You can get into cybersecurity without a degree by replacing the degree with three things employers can check: demonstrable skills, a recognised entry-level certification, and some form of real experience, even if it is unpaid or adjacent. The degree is a proxy for “this person can learn and stick at something”. Your job is to give hiring managers better evidence than the proxy.
That is harder than having the degree, not impossible. This guide covers which roles are most open to non-graduates, what to learn, how to build proof, and how to handle job adverts that say “degree required”.
Do you really need a degree for cybersecurity?
For many technical roles, no. Security work is judged on what you can do: read a log, harden a server, find a vulnerability, write a clear report. A degree in computer science helps, but it does not teach most of that directly, and many working practitioners came in through IT support, the military, self-study or a career change.
Where a degree still matters:
- Some large employers and governments use it as a hard filter, especially for graduate schemes.
- Visa and immigration routes in some countries consider qualifications.
- Certain senior or academic roles, such as research, cryptography or some consulting positions.
Where it matters less:
- IT support and helpdesk.
- SOC analyst roles.
- Junior GRC and compliance roles, especially if you have related work experience.
- Penetration testing, where practical skill and reputation carry a lot of weight.
The NICE Workforce Framework for Cybersecurity, published by NIST, describes security work in terms of tasks, knowledge and skills rather than qualifications. It is a useful way to see how many distinct roles exist, and that most of them are defined by what you do, not what you studied.
Which cybersecurity jobs hire people without a degree?
These are the most realistic first roles, roughly in order of how open they tend to be to non-graduates.
| Role | What you do | What gets you hired |
|---|---|---|
| IT support / helpdesk | Fix user issues, manage accounts and devices | Customer skills, Windows/Linux basics, networking basics |
| Junior SOC analyst | Triage alerts, escalate incidents | Log analysis, SIEM practice, Security+ or similar |
| Junior GRC / compliance analyst | Policies, risk registers, audit evidence | Writing, organisation, framework knowledge, adjacent experience |
| Vulnerability management analyst | Run scanners, track and chase fixes | Scanner practice, patching knowledge, persistence |
| Junior penetration tester | Test systems with permission, write reports | Strong lab portfolio, write-ups, practical certifications |
Penetration testing is at the bottom for a reason. It is the role most beginners want and the one with the fewest true entry-level openings. Many testers start in support, SOC or development first. If you want the step-by-step version of the whole journey, our roadmap for getting into cybersecurity with no experience covers it in detail.
What should you learn first?
Skip the urge to start with hacking tools. Everything in security rests on three foundations, and interviews test them constantly.
1. Networking
Know how data moves. IP addressing and subnetting, TCP vs UDP, DNS, DHCP, common ports, what a firewall and a proxy do. You should be able to explain, in plain language, what happens when someone opens https://example.com.
2. Operating systems
Be comfortable on Windows and Linux command lines. A few commands worth practising until they are automatic:
# Linux: who am I, what’s listening, who logged in
$ whoami
analyst
$ ss -tulpn | head -4
Netid State Recv-Q Send-Q Local Address:Port Peer Address:Port Process
udp UNCONN 0 0 127.0.0.53%lo:53 0.0.0.0:*
tcp LISTEN 0 4096 0.0.0.0:22 0.0.0.0:*
tcp LISTEN 0 511 0.0.0.0:80 0.0.0.0:*
$ last -n 3
analyst pts/0 192.168.56.1 Sat Oct 10 09:12 still logged in
analyst pts/0 192.168.56.1 Fri Oct 9 18:40 - 19:02 (00:21)
reboot system boot 6.8.0-45-generic Fri Oct 9 18:39 still running
# Windows (PowerShell): local admins and recent failed logons
PS> Get-LocalGroupMember -Group “Administrators”
ObjectClass Name PrincipalSource
----------- ---- ---------------
User LAB-WS01\Administrator Local
User LAB-WS01\labadmin Local
PS> Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625} -MaxEvents 3
The last command lists recent failed logons (event ID 4625), and needs an elevated prompt. Run it in your own lab after deliberately mistyping a password a few times.
3. Security fundamentals
The CIA triad, authentication and authorisation, encryption and hashing, common attack types (phishing, password attacks, malware, web attacks), and the basics of incident response. The MITRE ATT&CK knowledge base is a free, structured way to learn how real attackers behave.
Which certifications help most at entry level?
Without a degree, a certification does a lot of signalling work. It tells a recruiter that an independent body has tested you. Pick one or two, not five.
- CompTIA Security+ (SY0-701) is the most common entry-level security certification. Its five domains run from General Security Concepts to Security Program Management & Oversight, with Security Operations the largest at 28%. It is up to 90 questions in 90 minutes, with a passing score of 750 on a 100–900 scale. See CompTIA’s Security+ page for current details, including the upcoming next version.
- CompTIA Network+ (N10-009) if your networking is weak or you are aiming for infrastructure and support roles first.
- CompTIA A+ if you have never worked in IT and want a helpdesk job.
- Later: CySA+ for SOC work (check CompTIA’s site for the current version), PenTest+ (PT0-003) for offensive work, or GRC-specific qualifications for compliance roles.
Two cautions. First, a certificate is not a certification: a course completion certificate shows you finished a course, while a certification is an exam-based credential from a certifying body that employers can verify. Second, no certification guarantees a job. It gets your CV past filters; your skills and evidence get you through the interview. Our guide to the best cybersecurity certifications for beginners covers the order in more depth.
Never use exam dumps. They breach the exam provider’s rules, can get your certification revoked, and leave you unable to answer the first technical interview question.
How do you get experience without a job?
This is the real problem, and there are honest ways round it.
Build a home lab and document it. A free VirtualBox setup with a Kali Linux VM, a Windows VM and an Ubuntu server on a private network such as 192.168.56.0/24 is enough. Install a SIEM such as Wazuh, generate events, and write up what you found.
Practise on deliberately vulnerable apps. OWASP Juice Shop is a free, intentionally insecure web application you run locally. Solving its challenges and writing up how you did it is genuine evidence. Only ever attack systems you own or have written permission to test.
Volunteer. Small charities, schools, religious organisations and family businesses often have no security help at all. Setting up multi-factor authentication, backups and a basic password policy for one of them, with their permission, is real work you can describe in an interview.
Use your current job. Whatever you do now, there is probably a security angle. An accounts assistant can map who has access to the finance system. An admin officer can draft a clean-desk and data-handling policy. Ask your manager if you can take it on.
Play capture-the-flag (CTF) events. Beginner-friendly CTFs teach practical skills and give you something to discuss. Write up the challenges you solve after the event ends.
How do you get past “degree required” in job adverts?
Many adverts list a degree as a default, not a real requirement. A few tactics:
- Read the whole advert. If it says “degree or equivalent experience”, apply.
- Apply anyway if you meet most of the other requirements. Recruiters often screen on skills first.
- Lead your CV with evidence. Put a “Projects” or “Labs” section above education, with links to write-ups. Our guide to writing a cybersecurity CV with no experience includes a sample layout.
- Use referrals. A message from someone inside the company often bypasses the filter entirely. Engage genuinely in local security meetups and online communities before asking for anything.
- Target smaller companies and managed service providers. They tend to care more about what you can do on day one.
A realistic six-month plan
Illustrative example, not a real student: someone working full-time in retail, with no degree and no IT job, studying around eight to ten hours a week.
- Months 1–2: networking and operating-system basics. Build the home lab. Learn 20 common ports and what runs on them.
- Month 3: security fundamentals. Start Security+ study using the official exam objectives as a checklist.
- Month 4: hands-on practice. SIEM lab, OWASP Juice Shop, two or three CTFs. Publish one write-up a fortnight.
- Month 5: sit Security+. Volunteer to secure one small organisation’s setup.
- Month 6: rewrite the CV around projects, apply for helpdesk and junior SOC roles, keep publishing.
Six months is not a promise. Some people take longer, especially with family or work pressures, and that is fine. Consistency beats intensity.
FAQ
Can I become a penetration tester without a degree? Yes, many have. Expect to build a strong portfolio of lab work and write-ups, and consider starting in support or SOC to get your first security job on your CV.
Is cybersecurity hard to learn without a technical background? It is learnable, but the first few months feel steep because networking and operating systems are new. Once those click, security concepts build on them quickly.
Are bootcamps a replacement for a degree? A good one can replace some of the structure and teaching, not the credential. Judge any programme by how much hands-on lab work it includes and who teaches it, and avoid any that promise jobs.
What is the best first certification without a degree? For most people aiming at security roles, Security+. If you have no IT background at all, start with networking or A+ material first.