The Hacker's Cache
The show that decrypts the secrets of offensive cybersecurity, one byte at a time. Every week I invite you into the world of ethical hacking by interviewing leading offensive security practitioners. If you are a penetration tester, bug bounty hunter, red teamer, or blue teamer who wants to better understand the modern hacker mindset, whether you are new or experienced, this show is for you.
The Hacker's Cache
#84 More Cybersecurity Certifications Won’t Fix Your Career
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
More cybersecurity certifications will not automatically fix your career, raise your salary, or create the opportunities you want. In this episode of The Hacker’s Cache, Kyser Clark shares why he is slowing down after years of nonstop upskilling, pursuing certifications, and pushing toward bigger cybersecurity roles. He breaks down what actually moves the needle in cybersecurity careers: relevant hands-on experience, protecting yourself from burnout, understanding how employers evaluate resumes, and building a sustainable career instead of endlessly chasing the next credential. Whether you are trying to break into cybersecurity, land your first pentesting or cloud security role, or avoid burnout as an experienced professional, this episode offers an honest look at certifications, career growth, salary, job titles, and long-term success in cybersecurity.
Connect
---------------------------------------------------
https://www.KyserClark.com
https://www.KyserClark.com/Newsletter
https://youtube.com/KyserClark
https://www.linkedin.com/in/KyserClark
https://www.twitter.com/KyserClark
https://www.instagram/KyserClark
https://facebook.com/CyberKyser
https://twitch.tv/KyserClark_Cybersecurity
https://www.tiktok.com/@kyserclark
https://discord.gg/ZPQYdBV9YY
Music by Karl Casey @ White Bat Audio
Attention Listeners: This content is strictly for educational purposes, emphasizing ETHICAL and LEGAL hacking only. I do not, and will NEVER, condone the act of illegally hacking into computer systems and networks for any reason. My goal is to foster cybersecurity awareness and responsible digital behavior. Please behave responsibly and adhere to legal and ethical standards in your use of this information.
Opinions are my own and may not represent the positions of my employer.
Welcome to the Hacker's Cache, the show that decrypts the secrets of cybersecurity one bite at a time. I'm your host, Kyser Clark. And in this episode, I'm going to talk about why I am slowing down in my cybersecurity career and why you might want to as well.
And for those who know me, those who've been following me and paying attention to my journey, you're like, wow, why is Kyser slowing down? Because I've typically been a pretty hard charger, someone who gets after always upskilling, always getting a new certification, always learning a new skill, always just everything I could. I mean, I'm getting certifications. I'm reading blog posts.
I'm listening to cybersecurity news. I'm scrolling LinkedIn, seeing what's up in the industry. I'm reading books.
I'm trying to learn on the job as well. And I'm spending literally every minute of every day, no days off for literal years on end to become the best cybersecurity professional that I can be. And ultimately, that led to my burnout.
So I've talked about burnout and why I took a long break from cybersecurity. And ultimately, now that I'm back in it, I've said, yeah, I'm slowing down. But like, I never really gave an explanation of why I'm slowing down rationally, I guess.
It is to prevent burnout and to kind of extend the longevity of my career. But if you think about it, there's more reasons for that. That's what this episode is going to be about.
And you can apply this to your career as well. I think this is some pretty good advice. Keep in mind, I'm also just figuring out my career, much like everybody else.
But I think the biggest reason why I'm slowing down my cybersecurity career, when I say I'm slowing down, I'm basically like, I'm not studying for three to five hours a day after work on certifications. I'm not putting 10 to 12 hours a day on the weekends towards certifications. Do I want more certifications? I do.
But I'm going really, really, really slow about it. And here's why. Because in the past, I assumed more knowledge, more credentials, more skills, more wisdom equated to more pay, higher, more responsibilities at a job, promotions, and ultimately more pay.
I am motivated by money. And there's no shame in that. I would not be in this field if this field didn't pay good to be fair with you.
So if you're in the field to earn a good living, that is a perfectly good reason to be in this field. Now, I have said like, you don't want money to be your only reason. But you have to have a great passion for technology and cybersecurity specifically to really last in this career field.
Because I have a high passion. I enjoy the technologies. I enjoy the learning process.
I'm naturally good with technology. I'm just naturally curious with technology, if that makes sense. It's interesting to me.
So I'm not naturally good at it. I'm just naturally curious and always wanting to learn about it. So which kind of makes you naturally good.
So that helps a lot. But at the end of the day, if I wasn't making what I make now, if I wasn't, you know, an upper middle class in terms of income, then I wouldn't be here. To be honest, I'd be doing something else.
Because money is important. And people, you know, other people want to admit or not, it is important. And making a living is important.
And you can live comfortably in this career field. Which is why I'm here. And which is why I try to help people break in the field.
Because it is a lucrative career option. And it is a great way to escape the lower class and even the middle class. Like I said, I'm currently like in the upper middle class tax bracket.
So and you can get there as well. If you are trying to break in. And some of you guys are already in the field.
And you're already there. And you already know what I'm talking about. So that's kind of a long way of saying I am in this field for the money.
That's not the only reason why I do have a high passion in this field. So I always equated more skills, more knowledge, more certifications to raises, promotions, and more job opportunities. Which equates to more financial income.
Financial freedom. Because financial freedom is very, very important to me. I'm not greedy.
I don't really care about money if I'm honest. I just care about freedom. And having a certain amount of money, that number is different for everybody, equates to financial freedom.
That's my big goal in life is to reach financial freedom. And cybersecurity is a way to do that. And that's why I've put so much effort into not only my career, but also my content.
Because this content does help my career. Not as much as upskilling. But it does help me make connections and helps me meet people.
And I enjoy teaching you guys and sharing my wisdom and my knowledge and my struggles along the way. Because I know it's helping people out. Because this field is very, it's hard.
It's grueling. And that's why I'm slowing down. So if I say that I stopped pursuing like upskilling because I always equate it to more money.
Does that mean upskilling doesn't equate to more money? And yeah, that's kind of what I'm saying. That's kind of what I'm getting at here. So while certifications and your skills and your wisdom absolutely does matter.
And it does absolutely play a part in the type of roles you can achieve and the types of salaries you can negotiate for. It's not the most important thing. I've always said it.
And a lot of people in cybersecurity and tech have said it. The most important thing is your experience. So once you get your first cybersecurity job, the best thing you can do for your job, for your career, is to hold that job.
Because the number of years of experience that you have has the biggest impact on the types of opportunities that you get and the types of raises and promotions you get and the types of salaries you can command. That's the most important thing. So certifications and upskilling absolutely helps.
But if I'm honest with you, if I could wave a wand and get five new certifications right now, I don't think it would command. I could probably get a small raise, but I don't think it would be a substantial raise. Where would a substantial raise come from? It would come from me putting an additional two, three, four, five years into the profession.
That would be the most important deciding factor on that. And when I talk about certifications, I'm also talking about college degrees because that's a credential. Right now, I'm currently working on my MBA.
And I'll be honest, guys, I recently went to a job search. I've been in my current role for about a month and a half now. And I don't think the MBA, I don't think anybody really cares.
Granted, it's not a cybersecurity certification. I do have two cybersecurity certifications. I got a bachelor's and a master's in cybersecurity management policy.
But I don't think employers really care too much about that either. If I'm honest, I've definitely had employers be impressed with the amount of certifications I have. And for those who are new to the channel, welcome, by the way, new to the podcast, I have currently 19 certifications.
And that's actually quite a lot, much higher than most people. And it's absolutely helped me. It's helped me get the knowledge I needed.
But like I said, if I went to management one and got five new certifications, even if they were advanced or expert level certifications, they're not really going to help me out too much at this point in my career. Now, that's not saying don't get your certification. I'm a huge advocate for certifications.
If you have zero certifications or you have one or two certifications, getting five certifications is really going to help you out. But once you reach 15, 16, 17, 18, 19 certifications like me, adding another certification doesn't really move the needle too much more. What's moving the needle is my time in a actual paying full time cybersecurity position.
So my number one focus is really just to keep my job and show up and do my job the best I can. And part of that is not staying up to midnight studying for a certification. If I relax when I get off work and I don't think about cybersecurity after work and I go to bed on time, I can wake up and go do my job more efficiently.
And it took me a long time to realize that, guys. Now, this advice only applies. And it might not even be advice.
This is just what I'm doing. You can mimic me all you want. But I am telling you right now, the majority of people, maybe even all people, like if you are doing your eight hours a day and you get off work and do three hours of study and then on the weekends you're doing, you know, eight to 12 hours a day on studying more, you're going to get burned out.
You are going to get burned out. There's just no question about it. Okay.
But that's exactly what I did to break in this field. When I was in the military and I knew I was getting out on a set date, I was on a time crunch. I was like, I need to get this certification, this certification, this certification, I got to get these skills.
It was more about getting this skill, this skill, this skill, and this skill to become a pen tester. And when I looked at the skill sets that I needed to obtain, I just looked, okay, this certification will give me these skill sets. This certification will give me these skill sets.
This certification will give me these skill sets. That's why I have so many certs. It absolutely helped me land my first pen testing job out of the military.
I talk about that all the time on this podcast and you need to bust your butt to break in this field, guys. And I, I've responded to some comments about when I had my burnout episode that I don't regret anything. I don't regret anything.
Prior to landing that first pen testing job, I don't because that was required. That's essential to breaking into this field. You have to put in that much time, right? I don't think there's any way around it because you have to get a lot of knowledge, a lot of skills to go on these interviews and answer the questions and then go into the job and actually know what the heck you're doing to a certain level.
Otherwise, you're going to be clueless because they're not going to teach you on the job. Not much anyways. They're not going to teach you much on a job.
And I mentioned earlier on, I don't know what episode it was, but maybe a few episodes ago that my current role, which is a cloud security engineer, by the way, for those who didn't get the memo that I started a new job, I was talking about how they're handholding me a little bit. And honestly, the handholding didn't last long. I'm kind of on my own now, which is good.
Because I'm not being micromanaged and they're kind of letting me figure things out. They trust me to figure things out myself. But yeah, the handholding only lasted maybe a couple of weeks, a few weeks.
And then they're like, all right, push me out of the nest and let me fly, you know? And that's exactly what you can expect in any cyber security job, by the way. And some jobs won't even give you any handholding for zero amount of minutes. Maybe a couple of days tops.
So you really need to hit the ground running in these positions and upskilling and studying the profession, reading books, getting certifications, listening to podcasts. That absolutely helps out for sure. And another reason why I'm slowing down is because honestly, my passion is kind of going away for the field.
And I hate to admit it, but it's just the truth. Because I got in this field thinking like I was going to make a difference in the world. Because like, oh, I'm like protecting companies from cybercrime.
I'm protecting end users from getting phish. I'm protecting customer data, client data, company data, and saving headaches. And because no one wants to get an email saying, hey, that dentist office you went to last year got breached and they have all your dental records now.
No one wants to get an email saying that. Or, you know, my brother, he works in a factory. And he got a notification saying that they got breached, his company that he works for saying, oh, they got all your data.
No one wants to get that. No one wants to get that memo. Right.
So I thought I was doing something good in the world. And I am. We are, as cybersecurity professionals, you are contributing to society in a positive way by preventing these cyberattacks.
Because cyberattacks, cybercrime is very painful to deal with. Very painful to deal with for companies and people. Remember, companies equal people.
Companies are run by people. And every company has customers. So when you protect a business, you're protecting people as well.
And when you're protecting these people, like, yeah, you're doing good in the world. However, big asterisk, no one knows it, though. No one cares.
Like, you don't realize, like, they don't realize, like, there's people like for, like security systems, right? Most people go about their day, especially non-tech people, they go about their day, they do not think about cybersecurity at all. At all. Zero.
I have clients who are in the past who, they simply just don't seem like they care. And even in my current role, I still feel like they don't care, right? Because the client, they have their business to run and their business could be, for example, a country club or a carwash or an electric power plant, a hospital. And each one of these examples I just gave, they're focused on their business.
Like hospital, they, their, their mission is to treat patients, carwash. Their mission is to get people clean cars, power plant, get people electricity. What I say, country club, give people a good experience.
And they're not concerned with cybersecurity. It's like the last thing. And cybersecurity nine times out of 10 is a compliance checkbox.
So then when you, now I'm a consultant, by the way, I've been a consultant ever since I've been in the military in my current role and in my last role. And working with all the clients, I just realized like most companies do not care about cybersecurity. They just don't.
And that's a bitter pill to swallow because you can find all the vulnerabilities you want. You can look at all the remediations and you can have, you can write out the fanciest, nicest, most accurate report ever about, Hey, you need to fix this. And here's why it's important.
Here's why it's going to, here's what's going to happen. If you don't do it, this is the impact. Here's the risk, yada, yada, yada.
And they're still going to look at that report and be like, I don't want to do this. That's a lot because cybersecurity is a lot of work on them. Right.
When you tell them to fix it, when you tell a client to fix something, that's a lot of work that they have to do. And that's money and time that they had to put in to remediate the issue. And that's if they even decide to remediate nine times out of, I don't want to say nine times out of 10, it just depends on the business, depends on the risk, depends on the vulnerability, depends on what's going on.
Well, a lot of times they'll just simply ignore it. Like this isn't a priority. It can be a high severity vulnerability and they'll be like, this isn't important.
And you're like, yes, it is. It's just kind of a big deal. This is, you know, you know, you're an entire database can get leaked out.
And they're like, eh, I don't think so. Are we really under threat right now? Who's trying to attack us? You know? So it's just like, it's like pulling teeth to get clients to do cyber security, like to follow your advice, to follow your remediation actions. And if you're a non-consultant, if you're an internal role, which I don't have experience with in the civilian world, but in the air force, when I was active duty cyber defense operations, I do have experience because I wasn't a consultant.
My goal was to work on air force networks. So I do have some experience being internal, a non-consultant, but it's a little bit different because the military isn't motivated, motivated by profit. So profit margins isn't part of the equation.
So that's why it's a little bit different. So I don't have the full internal cyber security professional experience, but I would imagine if I did have one, let's say you accept a position to be a cyber security engineer for a casino, executive leadership's going to be like, we have to spend a quarter million dollars for all these types of security things. That's going to cut on our profit margins.
Do we really need this? And a lot of times they'll just be like, no, except the risk. And it's like, what the heck am I even here for? You know what I mean? So just put yourself in that, in those shoes. I mean, most of you can relate to this.
Let's say if you're a homeowner, which I recently became a year ago, I had to get a home inspection. A home inspection report looks a lot like a pen test report. I'll say that.
Um, and one of the things that they wrote as a critical risk for my house was like my deck, my deck is about to fall down apparently. And I'm just like, and I have a very large deck, by the way. Um, it's like a double deck.
It's very, it's a very large deck in the back backyard of my house and, um, attached to my house. And it's going to cost me 10 to $15,000 to replace it. I'm like, I don't want to spend 10 to $15,000 to replace this deck.
Like I go out and walk on it and I'm like, yeah, there's a couple boards or, you know, rotten here, rotten there. And I can see some rust on the, on the metal brackets and the paint's chipping off. But when I walk on it, it don't feel like it's about to fall.
It doesn't feel like it's about to collapse. So I just accept the risk. You know, it's going to collapse eventually, but if it does, it's not going to destroy my house.
So I'm not really too concerned about it. So that was, that's an example of me personally accepting a risk. So you got to put yourself in the business owner or the executive shoes.
They're just things that's just not a priority. Like, yeah, would it be nice for me to have a deck that's not about, that's not rust underneath and rotting? Sure. But I don't want to spend 10 to $15,000 to replace that thing.
That's a, that's another thing you got that's similar in business casino. Like, yeah, would it be nice to have the top notch cybersecurity tools? Absolutely. A hundred percent.
Do we want to spend a quarter million dollars on it? No, that's a lot of money. I just don't have numbers. I don't know what.
That might not even be a lot of money to a casino, but that's just an example. So hopefully you're getting, you're seeing what I'm getting at here. So that's another reason why I'm slowing down because like, it just seems like your customers, your clients, they do not care.
Your employer, unless you're in a consultant like me, if you're in a, if you're a consultant like me, your employer is going to value a lot because you're driving revenue to the business, right? However, your clients aren't going to care that much because you're not driving revenue to your clients. They, it costs them money for your services and it's not money that they are always willing to pay. It's like a bitter pill to swallow.
The best way I can put it is like, think about like car insurance, right? It's like we all, at least for me, and I imagine a lot of you guys listening, watching can probably relate to this. Like we all have to have car insurance. Do we like paying car insurance? No, absolutely not.
And if I could, I probably wouldn't pay car insurance if there was no legal requirement. And that's a lot of these companies, they probably wouldn't worry too much about cybersecurity if there was a legal requirement to do it. So you understand it's a, it's a line item in their budget that they are reluctant to pay.
And that's the biggest problem in cybersecurity, right? We're not, we're not selling something that is enjoyable to spend money on. So, and that's why clients, they are reluctant to apply what you recommend. And if you're an internal cybersecurity professional, that's why the company you work for, whether that's a hospital or a casino or carwash or a restaurant, whatever you're working at, that's why they're reluctant to apply the changes because it's a cost to the business that they just don't want to pay.
It doesn't help them drive revenue. Now I can help them save revenue by preventing a cyber attack. And that's where the skill of like explaining cyber risk comes into play.
But they, most people take the mentality is like, Oh, a cyber attack. It's not going to happen to me. Even though they happen all the time.
Same thing with like, like, yeah, it's probably a good idea to car insurance. But it's like, when's the last time I was in a car wreck? It wasn't, it's been a long time for me anyways. So it's like, it just seems like a useless expense, you know? So it's similar to the car insurance.
If you disagree, let me know. But I think it's a good analogy. And if you have a different analogy, feel free to drop a comment and let me know what you think in terms of a different analogy.
That might be better. But yeah, guys, the biggest and most important thing when it comes to your cybersecurity career in terms of promotions raises new job opportunities is the number of years of experience that you have on your resume. And I learned this the hard way, but your years of experience is going to get split up.
What do I mean by that? So if you look at my resume, it says six years, cyber defense operations, United States Air Force, active duty. It says a year and a half, penetration tester at a consulting firm. And now it says a month and a half, cloud security engineer at a consulting firm.
Let's say I was applying to an instant response type of role. I have zero years of experience working as a response. Zero.
If you add up all my years of experience in cybersecurity, it's over eight now. I started in April 2018. It is now September 2026.
It's the time of this recording. I have over eight years of experience in this field. However, like I said, if I wanted an instant responder job, I've never had a dedicated instant responder job.
Do I have? I've done instant response. Yeah, I've done it several times in my current role already, actually. And even in the United States Air Force, the cyber defense operations.
But it was like one off tasks. It's a little more frequent in this current role. But the point is, it doesn't say instant responder.
Three years or whatever. If I go to apply for a penetration testing position, they don't see eight years of experience cybersecurity. They see a year and a half of experience in penetration testing.
See what I'm getting at? If I try to apply for a cloud security engineer at another company right now, they don't see eight years cybersecurity experience. They see two months cloud security engineer. You see what I'm saying? See what I'm getting at? It's almost like the pen testing experience and my cyber defense experience is irrelevant because they're not the same role.
You know what I mean? And that is unfortunate because there's a lot of crossover between these roles, guys, and skill sets. But a lot of companies, a lot of HR professionals, they can't read between the lines on a resume. That you really do need to put the exact title that you're applying for.
So I would say in the future, and this isn't really... If you think this is lying, then fine. But you do need to do this. It's not lying.
It's just changing words around to better fit what you're applying for. So for example, if I find myself in a job search again, and I want to apply for a cybersecurity engineer position, I would change cyber defense operations to cybersecurity engineer on my resume. And that would give me six years cybersecurity engineer experience because that is an engineer type position.
It's almost very similar, even though I don't have the title of cybersecurity engineer. Now, I do. I have cloud security engineer now.
But yeah. But you don't want to lie because I couldn't do penetration tester United States Air Force six years because I didn't do any pen testing. So I'm not saying do that.
But if you have a role that's similar, you can change the title to match what you're applying for. So that's a big deal. Hopefully you understand what I'm saying.
If not, feel free to drop questions in the comments on YouTube. And but the same thing does apply. Let's say I was right.
I was applying for red team engineer positions. I would change my pen testing experience to red team engineer because the skill sets overlap a lot. Did I have a title red team engineer? No, but pen testing red team engineer.
So similar, you can change the title on your resume to help you get eyes on it, because, like I said, it's because HR professionals, they can't read between the lines like when they see what HR professionals, they don't know this field at all. So when they see what let's say they're trying to hire for a red team engineer position and they see. They see.
I'm just give my resume as an example. They'll see class security engineer, they'll see penetration tester, and they'll see cyber defense operations. Nowhere does it say a red team engineer out.
Throw that resume away. That's literally what they think. So you need to help the HR professional read between the lines and just like just clearly stated.
So that's that's what I would do in my next job. I didn't do that in my current one, but I feel like you'll have more success if you do stuff like that. And like I said, it's not lying.
You don't want to. You can do that. Like if you have blue team experience and you're applying for a blue team role, you can you can change those titles however you want.
Same thing for red team or offense security. You can change those titles however you want. So if you see like.
If you have a red team engineer position and you're applying for a pentesting position, I absolutely change that title to pentester because offensive skills are they overlap so much that you can change the title. But I wouldn't change like if you have six years of blue team experience and you're applying for your first pentest job, I wouldn't say, you know, I was a security engineer for six years. Let me just change that to penetration.
That's that's that's a lie. OK, so don't don't do that. But you can change blue team titles interchangeably.
You can change red team and offense security titles interchangeably as well because the skillsets are they overlap so much. You can even do like if you was a stock analyst for. Seven years and you're like, I'm applying for cybersecurity engineer, you can you can change.
I would be willing to say like, yeah, you can change your stock analyst title on your resume to cybersecurity engineer just to. Help help get that interview. OK.
Now there's going to be different philosophies there, but like I said. What you write on your resume in terms of titles matters a lot, unfortunately, because like I said, HR professionals, they cannot they cannot read between the lines now hiring managers. And seasoned cybersecurity professionals, they can.
But HR professionals cannot. And there's like a million different titles out there. And by the way, whatever title.
That you accept. Like you don't have to put down a resume, you can change the wording and you want because every company like has different ways of writing things. So you can kind of like, for example.
I think the title that I accepted was like. Azure security administrator, I think that's a title. I think it's official title that I accepted.
Azure security administrator. And I just changed to cloud security engineer. See what I did there? Just because it looks it looks better and it's more widely applicable and more well known if I just put cloud security engineer compared to Azure security administrator.
Hopefully you got some value out of this one, guys. Let me know your thoughts and feelings in the comments. Feel free to ask any questions.
And if they're good, I'll feature on my next Q&A episode. I appreciate you guys support. And thanks for watching.
Thanks for listening. And hope I see you on the next episode. Till then, this is Kyser signing off.