Career Path Partners
AI  ·  Cyber  ·  Software

The guide

Capability before credentials.

How people with no degree, no tech background and no five years of experience actually get into security, software and data — and where the ones who don’t make it get stuck.

About a 12-minute read · Free · Nothing gated

The premise, in one line. In the military, advancement isn’t granted for time served or courses completed — it’s earned by demonstrating you can do the thing under real conditions. Civilian hiring claims to work that way and mostly doesn’t, which is why so many people collect credentials and stall. This guide is the other order of operations.

That model comes from Jacob Hess, Air Force veteran and network engineer, who built our cybersecurity path on it.

Part 01

The credential trap

The standard advice is a ladder: get a certification, then another, then apply. It is not wrong so much as incomplete, and the incompleteness is expensive. A certification proves you passed a test on a body of knowledge. It does not prove you have ever triaged an alert, read a log that mattered, or made a judgment call with incomplete information — and that is the thing an employer is actually trying to find out.

This is why so many people end up with two or three credentials and no offers, and then conclude the problem is that they need a third or a fourth. It usually isn’t. The gap is not more knowledge. It is evidence.

Certifications still matter — several of the roles below will not shortlist you without one, and they are the cheapest way to clear an automated filter. The correction is not to skip them. It is to stop treating them as the finish line and start building the evidence alongside them, from week one.

The question underneath every interview is “can you do the work?” A certificate is one answer to it. A record of having done the work is a better one, and almost nobody entering the field arrives with one.

Part 02

Which doors are actually open

“Get into cybersecurity” is not a plan, because cybersecurity is not a job — it is about a dozen of them, with wildly different entry requirements. Some need heavy technical depth. Some need almost none and reward being organized and a clear writer. Picking the wrong door is the single most common reason a well-executed year produces nothing.

Here is the honest map, including the software and AI routes, since for a lot of people those turn out to be the better fit once they see the actual work:

RoleTypical entry payTime inUsual credential
🛡️ Security OperationsWatch for threats and respond when something goes wrong.$50k–$75k8–14 wksCompTIA Security+
📋 GRCMake sure companies follow the security rules.$55k–$80k6–12 wksCompTIA Security+
☁️ Cloud SecurityKeep companies' data safe in the cloud.$70k–$110k12–20 wksAWS Cloud Practitioner
⚔️ Pen TestingGet paid to hack companies (legally).$60k–$90k16–24 wksCEH
🔍 Threat IntelResearch hackers so we can stop them.$55k–$80k12–18 wksSecurity+
🎓 Security AwarenessTeach employees to spot scams.$45k–$65k4–8 wksOptional
🔬 Digital ForensicsInvestigate cybercrimes.$55k–$78k12–18 wksSecurity+
🔐 IAMControl who gets access to what.$60k–$90k8–14 wksSecurity+
Software DevelopmentBuild the products people use every day.$70k–$95k16–24 wksNone — portfolio counts
🧪 QA EngineeringBreak software before customers do.$65k–$85k10–16 wksNone required
🤖 AI OperationsRun the AI systems companies bet their future on.$65k–$90k8–14 wksNone — judgment counts
Prompt EngineeringGet world-class output from AI systems.$80k–$110k10–16 wksNone required

Pay ranges are typical posted entry compensation for the US market and are not a projection of your earnings. Time-in is study time for someone working a full-time job while they do it.

Two things people get wrong reading a table like this. The first is chasing the top number: cloud security pays the most on that list and also asks the most, and starting there with no foundation is how people stall out at month four. The second is dismissing the fast doors. Security awareness and GRC are the least technical routes in, they are real jobs with real progression, and a year inside the industry is worth more than another year outside it studying for the door you wish you could walk through.

Full breakdown of every role — day in the life, skills, roadmap →

Part 03

Your current job is the asset

The most common thing we hear is a version of “I don’t have a technical background.” Usually the person saying it has been doing the core cognitive work of a security role for years, in a setting that didn’t call it that. This is not a pep talk — it is a practical point about how you write your résumé and how you answer the first interview question.

Take the most common entry role, Security Operations. The job is: watch for things that don’t fit the normal pattern, investigate the ones that matter, document what you found, and tell someone. Here is what that maps to:

Teaching / Educationclassroom monitoring

You watch for problems in a room of 30 students. SOC analysts do the same with network traffic.

Military / Governmentsituational awareness

Your threat assessment training translates directly to security operations.

Retail / Hospitalityloss prevention

You've spotted shoplifters in real-time. That's incident response.

Office / Adminprocess management

You catch errors before they escalate. SOC work is the same skill.

Healthcarepatient monitoring

Watching vital signs and responding to alerts is exactly what SOC analysts do.

Otherpattern recognition

Noticing when something doesn't fit the pattern is the #1 cybersecurity skill.

The practical instruction: stop describing what your job was called and start describing the judgment it required. “Monitored a 30-student classroom and identified behavioural anomalies in real time” is the same sentence as half a SOC job description. Hiring managers are not looking for people who have already done security. They are looking for people who will not freeze when something is wrong.

Part 04

The route, in three phases

Every workable version of this looks roughly the same, regardless of which door you pick. What kills people is not the difficulty of any phase — it is doing them in the wrong order, or spending eleven months in phase one because it’s the comfortable one.

PHASE 1Foundation4–6 wks

Get CompTIA Security+

Learn networking basics

Set up a free home lab

PHASE 2Build Skills4–6 wks

Complete TryHackMe SOC Level 1

Practice analyzing alerts

Learn MITRE ATT&CK

PHASE 3Get Hired2–4 wks

Build a lab portfolio

Apply to SOC Analyst I roles

Interview prep with our team

The rule that makes it work

Phase two starts before phase one finishes. The moment you understand a concept well enough to describe it, you should be practising it somewhere real — a home lab, a free-tier cloud account, a guided environment. The people who study fully and then practise fully end up with a lot of knowledge and no evidence, which is exactly the trap in part one, arrived at by a longer road.

Part 05

How you prove capability

Evidence beats assertion, and this is the part that’s within your control regardless of budget. Four things work, in rough order of how much they move a hiring conversation:

1. A documented investigation

Not “I completed a lab.” A short write-up of one specific thing: here was the alert, here is what I checked and in what order, here is what it turned out to be, here is what I’d do differently. One good write-up outperforms a list of twenty completed modules, because it shows the thing a module completion cannot — how you think when the answer isn’t given.

2. A home lab you can talk about

It costs nothing but time and it produces an unlimited supply of specific answers to “tell me about something you built.” The point is not the sophistication of the lab. It is that you have stood in front of something broken and fixed it.

3. The certification, in its right place

CompTIA Security+ clears filters and it signals seriousness. Take it when the material is genuinely familiar, not as a way of learning the material — and do not book the exam on optimism. Failing costs you the fee and a month of confidence, which is the more expensive half.

4. Public work

Writing up what you learn in the open compounds in a way nothing else on this list does. It is also the single best answer to “why should we take a chance on you” — because it demonstrates you were doing the work before anyone was paying you to.

Where to go from here

Three steps, all free.

Take the assessment to find which door fits you. Read the live board to see what those roles pay in your market this week. Talk to an advisor if you want a second opinion on the plan — including one that says you don’t need us.

Take the assessment →See live rolesTalk to an advisor

610+ people have come through our placement network, adding $148K on average in 75 days. See the wall →

Career Path Partners does not guarantee employment or income from our training, strategies, or resources. Salary ranges reflect typical posted compensation and are not a projection of your earnings. Any examples of success represent what is possible, not what is promised; individual results vary. Nothing here is professional, legal, financial, or tax advice.