuwtYxqsy

When most businesses think about cybersecurity, their first instinct is to invest in more technology. A new firewall. A more advanced EDR platform. A better email security solution. An AI-powered SOC. Those investments absolutely matter, but they often overlook the biggest vulnerability in almost every organisation - people. After years of working with the MSP and MSSP market, I've noticed something interesting. The organisations with the strongest security posture aren't always the ones with the biggest technology budgets. They're the ones that have built a security-first culture where every employee understands their role in protecting the business. They recognise that cybersecurity isn't just an IT responsibility - it's a business responsibility. Think about how many breaches still begin with something surprisingly simple. Someone clicks a phishing email. A password gets reused. Multi-factor authentication is ignored. Sensitive data is shared without thinking. An employee grants access to someone they shouldn't. In most cases, the technology didn't fail. Human behaviour created the opportunity. That's why the role of an MSSP is changing. It's no longer enough to deploy security tools and respond to alerts. The most valuable MSSPs help clients build a security culture where every employee understands that cybersecurity is part of their job. They educate, challenge assumptions, improve processes and encourage behaviours that reduce risk long before an attack occurs. The real value isn't simply detecting threats - it's helping businesses create fewer opportunities for attackers in the first place. The businesses getting cybersecurity right understand that technology alone isn't enough. They create environments where people feel comfortable reporting suspicious emails, admitting mistakes and asking questions without fear of blame. They know that a well-informed employee can be just as valuable as the latest security platform because awareness and good decision-making prevent incidents before they ever reach the SOC. If you want to strengthen your organisation's security posture, it's worth asking a few important questions: - Is cybersecurity discussed outside the IT team? - Are employees regularly educated, or just once a year? - Do leaders model good security behaviours themselves? - Are people encouraged to report mistakes quickly without fear? - Are we investing in our people as much as we're investing in technology? Technology will continue to evolve. Attackers certainly will. But the organisations that will stay ahead are the ones that understand cybersecurity is ultimately about people. When every employee understands their role in protecting the business, security stops being another compliance exercise and becomes part of the company's culture. And that's something no software alone can ever replace. Want more FREE content around building culture and hiring? 👉 https://jmp.sh/Blgq4f8A Want more FREE content around career development and job seeking? 👉 https://jmp.sh/gla70YWp Some great videos here as well 👉 https://www.youtube.com/playlist?list=PLWCIjFeFwvnmiULvInFNx2IkTuwtYxqsy



