Issue #9 — Your Old Job Is Your Unfair Advantage

Cyber Security Career Newsletter

Hey,

Issues #1 to #8 covered the fundamentals: your first week, interviews, home labs, LinkedIn, certifications, GitHub, AI security, and why most people quit. This issue starts a new run, and I wanted to open it with the topic I get asked about more than almost anything else in my DMs.

"I've spent ten years in a completely different career. Am I starting from zero?"

No. And the fact that so many people believe they are is costing them interviews.

🔥 THIS WEEK'S INSIGHT: Stop Burying Your Previous Career

Here's the pattern I see on CVs from career changers almost every week. Fifteen years of real working experience gets squeezed into a vague "Employment History" section at the bottom. At the top sits a half-finished Security+ and a home lab from last month. As if the first fifteen years of their working life didn't happen.

I understand the instinct. You assume this industry only values industry experience, so you hide everything else. But that's not how hiring actually works, at least not when I'm the one doing it.

When I hire for a GRC role, I don't just want someone who knows what ISO 27001 is. I want someone who can write clearly, handle a stakeholder who disagrees with them, and stay calm auditing something that's obviously broken. When I hire a SOC analyst, I want someone who stays methodical when everything around them is noisy. Most career changers already have those skills. They just don't describe them in a language I recognise.

Here's what that translation actually looks like:

Teaching → Classroom management under pressure is incident triage. Lesson planning is policy writing. Making thirty people care about something they find boring is security awareness training.

Finance or accounting → If you've prepared for a financial audit, you already understand most of what a security audit requires. Segregation of duties is least privilege under a different name.

Project management / PMO → Roughly half of GRC work is project management: running an ISMS rollout, a compliance programme, a risk remediation timeline. This is one of the most direct and underrated transfers into the field.

IT support / help desk → Account provisioning and password resets are literally IAM tasks. You've been doing entry-level identity work without the title.

Military or law enforcement → Chain of custody in an investigation is the same principle as chain of custody in digital forensics. Following procedure under pressure transfers with almost no translation.

Healthcare → You already understand data sensitivity, need-to-know access, and regulatory consequences better than most technical candidates. Healthcare compliance is a specialised, well-paid GRC niche.

None of this means pretending your old job was secretly a cybersecurity job. It means being specific about which skills carry over, and saying so plainly instead of hoping the interviewer connects the dots for you. Most won't.

📰 ONE THING HAPPENING THIS WEEK

A member of the community, Sam, set up his LinkedIn properly using the guidance inside and posted about his project work. It was his second ever post. A hiring manager messaged him about a senior role.

I share this not because it'll happen to everyone, it won't, but because it shows what happens when you make your skills visible instead of assuming nobody's looking.

🛠️ FREE TOOL OF THE WEEK: The Cyber Career Path Assessment

What it is: A 3-minute assessment at path.mpcybersecurity.co.uk. You tell it your previous career and answer 16 questions about how you actually like to work. It recommends one specific cybersecurity path, explains what from your background already transfers, and gives you three concrete steps for this week.

Why it matters: This does the translation in this issue automatically. If you're a teacher, a nurse, or a project manager and you're not sure which of the seven paths suits you, this is the fastest way to find out.

Cost: Free. No signup to see your result.

💡 CAREER ADVICE FROM THE HIRING TABLE

A transferable skill only counts if it's written as evidence, not as a claim.

"Strong communication skills" tells me nothing. Everyone writes it.

"Delivered compliance training to 200 staff annually and reduced policy breaches by a third" tells me you can run a security awareness programme. That line belongs on a GRC CV with the same weight as a certification, because in an interview it often carries more.

Use the same Action + Proof formula I use for technical projects: what you did, the evidence it worked, and the result. It works just as well for skills you built in a completely different industry.

🎯 YOUR ONE ACTION THIS WEEK

Pick one bullet point from your previous job on your CV. Rewrite it in cybersecurity language using the Action + Proof formula above.

Not your whole CV. One line. Then read it back and ask yourself honestly: would a hiring manager in your target path recognise this as a skill they need?

🧰 THREE FREE TOOLS, IF YOU HAVEN'T TRIED THEM YET

I've built three free tools that each solve one specific problem people get stuck on:

🧭 Find your path: path.mpcybersecurity.co.uk — your background and working style turned into one recommended path, with your first three steps.

📊 Check your skills gap: skills.mpcybersecurity.co.uk — see exactly where you stand against your target role, so you stop guessing what to study next.

🧠 Practise for Security+: practice.mpcybersecurity.co.uk — 200 exam-style questions, weighted like the real exam, with a full explanation on every answer.

All free. No signup required to see your results.

🔜 WHERE THE TOOLS STOP, THE COMMUNITY STARTS

The tools can tell you which path fits, where your gaps are, and which questions you're getting wrong. What they can't do is look at the CV line you rewrote this week and tell you whether it actually lands.

That's what the CTRL+ALT+DEFEND Community on Skool is for.

Weekly live Q&A, direct with me. Bring your rewritten bullet point, your career question, whatever's blocking you.

CV and portfolio reviews from someone who reviews real applications for a living, including how to present your previous career so it counts.

Study groups by career path, so you're working alongside other career changers heading the same way.

Every digital product I've built, included, including the Career Changer Workbook, skill matrices, lab guides, and the CV template.

I'm not going to promise it guarantees you a job. Nobody honestly can. What I can promise is direct, ongoing access to someone who has hired people from every background listed in this issue.

One plain note on pricing: $22/month is underpriced for what's inside. It's moving to $39/month permanently, and the first 30 members keep $22 for as long as they stay.

👉 Join here: https://www.skool.com/cybersecurity-careers-guide-1773/about

If you've been introducing yourself as "starting from scratch," stop. You're not. You're starting with years of skills that need a new vocabulary, not a blank page.

Reply to this email and tell me your previous career. I read every one.

See you next week.

Marius Poskus Global VP of Cybersecurity / CISO CTRL+ALT+DEFEND

Next
Next

Issue #8 — Why 8 Out of 10 People Quit (Plus: A Launch)