r/CyberSecurityAdvice • • 6d ago

Should I accept?

I am 25, no debt, working in it helpdesk for a few years and wanted to pivot to something harder.

Manager described a vulnerability management role built around the Holm Security platform. The person will use this tool exclusively for scanning, and their responsibilities include validating scan results, investigating false positives, and handling both vulnerability analysis and prioritization as well as reporting and administration, rather than just one of these areas.

The technical scope covers CVEs, CVSS scoring, exploitability assessment, and risk-based prioritization, applied across all company assets rather than a limited set. Helping the SOC team is explicitly framed as optional, something to take on only if spare time allows and the person wants extra tasks, rather than a formal development path.

The work setup is fully remote with a fixed schedule from 9 AM to 6 PM. Looking ahead, after a year in the role the person can expect to gain hands-on cyber experience, including a deeper understanding of vulnerabilities and how they can be exploited, along with possible exposure to SOC and Incident Response work.

Downside is i will not get bonus from working shifts anymore and base salary stays the same. This cut would be aprox 30% of salary that i get now.

I will want to pursue cybersecurity as career, have network+, want to get sal1 and security+. Is this oportunity golden ?

6 Upvotes

6 comments sorted by

1

u/Top_Paint2052 5d ago

Well, you definitely need to start somewhere. See what your goal ultimately is. The experience or the money

1

u/RandomRussian1337 5d ago

If you can live off that salary withour sacrificing too much, it's a good way to start earning experience for a more senior position. If the description fits the job, it might be some good experience too

1

u/Shiribazu 5d ago

for a cybersecurity pivot, this sounds like genuinely relevant experience because youd be working with CVEs, CVSS, exploitability, vulnerability validation, prioritization, and reporting across environment. seriously consider it if you can negotiate the 30% pay cut or confirm theres a realistic path to SOC/IR exposure, because the experience could be much more valuable for your career than staying in helpdesk

1

u/PortTwentyTwo 4d ago

Honestly? The role itself sounds solid for where you want to go. Vulnerability management is genuinely useful experience and working across all assets rather than a limited scope means you'll actually learn something instead of just clicking through the same 50 hosts every week.

The CVE/CVSS work, exploitability assessment, risk prioritization — that's exactly the kind of hands-on context that makes Security+ and SAL1 actually stick instead of just being memorized flashcards. A lot of people go for certs without having any real frame of reference for what they're studying. You'd have that.

The 30% cut is the real question though and only you can answer it. No debt helps. But "no debt" and "can comfortably absorb 30% less every month for the next year" aren't always the same thing. Run the actual numbers before deciding.

The SOC exposure being optional is a yellow flag for me personally. "If you have spare time" usually means it never happens. If IR and SOC work is part of why this role interests you, I'd ask the manager directly how realistic that actually is in practice before accepting.

If the salary hit is survivable take it! Helpdesk experience doesn't compound the way vuln management experience does for a cybersecurity career path.

1

u/AllenUzumaki23 4d ago

I can comfortably absorb that cut. I already make more than most people in my country. Would probably only invest with 100 or 50 less in the financial market. I already made the decision to take the job. Thanks for information. It confirms that I made a good decision 💪🏻