The Hacker's Cache

#81 The Harsh Reality of Getting Hired in Cybersecurity

Kyser Clark - Cybersecurity Season 3 Episode 82

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 36:45

The cybersecurity job market is more competitive than ever, even for experienced and highly certified professionals. In this episode of The Hacker’s Cache, I share the harsh reality of getting hired in cybersecurity, why breaking into penetration testing has become so difficult, and what employers expect from candidates entering offensive security roles. I also explain what companies charge for penetration tests, what new pentesters should expect on the job, which cybersecurity certifications were actually worth earning, and whether certifications provide more career value than a cybersecurity degree. If you are trying to land a cybersecurity job, transition into a new security role, or decide where to invest your time and money, this episode provides an honest look at the challenges, expectations, and career decisions professionals face in the current market.

Connect
---------------------------------------------------
https://www.KyserClark.com
https://www.KyserClark.com/Newsletter
https://youtube.com/KyserClark
https://www.linkedin.com/in/KyserClark
https://www.twitter.com/KyserClark
https://www.instagram/KyserClark
https://facebook.com/CyberKyser
https://twitch.tv/KyserClark_Cybersecurity
https://www.tiktok.com/@kyserclark
https://discord.gg/ZPQYdBV9YY


Music by Karl Casey @ White Bat Audio

Attention Listeners: This content is strictly for educational purposes, emphasizing ETHICAL and LEGAL hacking only. I do not, and will NEVER, condone the act of illegally hacking into computer systems and networks for any reason. My goal is to foster cybersecurity awareness and responsible digital behavior. Please behave responsibly and adhere to legal and ethical standards in your use of this information.

Opinions are my own and may not represent the positions of my employer.

Hello, hello, welcome to the Hacker's Cache, a show that decrypts the secrets of cybersecurity one byte at a time. I'm your host, Kyser Clark. And in this episode, I have another Q&A episode for you, where you, the viewer slash listener, ask questions, and I answer them here on the Hacker's Cache podcast.

 

Before we get into the questions, I do want to say that DEF CON has basically begun. So when this video releases, when this audio releases, DEF CON's literally the next day. So I'm actually, at the time of this recording, en route to DEF CON.

 

And I just want to say, hey, I'm going to be at DEF CON. So if you are going to be at DEF CON, hit me up and feel free to meet with me. I'd love to chat with you, love to meet with you.

 

So if you're at DEF CON, definitely don't be afraid to say hi. I look forward to meeting as many of you as I possibly can. With that out of the way, let's go ahead and get into the questions.

 

Question number one, what do companies charge for a pen test? Would be a great topic to explore. Also, what is a typical day in the life of a newly joined pen tester? And then a senior joining a new company. Would love to know your insights into these alien worlds.

 

Good question. So for those who don't know, I was a pen tester for about two years. I spent about four months at an intern company.

 

Well, it wasn't an intern company. It was a full-fledged pen test role. But I was interning there because I was doing the DOD skill bridge, which basically means I was getting paid by the Air Force and still working in a civilian job.

 

But it was a full-fledged pen test organization. And I also spent my first job out of the military was a full-time penetration testing position. And I was a mid-level penetration tester.

 

So I have a lot of insights here for you. So first and foremost, what does companies charge for pen test? This is a tricky question because it definitely just depends, right? It depends on the company and also depends on the scope of the work. So the more work you do, the more it's going to cost the client.

 

But typically speaking, in my professional experience, I've seen pen tests being sold from $10,000 to $30,000. On average, it's going to be about $15,000, I would say, for a proper pen test. Now, you can get them way cheaper than that.

 

But if you get them under $10,000, it's probably going to be a vulnerability scan. And that's it and not a proper manual pen test. So keep that in mind.

 

A proper manual pen test is going to be at least $10,000, only for like a week's worth of work. So typically speaking, it's about $12,000 to $15,000. But they can go all the way up to $30,000, just depending on the scope and how many pen testers you have on the job.

 

But I would say for a week's worth of work for one pen tester, I would say, on average, $12,000 to $15,000. And so a newly joined pen tester, so if you're a brand new pen tester, so I have experience being an intern. I also have experience being a mid-level professional.

 

So as an intern, there's a little bit more hand-holding, right? I was basically under the guidance of a senior pen tester. And they basically gave me a lot of guidance on how to do this pen test and all this stuff. And then it wasn't like hand-holding every step of the way.

 

I would have a couple of touch points throughout the day, like maybe one or two meetings a day. And just to see how I was doing, a couple of pings over Slack, just see how I was doing. And I could ask any questions throughout the day.

 

And I would get my questions answered and go from there. But it was a little micromanaging, if I'm honest. They would always ask me, like, hey, where's your notes on this? Where's your notes on this? Where's your notes on this? Because we used a Microsoft OneNote, and anybody could see my notes.

 

So the senior pen testers would go in and note my notes and see what I'm writing. And then they'd be like, hey, you didn't write enough about this here. You didn't write enough about this here.

 

And that was a little aggravating, if I'm honest. So if you're a new pen tester, you can expect to be handheld a little bit. And this is why there isn't that many junior pen testing positions available, guys.

 

And keep in mind, like, as an intern, I wasn't getting paid by this company. And that was pretty much the only reason how they would get an internship was because as I was transitioning out of the military, I was still getting my military pay. Technically, I was still active duty.

 

But I was transitioning out. And the whole point of the DoD skill bridge is to help service members transition into civilian roles. So I was working in a civilian role, but getting paid by the United States Air Force.

 

And this company, this pen test firm, wasn't paying me a penny of all my money I was getting from the Air Force. So that was the only way I could get an internship. I would imagine there's not many internships like that.

 

I pretty much created my own internship. I was coming out of the military, and I was applying for pen testing positions. And I would go into interviews, and the question of when can you start or when are you looking to start usually comes up.

 

And if it doesn't, then I would, when they give me time to ask questions, I would pitch this to them. And I would introduce them to the DoD skill bridge. And I would pitch something like this.

 

I'm like, hey, you're looking for someone to fill this role. And with the DoD skill bridge, you're not going to have to pay me. You don't have to give me any kind of benefits.

 

And it's essentially a free trial run of me for four months, four to six months. And if you like me, then you can bring me on full time. If not, then we can just part ways, no harm, no foul, because I'm not in your company, technically.

 

And you don't have to pay me. You're essentially getting me for free. Now, it's not free for them, because they do have to take time out of their day to onboard you and get your account set up and train you and all this stuff.

 

But it is time consuming then. But it's significantly cheaper than bringing a new person. So that's how I was able to get my internship.

 

And like I said, I had to make my own. They did not exist. They did not exist.

 

And like I said, I just applied to every pentesting position I could. And then I just told every company that I interviewed with, hey, I'm trying to do an internship, because that's what I have to do. Um, well, I don't have to do it, but that's what I want to do.

 

Coming out of military, I want to use my last four to six months doing the DVD Skill Bridge program. And it worked out eventually. But I did get a lot of denies, because a lot of companies were like, I have no idea what this is, or like, this is too much paperwork, which is really not that much paperwork, if I'm honest.

 

So it was just a way for them to like opt out of it, or it was just an unfamiliar thing to them. So they would just deny me for that. But one company did take chance on me.

 

Shout out to that company, if you're listening. Really do appreciate that was very, very valuable experience, even though I didn't get hired to that company full time, just because I ended up going to a different company due to my choice. They probably would have hired me full time if I wanted to work there.

 

But I just had a better opportunity somewhere else. So that was kind of how it's like being an intern. Now, as a junior pentester, I imagine it's going to be pretty similar.

 

But as a junior pentester, you can expect to be paid. So there's that. And yeah, I would expect a little handholding.

 

But if for any like mid-level and especially senior pentesters, that's a totally different thing. If you get hired into a company as a mid-level professional, you are expected to know what you're doing day one. So when I got done with my internship, I found my full time pentesting position as a mid-level penetration tester.

 

And I had one week of onboarding. And then literally week number two, I was doing a penetration test by myself without any assistance. Of course, I could pick the team with any questions I had.

 

But I was expected to go in and deliver that. But at the same time, they knew I was experienced because they knew I had four months of that internship. So it just depends on your experience level.

 

And, you know, different players are going to be different, obviously. So my current role, I've been working there for I'm starting my third week now, and I'm getting a little handheld here a little bit. I'm not going to lie, like, because they know I don't have any cloud security experience.

 

And now I came from office security background. And they know, you know, they know I know the fundamentals of cybersecurity, but they know I don't know, like, the specifics of being an MSP and cloud security specifically. So they're kind of like teaching me, like, the processes that they do specifically for these companies at this company.

 

So even though I am a mid-level professional, I am getting handheld a little bit in this role. But in penetration testing, you can expect a company to not want to train you or really show you much. They're going to expect you to hit the ground running very quickly unless you have it unless you get an internship like me or maybe a junior level pentesting position.

 

Junior pentesting positions are pretty much non-existent because AI can pretty much do the work of a junior pentester now. And even when I was coming out of the military, there was no junior pentesting positions. And you just you're most of the penetrating testing positions are you're expected to be at a senior level.

 

And this is going to tie well into the next question. But essentially, one of the big reasons why I'm not a penetration tester anymore is because even with two years of experience, that's still not enough, unfortunately, to get a pentesting position. I was denied by several penetration testing positions because I didn't have enough experience, even though I have the certs, the education, the experience.

 

I had two years experience, but they're really looking for two to five years experience. So how do you break into penetration testing? Man, I got pretty lucky on the military, if I'm honest. But the job market was a lot different back then.

 

I would say if you're in a penetration testing position, you need to do everything you can to keep that position if you want to remain a penetration tester. Because if you're under that five year experience mark and you start trying to switch roles, like it's probably not going to happen for you because everyone's looking for at least five years experience and penetration testing. It's incredibly difficult to get a penetration testing position these days.

 

And that's why I would recommend doing something on the blue team. And that's essentially why I'm in a blue team position now. That goes into the next question.

 

Congrats with your new job. So it involves consulting and it is an MSP. Did you want to avoid that? That is an excellent question.

 

So I did say I was tired of consulting because that was one of my pain points that I talked about with my last role and why I ended up ultimately getting out of that position and why I got burned out. And MSP, best managed service provider, for those that don't know, that's where you're working with multiple clients. So I did say I wanted to avoid that.

 

So why did I go into that position? And I also had someone DM me, hey, why did you choose cloud security? Why did you choose to go into cloud security? So because I've been asked this twice, like why did you pick this role specifically? I figured I'd throw it on the podcast for you guys. So why did I choose to become a cloud security engineer at a managed service provider and be a consultant again? And the answer is it's really the only position that was offered to me. So I applied to 200 plus positions.

 

I've done interviews with dozens of companies. I had, I made it to the third round with three or four different companies, but ultimately they all ended up rejecting me. And it was the only job offer I had.

 

And that's really the reason why I chose to go in this particular position. It was the only offer I had. It wasn't my first choice.

 

It wasn't my, this isn't my dream job, if I'm honest. It wasn't my first choice. And honestly, I wasn't even that excited when I accepted it, but I was pretty much forced to accept the role because it was my only option and I had bills to pay.

 

So I have, I had to take something, right? I couldn't hold out. So that's the real reason. I did apply to all kinds of positions, penetration testing positions, cloud security positions, AI engineering positions, AI security positions, cyber investigator positions.

 

I made it to a third round interview with them, which surprisingly somehow I didn't expect to be at the right interview with it for a cyber investigator position. That was a really interesting position that I didn't even know existed, if I'm honest. Essentially, it was like reviewing chat logs with AI and seeing if people were using AI maliciously or not, essentially is what it was, which was really interesting, but didn't get that position.

 

Granted, that was for a principal position as well. I might've gotten if I would have applied for the junior position, but I got this role and I'm like, I'm not even applying anymore. So that's the real reason, but I'm glad I got the position that I did because man, I'm learning a lot.

 

Like I said, I'm on my third week at the company and I am learning so much because this is new territory for me. I've never been a cloud security engineer. I've never worked at MSP and I don't really have proper blue team experience.

 

All my experience was cyber defense operations in the United States Air Force. Yes, that is technically cyber defense, but that was more IT, more system administration, more help desk with like security built in rather than a full-fledged security role. And being in a full-fledged cyber security role and a blue team position is a pretty new thing for me.

 

And I'm glad that it worked out the way it did because I was hesitant to accept that position because it wasn't my first choice, but it was my only choice. So I was kind of forced to do it. And the job market is that bad guys, by the way.

 

I mean, cause I am experienced. I'm credentialed. I have my degrees.

 

I have my education. I have my CTFs, hack the box, try to hack me. Like I've done pretty much everything you can do in terms of like leveling up.

 

And I only had one position offered to me. So the job market is incredibly difficult guys. So if you're just getting started, man, I don't know.

 

I don't know, really know what to tell you. Like just keep trying, I guess. Hopefully it gets better, keep leveling up.

 

And I mean, you really need to put in your time. You really need to put in your effort. You really need to learn this stuff because even someone who has a lot of experience still gets rejected a lot.

 

So if you have, if you're just getting started, then I can imagine it's even worse than you cause at least I was getting interviews like left and right. But yeah, I know. I know a lot of you guys are getting rejected left and right, not even getting interviews.

 

So it's a tough job market. Hopefully it gets better. I don't know where the job market is going to go.

 

I hope it gets better, but I also wouldn't be surprised if it got worse because I do believe AI is taking those entry-level rules. But yeah, like I said, cloud security engineer, super excited of learning a lot of new technologies I've never worked with before. And just being a defender rather than an attacker and offense security professional.

 

So it is nice to see this side of cybersecurity. And one thing that I have already started seeing is some cyber incidents, like some actual breaches, some account takeovers. So that's really cool to see that.

 

Cause I never got to see that as a pen tester. So that's really interesting. I actually do seeing real world cyber attacks.

 

So that's really interesting for me to see firsthand. And I've never been able to experience that because when I was in United States Air Force, that network is so secure that we never really had. I mean, there was some incidents, but it was like self-induced incidents, if that makes sense.

 

Like people on the network, like authorized users on the network, were doing bad things or not. I won't say bad things, but like they weren't doing things properly, if that makes sense. Like there was incidents like, with data protection and stuff like that.

 

Anyways, super glad I got it. Wasn't my first choice, that's why I'm there. But I guess everything happens for a reason and this is, it's definitely a learning opportunity for me.

 

I'm excited for that. It's gonna help me grow in my position or my career and help me get those blue team skills that I haven't really been working on the past seven years. So really nice.

 

So yeah, that kind of ties in with the last question with like, I did apply for pen testing positions, but they all declined me. So even with someone with two years of pen test experience with several penetration testing certifications, like it's just hard to become a pen tester. I would not advise trying to become a pen tester.

 

Right when I was coming out of the military, it was penetration test or a bust. Like I was only applying for penetration testing positions because that's what I wanted to do. And I wouldn't accept any other role.

 

So I only applied for pen testing roles and eventually got it and eventually worked out. But after a year and a half of doing that job, I just, I honestly, I hated it. Like I really didn't like it anymore and that's what really burned me out and really hurt me.

 

It hurt me like, in a sense that like, this was supposed to be my dream job. And it's like, wow, this isn't my dream job. And it like, it threw me, like it confused me so much.

 

And that's why I had to take a break from cybersecurity for several months. So I'm in this new role, very excited about it. And like I said, I'm learning a lot.

 

So job market's not looking good guys. Still, and it seems like it's getting worse and worse. So it was bad when I was coming out of the military, it's even worse now.

 

I'm more, I have more credentials. I have an extra degree and I have more experience. But yeah, I got less interviews with this job search than I did my first job search coming out of the military.

 

So like, that just tells you that the market is just not as good as it was. And it's just declining over time, it seems like. So I don't know, is it going to recover? Is it going to get better? Time will tell.

 

All right, next question. Great video. Since you have 19 certs, I have to ask, obviously, OSCP and CISP are must-haves.

 

But out of the rest, which ones do you feel you didn't really need? And which ones are you glad you got? This is an interesting question. So this is basically asking like, hey, what certifications did you get that you don't think you really needed? And to answer the question, in short, like every certification I got for a reason, and I'm glad I got every single one of them. But however, there are some that I was like, I didn't really need.

 

So I would say the first one would probably be the CCNA. I always talk about how like, the Network Plus would have been good enough for a pentesting position. Because I haven't touched a Cisco firewall or switch in my career.

 

And even in my current role, we don't use Cisco firewalls and switches. We use a different brand's firewalls. So CCNA was a little overkill, if I'm honest.

 

So that was one I didn't really need. I'm glad I got it because it forced me to really understand networking because it is a harder networking certification than the Network Plus. So in essence, I am glad I got it.

 

And it's going to help me land other features, cybersecurity engineer roles in the future because CCNA is a good one for cybersecurity engineers. And that's kind of the direction I'm going in right now. Like I got cloud security engineer and eventually I can see myself becoming a cybersecurity engineer at my current company or even another company.

 

So it's going to come in handy. So that's probably the one I didn't need the most, but I'm very glad I got it. And that's a very hard certification.

 

By the way, I did fail that my first time. I don't fail certs often, but that was one of the ones I did fail. Other ones I didn't really need.

 

I did let the EJPT expire. That's the E-Learn Security. Well, it used to be E-Learn Security.

 

It's now INE Security Junior Penetration Toucher. I did let that one expire, but it was worth getting because that training really helped me out. And it was a building block to get the OSCP, the Office X Certified Professional.

 

So without that, the OSCP would have been much more difficult. So I don't want to say it wasn't needed as a credential, but the training was extremely valuable. But the credential itself, not needed.

 

But the training, absolutely essential to help me bridge the gap between CompTIA, Pentest Plus and OSCP because that is a very large gap. And I thought the INE Security Junior Penetration Toucher bridged that gap very well. Now, at the time I got the EJPT, the TCM Security PJPT, that's a Practical Junior Penetration Toucher, that certification did not exist.

 

So my current advice would be to, if you're in that role, like in that position, like between CompTIA, Pentest Plus and OSCP or the Hack-to-Box CPTS or the TCM PJPT. So those are like the main three. Like if you're going out for one of those mid-level penetration testing certifications, again, that's the OSCP TCM PMPT, Practical Network Penetration Tester.

 

And then the Hack-to-Box CPTS, Certified Penetration Testing Specialist. Those are like the big three in terms of mid-level penetration testing certifications. And I think the TCM Security PJPT, Practical Junior Penetration Tester is better than the INE Security Junior Penetration Tester, the EJPT.

 

And the main reason for that is because the practical, these TCM Security Practical Junior Penetration Tester is more practical. The Junior Penetration Tester from INE Security, the EJPT, that has vulnerable choice certifications and that certification actually expires. Like it actually expires.

 

Like I said, I let it expire. The TCM Security certifications do not expire. I'm a huge fan of certs that don't expire because the certification companies, they just want to charge you every year, like just to renew your certifications.

 

It costs a lot of money to renew your cert. If you have a lot of certifications, it costs a lot of money per year to renew these things. So having as many certifications as I do, I value certifications that don't expire because they're not nickel and diming me every year.

 

Like the ISSP, I got to spend $150 a year on. CompTIA certifications, I had to spend $50 a year on. So it adds up.

 

So I like certs that don't expire. And that's why I would go for the TCM over the INE Security cert. Of other certs I don't really need.

 

Honestly, at the time, I didn't really need the TrihackMe SAL-1 because that's a straight up SOC Analyst Level 1 certification. And when I was a Penetration Tester, clearly didn't need it. But it helped me transition from Penetration Tester to Cloud Security Engineer and to a Blue Team position that has a little bit of SOC Analyst type work involved with it.

 

Some investigating stuff involved with it. So that certification absolutely came in handy. Now granted, I didn't even study for that.

 

I just took the exam. But that exam was pretty practical, believe it or not. And it was fairly real world.

 

So you never really know. These certifications, sometimes it doesn't feel like it's worth getting, but it could help you make a transition down the road. That you don't even know about.

 

So that's a good example of that one as well. Honestly, every certification has really helped me out. Like all my pen testing certs, obviously I've been in pen testing roles.

 

Some TIA certifications, some people think they're a waste. But I mean, getting the book smarts is just as valuable, guys. Like you gotta be able to understand the theory behind the hands-on keyboard stuff as well.

 

Because when you're in these interviews, guys, they're going to ask you questions that you have to pull out of your head. And that's where the memorization, people dog CompTIA, because like, oh, you have to memorize all these facts and memorize all these things. And while they aren't that practical, like in interviews, you do have to pull the information out of your head.

 

Like you don't get a cheat sheet. You don't get notes. Like you can't look at your notes during these interviews, guys.

 

So that's where CompTIA, CompTIA certifications are good to help you prepare for interviews, if I'm honest with you. And I mean, if I had to pick one, maybe the Linux Plus, because like as a credential, I didn't need it. But again, the training was so valuable because I use Linux every day.

 

Well, I was using Linux every day as a pen toucher. Now I haven't touched Linux in my current role. We'll see how far, how long that lasts.

 

I'd imagine I'll get back on a Linux box eventually. But Linux is a valuable skill to have. And if it wasn't for the Linux Plus training, then I wouldn't learn Linux as thoroughly as I did.

 

Again, that credential is not that needed, but learning Linux is an essential skill. You can learn Linux in other ways. You don't need to get the certification.

 

Other than that, like I said, there's a reason all my certifications have a valid reason. Like these all take an incredible amount of time to get, a lot of effort to obtain, and even money, right? You gotta pay for the training, you gotta pay for the vouchers. And there's a huge investment in terms of money and time and effort.

 

And when you choose a certification, like there's a very, there's gotta be a valid reason to do it. Because they're not easy either. They're not, they're not easy.

 

Now, sometimes they are a little easy if you have as much experience in certification as I do. Sometimes they are a little easy, but for the most part, every certification that I have is truly worth it. Like there's a very, there's a valid reason for me to go after it.

 

And they've all helped me in some way, shape or form. None of them were a waste of time. Not a single one of them.

 

Moving on to the next question. If I have a master's degree in a non-relevant field, do you think it's worth going back to WGU to career switch into cybersecurity? Employer is only paying $5,250 annually, so I'd be out of pocket, possibly one semester, two at most. I honestly feel like I benefit more from just doing certs and hack the box, but can't shake the fact that employers may overlook me over someone with everything.

 

Man, this is a very valid question. And I'm going to help you out here because I do have a master's degree in cybersecurity. And let me tell you what, I don't think it really helped me open, I don't think it opened up that many doors for me, if I'm honest with you.

 

I had more interviews coming out of the military with just my bachelor's degree. Granted, I was currently pursuing my master's degree. I didn't have it finished when I was coming out of the military.

 

Finished it up within my first year, my first job. And I did use that as a bargaining chip to get a raise in my first position. So after a year, I did ask for a raise, a very significant raise.

 

How much money did I ask for, actually? I think it was about, I think I asked for about $25,000 more a year. That's a pretty significant raise. And then I ended up getting like 20,000 more.

 

So they did give it to me. But I did use the master's degree as a bargaining chip in that discussion, as well as five other certifications. So I got five certs, and I got my master's degree.

 

And obviously, I did very, very high quality work. I was getting all my penetration tests done on time. And I was doing thoroughly.

 

I got good customer reviews. And all that combined helped me get an extra $20,000 a year after I worked there for a year. Granted, that is a big jump, but I was slightly underpaid my first year working for that company.

 

So I was supposed to make like $115,000 a year. I only made like $104,000 a year because the way they did revenue share was a little weird. And I was like, hey, I was supposed to get $115,000 or at least in the ballpark of that.

 

And I'm like, 10,000 short of that. So that was one of the reasons why I was able to get a significant raise. But I did get a $20,000 raise because, and like I said, the master's degree played a part.

 

I don't know what, I would say my work, the fact that I was underpaid my first year, and the fact that I was doing high quality work and make sure I was getting all my pen tests done on time and just being really attentive and really just a go-getter at work, that really helped out probably the most. But like I said, I did use the master's degree as a bargaining chip to get that raise. But moving into my new role, the one I just obtained, I don't think the master's degree really helped me out that much.

 

If I'm honest with you, I don't think employers really care about my master's degree. I really don't, or my bachelor's degree. I don't, I mean, maybe they do.

 

It's hard to tell. It hardly ever comes up in conversation. I have had employers specifically mention that they are impressed with the amount of certifications that I have.

 

I've never had an employer be impressed with my master's degree, or at least I never said that. So it's interesting conversation. Like, is it worth it? I mean, if you're gonna get your employer to pay for it, I think you should go for it because if you're only gonna pay for two semesters, probably worth it.

 

If you don't have to go into debt, I would probably do it. If you gotta pay for it, I wouldn't do it. For me, I don't pay for my degrees.

 

I got my first degree through military tuition assistance. I got my second degree through GI Bill, and I'm currently working on my MBA and my third degree with the GI Bill as well. If it wasn't for the military tuition assistance and GI Bill, I wouldn't be pursuing education like that because I still don't really know how much it helps.

 

I think certifications definitely do help way more than degrees. But every employer is different. Some people, especially if you're an older employer, like older hiring managers, it might value the degrees more than certifications.

 

So it just depends on the employer, depends on the role. There's a lot of variables that go into it, but generally speaking... Now, I wouldn't... I would say generally speaking, certifications, in my opinion, if you get multiple ones, is more valuable than a degree. But you have to have multiple high-quality certifications.

 

It can't be low-level certifications. It can't be just one certification. You need to have multiple mid-level certifications to make it more valuable than a degree.

 

And then if you do pursue a degree, you need to ensure that you're also getting your certification. So if you just have a degree or even multiple degrees, in my opinion, you're cooked. I think certifications really are the key to success in this field.

 

I know a lot of people say they're not and you don't need them, but they've definitely helped me out a lot, actually. So that's why I'm a huge fan of certifications and why I tell people to get certifications because honestly, I feel like I've learned the most through certifications. You would be surprised that you don't really learn that much on the job because when you're on the job, you're doing the same like 20 tasks over and over again, okay? Like that's just the reality of the situation.

 

Even in a pen testing role, my last role, I'm reporting the same 100 vulnerabilities over and over and over and over and over and over. And that's one of the reasons I got burned out. And I can even see in my current role, like there's documented processes and like, yeah, you're going to get an oddball things here and there.

 

But for the most part, the work is like pretty routine and it's going to be the same 100 things that pop up. I'm certain to notice or we'll see. But you learn less on the job than you think, guys.

 

And that might be a hot take, but I've definitely learned more through self-study and certification on the side than I have on the job. Because again, back to what I was saying in that first question, employers, they want you to be an all-star day one. They don't want to teach you.

 

They don't want to train you, right? The only thing that they're going to show you is like processes that is specific to their company, to their organization. They expect you to have all the type of security knowledge already. They do.

 

So that's why certifications are so valuable. In my opinion, as someone who has 20 certifications, well, I have 19 active. I would have 20 if I didn't let AJPT expire.

 

But as someone who has passed 20 certification exams and who has a bachelor's, master's degree, I can with confidence tell you that certifications have grown my cybersecurity skills far more. Granted, every school is different. Every degree program is different.

 

In my degrees, both of them are in cybersecurity management policy. I specifically went into a non-technical thing for school because all my certs, or at least the bulk of them, are technical and I was in high technical roles. So that's another thing to consider there as well.

 

Not saying degrees can't be technical, but I specifically chose, because there was another, at my school, there was another pathway I could have went that was more technical in nature. But I chose to go with management policy because there really wasn't, I mean, there's a couple GRC-type certifications out there. But I felt like GRC was a little bit of a weakness of mine because I wanted to pursue a highly, highly technical role, which is penetration testing.

 

So that's why I chose that over a technical degree, because I already had technical experience and I already had technical, or I was pursuing technical certifications. And eventually I want to be a manager. Like in my career, like further down the road, I do want to be some type of manager.

 

So there's that. Hopefully that answers your question. If you have any other questions regarding that or anything else I said here or anything cybersecurity related at all, ask your questions.

 

And if it's a good question, I will feature on the next Q&A episode here on Hacker's Cache Podcast. Hopefully you enjoyed the show. Thank you so much for watching.

 

Thanks for listening. If you enjoyed it, rate the show five stars if you're on Spotify or Apple Podcasts or any of those other audio platforms. I know I'm on like 20 of them, but Apple Podcasts and Spotify is my main two.

 

And then if you're on YouTube, guys, hit the like button and hit the subscribe button for more cybersecurity content. Hopefully I see you at DEF CON. If you're going to DEF CON, definitely hit me up.

 

And if you see me walking around, say hi. I love to meet you guys. So that fueled my passion so much last year.

 

I'm so excited to see you guys at DEF CON. And see you around, guys. Thanks for watching.

 

Thanks for listening. Peace out. Take care.

 

Have a good one. Kyler, signing off.