Start in IT support, step into a junior security seat, then specialize — the realistic cybersecurity ladder

Asked (summary):
I’m young and want to work in tech — which jobs should I aim for on the way in? I’m really into cybersecurity.

This roadmap is built from 15 sourced career-path records covering attainable starting roles, early cybersecurity targets, and later specializations, drawn from five independent sources (ISC2, CompTIA, NIST, CISA and CompTIA Solutions). ISC2’s 2025 hiring research found 90% of hiring managers would consider a candidate with only prior IT experience and 89% one with only an entry-level certification — a degree is one route, not a requirement.

The ladder: four stages, fifteen real roles

What the ladder can’t say alone

90% of surveyed hiring managers would consider a candidate with only prior IT experience, and 89% one with only an entry-level cybersecurity certification — hands-on experience and certifications beat education alone. isc2.org
Cybersecurity analyst demand is projected to grow 267% above the US national rate over the next 10 years — but the recommended route into it runs through help desk, tech support and sysadmin work first. comptia.org
IT support is a direct feeder role: over 219,000 open US IT support jobs ask for cybersecurity skills, and CyberSeek counts it inside its cybersecurity career pathways. comptia.org
Cybersecurity engineer, security architect and CISO are later destinations, not first jobs — the NIST ambassador profile behind the CISO path shows 13 years of hands-on experience before security leadership. nist.gov

Your first 12 months

Months 1–3

Fundamentals + home lab

Networking, Linux, Windows and Active Directory, basic Python or PowerShell, security fundamentals. Build a small home lab and document everything you break and fix.

Months 4–6

One beginner credential + projects

ISC2 CC (no experience required) — or CompTIA A+ first if basic IT knowledge is weak. Work toward Network+ and Security+ knowledge. Publish lab write-ups as projects.

Months 7–9

First paid role + junior applications

Apply for internships, apprenticeships, help desk, IT support, desktop or network support — and in parallel for junior SOC analyst and junior security analyst seats.

Months 10–12

Iterate and deepen one specialty

Fix the gaps interviews expose. Pick one lane — defense, offense, investigation or GRC — and go deeper. Skip advanced certificates until the practical experience is there.

Apply for these titles

All fifteen roles, with sources

RoleStagePreparation (short)Source

Career-path roadmap from 15 sourced rows gathered across five independent hosts; no single page supports more than one row (6.7%). Fields: role, pathway stage, preparation, career value, projected growth, source. Pay varies significantly by country and was not used to rank paths; median pay was absent from all rows and is omitted. Long preparation and rationale text is shortened on cards and in the table; full pages are linked. Compiled from ISC2, CompTIA, NIST NICE and CISA NICCS material dated 2022–2026.

This report was generated automatically by Keenable SELECT at a user's request, from publicly available web sources linked herein. Keenable does not review, verify, or endorse its contents and makes no representation as to accuracy, completeness, or timeliness; AI-based extraction may contain errors. Nothing in this report is investment, legal, financial, or other professional advice. All trademarks and referenced content remain the property of their respective owners; no affiliation or endorsement is implied. To report an error, rights concern, or request removal: legal@keenable.ai.

Keenable SELECTAsk your own question
Made with Keenable SELECT