August 27, 2026
If I Had to Start Over Today, Iโd Do These 5 Things
Not the most comprehensive path. The fastest one to employable.

By Manubhav Sharma
3 min read
If I woke up tomorrow and had forgotten everything I know about cybersecurity, my goal wouldn't be to relearn all of it.
It would be to get hired as fast as possible.
Those are different goals. And most students are accidentally optimising for the wrong one.
The typical approach goes like this: collect resources, cover as much ground as possible, do labs on every topic, stack certifications, feel more prepared before applying.
Months go by. The knowledge base grows. The interview calls don't come.
The problem isn't effort. It's that scattered effort doesn't compound the way focused effort does.
Here's exactly what I'd do if I had to start from zero.
1. Pick a destination and make every decision point back to it
Cybersecurity has a dozen directions you can go. SOC analyst. Threat hunter. Incident responder. Penetration tester. Cloud security. Digital forensics.
Trying to prepare for all of them at the same time means you're preparing for none of them properly.
Pick one. For most people reading this, that means SOC analyst, the most accessible entry point with the most open positions at the junior level.
Once you've picked it, every learning decision gets one filter: will this help me investigate alerts, analyse logs, or understand incidents?
If the answer is no, it can wait. Not forever. Just until you're employed.
The goal isn't to understand cybersecurity. The goal is to become employable in a specific role. Those require different paths.
2. Build one thing you can explain confidently in an interview
Most students build ten small labs. One Nessus scan here, one Wireshark capture there. A TryHackMe room. A port scanner script.
None of it adds up to a story.
What actually works is one complete investigation you can talk through from start to finish.
Set up a scenario. Generate some activity in a lab. Collect the logs. Investigate what happened. Write up your findings. Put it on GitHub.
That project becomes the answer to "tell me about something you've worked on" in every interview. It shows you can start with a question, follow the evidence, and reach a conclusion. That's exactly what the job is.
Ten half finished labs don't give you that. One documented investigation does.
3. Rewrite every resume bullet as an outcome
Most resumes read like a software inventory. Tools listed. Platforms listed. Certifications listed.
None of it says: this person knows how to think.
Go through every bullet on your resume and ask one question: what problem did I solve?
"Used Splunk for security monitoring" doesn't answer that question.
"Investigated suspicious authentication activity in Splunk, identified repeated login failures targeting multiple accounts, documented findings, and recommended preventive controls" does.
Both can come from the same lab. The second one makes a hiring manager read the next line. The first one doesn't.
Rewrite until every bullet describes an investigation outcome, not a tool you touched.
4. Start applying before you feel ready
This one is uncomfortable to say but it's probably the most practically important.
Most students are waiting for confidence before they start sending applications. The problem is that confidence doesn't arrive before experience. It arrives because of it.
Interviews give you feedback. Rejections give you feedback. Even getting a call and performing poorly gives you information about what to fix.
The students who get hired fastest are almost always the ones who started applying while they were still learning, not the ones who waited until they felt fully prepared.
You don't need to be ready. You need to be in motion.
Apply somewhere this week. Track what happens. Adjust. Apply again. Treat the process like an investigation: collect data, notice what's working, change what isn't.
5. Practise explaining your thought process out loud
This is the gap that kills otherwise strong candidates in interviews.
At some point you'll get a question like: "How would you investigate a suspicious login alert?"
The interviewer isn't listening for tool names. They want to hear you reason through a problem. What would you check first? Why? What does that tell you? What's the next step? How do you decide when you've seen enough to make a call?
Most students know the answer in their head. They struggle to say it clearly under pressure because they've never practised it.
The fix is simple. Once a week, pick a scenario like a phishing alert, a failed login, a suspicious process and talk yourself through the investigation out loud. What would you look at? What would each piece of evidence tell you?
Do this ten times before your first interview and you'll answer technical questions better than candidates who have more experience but have never practised explaining their reasoning.
The one thing I'd cut completely
I wouldn't spend a single week in the first three months doing anything that didn't directly support getting hired in a SOC role.
No rabbit holes. No "interesting" topics that aren't relevant yet. No certification for the sake of having another line on the resume.
One destination. One investigation project. One resume that shows how I think. Applications starting from month two.
That's the path. It's shorter than most people think because most people are making it longer than it needs to be.
If you want a structured path that builds analyst thinking from the ground up, the Cybersecurity Foundations course is built around this approach. Real scenarios, investigation-first, no tool walkthroughs.
๐ Cybersecurity Foundations Course
Want to talk through your specific situation, where you're stuck, what to focus on next?
๐ Career Clarity Call
For a weekly breakdown on building a cybersecurity career that moves forward:
๐ Join the newsletter
โ Manubhav Sharma Threat Analyst at Sophos ยท Follow on LinkedIn