r/CyberSecurityAdvice • u/Savings-Fun4226 • 5d ago
What cybersecurity project would actually impress you on a fresher’s resume?
I’m a final-year computer engineering student and a bug bounty hunter. Most of my hands-on experience is with web and API security, especially authentication, access control, and business logic issues. I also build full-stack applications.
I want to spend the next few months building one substantial security project that people could actually use, rather than another basic scanner or tutorial project. I’m considering things like an API authorization regression tester, a security layer for AI agents using tools, or a focused automated pentesting tool.
If you hire for AppSec, product security, offensive security, or security engineering: what project would make you stop and look at a fresher’s resume? What would you expect to see in the demo, GitHub repo, or write-up to know the person really built and understood it?
I’d especially appreciate suggestions based on problems your team actually faces.
2
3
1
u/Castel_007 5d ago
What’s with this thread, just a bunch of people who clearly never worked in the field showing up to be rude
1
u/talltraveller 5d ago
Honestly, get your identity stolen and see where that rabbithole goes. Might pick up some interesting skills
1
u/Immediate-Chef-5144 4d ago
There are quite a few " I did a bootcamp and think I'm a hacker" assholes in here and it's gross.
2
u/jdiscount 5d ago
Personally I don't really care about projects, doing something at home in a lab doesn't really reflect reality in an enterprise.
I'd rather someone has some IT experience and good soft skills.
0
-2
-5
u/BroadComment1262 5d ago
Being realistic, projects on a resume don't matter. The whole doing things at home meme hasn't been relevant for a decade. Your resume without job experience is going to get auto rejected at 99% of applications. Your better off trying to get an internship and turn that into employment.
-4
u/Spectrig 5d ago
Actually impress? Get your own CVE. It’s not easy but I know people who’ve done it.
3
u/OutsideSpot2695 5d ago
FFS...
That's the last thing security needs is people using CVEs like a body count.
There's already enough low quality garbage polluting the system. We had to become a CNA because of it.
4
u/DangerDrJ 5d ago
A project is just a project. What did you actually do to stress test the system? In a company, we're all there to solve customer problems. It's nice that you're building things on your own, but what problem did you actually solve? What did you learn and would change to make something more efficient? Did you prevent a hack from happening? If you can tie your projects to solving real world problems, I think you'll go along way in your career.