Description:
Been on help desk for 3 years, and I’m torn between staying on my current team for a possible promotion or jumping to a junior cybersecurity role that says it wants SIEM and incident response experience. I’m getting mixed advice because I have solid troubleshooting and ticketing skills, but my hands-on security work is mostly from labs and a few internal audits. How do I position myself for the cybersecurity move without making my resume look too thin, and is it smarter to wait for a help desk to sysadmin step first or apply now?
3 Answers
Go after the junior security role now, and frame your help desk time as real ops experience with user access, phishing reports, endpoint issues, and calm communication under pressure. Pair that with labs by naming tools you used, plus one or two internal audit wins. Huge W if you can show you already think like an analyst.
Apply now. Your help desk time isn’t thin - it’s the base layer. Ticket triage, user access, endpoint weirdness, and incident-style troubleshooting map cleanly to SOC work. I watched a whole team get hired off that story because they could already think in signals, not just clicks.
help desk first, cyber later was the old corporate conveyor belt, and I would not wait for a sysadmin badge if the junior security post is already asking for SIEM and incident response. Frame 3 years as volume plus pattern recognition - 50+ tickets a week, access resets, phishing triage, endpoint fixes, audit notes - then add labs with exact tools like Splunk or Sentinel and 2-3 concrtee detections. Apply now; the promotion queue is usually just another meeting loop.
Join the conversation and help others by sharing your insights.
Log in to your account or create a new one — it only takes a minute and gives you the ability to post answers, vote, and build your expert profile.