Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More

Owned by Marius

MP Cyber Security Community

15 members • $22/month

Break into cybersecurity with a CISO in your corner. Weekly live Q&A, career path study groups, CV reviews, and every skill matrix included

Skoolers

160.9k members • Free

73 contributions to MP Cyber Security Community
Most Juniors Face This 👇
Every junior cybersecurity candidate eventually hits the same wall: "requires 2-3 years of experience" on an entry-level posting. It's a genuine paradox. You can't get experience without a job. You can't get the job without experience. And nobody sits candidates down to explain how to actually break that cycle. Here's what I tell people directly, because I don't think this gets said enough. Experience isn't defined by a job title on a payroll. It's defined by demonstrated capability. A home lab where you deployed a SIEM, wrote detection rules, and validated them against simulated attacks is experience. A documented cloud security project where you found and fixed real misconfigurations is experience. A mock ISO 27001 gap analysis you ran against a fictional company is experience. The mistake most career changers make is separating these into a vague "Projects" section at the bottom of their CV, treated as an afterthought. Don't. Present them with the same structure you'd use for a job: what you did, what tools you used, what the outcome was. Action, proof, impact. A hiring manager reading it shouldn't be able to tell whether it came from a paid role or a self-directed project, only whether it demonstrates the skill the posting actually needs. I want to be honest about something else too. The "2-3 years required" line is very often written by HR as a filter, not a hard requirement from the hiring manager. I have interviewed and hired candidates with zero professional cybersecurity experience specifically because what they'd built on their own told me more than a generic CV with the "right" years attached to it ever could. This doesn't mean the barrier isn't real. It is. But it's not the closed door it appears to be from the outside. It's a door that opens for people who can prove capability in a language hiring managers actually read: specific, demonstrated, documented work. If you're stuck in this exact paradox right now, my advice is simple. Stop waiting for permission to call your work "experience." Build it, document it properly, and present it with the confidence of someone who already knows it counts.
0
0
Most People Breaking into Cybersecurity Has Been Sold A Lie
Here is my post from LinkedIn today, this is the reality that most people face, because they keep falling for certificate marketing, hopefully guys and gals, i can remove that barriers for you and pave the way into successful cyber career that will change your life forever: Entry-level cybersecurity is broken, and marketing built most of the cracks. Search "how to get into cybersecurity" and you'll find the same promise repeated endlessly: this ONE certificate, this ONE course, this ONE shortcut, and a 6-figure entry-level role is waiting for you. It sells because it's exactly what someone desperate for a way in wants to hear. The reality looks nothing like that. And the gap between the promise and the reality is exactly why roughly 8 out of 10 people trying to break into this industry never make it to their first role. I see the same question constantly: what's the best certificate, what's the fastest path. Wrong question. There is no fastest path, and chasing one is precisely what stalls people for years instead of months. Here's what actually determines who gets hired. Solid fundamentals. Networking, operating systems, how systems actually communicate. Not memorised for an exam, understood well enough to explain simply. Hands-on skill, not theoretical knowledge. The difference between reciting a concept and demonstrating it under pressure is the difference that shows up in every technical interview I've ever run. And above almost everything else, a real personal project portfolio. I have watched a candidate with one certification and a documented home lab beat a candidate with four certifications and an empty GitHub, consistently, without exception. A portfolio proves capability. A certificate proves you passed an exam. None of this is a popular message, because it's slower and harder than "buy this course, get this job." But it's the honest one, and honesty is in short supply in this part of the industry right now. If you're early in this journey, or mentoring someone who is, this is worth saying plainly: stop looking for the shortcut. Build the fundamentals. Build the proof. That is the only path that has ever actually worked.
2
0
Do Not Think You Are Alone
I know all of you are on different paths, different starting points, but you all have one thing in common - goal to build a credible cybersecurity career. Whatever the reason might be why you have made that decision, improve your life, provide for your family and maybe kids, i can honestly tell you, that starting a cyber security career has been the best decision i have made in my life Not only it has completely transformed my life, but brought tremendous opportunity to be on the biggest stages in the world, become board advisor for a number of cyber security companies, run ISACA webinars, watch my mentees land their first ever cyber roles and so much more You have some great dedicated people in this community which hopefully with just go from strength to strength, but remember aside from the live Q&A and guide documents, use people around you as your accountability to keep showing, showing your progress and sharing what you have learned because validation and uplifting those around you can give you a tremendous boost I know some of you might be doubting yourself, whether this is the right call, because this career starting journey is never easy and believing in yourself is probably the most important part, because if you don't how can you expect others to You are doing great, keep grinding, keep showing up and I am here to help you get there
The Troubles People Face When Starting Their Cyber Journey
If you have not seen this video it's worth a watch, because i witness this pretty much every single day!
1
0
Issue #6 — The GitHub Portfolio Checklist (What Hiring Managers Look For in 30 Seconds)
🔥 THIS WEEK'S INSIGHT: The 30-Second Test I have 200 applications. I click maybe 60% of the GitHub links. Of those, I decide whether to look further in 30 seconds. This isn't a metaphor, it's roughly how long I actually spend before deciding your repo is worth more of my time. Here's the exact checklist I run, whether I realise I'm running it or not. Profile level, before I even open a repo: - Is there a profile README? (Most candidates don't have one, and it's the first thing that appears on your GitHub homepage) - Is the profile picture professional? - Are the pinned repositories your BEST work, or just your most recent commits/ Repository level, for whichever project I click into: - Does the README exist, and does it load without broken images? - Is there an architecture diagram, and is it the first thing I see, before any text? - Is the code organised into logical folders, or dumped in the root directory? - Is there a "What I Learned" section that's specific, not generic? - Is there a "What I'd Improve" section at all? That last one matters more than people realise. I've changed my opinion of a candidate specifically because of a well-written "What I'd Improve" section. It shows self-awareness and growth mindset in a way that a perfect-looking project never can. The fastest way to test your own portfolio: ask a friend outside cybersecurity to look at your top repo for 30 seconds, then explain back to you what it does. If they can't, your README isn't clear enough, even a non-technical reader should understand the WHAT and WHY, even if not the technical HOW. 📰 ONE THING HAPPENING IN CYBERSECURITY THIS WEEK Two new videos went up this month that connect directly to this issue. "5 Cybersecurity Certifications You Should Avoid in 2026" makes the case that the money spent on the wrong certification is almost always better spent building the exact kind of portfolio this issue describes. And "Why I'd Choose GRC Over Pentesting in 2026" shows that even in a non-technical path like GRC, a documented risk assessment or mock audit in your portfolio carries the same weight as a technical project does for an engineering role. The 30-second test applies no matter which path you're on.
1
0
1-10 of 73
Marius Poskus
4
74 points to level up
@marius-poskus-7032
Cybersecurity leader with over 10 years of experience helping others to advance their career and land their first cybersecurity job

Active 1h ago
Joined Dec 10, 2025