Start in IT support, step into a junior security seat, then specialize — the realistic cybersecurity ladder
Asked (summary):
I’m young and want to work in tech — which jobs should I aim for on the way in? I’m really into cybersecurity.
This roadmap is built from 15 sourced career-path records covering attainable starting roles, early cybersecurity targets, and later specializations, drawn from five independent sources (ISC2, CompTIA, NIST, CISA and CompTIA Solutions). ISC2’s 2025 hiring research found 90% of hiring managers would consider a candidate with only prior IT experience and 89% one with only an entry-level certification — a degree is one route, not a requirement.
The ladder: four stages, fifteen real roles
What the ladder can’t say alone
90% of surveyed hiring managers would consider a candidate with only prior IT experience, and 89% one with only an entry-level cybersecurity certification — hands-on experience and certifications beat education alone. isc2.org
Cybersecurity analyst demand is projected to grow 267% above the US national rate over the next 10 years — but the recommended route into it runs through help desk, tech support and sysadmin work first. comptia.org
IT support is a direct feeder role: over 219,000 open US IT support jobs ask for cybersecurity skills, and CyberSeek counts it inside its cybersecurity career pathways. comptia.org
Cybersecurity engineer, security architect and CISO are later destinations, not first jobs — the NIST ambassador profile behind the CISO path shows 13 years of hands-on experience before security leadership. nist.gov
Your first 12 months
Months 1–3
Fundamentals + home lab
Networking, Linux, Windows and Active Directory, basic Python or PowerShell, security fundamentals. Build a small home lab and document everything you break and fix.
Months 4–6
One beginner credential + projects
ISC2 CC (no experience required) — or CompTIA A+ first if basic IT knowledge is weak. Work toward Network+ and Security+ knowledge. Publish lab write-ups as projects.
Months 7–9
First paid role + junior applications
Apply for internships, apprenticeships, help desk, IT support, desktop or network support — and in parallel for junior SOC analyst and junior security analyst seats.
Months 10–12
Iterate and deepen one specialty
Fix the gaps interviews expose. Pick one lane — defense, offense, investigation or GRC — and go deeper. Skip advanced certificates until the practical experience is there.
Apply for these titles
IT help desk technician / first-level support
IT support specialist / desktop support
Network support analyst
IT or security intern / apprentice
Junior SOC analyst
Junior security analyst
Cybersecurity specialist
Security administrator
GRC analyst (if policy and risk appeal to you)
All fifteen roles, with sources
Role
Stage
Preparation (short)
Source
Career-path roadmap from 15 sourced rows gathered across five independent hosts; no single page supports more than one row (6.7%). Fields: role, pathway stage, preparation, career value, projected growth, source. Pay varies significantly by country and was not used to rank paths; median pay was absent from all rows and is omitted. Long preparation and rationale text is shortened on cards and in the table; full pages are linked. Compiled from ISC2, CompTIA, NIST NICE and CISA NICCS material dated 2022–2026.