Career
How to Get Into Cybersecurity With No Experience: The Complete 2026 Roadmap
Table of Contents
- Step 1: Get In Tune With the Industry
- Step 2: Build Foundational Knowledge
- Step 3: Earn a Credential and Get Hands-On
- Step 4: Fix Your Resume and LinkedIn
- Step 5: Start Applying
- Step 6: Prep for Interviews
- Step 7: Network
- Sample Resume Walkthrough
- Frequently Asked Questions
- How long does the self-study part (Steps 1-3) actually take?
- What does each certification actually cost in time and money?
- Am I too old to start?
- Does unpaid or informal experience actually count on a resume?
- Should I be networking more than Step 7 makes it sound?
- I’m more interested in compliance or GRC than hands-on technical work — does this roadmap still apply?
Every “entry-level” cybersecurity job wants 3-5 years of experience. That’s not a typo — that’s just what the market looks like from zero, and it’s enough to freeze anyone up.
Here’s the deal: there’s no shortcut, but there’s a checklist that works. I laid this out a few years ago, and it still holds — tightened up for 2026 below. Some steps come in tiers: do the bare minimum, or go hard. The more of it you do, and the better you do it, the faster you get hired.
Step 1: Get In Tune With the Industry
Before you touch a single certification, get yourself immersed in how security people actually talk and think. This is a background task you run for the rest of the process — and ideally for the rest of your career.
Tier 1 (Minimum): Listen to Darknet Diaries
Darknet Diaries by Jack Rhysider is storytelling, not news — deep dives on real breaches, hackers, and criminals. It’s genuinely entertaining, and it gives you talking points for interviews. You will get asked some version of “what’s the most interesting breach you’ve followed” or “name a few security events from the last year.” If you only do one thing on this list, make it this one.
Tier 2: Add CyberWire Daily
CyberWire Daily is a tightly produced daily news podcast hosted by Dave Bittner and Rick Howard. Pick up today’s episode, not the back catalog — it’s news, so staying current is the point. Listening regularly gets you fluent in the jargon (APTs, TTPs, IOCs) without grinding through a textbook.
Tier 3 (Go Hard): Follow Security Accounts on X
Round it out by following a handful of active security accounts on X — Huntress Labs and The Hacker News are both solid starting points for real-time breaking news.

Step 2: Build Foundational Knowledge
Cybersecurity is a subset of IT, so you need a working foundation in computing and networking before the security concepts click. You don’t necessarily need to sit the exams — you need to actually know the material.
Tier 1: Learn the Fundamentals and Code
Learn the A+, Network+, and Security+ curriculum — you don’t have to sit all three exams, just actually know the material. Alongside that, learn Python basics through a free course and build one small project.
If you don’t already know how to code, stop avoiding it. You don’t need to become a developer, but avoiding programming entirely in IT or security is doing yourself a disservice. Learn the basics of Python, then build something small — a basic port scanner is a classic starting project. Push the code to GitHub. Don’t try to memorize the language; nobody memorizes syntax while coding, you just get comfortable enough to look things up fast.
Tier 2: Get Certified
On top of Tier 1, actually sit and pass CompTIA Security+.
Step 3: Earn a Credential and Get Hands-On
Once you’ve got the foundation down, it’s time to go deeper into security and start putting skills into practice yourself.
Security work generally splits into two lanes: offense (finding weaknesses by trying to break into systems) and defense (protecting, monitoring, and responding to attacks). Even if you’re aiming for defense long-term, I’d recommend spending some time on offense early on. Here’s why: trying to break into a system gives you a gut-level understanding of why defense matters — you start to see exactly why patching matters, why old software is a liability, and how attackers actually think. (If you want to go deeper on choosing between the two once you’ve got the basics down, I broke down the full blue team vs. red team specialization path here: Top Cybersecurity Skills You Must Learn Before 2030.)
Tier 1: eJPT Plus Hands-On Practice
For this tier, look at the eJPT (Junior Penetration Tester certification, offered by INE). As of 2026, it’s been expanded with more web app testing and recon training, plus coverage of AI-assisted offensive workflows. Pricing runs around $249 depending on the package. Even so, it’s still one of the most accessible, genuinely hands-on entry points into offensive security — you get dropped into a live lab and have to actually break into machines, not just answer multiple-choice questions.
Pair it with hands-on practice on your own:
- CTFtime.org for capture-the-flag competitions
- HackTheBox modules — web app pentesting, OSINT, and Active Directory modules are all solid picks
- Publish what you learn — a blog write-up or a short video walkthrough of an attack you learned is a great way to reinforce the material and show your work. For more ideas on manufacturing your own experience this way, see: Getting Started in Cyber Security: A Guide for Newbies
Tier 2 (Go Hard): Level Up With OSCP or CISSP
Yes, these usually get listed as mid-career certifications, and a lot of people will tell you they’re not “entry-level.” That’s fair for OSCP — it’s genuinely difficult and I wouldn’t rush into it. But CISSP is different. If you’ve worked in IT before, you likely meet the domain requirements even without a security-specific title, and CISSP functions as close to an automatic HR filter-bypass as any credential in the industry. Everyone in HR recognizes the name. It won’t teach you technical skills the way eJPT will, but it gets you more interviews.
Step 4: Fix Your Resume and LinkedIn
Build the Resume
Take everything from the last three steps and put it on your resume in a way that actually conveys the knowledge and experience you’ve built. Don’t leave things out — a lot of people undersell self-taught work because it didn’t come from a W-2 job. It counts. If you want a deeper walkthrough of what actually belongs on an entry-level IT resume, I broke it down in more detail here: Creating Your Dream IT Resume.
Fill Out LinkedIn and Indeed
Get your LinkedIn fully filled out and start making connections. Don’t go add 200 people in a day — that’ll get you flagged by their anti-spam system — but steadily connect with people doing the job you want, follow a few well-known voices in the industry, and fill out at least one other job board profile (Indeed, etc.) so you’re not relying on a single source of leads.
Step 5: Start Applying
Tier 1: Apply Locally and Remote
If you don’t have any IT experience yet, apply broadly to both IT roles and cybersecurity roles. Don’t hold back on postings that look senior or mid-level just because you only meet a quarter of the listed requirements — apply anyway. If your resume and interview demonstrate that you’re the type of person who can learn and figure things out independently, employers are often willing to take a chance on you above the “years of experience” line.
One tactical tip: don’t just search “entry level IT” or “help desk” — everyone else is searching those exact terms too, which means more competition. Less common titles like “Support Engineer” or “Tier One” turn up listings that a lot of other applicants never find. Here’s a fuller list of keywords worth trying.
Tier 2: Widen Your Search Nationally
Seriously consider remote roles, or even relocating for that first job. If you’re in a mid-sized town but you’re open to working anywhere in the country, your pool of available jobs increases dramatically — which increases your odds of getting hired exponentially. You can always take that first role for eight months to a year, bank the experience, and then apply somewhere else. I go deeper on this exact strategy here: Secure Your First Job Fast: Embrace the Uncommon Approach.
Tier 3 (Go Hard): Go Global
If you’re truly open to it, widen your search worldwide. Fully remote roles at companies that hire internationally exist, and casting the widest possible net is how you turn a slow job hunt into a fast one.
One more thing worth internalizing: if it takes eight months to land a security job but only two months to land an IT job, take the IT job. Nearly every IT role has a security component to it, and it’s a much easier lateral move from IT into security than it is to walk in cold with zero IT experience. Get in, get paid, get experience, and pivot from the inside.
Step 6: Prep for Interviews
Practice Real Questions Out Loud
Get your hands on as many real IT/cybersecurity interview questions as you can, and practice answering them out loud — not just reading them silently. This does two things: it fills knowledge gaps before the interview, and it gets you comfortable articulating answers under pressure. There are only so many questions that actually get asked, and a lot of them get recycled, so the odds are decent that you’ll walk into a question you already rehearsed.
Practice What You Don’t Know
Just as important — practice answering questions you don’t know the answer to. “I don’t know this yet, but here’s what I do know” or “I haven’t worked with this directly, but I can learn it” lands far better than a flat “I don’t know.” Don’t skip the personality-based questions either; get reps in on those too.
Real quick, before the last step — almost everything in Steps 1 through 6 above is now something you can go through directly inside the Cyber Range.
I put this checklist together back in 2021, and it got a lot more traction than I expected. People kept coming back wanting more structure than a video description full of links could really give them. So I took the time, planned it out, and built the thing properly — a real platform instead of just a checklist scattered across different videos.
It’s working. People are already getting hired out of it, and inside the community, members are actively trading resume feedback, job leads, and advice with each other.
I’ll say it straight — I recommend it. Start with the free 7-day trial and see how it feels for yourself. If you’ve got questions along the way, ask inside the Cyber Range community. Me, the team, or one of the 1,500+ members in there will get back to you.
Try the Cyber Range free for 7 days →
Step 7: Network
I’ll be honest — this is the step I personally use the least, and I’ve gotten most of my own jobs through people who already knew my work rather than cold networking. But it’s still the most powerful lever on this list if you use it. If you have a strong network, or even one solid connection, it can functionally replace a lot of the other steps.
The simplest version of this: find people on LinkedIn working the role you want, and send a short, polite message asking about their job or for advice on breaking in. You don’t need to know them already. Offer to buy them coffee, or ask for a quick 15-minute call. Most people are more receptive to this than you’d expect.
Sample Resume Walkthrough
Here’s roughly what a resume looks like for someone with zero traditional experience who worked through this checklist at an average level:
| Section | What Goes Here |
|---|---|
| Certifications | eJPT, CompTIA Security+ (or Associate of ISC2 if CISSP’s experience requirement isn’t met yet) |
| Experience | Self-generated projects — a personal domain, a GitHub with HackTheBox write-ups or Python projects, a small YouTube channel documenting the learning process |
| Education | A+/Network+/Security+ curriculum study, a free Python course, or any relevant coursework — even without a formal degree |
| Past Work | Whatever you’ve got — it doesn’t need to be tech-related. Your first job doesn’t disqualify you |
You don’t need a flashy resume with a dozen buzzwords. A resume like this — built entirely from self-directed work — is genuinely good enough for entry-level security roles, and it’s more than enough for entry-level or even mid-level IT roles.
Frequently Asked Questions
These are real questions people have asked me about this roadmap over the years — pulling straight from the comments.
How long does the self-study part (Steps 1-3) actually take?
If you’re putting in 10-15 hours a week, rough numbers: about 100 hours of active podcast listening for Step 1 (the fun, easy part), around 100 hours of studying for Step 2, and 50-200 hours for Step 3 depending on how far you take it. That’s roughly 250-400 hours total, or about 16-26 weeks. This varies a lot person to person, but it’s a reasonable planning number — and the hardest parts are front-loaded, so it gets easier from here.
What does each certification actually cost in time and money?
Rough ranges: CompTIA certs (A+, Network+, Security+) each run 60-100 hours of study and a couple hundred dollars. CISSP is a bigger lift — 300-400 hours and around $750. eJPT is closer to 150 hours and around $200-250. Use these as planning numbers, not guarantees — your mileage will vary.
Am I too old to start?
No. Ageism exists in some corners of tech, but it’s genuinely not a big factor in IT and security compared to other “-isms” out there. I’ve heard from people starting this in their 30s, 40s, and beyond who broke in just fine.
Does unpaid or informal experience actually count on a resume?
Yes, and don’t undersell it. Setting up wireless networks for neighbors, fixing computers for family, volunteering IT help for a non-profit or church — that’s real experience, even unpaid. Hiring managers who’ve actually done the job know that a few years of scrappy, self-directed troubleshooting often beats someone with only classroom knowledge and zero hands-on time.
Should I be networking more than Step 7 makes it sound?
Honestly, probably yes. I put networking last on this list mostly because it’s not the tool I personally lean on, and I don’t want to discourage the introverts reading this. But readers who broke in with zero experience have told me repeatedly that networking was the single thing that got them their first offer — reaching out to a hiring manager directly after weeks of silence, going to local meetups, asking people questions. If you only have energy for one extra thing beyond this checklist, make it that.
I’m more interested in compliance or GRC than hands-on technical work — does this roadmap still apply?
Mostly yes, with one tweak: instead of leaning into offensive projects in Step 3, build content or projects around frameworks like NIST 800-53, PCI-DSS, or HIPAA instead. It sounds dry, but it demonstrates the same thing — that you understand the subject deeply enough to explain it, not just pass a multiple-choice exam on it.
If you implement all seven steps as well as you can, it’s a matter of time before you get hired. Getting an IT job first tends to be the faster path, but if you stay consistent, cybersecurity is absolutely reachable.
Ready to put this into practice instead of just reading about it? Like I mentioned above, the Cyber Range is the fastest way through most of this checklist — free 7-day trial, no pressure.
And if you just want a place to ask questions, get feedback on your resume or your projects, and connect with people going through the same grind, the Cyber Community is free to join.