By Luke Gough, cybersecurity recruiter and career coach. Based on my most-watched YouTube video.
If I had to start a cybersecurity career from absolute zero in 2026, knowing what I know now as a recruiter, I wouldn't start by buying a bootcamp or booking an exam. I've watched that pattern play out too many times: someone gets excited, spends thousands on a course or certification, studies for months, and then hears nothing back. No interviews, no callbacks.
The reason is almost always the same. They skipped the fundamentals that actually get people hired. Here's the six-month plan I'd follow instead.
Weeks 1 to 2: map the battlefield
Most people skip this step or spend five minutes googling "cybersecurity jobs". That can cost you months on the wrong path.
Week 1: role research. Spend 30 minutes a day reading job ads on LinkedIn, Indeed or your local job site. Don't apply for anything. Open 10 cybersecurity job descriptions a day and ask one question: does this day-to-day actually excite me?
- SOC analyst: does hunting threats in log files sound good to you?
- GRC analyst: does building security frameworks and working on compliance appeal?
- Cloud security: do you want to protect AWS, Azure or Google Cloud environments?
Keep a simple notes document and write "sounds great" or "sounds boring" next to each one. No judgement, just honesty.
Week 2: reality-check conversations. Message three people who actually do the roles you're considering. Something like: "Hi, I'm exploring cybersecurity and your background as a SOC analyst caught my eye. Would you have 15 minutes to tell me what your day-to-day is really like?" You'll be surprised how many say yes. Fifteen minutes with the right person can save you months preparing for a job you wouldn't enjoy.
A 2026 shortcut: paste 10 job descriptions into ChatGPT or a similar AI tool and ask which five skills appear most often. By the end of week two you should know your lane.
Month 1: build your foundation with free resources
This is where most people make their second big mistake: they buy expensive certifications straight away. Don't, yet.
- Weeks 1 to 2, IT fundamentals. Watch Professor Messer's free CompTIA A+ videos on YouTube. Not to sit the exam, just to understand how computers, operating systems and hardware work. Thirty minutes to an hour a day, with notes.
- Weeks 3 to 4, networking. This is non-negotiable. Every attack happens across a network in some way. Use the CompTIA Network+ syllabus as your structured study guide: the OSI model, TCP/IP, DNS, DHCP, firewalls, subnetting basics and network security concepts. You can decide later whether to sit the exam; the knowledge itself is essential for every cyber role.
If you'd like a structured course rather than stitching videos together, the CompTIA Network+ course on Coursera (partner link) covers the same ground.
Month 2: get hands-on and start your portfolio
This is where you separate yourself from most beginners, because most never do it.
- Week 1, home lab. Install VirtualBox (free), add a Windows Server evaluation copy and build a mini network on your laptop. Get comfortable creating users, setting permissions and seeing how systems talk to each other. Free YouTube tutorials walk you through it step by step.
- Weeks 2 to 3, guided labs. Sign up to TryHackMe (the free tier is fine) and start with the Linux Fundamentals, Network Services and Intro to Offensive Security rooms. After every room, write a short LinkedIn post or blog about what you did and learned. That's your portfolio starting.
- Week 4, your first real project. Set up a basic SIEM (security information and event management) tool such as Splunk Free or the ELK Stack, feed it sample logs and practise spotting suspicious activity. Document it on GitHub with screenshots and a write-up: "How I built my first SIEM lab".
Why this matters to recruiters: I see hundreds of resumes that say "CompTIA Security+ certified". That's important. But the person with Security+ and three documented hands-on projects on GitHub is the one who gets the interview first.
Month 3: join the cybersecurity community
Cybersecurity is one of the most welcoming industries I've seen, but you have to show up.
- Weeks 1 to 2: follow 20 to 30 security professionals on LinkedIn and X. Comment with genuine questions and share what you're learning ("Just finished my first TryHackMe room on network enumeration. Here's what I learned.").
- Week 3: find local meetups, conference chapters and security groups, even if you feel you don't know enough yet. Many jobs are filled through connections before they're ever advertised.
- Week 4: pick one podcast (Darknet Diaries is brilliant storytelling) and one newsletter to stay current. Online communities like the TryHackMe and CyberDefenders Discords mean you can network globally from home.
As a recruiter, I've lost count of the people hired because someone in the community referred them.
Month 4: now get certified
Now, and only now, I'd get certified. If you haven't finished Network+, do that. Then, with no hesitation, I'd do CompTIA Security+.
In my view Security+ is still the gold standard entry-level certification. It's recognised globally, it's vendor neutral, and it covers the fundamentals every path needs: threats and vulnerabilities, security architecture, operations and incident response, and governance, risk and compliance basics. It's the one I'd do whichever path I chose.
By month four it isn't just proving you can pass a test. It validates skills you've already shown through labs and projects.
Study tools I recommend: the CompTIA Security+ preparation course on Coursera and Pocket Prep for practice questions (both partner links).
Then specialise. Based on everything you've learned in the first three months:
- SOC: CompTIA CySA+ and vendor tools like Splunk.
- Cloud security: AWS Certified Security Specialty, Microsoft's Azure security engineer certification, or Google Cloud's Professional Security Engineer. Pick the platform most in demand where you live.
Months 5 to 6: apply strategically and get hired
Week 1: fix your resume and LinkedIn. Your LinkedIn headline should say exactly what you're aiming for, for example: "Aspiring SOC Analyst | CompTIA Security+ | Home lab projects in SIEM and threat detection." Your resume should lead with projects, not just certifications, and every bullet should show what you did: "Built and configured a home SIEM lab using Splunk to detect and analyse network anomalies."
Weeks 2 to 6: targeted applications. Apply to 5 to 10 roles a week, and only roles you're genuinely qualified for: junior SOC analyst, cybersecurity analyst, IT security analyst. Don't send your resume to everything with "cyber" in the title.
For every application, find the hiring manager or the closest person you can on LinkedIn and send a short message: "Hi John, I've just applied for the SOC analyst role. I've been building hands-on experience through home labs and TryHackMe and I'd love to bring that energy to your team." Very few candidates do this, and it can be what gets you the interview.
The six-month plan at a glance
- Month 1: map your path and build your IT and networking foundations.
- Month 2: home lab, guided labs and your first documented project.
- Month 3: join the community and start building your network.
- Month 4: get Security+, then choose your specialisation.
- Months 5 to 6: sharpen your resume and LinkedIn and apply strategically.
It might feel slow to wait five months before applying. But doing it in this order is the path I've seen work. Companies want people who can do the job, not just pass a test.
Want the full plan, with templates?
The Cybersecurity Job-Ready Blueprint turns this roadmap into 9 modules, 19 tools and templates, proof projects for SOC, GRC and IAM, and a 90-day action plan.
Get the BlueprintWant a recruiter to look at your resume and LinkedIn? Get a Resume + LinkedIn Video Review: a recorded walkthrough and written fixes, no call needed.
Get more career advice like this, free
Join The Career Compass, my free newsletter. Job-search tactics, certification advice and what I'm seeing in cyber hiring, straight from a recruiter.
Subscribe freeSome links in this article are partner (affiliate) links. If you buy through them I may earn a commission at no extra cost to you. It never changes what I recommend.