← All talks

How to Land Your First Cyber Role: A DIY Approach

BSides Exeter · 202615:504 viewsPublished 2026-05Watch on YouTube ↗
Speakers
Tags
CategoryCareer
DifficultyIntro
StyleTalk
About this talk
A practical guide to breaking into cybersecurity without relying on expensive bootcamps or formal credentials. Gleb Tumanov shares his DIY strategy for landing a first cyber role: conducting market research to filter noise, assessing skill gaps, building a targeted application database, and leveraging community networks to accelerate the job hunt.
Show transcript [en]

Yeah. Uh thank you for coming guys. I'm so excited. How many people do we have today? Uh because today we will have a very important topic and it will be practical talk because yeah I can speak with you about different things. I can speak about like rocket science about AI about quantum computers but in the end of the day what's a point of this talk if we do not have an access to the job market if we can find uh the job so we have 20 minutes and let's discuss and in the beginning I would like to make a small introduction about who am I uh before I came to the UK I had very

multi-disiplinary uh experience. So for example, I was involved in some marketing processes, in some financial processes, in a lot of different processes, but at the same time, it was nonIT background. And when I found the huge passion to cyber security especially to the blue teaming 2025 I was in the UK I realized that I should start from the scratch from the absolutely ground zero because I hadn't any professional connections I hadn't any images in my head about the market so I start my learning path and I was not a student of the university so it was uh absolutely DIY learning path and I studied a lot. I did a lot of home labs. I uh and you know these names like

try hack me hug the box let's defend all of these things and at the same time I prepared for some professional certifications plus I was involved in some activities of local communities in university community or for example southwest cyber security cluster and after these 12 months uh I realized that now I'm well prepared for the job hunt and It was not just you know the provision it was the part of the strategy and why we should create some strategy um because we already have a lot of uh websites we have a lot uh we had of a lot of published vacancies from link in from Indeed from all of this but at the same time I would like to say that

yeah where is the previous slide Yeah. Uh that's something is happened with the market and I mean that we have a lot of noise on the job market and what does it mean? It means that uh we do not have right now an access to the real verified vacancies and this noise produced by a lot of different actors for example by scammers by bots by unresponsible recruiters whatever. But the main thing that uh we need to understand here that we should somewhere or somehow to filter all this noise. And my suggestion is to use asin filter. Uh and yeah we speak about as it's like open source intelligence but at the same time our approach will be very simple

and as the result of uh this research which I made it was this one. So it was one month of hard research and I had 12 job applications and I was invited to the three interviews and I received one offer. Some of you uh can think that it's something unreal because where is the funnel with thousand job applications? Where is the months of the research? But I would like to say that is not so much necessary because how we spoke before we need some filter for the job market and it's pretty easy. So we will not have some repetitive phrases. We will not have some very overgineered and over um s um like very sophisticated things.

It will be just two phrases preparation and action. And it's very important to understand as a junior specialist we should be very proactive because we are much more interested and much more uh much more worried about the roles about the jobs than companies and it means that we should be proactive and when we start with the preparation phase why we should make our market research because uh we have a lot of different actors on the market and some influencers, some bloggers, some vendors and they try to push us to do something to learn something to buy something but do we really need these certificates? Do we really need these boot camps uh for thousands and thousand pounds? I'm not

sure because what we really need we can understand only through our own research and it's not again it's not something very sophisticated I mean that you should open link it in or indeed and just copy paste from 30 40 vacancies related to your professional path uh all the job requirements to the simple notepad and in the end after one or two hours you will have a huge list of all the requirements and you will see some patterns because companies like 25 companies they will ask you about the certificate A like 15 companies they will ask you about certificate B and like 10 companies will ask you about some specific skills and it will be your

baseline and uh it will be much more easier to understand what you need to achieve and when you finished this part with the outer research. Let's start in the research ourself and probably it will be much more difficult uh than um uh research the market because sometimes it can be very tough uh because um sometimes we even do not know what we want and here you have an example of my answers but uh I would would like to say that you should be more detailed more concrete because yeah obviously who am I like I'm gtoman but at the same time we should speak about the background we should about we should speak about the interest skills about our previous

experience or for example we can say uh I'm looking for sock analyst L1 role but uh is it forever uh for example uh what do you expect from yourself in the next like 2 three four five years what is your motivation what is your goal so put as much as possible information to these uh questions because more information you will have you uh more visibility you will uh have next and when you finish uh out um out research and inner research you will have the next slide assessment of chances. So it means that you can make a compare how you are aligned to the market requirements. And for example, if market if they ask you A, B,

C and D and you have only A and B, it means that probably you should spend some more time for preparation. And yeah, you still have a chances to to secure the role, but at the same time, the main important thing to increase your chances. But if you find that everything fine and you have like a lot of certificates, you have a lot of knowledge and you are really ready for the job hunting, let's go. And the first phase is action phase. But before we start to do something, it's very important to create the space where we would uh organize all the data and where we can uh manage all our things from the research. And my suggestion is

just use the simple to-do list and the first uh column will be database. So the uh all all the companies uh their cards. Second one it will be in progress. It means that for example we if we have some interaction with uh the company for example we send uh our um cover letter or CV just put this cards to this uh column and the third one is decision like uh rejection or for example they will offer something for us and uh what is the main difference between ordinary to-do list and uh our database that we will operate with the cars with the cars of the companies and We try to enrich these cards as much as possible. So we

just collect all the data about the role and it means like salary, place, role, all details which you even can find and when you finish this preparation phase, you are ready to the next chapter. And the next chapter is about the collection data. And I would like to show you the gold mine and because yeah we know that somewhere and somehow you can find the gold but where and I would like to share share with you this gold mine. It calls National Cyber Security Center. And why it is a gold mine? Because they collected and they approved 440 different companies who operates in the UK in cyber security and it means that we can use filter and we can get an

access to the U proofed uh companies and the main information which we need for our database. We already have website and email. So we just go to the website and check all the information which we uh uh need and I do not know how many companies you will find for yourself. For example, I found like for me 70 different companies but uh if you think that you need another source, another source will be that link in. Yeah. And uh because Likodin is a database of existent roles, existent jobs because people they wrote about themselves that they already have these type of jobs which we just try to hunt and we just try to find sock analyst level one in

United Kingdom or for example you can filter like in London or for example in Cardiff and you will see the huge list of all of them and it means that you can just copy paste all the uh name of the companies to your database and my favorite type of the profiles top managers because they have a lot of experience and probably they already placed or placed they changed some places. So it means that from one profile you can collect like three four different opportunities and how it works. And this is example of my week in January 20206 and as you can see I did not put uh a lot of efforts and all things to one

day. I separated the activities because from my perspective of you best days for job application for applying parole sorry uh Tuesday and Thursday. So it means that we have some free days on Monday, Wednesday and Friday and what to do uh on Wednesday and Friday. My suggestion add that we should continue to studying and learning because you will have some job interviews and they will ask you some practical and technical questions. And my suggestion to do labs during this uh job hunt because uh yeah uh plus uh we should update and work with our database because uh database should be updated and refreshed by the new roles and why it works and what comes next. It

works because uh there is no any magic under the hood and uh the approach is very simple. Sometimes when we have a difficulties when we have a problem we can think that the solution can should be also very difficult and complicated but no sometimes solution can be just very easy like that because what we need we need to get an access to the market. Right. Right. And we filter uh these uh unnecessary vacancies uh from the previous slides. And right now we have an access to these uh actual jobs. Plus uh we understand our needs. We understand what we have. So we are um we we we we just can uh be align with the job market

requirements and then it's just about the interaction human with human we are with other companies and it means that we do not try to I don't know send them like thousands and thousand different applications it's just tailored cover letters tailored uh CVS and actually company like that and uh if you still not satisfied if you think that we should like do something more we need a boost for our method I have this boost and this boost is community power of the community uh because guys community is everything this is a source of inspiration this is a sort of learning and knowledge and for example uh your future employer uh they will ask you about two professional

references where you can find them in the community at the same time you have a struggle you have some ideas about your path you are not so much you have a lot of concerns and for example where you can receive the feedback again in the community because we have a lot of specialists who are very happy to share their knowledge, who are very happy to share uh their help with you. And uh what else? Uh I would like to say that guys, we should be focused. We should be curious at the same time uh be uh positive, support our local communities. And I'm pretty sure that like in this year or probably in the next one, you

will be succeed and you find your first cyber role. Thank you so much, guys. Uh if you have any questions, feel free to ask me uh in the break or add me to LinkedIn. Thank you so much.