A degree is not the barrier most people assume. What employers check is whether you can do the work, and there are faster ways to show that.
Updated 2 October 2026
When a posting lists a degree, it can be a filter for a large pile of applications rather than a hard requirement. What a hiring manager actually wants to know is whether you can be trusted near their systems and whether you learn quickly. A degree is one way to signal that. It is not the only one.
The things that carry weight instead:
Before you study anything, read ten postings for the roles you want and note what they ask for. Where a degree is listed with the words or equivalent experience, that is your opening. The skills that appear in most of the postings are your study list.
Many people do. Entry-level monitoring roles tend to ask for networking and operating-system knowledge, familiarity with security tools and logs, and often a foundational certification. A degree helps in some postings but is rarely the only route. Check the specific postings you are aiming at.
It depends on the role you are aiming for. Our guide comparing Security+ and CEH walks through how to choose.
A course gives you structure and a syllabus, but it is rarely enough by itself because employers want to see that you have applied what you learned. Treat training as the start of your evidence — add lab work, write-ups and a project — rather than a substitute for it.
Order matters because each layer makes the next one easier to understand.
The first modules of our Ethical Hacking course follow roughly this order: networking fundamentals including the OSI model and subnetting, then Linux and the command line, then web application and API security. That makes it a structured way through the early layers even if your target job is defensive.
To be straight about it: the course takes the attacker's view, which is useful for understanding what you will be defending against, but it is not a security operations analyst programme. If you are not sure the field suits you, the Ethical Hacking Starter is the cheaper way to find out.
A project is evidence. Aim for two or three small ones that you can explain in detail, rather than a long list you cannot talk through.
Only test systems you own or have written permission to test. That is the line between security work and a crime, and interviewers will ask whether you understand it. Practise in your own lab or on purpose-built practice targets, never on someone else's website or network.
Lead with a short summary naming the role you are aiming for, then put a projects section above your work history. For each project, say in one or two lines what you did, which tools you used and what you found.
Translate your existing experience. IT support shows you handle incidents and users. Customer service shows you stay calm and explain things clearly. Any job that touched access control, records or compliance is relevant, so describe it in those terms.
List certifications you hold or are working towards, with dates, and link to your write-ups. Keep it to one or two pages and echo the wording of the posting wherever that is honest.