StoryCareer Editorial
Published Aug 3, 2026 · 1 min read
I moved from a retail job into security analysis through free labs, homelab practice, and a first role that paid less than my old job but taught me everything.
I had zero technical background when I started learning about security. What drew me in was the puzzle-like nature of it: each alert was a question, and I wanted to get better at answering them quickly.
Breaking in was the hardest part. Security roles wanted experience, and experience required a security role. The courses I took covered theory, but I had never triaged a real alert or written an incident report.
I practiced in free platforms and built a small home lab where I generated my own alerts and wrote reports about them. I applied for an entry-level monitoring role that was underpaid but gave me real tickets, and I spent my evenings turning that hands-on experience into skills I could talk about.
I review alerts in the morning, investigate anything that looks abnormal, and write up findings for the team. A few times a week I help update detection rules based on recent incidents.
Theory will not get you hired, evidence will. Set up a lab, create realistic incidents, and document what you did and what you found. Be honest about what you know and be relentless about the part you find fun.
After eight years in corporate jobs, I left to build a small software product. It failed twice before I found something people were willing to pay for.
I started a weekly newsletter about marketing experiments. Two years later it pays a meaningful part of my income — and it taught me more than any job.
My first product was a two-person build with an eight-week deadline. I learned that writing the spec was the easy part — the hard part was saying no.