How I skipped the line

by Brian Randall 

In 8 months’ research, I’ve found 5 pipelines for “breaking into” Cybersecurity. 

#1: helpdesk → sysadmin (or similar) → SOC Analyst 

#2: Lifelong nerd → Bug Bounty → Pentesting/Red Team 

#3: IT degree/career → Cert study → Project demonstration → SOC Analyst 

#4: Self-Study → Cert Chasing → Project compilation → build a professional network → SOC Analyst

#5: Cybersecurity degree + #4 and/or #1

5 is straightforward, degree programs are made to be concrete pathways full of support.

4 is about as straight and narrow as a toddler’s coloring.

Now, why would anyone pursue 4 over 5? Or in fact 4 over 1/2/3? 

From surveying real people’s real stories via LinkedIn, Discords, YT livestreams, Reddit, etc I’ve found that generally 

#1 takes ~5 years

#2 takes ~1-2 years (plus the lifetime of being a nerd thing) 

#3 takes ~6-8 years

#4 takes ~½ - 1 years

#5 takes ~4.5-9 years



But you could find that info on reddit somewhere, right? So here’s the wisdom I have to offer that others don’t. 

#4, the solo path as I call it– it’s not the rigor or number of unknowns that makes it difficult. It’s the way your body treats it.

Humans are supposed to fear the unknown, It’s a great way to survive. So naturally, #4 can be full of stress responses, overload, overchoice, task paralysis. But at the point of starvation, we get over it.

So how did I become an L1 SOC Analyst candidate in only ~6 months?

I got really hungry and hijacked my reward system in the process, which, admittedly, took a minute.

Through my tenure as a musician, I was always weighing the costs, the ROI so to speak. This means I had 12 years of building an argument for or against my pursuit of music. But justifying music was always a battle, and once I ran out of breakups to write about and gigs I wanted to play, I placed those questions onto Cybersecurity. 

The weight of 12 years’ constant choice-making and self-justifying suddenly shifted. All those questions like, “Does this align with my life goals?” and “Is this work I believe in?” were given green lights by cyber. 

So I tallied my successes and failures of my past career and made them into an actionable philosophy. I did well in music because I actively sought the most sustainable and effective pathway toward growth. Not money, not admiration, no– growth. Here’s the gist: 

  1. Find yourself someone you trust to guide you. Someone who’s been there, done that, and made it out successful. 

  2. Convince this person that you’re a capable mentee, prove yourself by showing actionable curiosity, not tentative interest or vague questions.

  3. List what you’re willing to sacrifice to make it happen. Cliche, grindsetty, whatever. Don’t be toxic about it. Make it sustainable, make it worth doing, but don’t kill yourself. 

  4. Forge a lifestyle around making it happen.

I assumed that people with a Cybersecurity degree had this list down pat. After all, I came out of music school with enough professional experience to hit the ground running.

When I first heard of Cybersecurity degrees, I drafted a model resume of a graduate. This is what I imagined the project list to look like:

“__ weekly escalation reports completed and peer-reviewed for __ semesters”

“Investigation report based on open-source database xyz following NIST SP 800-61 standards”

“APTxyz research and adversarial re-creation via scaled-down environment utilizing Proxmox” 

And of course 10+ certifications, naturally.

Doing some online stalking and connecting with a couple folks, I’ve found this isn’t usually the case. I’ve seen people with 4 year degrees announce that they’re planning to get Security+. 

I support this, don’t get me wrong– but the question isn’t whether they should be getting it, it’s why don’t they already have it? 

That’s the line I’ve skipped. They chose number 5. I chose 4. And they know so much more than me about so many topics. Unfortunately, those topics don’t make them any more competitive as an L1 SOC Analyst. 

Now for the plot twist– I’m not in it for SOC Analysis. I’m in it for Cybersecurity. SOC Analysis is just the perfect vessel. 

So here’s my last anecdotal wisdom for this article. 

Despite Hayden being a great source of all things helpful, I cross-reference everything he says. Not because I don’t believe him, but because I want to know why he said that. 

I’m not blindly following advice, I’m dissecting it. Extracting the essence and using it to fuel my decisions. 

So yeah, I skipped the line. 

I’m as strong a SOC Analyst candidate as many folks who have cybersecurity degrees/IT experience. 

Nothing against them, I even envy them a bit.

I’m not the guy you ask when you need to reform your organization’s GPOs. 

I’m not the guy for implementing company-wide credential rotation. 

I’m not the guy you ask to purchase and configure your network infrastructure.

But do I need those skills as an L1 SOC Analyst? 

No. 

I need to understand the concepts, maybe have the entry knowledge to guide someone through the why’s and how’s.

But I do not need the automated workflow of remotely installing printer drivers. 

I need the automated workflow of SIEM navigation and documenting investigation reports. 

And the real key– I know why I’m navigating that SIEM for that investigation. 

Read through my other articles to learn more about how I took the soft skills of a completely different profession and applied them here, letting me skip the line in Cybersecurity.

- Brian 

Brian Randall

Cybersecurity Practitioner 2026 - Present
Professional Musician 2017-2026

https://www.SolvingCyber.com
Previous
Previous

What Mentorship in Cybersecurity Should Actually Look Like

Next
Next

Why I’m Solving Cyber (Hayden)