With no previous IT employment, no relevant degree, no U.K. citizenship and only a self-study background, Gleb Tumanov, CC, secured his first SOC role after 30 days of active searching and submitting 12 applications. He shares his strategic approach to job hunting and understanding of how employers hire.
Disclaimer: The views and opinions expressed in this article belong solely to the author and do not necessarily reflect those of ISC2.
Three problems undermined my early job search. I quickly realized they reinforced one another.
The first problem was a mismatch between my expectations and reality. Training providers and career influencers often paint a more optimistic picture of the market than reality justifies, promising rapid career progression and high demand.
One example illustrates the consequences well for me. In the U.K., many cybersecurity roles, particularly in government and defense, require candidates to be eligible for security clearance, which generally means having lived in the U.K. for at least five years. As someone who had recently moved to the U.K. to build a career, I found this to be a major and completely unexpected obstacle. It was the kind of information I wish I’d known before choosing a course of study, rather than after submitting my first applications.
The second problem was automation. As is well known, candidates increasingly use AI to generate CVs and cover letters and to submit applications while, in turn, recruiters use AI to screen applications and automate communication. The result is that both sides often end up interacting more with machines than with people. Response rates decline, hiring processes become noisier and real indicators of candidate fit are easily overlooked.
When I encountered this problem, my first instinct was to solve it by using even more sophisticated automation. What I found eventually is that the opposite approach worked better: in a recruitment process saturated with automated content, showing up as a real person became a competitive advantage.
The third problem was unreliable vacancy data. Job boards aggregate listings from multiple sources without consistently removing duplicates or verifying whether positions are still open. A single vacancy may appear several times through different recruitment agencies, while some listings are outdated or were never genuine opportunities to begin with. Search filters often return loosely related roles, while commercial ranking algorithms prioritize sponsored listings over the most relevant ones. I wasted a considerable amount of time before recognizing these patterns.
What struck me was that all three problems had the same solution. Rather than relying on career influencers, passive scrolling and high-volume applications, I adopted a more disciplined, open intelligence-led approach, built on verified information, targeted applications and sincere human interaction.
Phase One: When The Most Important Work Is Done
Through a random search across different job platforms, I began by collecting 30 active job postings for my target role (SOC Analyst), specifically roles in my target location. At this point my goal was not to find a job, but to understand what employers were actually looking for.
From each job description, I logged every requirement into a spreadsheet: educational background, certifications, technical skills, security tools, soft skills and any other recurring criteria. The process only took a few hours. Its value became obvious almost immediately; patterns emerged very quickly. When a certification, technical skill, or qualification appeared repeatedly across different vacancies, it provided a much more reliable picture of employer expectations than any marketing material from training providers or career influencers.
The next step was to evaluate myself with the same level of rigor. I used the 5W1H framework to analyze myself: who I was professionally, what I could genuinely offer, where I wanted to work, when I would realistically be ready based on employer expectations, why I had chosen cybersecurity and how I planned to get there.
The exercise exposed several uncomfortable truths. What had initially felt like readiness turned out to contain some gaps that only became visible through a structured, reflective assessment. It also helped me understand what I expected from my future employer and why, what I could realistically offer in return and at what stage of my professional development I could do so.
By the end of this process, I had two things: a realistic picture of what employers were looking for and an equally realistic understanding of what I could offer. Where my profile aligned with market requirements, I had the confidence to apply. Where gaps existed, I had a choice: either to invest time in closing those gaps by developing new skills and earning the relevant certifications, or to adjust my expectations about the roles I was realistically ready to secure.
Phase Two: Replacing The Algorithm-Driven Feeds with A Curated List of Verified Opportunities
I found a list of organizations certified by the UK's National Cyber Security Centre (NCSC) and used that directory to build a list of legitimate cybersecurity employers. It eliminated many of the problems I had encountered earlier, such as duplicate listings, outdated vacancies and questionable recruitment agencies.
Rather than searching only for vacancies, I searched LinkedIn for people already working as SOC Analysts, noting where they were employed. This gave me another list of organizations that had previously recruited for the role I was targeting, including companies that were not actively advertising positions at the time.
I organized this information using a simple Kanban board with three columns: Prospective, Active and Closed. For each organization, I recorded available roles, salary ranges, key requirements, application dates and the status of my application. Rather than waiting for vacancies to appear on job boards, I checked company careers pages directly and regularly; in many cases, employers published openings on their own websites before they appeared elsewhere.
Routine helped:
- On Mondays I updated my list of target employers and checked for newly advertised roles.
- On Tuesdays and Thursdays I submitted applications, finding them less susceptible to the post-weekend backlogs or pre-weekend wind-downs.
- Wednesdays and Fridays were reserved for developing the technical skills needed to close the gaps identified earlier.
At this stage, practical work proved far more valuable than pursuing additional certifications. Building home lab projects, completing hands-on exercises and sharing my results and journey on LinkedIn gave me tangible evidence of my skills. More importantly, they provided concrete examples to discuss during interviews, making it much easier to demonstrate real-world ability to do the work than simply listing another certificate on my CV.
Phase 3: Engaging With the Community
My job search only started working once I stopped doing it alone. When I tried to manage everything in isolation, both the preceding phases were less effective. The groups and networks I’m part of shared and updated job opportunities, consistently finding openings faster than I could on my own: a vacancy mentioned, a hiring manager’s name, who was actively hiring – such signals circulated through people and communities.
I didn’t set out to “build a network” or promote myself but, in practice, I became more involved in the community: I attended BSides and CSides events, along with being a member of the Cyber Security Society at the local university. I was a Founding Member of the School of SOC and a member of the South West Cyber Security Cluster.
Most value came from informal conversations. With people earlier in their journey, I worked on CTF preparations and shared experiences around certifications and job searching. With more experienced practitioners, discussions focused on employer expectations and the industry landscape and particularly on what entry-level roles entail and which paths are realistic. Some connections later became professional references.
What I gained most from the community was less about formal opportunities and more about useful context: honest feedback on how my profile looked from the outside, early signals about roles before they were advertised and access to people willing to vouch for me. Just as importantly, I noticed that the way people communicated in this space was very similar to how I later had to communicate in interviews and on the job.
Conclusions
The difficulty I faced entering a cybersecurity career path turned out to be less about a shortage of roles and more about a systemic disconnect in how recruitment communication works. Treating the job search as an analytical challenge rather than a volume exercise consistently produced better results for me.
Yes, my approach requires rigor, honest self-assessment and a deliberate up-front investment of time. But the understanding it created didn’t expire once I’d secured my role. A clear picture of the job market, a structured view of my own profile and a network of engaged peers have remained useful beyond the search itself.
Done this way, job searching was not separate from preparation for the work, it was part of it.
Gleb Tumanov, CC, has 10 years of experience in digital marketing and project management. He held management roles, with responsibility for leading strategic projects and overseeing cross-functional communication across multiple teams. His cybersecurity work spans incident investigation, SIEM detection refinement and strengthening organizational threat response.
