Darren Saul • August 14, 2026

Cybersecurity is one of the most exciting, fast-moving and potentially rewarding areas of IT right now. It’s also one of the most misunderstood when it comes to actually building a career.
There’s a huge amount of messaging suggesting that if you complete the right certification, finish a cyber degree, build a home lab and learn a few security tools, you can walk straight into a cybersecurity role. And sometimes you can. Some people land that SOC Analyst opportunity straight out of university. Others meet the right employer at exactly the right time, secure a junior security position and never look back.
But for many people, the journey looks very different. And that’s perfectly OK.
In fact, some of the best cybersecurity careers start somewhere far less glamorous. The service desk.
You spend time troubleshooting Microsoft 365, resetting accounts, learning Active Directory and Entra ID, understanding permissions, networking, endpoints, servers and cloud infrastructure. You also discover the mysterious ability users have to break things nobody previously thought were breakable. π
It might not feel like cybersecurity at the time, but you’re building something incredibly important – context.
You’re learning how technology actually works inside a business. You see how users behave, how identities are managed, where permissions go wrong, why systems fail, how networks communicate and how seemingly small configuration mistakes can create much bigger problems.
Then perhaps you progress into L2 support, infrastructure, systems administration, networking or cloud. Gradually, security becomes part of almost everything you do. Identity, MFA, Conditional Access, endpoint security, firewalls, vulnerability management, email security, privileged access, patching and incident response.
Suddenly, you’re not just studying cybersecurity. You understand the technology you’re trying to secure.
And that foundation can be incredibly valuable.
Another misconception is that "getting into cyber" means getting one particular job, usually a SOC Analyst role. But cybersecurity is enormous. There are careers in security operations, security engineering, IAM, cloud security, governance and risk, penetration testing, vulnerability management, security architecture, incident response, threat intelligence and many other areas.
You don’t necessarily need to teleport from the service desk into a SOC. You can level up into cybersecurity.
A systems engineer working heavily with Entra ID, Conditional Access and privileged access might eventually specialise in IAM. A cloud engineer might move into cloud security. A network engineer could move towards network security. An infrastructure engineer who becomes increasingly involved in security projects could transition into security engineering.
Cybersecurity doesn’t always have to be a dramatic career change. Sometimes it’s simply the next stage of your technical career.
Certifications, degrees, home labs and courses absolutely have value. They demonstrate learning and show employers you’re serious about developing your skills. But they become far more powerful when combined with genuine hands-on experience.
If you’re trying to build a cybersecurity career and the direct route isn’t opening up yet, focus on a few things:
- Build strong IT foundations – networking, infrastructure, identity, cloud and endpoints.
- Find security inside your current role – volunteer for security projects, audits, migrations and remediation work.
- Combine certifications with practical experience – learn the theory, then find ways to actually use it.
- Build relationships with people already working in cyber – understand how they got there and what employers actually value.
- Look sideways as well as upwards – IAM, cloud security, security engineering and other areas can provide excellent transition points.
Most importantly, don’t think of time spent in support, infrastructure, networking or cloud as time wasted because you haven’t officially "made it into cyber" yet.
It could be exactly what makes you better when you do.
Cybersecurity needs people who understand security, but it also needs people who understand systems, infrastructure, cloud, networks, users and businesses. The more you understand how all those pieces fit together, the better equipped you can become to protect them.
There are multiple ways into cybersecurity. Occasionally somebody gets to skip a few steps. For everyone else, those steps aren’t necessarily obstacles.
They can become the foundations of a fantastic career.
So don’t become obsessed with getting into cybersecurity as quickly as possible.
Become obsessed with building a cybersecurity career that will last. π
Want more FREE content around building culture and hiring? π https://jmp.sh/Blgq4f8A
Want more FREE content around career development and job seeking? π https://jmp.sh/gla70YWp
Some great videos here as well π https://www.youtube.com/playlist?list=PLWCIjFeFwvnmiULvInFNx2IkTuwtYxqsy
