is this you?
Cybersecurity Analyst
You defend an organization's systems — watching for intrusions, hunting down alerts, patching the holes before someone walks through them. High demand and a real mission, wrapped in more routine than the movies admit. Honest picture below.
Median pay (US)
~$108k / yr
Degree required?
No — certs + labs count
What the job actually is
Security analysts monitor and defend: triaging alerts from detection tools, investigating suspicious activity, managing vulnerabilities, running phishing defenses, and writing up incidents. Entry seats are often in a SOC (security operations center) working a queue of alerts — genuinely important, genuinely repetitive. From there the field fans out: incident response, threat hunting, cloud security, GRC (the compliance side), and eventually red-team work if you want to be the attacker.
Is it actually you?
You'll probably love it if
- You think like an adversary — you see how things could be abused
- Calm under pressure is your superpower
- You like continuous learning; threats change monthly
- Detail-checking that would bore others feels like a hunt to you
- A mission (protecting people) matters to you as much as pay
Maybe not, if
- You need constant novelty — SOC work has grinding stretches
- On-call and incident nights would wreck you
- You want to build things more than defend things
- Compliance paperwork sounds unbearable (it's a real share of the field)
The real day-to-day (no hype)
- Entry level is a queue. Your first year is likely alert triage — lots of false positives, strict procedure. It's the apprenticeship of the field; the interesting work is earned through it.
- "Talent shortage" has an asterisk. The shortage is in experienced people. Entry-level is competitive, and the door usually opens from IT — help desk or sysadmin first, security second.
- Certs are currency here. Unusually for tech, certifications genuinely move hiring: Security+ to enter, then CySA+/GCIH/OSCP depending on direction. Budget for them like tuition.
- Incidents don't keep office hours. When something's burning, you're on. Many roles have on-call rotations; ask about them in interviews, not after.
How people break in — or switch in
The reliable path runs through IT: help desk → sysadmin/network admin → security analyst, with Security+ earned along the way. You can compress it with home labs (TryHackMe, HackTheBox), documented investigations, and visible curiosity — hiring managers love a lab writeup more than a résumé keyword. Military and law-enforcement backgrounds transfer surprisingly well; so does any job where you followed procedure under pressure.
IT support → securitySysadmin → securityMilitary → security
Security hires trust and judgment as much as skill. A history of being the careful, reliable one — in any field — is evidence. Tell that story.
Your application, already half-written
Here's a question every Cybersecurity Analyst application asks, answered the way pirch would — in a real voice, grounded in real experience:
“Tell us about a time you found something others missed.”
Working help desk, I noticed three password-reset requests in one week from the same department, each "from" a manager who was traveling. Policy said reset with manager email approval, and the emails looked right — but the display names didn't match our directory format. I escalated instead of resetting. It was a targeted phishing campaign, and we caught it before any account fell. That's why I want to move into security formally: I already do the noticing, I want the training and the tools to do it at scale.
pirch's co-pilot writes answers like this for
your background and the exact job —
try it free →
pirch finds the security roles that are actually you
Tell pirch who you are — your labs, your certs, your IT background — and it hunts down real, still-open security jobs that fit the whole you, with a tailored cover letter already written.
start your free hunt
first hunt free · we never auto-apply · you stay in control
Common questions
Do I need a degree for cybersecurity?
No — certifications, home labs, and IT experience are the accepted currency. Security+ is the standard entry cert; a documented lab portfolio often beats a general degree.
How much do cybersecurity analysts make?
US median around $108k, with entry SOC roles starting near $68k and experienced analysts, incident responders, and cloud security engineers reaching $155k+.
Can I get into cybersecurity with no IT experience?
It's hard directly. The realistic route is 1–2 years in IT support or sysadmin work while earning Security+ and building labs — then security roles open. Trying to skip that step is the most common way people stall.
Is cybersecurity stressful?
It has two speeds: routine monitoring and compliance most days, genuine adrenaline during incidents. On-call rotations are common. People who like calm-procedure-plus-occasional-fire tend to love it.