To enter cybersecurity without professional experience, choose a target role, learn its foundations, build two or three demonstrable projects and document your method. Recruiters can assess clear evidence more easily than a long list of topics.
projected U.S. information-security analyst growth
The BLS projects 21% growth from 2025 to 2035, with about 14,100 openings per year. This is a U.S. indicator and should be paired with local job-market evidence.
U.S. BLS — Information Security AnalystsChoose an observable first role
Cybersecurity includes SOC, GRC, penetration testing, IAM, cloud and product security. Read local job postings and extract repeated tasks. Pick an entry point whose work you can simulate without touching real production.
For SOC, practice log analysis and triage. For GRC, build a risk assessment and treatment plan. For cloud security, deploy and harden a small environment.
Build three complementary proofs
Create a technical lab, a written analysis and a short presentation. For example: detect a scenario, document assumptions and explain remediation to a non-technical audience.
Publish only environments and data you are authorized to show. A readable repository with context, decisions and limits reveals more than tool screenshots.

Turn learning into a professional story
Describe the problem, approach, result and what you would change. Quantify only what you measured, such as triage time, log coverage or passed tests. Do not present a lab as client work.
Tailor the CV to the role using demonstrated skills and links to matching projects.
Create experience before the first job
Contribute to open source, support a nonprofit within an authorized scope, join exercises and publish analyses. Ask professionals for specific feedback on deliverables.
Sustainable cadence beats a certification sprint. Each month should produce a stronger proof and a targeted conversation.
- Target role
- Skills observed in postings
- Technical project
- Written analysis
- Presentation and feedback
Operational decision matrix
| Stage | Question to resolve | Expected outcome |
|---|---|---|
| Target | Choose a role and analyze local postings. | List recurring skills |
| Learn | Strengthen systems, network, cloud and security. | Avoid shallow stacking |
| Prove | Build a readable authorized project. | Show decisions and outcomes |
No experience does not mean no evidence
A well-documented lab can demonstrate reasoning and execution if it is not presented as client work.
The right control level depends on context, exposed assets and business impact: document assumptions, measure the outcome and reassess after every material change.
Frequently asked questions
Do I need a computer-science degree?
Not always. Requirements vary, but strong foundations and concrete evidence remain essential.
Which certification should I start with?
Choose based on the target role and local postings. It should support practice, not replace it.
How many projects should I show?
Two or three deep, readable and role-relevant projects often beat ten shallow demos.
Official sources
Achraf Hachimi
CISSP-certified Senior SOC / CSIRT Engineer specializing in Incident Response, Threat Hunting and Detection Engineering. Eight years of experience in critical environments with Splunk ES, Microsoft Defender XDR, SentinelOne and Cybereason.
