Cybersecurity has a certification problem. The problem is not that certifications are useless. Many of them are valuable. The problem is that people often collect them without deciding what kind of work they actually want to do.
I’m Nigel Roberts, CISSP, a cybersecurity advisor and mentor with more than 20 years of experience across information technology and security. I regularly speak with career changers, students and experienced IT professionals who have spent money on credentials but still cannot explain which role they are targeting.
Start with the work, not the certification
Cybersecurity is not one job. A security analyst, cloud security engineer, governance specialist, penetration tester, incident responder and security architect may all work in the same field, but their daily responsibilities are very different.
Before buying another course, read real job descriptions. Pick ten roles that sound interesting and compare them. Look for repeated responsibilities, tools and experience requirements. Pay attention to the work described, not just the title. Employers use titles inconsistently.
Ask yourself a few honest questions. Do you like troubleshooting technical problems? Do you enjoy writing policies and explaining risk? Are you comfortable working through incidents under pressure? Do you prefer building systems, reviewing evidence or advising leaders? Your answers will narrow the field faster than another broad certification guide.
Use your current experience as an advantage
You do not need to erase your previous career to enter cybersecurity. IT support experience can lead toward security operations, identity management or endpoint security. Network administration can support a move into network defense or security engineering. Software development can lead toward application security. Audit, legal, privacy, project management and business operations experience can support governance, risk and compliance work.
The strongest career changes usually connect existing credibility to a security problem. Starting from zero is rarely necessary.
Build a role-specific skills map
Once you choose a target, create a short list of the abilities that role requires. Separate them into three groups: skills you already have, skills you can demonstrate soon and skills that require longer experience.
For a junior security operations role, that map might include networking basics, Windows and Linux logs, identity concepts, alert investigation and concise incident notes. For governance work, it might include risk assessment, control frameworks, policy writing, evidence review and communication with business owners.
This map should drive your learning plan. If an activity does not close a real gap for the target role, it probably should not be your priority.
Choose certifications with a purpose
A certification can help when it validates knowledge employers repeatedly request, gives structure to a new subject or strengthens a believable career story. It is a poor investment when it duplicates what you already know or has no connection to the roles you are applying for.
Do not confuse passing an exam with being ready to perform the job. Employers also need evidence that you can investigate, build, document, explain and make reasonable decisions. One relevant credential plus strong practical evidence usually tells a better story than a long list of unrelated acronyms.
Create proof of work
Practical evidence does not need to expose confidential employer information. You can document a home lab, write a short incident analysis, review a public security architecture, create a risk register for a fictional business or explain how you would secure a small Microsoft 365 environment.
Keep the work focused. A hiring manager should be able to understand the problem, what you did, why you made those choices and what you learned.
Make your résumé and LinkedIn tell the same story
If your target is cloud security, your résumé, projects, headline and recent learning should point in that direction. If every section presents a different identity, recruiters have to guess where you fit. Most will not take the time.
A clear profile does not mean pretending you have experience you do not have. It means selecting the most relevant truth from your background and presenting it in a way that supports your target.
Set a 90-day plan
Choose one target role, one or two skill gaps, one practical project and a realistic networking goal. Review progress every two weeks. If the market evidence changes, adjust the plan. Do not change direction every time a new certification appears in your feed.
You can find more background and advisory resources at https://nigelrobertsadvisory.com/. I also share professional updates on LinkedIn at https://www.linkedin.com/in/nigel-roberts-cissp/. If you want focused guidance on your own path, visit https://buymeacoffee.com/nigelroberts.
The goal is not to collect the most credentials. The goal is to become a credible candidate for a specific kind of work.
