Skip to content
Security Notes

Breaking into security without a degree

By Elias Lankinen10 min read

The paradox at the front door

In the summer of 2025, a mid-sized managed security provider posted an opening for an "entry-level SOC analyst." The listing asked for three years of hands-on experience, a bachelor's degree "preferred," and two certifications. Within a week it had drawn several thousand applicants. That single posting is a decent snapshot of the whole strange landscape someone faces when they try to break into cybersecurity today: an industry that says, loudly and constantly, that it is desperate for people, guarded by a door that feels bolted shut to anyone new. The desperation is real, and the numbers behind it are large. The most-cited figure, a global shortfall of roughly 4.8 million workers, comes from ISC2, the nonprofit that runs the CISSP certification and surveys the field every year. But here is the first thing most articles get wrong: that record 4.8 million gap was the headline of the 2024 study. In the 2025 ISC2 Cybersecurity Workforce Study, based on 16,029 practitioners surveyed in July and August 2025, the organisation stopped publishing a gap number altogether. It concluded that the shortage is no longer mainly about headcount. It is about skills. That distinction matters enormously if you are trying to get in without a degree.

Source: UMD-Eskin, University of Maryland, via Wikimedia Commons
Source: UMD-Eskin, University of Maryland, via Wikimedia Commons

Why the "shortage" and the "wall" both exist

The comforting story is that a 4.8 million shortage means an open door for anyone willing to learn. The honest story is that the shortage is concentrated in the middle and senior ranks, while the bottom rung, where newcomers actually stand, has become brutally crowded. The 2025 ISC2 study makes the shift explicit. 59% of respondents reported critical or significant skills gaps on their teams, up sharply from 44% the year before, and 95% named at least one skill their team was missing. The most-wanted skills were not "willing to learn" but specific and advanced: AI (41%), cloud security (36%), risk assessment (29%), and application security (28%). At the same time, 36% of teams had had their budgets cut, and 33% said they lacked the money to staff adequately. For the first time, ISC2 found that budget, not a lack of qualified people, had become the top driver of understaffing. Read those two facts together and the paradox resolves. Organisations want people who can already do hard, specific things, and they have less money to train anyone who can't yet. That is why a junior role can attract thousands of applications while a cloud-security engineering role sits open for months. The gap is genuine. It is just not where beginners are standing. The demand for a degree, meanwhile, has genuinely softened. The US Bureau of Labor Statistics still lists a bachelor's degree as the typical entry credential for information security analysts, but it now explicitly notes that "some workers enter the occupation with a high school diploma and relevant industry training and certifications." ISC2's research has found that a large majority of hiring managers will consider candidates whose only background is general IT work, and many rank one to three years of hands-on experience above a degree for junior roles. The credential is no longer the gate. The problem is what has replaced it.

What the job actually pays, and how many jobs there are

Before going further, it is worth grounding the ambition in real numbers, because cybersecurity marketing tends to inflate them. According to the BLS, information security analysts had a median wage of $129,180 per year in 2025, well above the median for all occupations. There were about 192,900 such jobs, and the bureau projects the field to grow 21% between 2025 and 2035, roughly three times the average across the economy, with about 14,100 openings a year once you count both growth and replacement. Two caveats keep that from being a fairy tale. First, "information security analyst" is one BLS category; it does not capture the full messy sprawl of penetration testers, GRC analysts, and SOC staff, and it skews toward established, mid-career roles, which is part of why the median looks so high. Second, 14,100 openings a year is a healthy number, not an infinite one, and a meaningful share of those openings expect experience a first-timer doesn't have. The money is good. The runway to reach it is longer than the ads suggest.

Source: Buyerlerdeqalardim, via Wikimedia Commons
Source: Buyerlerdeqalardim, via Wikimedia Commons

The credential that still opens doors

If a degree is optional, certifications are how you signal competence without one. The single most useful entry credential is CompTIA Security+, and the reason is bureaucratic as much as educational. Security+ is one of the certifications the US Department of Defense accepts under its 8570 directive and its successor framework, 8140, the rules that govern who is allowed to touch DoD systems. In plain terms: a huge number of government and defense-contractor jobs legally require staff to hold an approved cert, and Security+ is the entry-level one that satisfies the most work roles. That single fact turns a $425 exam into a key that unlocks an entire category of employers who cannot hire you without it, degree or no degree. The certification is valid for three years. For someone starting from zero, there is a gentler on-ramp: the Google Cybersecurity Professional Certificate on Coursera, which costs roughly $294 for six months of access, requires no prior experience, and takes most people about six months at 5 to 10 hours a week. Google reports that 75% of US graduates see a positive career outcome, a new job, raise, or promotion, within six months, and it maintains a consortium of more than 150 employers who agree to consider its graduates. That 75% figure deserves a skeptical eyebrow: Google's own framing concedes it describes people who did more than finish the course, who also built portfolios, networked, and kept studying. The certificate is a foundation, not a finish line. A word on the misconception that a bootcamp or a stack of certs is a shortcut. It isn't. Certs prove you have a vocabulary and can pass a standardised test. What follows is the part that actually gets people hired.

Proof beats paper

The most important shift for degree-free candidates is that this field, more than almost any other white-collar profession, lets you demonstrate skill rather than assert it. You do not need an employer's permission to start doing the work. The standard path runs through hands-on platforms. TryHackMe offers structured, guided rooms that teach fundamentals step by step; Hack The Box drops you into deliberately vulnerable machines with far less hand-holding and rewards independent problem-solving. Recruiters hiring for SOC and junior penetration-testing roles increasingly recognise both, and a public profile showing consistent activity or a respectable ranking functions as evidence in a way a GPA never could. Beyond them, PortSwigger's free Web Security Academy teaches web vulnerabilities directly from the company that makes the industry-standard testing tool. Then there is the home lab, which costs nothing but time. A laptop, free virtualisation software like VirtualBox, a copy of Kali Linux, and a few intentionally broken target machines are enough to practise attacks and defences safely on your own hardware. The lab is also where you generate the raw material for a portfolio: write-ups of how you compromised a box, a script you wrote to automate a tedious task, a short analysis of a piece of malware you detonated in isolation.

Source: Barnacl437, via Wikimedia Commons
Source: Barnacl437, via Wikimedia Commons

For the offensively inclined, bug bounty programs on platforms like HackerOne and Bugcrowd let you legally test real companies' systems and get paid for genuine findings. A single accepted, well-written vulnerability report can say more to a hiring manager than a résumé line, because it is proof, timestamped and independently validated, that you found something real that a paying company cared about. This is also where the ISC2 data quietly reassures the newcomer. When the 2025 study asked hiring managers which qualities they valued most, the top answers were not exotic technical skills but problem-solving (29%), collaboration (24%), and communication (22%). A portfolio demonstrates the first. A clear write-up demonstrates the last. Those are learnable without a classroom.

The side doors: IT, help desk, and apprenticeships

The most reliable route into security is often not a security job at all. In the 2025 ISC2 study, 56% of professionals said they had entered the field through an IT pathway first, moving from help desk, system administration, or networking into a security specialisation. That is not a consolation prize; it is arguably the strongest foundation, because you cannot defend infrastructure you have never operated. A help-desk role that pays modestly and teaches you how real networks break is frequently a faster on-ramp than another certification. Notably, that IT-first pattern is weakening among younger entrants. Among professionals under 30, ISC2 found the split was even: 38% came in through IT, and an equal 38% arrived from non-IT backgrounds entirely, finance, the military, teaching, retail. The door is widening for people whose first career had nothing to do with computers. Apprenticeships are the most underused route of all. In 2022, the US Departments of Labor and Commerce ran a 120-Day Cybersecurity Apprenticeship Sprint to expand registered apprenticeships, programs where you are a paid employee learning on the job under a formal training structure. The country started that sprint with 714 registered cybersecurity apprenticeship programs and about 42,260 apprentices, and the push added 194 new programs. For someone who cannot afford to study unpaid, an apprenticeship inverts the usual bargain: instead of paying for credentials and hoping they lead to income, you earn income while the credentials accrue. Community is the multiplier on all of this. Capture the Flag competitions, the puzzle-hunt contests where teams race to exploit deliberately vulnerable systems, run constantly online and at conferences like DEF CON, and they double as both training and networking. Many people's first job offer comes not from an application portal but from someone they met solving a challenge, answering a question in a Discord server, or presenting a small finding at a local meetup.

What AI is doing to the bottom rung

The hardest question hanging over all of this is whether the traditional entry point is quietly closing. The classic first job in defensive security is a Tier 1 SOC analyst: the person who watches alerts, triages them, and escalates the real ones. That work, alert triage, initial investigation, log correlation, is also the most repetitive and therefore the most automatable part of security. The consequences are already visible. Gartner has projected that 75% of security operations centres will deploy AI analysts by 2026, and at some leading organisations AI agents now handle nearly all Tier 1 triage. In one survey cited across the industry, 56% of cybersecurity professionals said AI had somewhat or significantly reduced the need for entry-level positions over the previous year. Demand for senior analysts and threat hunters, meanwhile, keeps climbing. This creates what practitioners have started calling the pipeline paradox. Senior analysts have to be grown from junior ones, but if the junior rung automates away, there is no obvious place for the next generation to gain the reps that make a senior. Nobody has solved this yet, and it is the single biggest reason to be clear-eyed rather than starry-eyed about the field. The likeliest outcome is not that entry-level work vanishes but that it moves up a level: the newcomer who succeeds will be the one who can supervise and tune the automation, not the one who does by hand what the automation already does faster. That raises the bar for getting in, which loops back to why proof, a portfolio, a lab, a real finding, matters more every year.

What to watch

Breaking into security without a degree is not the myth its boosters sell or the impossibility its skeptics claim. The degree requirement really has eroded; the BLS and ISC2 both confirm it. But the thing that replaced it, demonstrable, specific, current skill, is in some ways a harder standard to meet than sitting through four years of coursework, because there is no attendance credit for effort. You are judged on what you can show. The open question is what happens to the first rung. If AI keeps eating Tier 1 work and companies keep declining to fund training, the field risks pricing out exactly the motivated, degree-free newcomers it claims to need, and starving its own future senior ranks in the process. The most interesting thing to watch over the next few years is not the salary numbers or the shortage headlines. It is whether employers, faced with a pipeline they are automating shut, decide to rebuild the entry rung deliberately, through apprenticeships and real junior roles, or whether they let it close and wonder, five years later, where all the seniors went.


Sources

  1. ISC2, 2025 ISC2 Cybersecurity Workforce Study, 2025.
  2. US Bureau of Labor Statistics, Occupational Outlook Handbook: Information Security Analysts, 2025.
  3. Infosec Institute, CompTIA & DoD 2025: 8140 vs. 8570 Explained, 2025.
  4. Google / Grow with Google, Google Cybersecurity Professional Certificate, 2024.
  5. US Department of Commerce, US Departments of Labor, Commerce Announce 120-Day Cybersecurity Apprenticeship Sprint, 2022.
  6. TryHackMe, How to Build a Cybersecurity Portfolio That Gets You Hired, 2025.
  7. Coursera, How to Get Into Cybersecurity Without a Degree, 2025.
  8. Simbian, Will AI Replace SOC Analysts in 2025? The Future of Cybersecurity Roles Explained, 2025.
  9. ACSMI, Will AI Replace Entry-Level Cybersecurity Jobs?, 2025.
  10. Medium (7yr4n7), The Cybersecurity Job Market in 2025: The Harsh Reality No One Wants to Admit, 2025.