I am trying to learn more about what an IT security career entails and whether I would be a good candidate for it. If I may, I would like to take a few moments to explain my background.

I am not a recent college graduate, though I do hold a BS in EE from years ago; I have IT experience (though not specifically with security) but in Document Management and in Systems Administration. All of my experience is with small companies, however. For my own personal benefit, I am trying to move towards larger environments for more growth opportunities. However, it seems the larger the company, the larger the scope of what I as an administrator would need to know. And I am the type of person that likes to know every little detail about what I am responsible for. In a larger environment, this may be difficult for a person like me because of my detail-oriented nature. I work better on a micro rather than macro level. The reason, then, that I am thinking about security as a possible career is I feel this field requires people who have very specialized knowledge and are very detail-oriented and focused. Am I right in coming to this conclusion?

I would also like to know more about the job itself, if anyone has any input. What is a typical day like working in this field? I have done some research on the ISC2 web site and am thinking about taking the SSCP certification as a starting point, but I am unclear as to whether my Systems Administration experience (mostly Microsoft) would count towards the experience requirement and whether I should start with the SSCP or some other security certification first. I am looking around on cccure.org and other tech sites for more information. I would appreciate any feedback and input anyone may have. Thank you in advance.

Dani AI

Generated

Good instincts — security fits people who like detail, but it also needs a range of roles from deeply technical, hands‑on work to higher‑level governance. There are many “micro” jobs (incident responder, malware/forensics analyst, IDS/URL tuning, vulnerability researcher) where the day is about digging into logs, packets and systems. Network security remains important, but modern security increasingly spans identity, cloud, application and operations as well (strong long‑term demand and pay growth for information security analysts). (bls.gov)

If you want a practical starting path: pick one entry cert and get hands‑on. CompTIA Security+ is a common baseline (no formal prereqs but CompTIA recommends ~2 years IT admin experience), and it’s a reasonable first step if you lack formal security experience. If your Windows sysadmin work already included access controls, patching, incident handling or logging, that counts toward practitioner certs — ISC2’s SSCP requires one year of relevant experience in its domains, and you can pass the SSCP exam and become an Associate of (ISC)2 while you finish the experience. (comptia.org)

For longer‑term goals, note the distinctions: management/strategy certs like ISACA’s CISM target experienced managers and require five years of relevant experience, while ISC2’s CISSP is similarly senior (five years across multiple domains). ’s CISM suggestion is solid if the aim is governance/risk management rather than hands‑on engineering. (isaca.org)

Concrete next steps: map your current tasks to security domains, ask for small security duties at your job (hardening, patching, logging), build a home lab (Windows + Linux VMs, basic network/scripting), and pick either Security+ or SSCP to study toward. Treat certifications as evidence, not a substitute, for practical experience — stack certs and hands‑on projects and you’ll make the move to larger environments much more smoothly.

Recommended Answers

All 3 Replies

Member Avatar for Member #148897

I dont see any reason why u cant shift ur career towards IT security. U may want to consider ISACA's CISM as well.

I think that security is a great place to be in IT. It will never go away as a career choice. My suggestion is to get experience with the most popular products in the field. Network security is hot.

I have to ask though,...if you are an EE, aren't there zillions of high-paying opportunities in that field? If you had some security experience, perhaps you could go to work for someone who designs security appliances or design your own.

I think that security is a great place to be in IT. It will never go away as a career choice. My suggestion is to get experience with the most popular products in the field. Network security is hot.

I have to ask though,...if you are an EE, aren't there zillions of high-paying opportunities in that field? If you had some security experience, perhaps you could go to work for someone who designs security appliances or design your own.

Ken,
Sorry for my delayed reply, but thanks for your response; how would someone like myself get started in the security field? The problem is I do not have any security experience and need to start somewhere.
Thanks.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.