September 12, 2026
How I Went from Teaching to Cybersecurity
I was a teacher, not someone who grew up around computers. A teacher.
By Saijalpreet Kaur
7 min read
I didn't even have a laptop until 2022. And now I have my OSCP+, I'm building a career in cybersecurity, and I'm writing this from a life that looks nothing like the one I had 3โ4 years ago.
This is a tutorial and an honest story of how I got here- the decisions, the breakdowns, the moments I almost quit, and what I'd tell someone standing where I stood.
The Life Before
I don't talk about this much, but context matters.
Teaching was my identity. It wasn't just a job- it was who I was. I was good at it. I could take something complex and make it click for someone. I could read a room and know who was lost and who was pretending not to be.
But something wasn't right. I felt like I was shrinking. The days started blending together. I was helping everyone else grow but I had stopped growing myself. And I couldn't shake this feeling that there was something else I was supposed to be doing- I just didn't know what it was yet.
Where it began
I have friends in tech and for years I have sat with them and heard their stories and plans about career and never really felt curious enough to learn what they do but one day out of sheer existential crisis, I did and it was the best idea. They guided me on a path I would have otherwise felt- and at times did feel- completely lost on.
I started watching introductory videos. Then reading. Then I went down rabbit holes at 2 AM. The more I learned, the more I realized- this is what learning is supposed to feel like. Not forced. Not structured by someone else. Just pure, relentless curiosity.
The problem? I knew absolutely nothing. I didn't know what Linux was. I didn't know what a port was. I didn't even know what "the terminal" meant.
But I knew how to learn. Teaching gave me that.
The Decision
Deciding to switch careers is terrifying. You're giving up stability, identity, a version of yourself that people already know and accept.
I understand when we begin to explore cybersecurity- red teaming, white hat, blue team and what not- we see tons of people already doing it on Instagram, LinkedIn, Twitter. People with computer science degrees and 10 years of experience. And suddenly we feel like we're not capable enough, or that the market is too saturated to even enter.
Maybe. Yeah, maybe it is. But so is anything and everything else.
I decided I'd rather fail at something that excites me than succeed at something that doesn't anymore.
Sometimes I still feel that I will never be able to keep up, today AI/LLM is the hot tea, tomorrow needing knowledge of something completely else will be.
Starting from Absolute Zero
I got my first laptop in 2022. Let that sink in. Everyone talking about cybersecurity had been coding since they were 14 and I was learning what a file path was. No wait, Oh yeah, how to open a terminal. lol.
The first thing I had to accept- painfully- was that I couldn't start with the cool stuff. I couldn't start with hacking. I had to start with understanding what a computer actually does.
Here is the list of videos or things I did:
- Computer & Technology Basics Course for Absolute Beginners https://youtu.be/y2kg3MOk1sY?si=6bDDN9b42mtj0_HC
- Introduction to Programming and Computer Science https://youtu.be/zOjov-2OZ0E?si=Ck-QqHqn-dKCMUsS
- TCM Helpdesk course (IT IS FREE)
Then I installed Linux on a virtual machine. I'd never seen a terminal in my life. (I started with Kali not Ubuntu bcz it got GUI and I was a noob)
- Linux 101 by TCM- you can even watch this now if you want
- OvertheWire: Bandit (IT IS A GAME VERY VERY USEFUL)
- Python by Mosh Hamedani or by TCM- both are good
- Make projects (search youtube make them side by side or Github for idea)
- LiveOverflow- his videos are different, he doesn't spoon-feed you. He makes you think. Honestly some of them went over my head at first but they planted seeds that clicked months later.
- PicoCTF videos by John Hammond- these are gold for beginners. He walks through CTF challenges and explains the logic so well. PicoCTF itself is a great starting point if you want to feel like you're "hacking" early on without drowning.
- Practical Ethical Hacking (PEH) by TCM Security- this was a big one. It tied everything together. Networking, Linux, scanning, exploitation, AD basics- all in one course. If you're going to do one paid course early on, make it this one.
- TryHackMe- only videos are boring. I chose TryHackMe.
- Pre-security and cyber security 101 paths
One thing that kept me sane when I was drowning in "what do I learn next"- roadmap.sh. They have a cybersecurity roadmap that visually lays out what to learn and in what order. When you're self-teaching and there's no syllabus and no teacher telling you what comes next, having one path to follow instead of 50 YouTube recommendations is everything.
Nobody talks about this part. The first 2 months were brutal. I constantly felt stupid. I Googled things that felt embarrassingly basic- "what is SSH," "how to copy a file in Linux".
Finding My Footing
After foundations, I moved into actual security concepts.
- Next step, start solving rooms, first room will feel so confusing but do it with walkthroughs.
What I have found is that doing builds this memory that just watching tutorials doesn't.
I did every room. Took ugly, messy notes in Notion. Understood maybe 60% of what I was doing. That was enough.
Also- and I'm not ashamed to say this- I used ChatGPT and Gemini a lot during this phase. To understand. When a concept wasn't clicking from a video or a blog, I'd paste it into a chat and say "explain this to me like I've never seen it before." I used them to organise my messy notes, break down difficult topics, and sometimes just to figure out what I should be learning next. They didn't replace the doing, but they made the learning less lonely.
I also polished my Python during this phase- not to become a developer, but because every exploit I downloaded was a .py file and I couldn't even read it.
Understanding the Web
Here's the thing nobody warned me about- you can pop shells on boxes all day, but if you don't understand how a web application actually works under the hood, you're going to hit a wall. I hit that wall.
So I took a detour. A long, humbling one.
I started with PortSwigger Web Security Academy- it's free, it's browser-based, and the labs are genuinely excellent. SQL injection, XSS, authentication flaws, access control- I did them all. Some I breezed through. Others made me want to throw my laptop out the window (Honestly, I would have but I only had one laptop).
First time you see burp suite requests, that's when it clicks.
- The Web Application Hacker's Handbook (2nd edition) โ you will not understand or complete all of it, yeah no you won't. It is 900 pages, a brick. Useful brick tho, can also throw at someone's head. Pick topics from index and make yourself familiar with it, don't go page by page.
- OWASP Testing Guide- it's dense and very reference-heavy, not something you read cover to cover like a novel.
PentesterLab- it's really good and real world focused. A little expensive so touch it a bit later in your journey. Also when you get those little badges after completing specific concepts? Straight dopamine.
This phase was quieter than the others. No flashy shell pops. No dramatic breakthroughs. Just me, a browser, and a lot of reading. But it filled in gaps I didn't even know I had.
Honestly? This was even harder than basics because it required me to sit down and read stuff.
Getting Serious
After TryHackMe, I moved to HackTheBox and Proving Grounds. And I got destroyed. These platforms don't hold your hand. I'd stare at a machine for two hours and have absolutely nothing.
That's when a friend told me to watch IppSec on YouTube. I'm not exaggerating when I say this single person changed my trajectory. He records himself solving HackTheBox machines, but the magic isn't in the solution- it's in how he thinks. I watched his Linux, Windows, and AD walkthroughs on repeat when I was preparing for OSCP+. First passively, then side by side while solving the same boxes on my own screen.
My approach to boxes became a system, I have posted separately about it. https://medium.com/@workwithsaijal/what-actually-helped-me-pass-oscp-6a31fb3844e0
The Final Push
I would like to clear that first I gave eJPT then CNPen, solved CTFs, started preparing for PJPT and then I started preparing for OSCP+.
It took multiple months, lots of practice, crying, almost giving up, 50+ existential crisis, never feeling prepared enough then I finally gave Pen- 200 and passed!!
If I map it out, here's what the journey actually looked like:
- Wrestling with the decision to leave teaching
- Learning what a computer actually does- networking, Linux, Windows
- LiveOverflow, John Hammond, PEH by TCM- building the foundation
- TryHackMe, Python, popping my first shell
- PortSwigger, WAHH, OWASPunderstanding the web
- PentesterLab- bridging labs and real exploitation
- HackTheBox, IppSec, Proving Grounds- getting destroyed and rebuilding
- Active Directory, priv esc, building my own methodology
- Passed eJPT and CNPen in 2025
- PEN-200 course + labs, exam simulations
- OSCP+ exam- passed
- Started bug bounty on HackerOne
What Teaching Actually Gave Me
People assume switching from teaching to tech means you're starting from nothing. That's wrong.
Teaching taught me how to learn things I had no background in, break them into pieces, and sit with confusion until it becomes understanding. That's literally what penetration testing is- you're given a black box, you pick it apart, you figure out how it works, and you write a report explaining what you found.
Teaching taught me patience. And stubbornness. And how to explain something complex to someone who's never seen it before- which, by the way, is half of writing a good pentest report.
I didn't leave teaching behind. I brought it with me. It just looks different now. Maybe your current experience gives you an edge you don't yet know.
What I'm Doing Now
Something I want to say to anyone reading this who thinks they need to "finish learning" before they can get hired- you don't. While I was still in the middle of all this, I was fortunate enough to land an internship and then a job. I was learning and working. And honestly? Being inside a real company taught me more about what to actually focus on than any course or box ever did. You see what matters in practice. You see what clients care about. You understand where your skills fit.
Don't wait until you feel ready. You won't. Apply anyway.
I have been doing bug bounty on HackerOne. Real companies. Real targets. No walkthroughs, no hints, no flags waiting at the end.
But here's what I know: the methodology I built- from TryHackMe to PortSwigger to HackTheBox to the OSCP exam- that's what gives me the confidence to sit down and try. I'm not guessing anymore. I have a process. It's messy and it's mine, but it works.
This isn't a finished story. I'm still in it.
From not owning a laptop to OSCP+ to helping real companies. It wasn't fast. It wasn't glamorous. It was lonely and confusing and exhausting. But it was mine.