Ask HN: Looking to Break into Cybersecurity – Where Do I Start?

13 points by OulaX 20 hours ago

I have a degree in Computer Science and currently work as a frontend web developer.

I live in a developing country where there’s no shortage of software developers who build systems for both personal and governmental use. However, many of these systems have serious gaps when it comes to security.

What’s really missing here are skilled cybersecurity specialists. From a career perspective, I see this as an opportunity to grow locally and contribute where there’s a real need.

That said, I’m not sure how or where to begin. I’ve done some research, but getting started in cybersecurity doesn’t seem as straightforward as in other fields.

I’d really appreciate any advice or tips on how to get started and move in the right direction!

0xCE0 10 hours ago

The obvious answer of course is that to be "cybersecurity specialist/expert", you have to be a hardcore hacker in its original meaning: to be a person who understands what things actually are (behave), not what people say they are (behave).

In my opinion, cybersec/infosec expertise/mindset should be always-on on everybody at 2025. Starting from scammers calling/messaging, to malware/spyware on devices, social engineering, physical security, people security/trustworthyness, trust/auth/integrity/encryption/backups/certs/audit-trail etc... Everything. One needs to know if one is hacked already ("Reflections on Trusting Trust.pdf"), and one needs to know when one is hacked (tripwire). And knowing what is/are your weakest link(s), because it usually defines the strength of your defences.

mettamage 10 hours ago

hackthebox.eu - hack 20 boxes on your own, a mix between easy and medium. Be sure to focus more on Windows than Linux. Then start applying for jobs at corporations. Do a double approach: just apply and do your best to network with people in the field by sending them a message that you want to switch over to the field as well. Keep on hacking and networking and eventually you'll land a job.

That's how a friend did it. To be fair, he's Dutch and did this with Dutch companies. So not sure if this would work in your country.

fedorvin 17 hours ago

Sine you already know frontend, I would recommend starting with burpsuit and web exploitation. The issue with cybersec is that there are just too many things you can/need to learn, so the best thing would be to start with the area you already know something about.

https://portswigger.net/web-security is a great resource to get you started.

Good luck!

re-thc 19 hours ago

> I live in a developing country where there’s no shortage of software developers who build systems for both personal and governmental use. However, many of these systems have serious gaps when it comes to security.

i.e. is there actually demand for Cybersecurity? A gap is not the same as demand. Maybe it shows they just don't care.