Learning Tech Skills on the Job: Thriving Without Formal Training

    May 8, 202616 min read
    Learning Tech Skills on the Job: Thriving Without Formal Training

    Learning Tech Skills on the Job: Thriving Without Formal Training

    The path to cybersecurity no longer requires a computer science degree or years of IT experience. Fritz Villanueva spent years as a nurse before becoming a threat hunter. Gina D’Addamio left bedside nursing to become a threat analyst. Mone Vines made the same transition to cybersecurity specialist. These professionals share something beyond their healthcare background: they learned the technical skills they needed while already working in the field.

    Career changers, recent graduates, and professionals entering cybersecurity without formal technical training face a common anxiety. The job postings demand experience. The technology seems overwhelming. The imposter syndrome feels real. Yet organizations across the industry are actively hiring people from non-traditional backgrounds, providing structured onboarding, and investing in on-the-job skill development. The question isn’t whether you can learn cybersecurity while working—it’s how to do it effectively.

    Why Non-Traditional Backgrounds Succeed in Cybersecurity

    The cybersecurity industry faces a persistent talent shortage. Organizations need problem-solvers, critical thinkers, and professionals who can communicate effectively under pressure. These skills transfer across industries more readily than many assume.

    Healthcare professionals bring systematic assessment methodologies. Nurses use APIE—Assess, Plan, Intervene, Evaluate—which maps directly to incident response workflows. The same framework applies to threat analysis, security operations, and forensic investigations. Military veterans understand chain of command, operational security, and disciplined documentation. Financial analysts bring risk assessment experience and regulatory compliance knowledge. Teachers excel at breaking down complex concepts and communicating with diverse audiences.

    According to hiring managers surveyed across enterprise security teams, approximately 65-70% explicitly value non-traditional backgrounds in entry-level cybersecurity roles. The reasoning is practical: diverse problem-solving approaches and resilience under uncertainty often outweigh narrow technical credentials. A candidate with weak technical skills but strong communication, documentation discipline, and learning capacity will frequently outpace a technically brilliant but isolated peer.

    The technical gap feels larger than it actually is. Most entry-level security operations roles require basic computer literacy, attention to detail, and willingness to learn specific tools and processes. The SIEM platform training happens on the job. The network architecture understanding develops through guided exposure. The threat landscape knowledge accumulates through daily alert triage and escalation.

    What Realistic On-the-Job Learning Looks Like

    The timeline matters. A junior SOC analyst typically requires six to twelve months to reach 70-80% independent productivity. Organizations with structured onboarding programs, dedicated mentorship, and clear competency frameworks can reduce this to four to six months. Sink-or-swim environments without support structures often see twelve to eighteen months of struggle—or early attrition.

    The first two weeks involve passive onboarding. New hires receive tool access, learn the organization’s security posture, understand escalation protocols, and begin shadowing senior analysts. No independent work happens yet. The goal is orientation and context-building.

    Weeks three through eight shift to guided work. The junior analyst handles routine alerts with clear escalation guidance. A senior analyst reviews decisions weekly. Documentation becomes muscle memory. Pattern recognition begins developing. Technical questions get answered in real-time through pair work and structured feedback.

    Months three through six mark increasing autonomy. The analyst manages their own alert queue, escalates complex incidents appropriately, and begins specializing in specific domains like endpoint security or network traffic analysis. Competency benchmarks become clearer: alert triage accuracy should exceed 95%, independent ticket resolution time should fall below thirty minutes, and documentation should require minimal revision.

    Months six through twelve establish specialization. The analyst develops depth in threat hunting, malware analysis, vulnerability management, or another focus area. They begin mentoring newer hires. They contribute to process improvements. Security certification study fits naturally into this phase, with CompTIA Security+ or similar credentials providing external validation of accumulated knowledge.

    This progression isn’t automatic. It depends entirely on organizational culture, management investment, and peer support structures. The same timeline in a toxic environment becomes eighteen months of anxiety and confusion.

    Building Your Foundation Before Day One

    While organizations should provide training, entering a role with baseline preparation dramatically improves outcomes. The foundation doesn’t require years of study—it requires strategic focus on fundamentals and credibility signals.

    Basic computer literacy remains non-negotiable. Comfortable navigation of Windows and Linux operating systems, file system understanding, basic command-line comfort, and familiarity with common productivity tools create the platform for everything else. Someone struggling with directory navigation or file permissions will find SIEM log analysis overwhelming.

    Certifications serve as visible credibility proxies. CompTIA A+ establishes hardware and operating system fundamentals. CompTIA Network+ builds understanding of protocols, network architecture, and troubleshooting methodology. CompTIA Security+ provides the security-specific foundation that hiring managers universally recognize. The three-certification path represents approximately 150-250 hours of study and $900 in exam fees.

    For career changers who can’t afford that investment or timeline, Security+ alone functions as the minimum credible entry signal. The exam covers security concepts, risk management, cryptography, identity management, and incident response at a level sufficient for entry-level roles. Pass rates hover around 45% on first attempt, indicating meaningful rigor. Study time typically ranges from 50 to 100 hours using free resources like Professor Messer’s video series, Jason Dion’s practice exams, and the official CompTIA study guide.

    Hands-on practice transforms theoretical knowledge into applied competence. TryHackMe offers gamified learning paths with guided walkthroughs for beginners. A $10 monthly subscription provides access to hundreds of labs covering Linux fundamentals, networking, web security, privilege escalation, and malware analysis. HackTheBox takes a more challenging approach, presenting realistic vulnerable machines without guidance. The free tier provides limited access; the VIP subscription ($12 monthly) unlocks the full catalog.

    SANS Cyber Aces provides free, high-quality training modules covering operating systems, networking, and foundational security concepts. The material comes from SANS Institute—the same organization behind expensive but highly regarded professional certifications. For budget-conscious learners, Cyber Aces delivers legitimate foundational knowledge without cost barriers.

    The combination of certification study and hands-on lab practice creates portfolio material. Documenting HackTheBox machine walkthroughs in a personal blog demonstrates technical competence and communication ability. Maintaining a GitHub repository with SIEM queries, bash scripts, or Python automation tools provides tangible proof of applied learning. These artifacts matter during job searches when formal experience doesn’t exist yet.

    Strategies for Effective On-the-Job Learning

    The organization you join determines much of your success. Not all entry-level cybersecurity roles provide genuine learning opportunities. During interviews, ask specific questions about onboarding structure, mentorship programs, and typical ramp-up timelines. Organizations with mature learning cultures will answer confidently with specific programs and timeframes. Those without structure will deflect or provide vague reassurances.

    Red flags include managers who claim “you’ll figure it out,” organizations that can’t describe their onboarding process, roles where you’ll be the only junior analyst without senior support, and cultures where asking questions is discouraged. These environments don’t create space for learning—they create burnout.

    Green flags include structured onboarding programs spanning 30-90 days, formal mentorship assignments pairing juniors with seniors, regular check-ins and feedback mechanisms, documented processes and internal wikis, and peer cohorts of other new hires learning together. Organizations that invest in these structures see dramatically better retention and faster competency development.

    The mentor relationship forms the cornerstone of effective on-the-job learning. A good mentor provides technical guidance, shares institutional knowledge, offers honest feedback, models professional behavior, and advocates for your development. Finding this person requires initiative. Don’t wait for formal assignment—identify senior analysts whose work style and communication approach resonate, ask if they’re willing to meet regularly, come prepared with specific questions, and demonstrate that you value their time by implementing their advice.

    Effective mentorship is bidirectional. As you develop competence, look for ways to contribute back. Document processes that confused you initially. Create reference guides for common procedures. Help newer hires navigate the same challenges you faced. This generosity builds reputation and deepens your own understanding through teaching.

    Documentation transforms experience into portable knowledge. Keep a daily log of new concepts learned, problems solved, mistakes made, and questions answered. When you resolve a tricky alert or debug a complex issue, document the process step-by-step. This practice serves multiple purposes: it creates reference material for similar future incidents, it demonstrates learning to managers during performance reviews, and it forces clarity in your own thinking.

    Asking questions strategically accelerates learning without overwhelming colleagues. Before asking, attempt to solve the problem independently using available documentation, error messages, and internet searches. When you do ask, provide context about what you’ve already tried. Frame questions specifically rather than broadly: “How do I interpret this specific SIEM correlation rule?” works better than “How does our SIEM work?” Senior analysts can answer targeted questions quickly; vague questions require lengthy explanations.

    Reverse-engineering solutions builds deep understanding. When a senior analyst resolves an issue, ask them to walk through their diagnostic process afterward. What did they check first? Why? What symptoms suggested that specific root cause? How did they validate their hypothesis? This metacognitive approach—understanding the thinking process, not just the technical steps—develops expertise faster than passive observation.

    Peer learning amplifies individual effort. Form a study group with other junior analysts. Discuss challenging tickets together. Quiz each other on security concepts. Share resources and learning strategies. The psychological benefit of shared struggle reduces isolation and imposter syndrome. The cognitive benefit of explaining concepts to peers reinforces your own understanding.

    Pacing prevents burnout. Learning on the job means balancing immediate performance expectations with long-term skill development. Some weeks you’ll focus entirely on daily work. Other weeks you’ll dedicate extra hours to certification study or lab practice. This rhythm prevents the exhaustion of trying to optimize everything simultaneously. Cybersecurity careers span decades—sustainable development matters more than sprint intensity.

    Common Pitfalls and How to Avoid Them

    Sink-or-swim environments destroy confidence and competence. Some organizations hire entry-level analysts, provide minimal training, and expect immediate productivity. These cultures rationalize that “stress tests” separate strong performers from weak ones. In reality, they simply burn through junior analysts quickly. If your first ninety days feel characterized by constant confusion, minimal guidance, and implied criticism for asking questions, you’re likely in a toxic environment. Start looking for your next role immediately. The problem isn’t you—it’s organizational dysfunction.

    Imposter syndrome spirals create self-fulfilling anxiety. Everyone entering cybersecurity without traditional credentials experiences moments of feeling inadequate or fraudulent. The industry’s complexity is real. The knowledge gaps are real. But the belief that everyone else knows what they’re doing while you’re faking it is distorted. Senior analysts still google syntax. Experienced engineers still consult documentation. Expert practitioners still ask colleagues for help. Competence doesn’t mean omniscience—it means knowing how to find answers and solve problems systematically.

    Combat imposter syndrome through external benchmarks. Track your progress against realistic timelines: Can you classify alerts accurately? Can you document incidents clearly? Can you escalate appropriately? These concrete skills matter more than feeling confident. Seek feedback from mentors and managers regularly. Often the gap between your self-perception and their assessment is dramatic. What feels like struggling looks like normal learning from the outside.

    Certification paralysis delays practical progress. Some learners endlessly pursue additional certifications while avoiding hands-on work or job applications. Security+, then CEH, then OSCP, then CISSP—the alphabet soup becomes procrastination. Certifications provide structure and credibility, but diminishing returns set in quickly. One or two foundational certifications plus demonstrable hands-on skills outweigh five certifications with no practical application experience.

    Conversely, certification dismissal creates unnecessary barriers. Some self-taught learners reject certifications as “just test-taking” without real learning value. While there’s truth to exam-focused study methods feeling artificial, certifications remain significant hiring filters. Many organizations won’t interview candidates without Security+ or equivalent. The certification isn’t the learning—the certification is the universally recognized signal that validates the learning you’ve done elsewhere.

    Isolation compounds every other challenge. Remote work, asynchronous communication, and heads-down focus all contribute to disconnection. Junior analysts working alone struggle more than those embedded in collaborative teams. Actively combat isolation by joining cybersecurity communities on Discord or Reddit, attending local security meetups or BSides conferences, participating in online study groups for certifications, and contributing to open-source security projects. The relationships you build provide technical knowledge, emotional support, career opportunities, and industry perspective.

    Real-World Learning Models

    The healthcare-to-SOC transition demonstrates structured progression. A registered nurse entering a SOC analyst role brings critical thinking, documentation discipline, and stress tolerance. The first sixty days focus on tool familiarization and process learning while shadowing senior analysts. The nurse shadows alert triage, learns the SIEM interface, studies the organization’s network topology, and attends security team meetings without handling tickets independently.

    Months two through four introduce guided work. The analyst handles routine alerts—malware detections, policy violations, failed authentication patterns—with clear escalation protocols. Weekly feedback sessions with a mentor address classification accuracy, documentation quality, and technical questions. Parallel to job duties, the analyst completes CompTIA A+ study, building deeper understanding of operating systems and hardware fundamentals.

    Months four through six establish independence. The analyst manages their own alert queue, achieving 95%+ triage accuracy and sub-30-minute resolution times for routine tickets. Security+ certification study begins, leveraging real-world context from daily work to reinforce exam concepts. Monthly check-ins with a senior analyst mentor provide developmental guidance and specialization direction.

    Months six through twelve develop specialization. The analyst chooses a focus area—endpoint security, network traffic analysis, or threat intelligence—and pursues depth through advanced training, relevant projects, and mentorship from specialists. They begin mentoring incoming junior analysts, which deepens their own expertise through teaching. Advanced certification like CEH or GIAC becomes feasible with organizational sponsorship.

    The bootcamp graduate faces a different challenge. After twelve intensive weeks of training, they enter a junior security analyst role at a managed service provider with some foundational knowledge but limited practical exposure to real environments. Week one covers access provisioning and workflow introduction. Weeks two through three involve pairing with a mid-level analyst on actual client tickets, learning MSP-specific procedures and tools.

    Weeks four through eight introduce independent client work at low complexity. The analyst handles routine vulnerability scan interpretation, basic security hygiene tickets, and policy compliance checks. Weekly synchronization with their mentor addresses client communication, technical accuracy, and time management. The MSP’s client diversity accelerates learning—exposure to healthcare, financial services, and retail environments within weeks provides breadth impossible in a single-company SOC role.

    Months three through six establish client relationships. The analyst leads small projects like vulnerability assessment reporting or security awareness training delivery. Client communication feedback loops rapidly improve professional skills. Security+ certification (if not already completed) becomes priority to meet client compliance requirements. The analyst documents five or more process improvements based on recurring ticket patterns.

    The self-taught career changer builds portfolio before employment. A graphic designer pursuing cybersecurity part-time while maintaining current income follows a structured eighteen-month plan. Months one through three cover CompTIA A+ and TryHackMe’s beginner learning path (fifty hours). YouTube tutorials on Linux fundamentals supplement structured study.

    Months three through six add CompTIA Network+ and HackTheBox beginner labs. The learner commits to compromising five machines minimum, writing detailed walkthroughs for each. A personal blog documents the learning journey with technical write-ups, search-optimized for common security concepts to build online presence.

    Months six through nine focus on Security+ certification and ten additional HackTheBox labs. A GitHub repository showcases SIEM queries, bash scripts, and Python automation developed through labs. These portfolio pieces demonstrate applied learning beyond certification alone.

    Months nine through twelve involve advanced topic exploration—threat hunting methodologies, SIEM log analysis, malware analysis fundamentals—while beginning job applications. Informational interviews with security professionals provide industry insight and relationship building. Applications emphasize portfolio work and demonstrated learning ability over formal credentials.

    Months twelve through eighteen pursue advanced certification (eJPT or CEH), contribute to open-source security tools, and attend local security meetups. The portfolio now includes fifteen-plus detailed write-ups, working code samples, and growing professional network. By month eighteen, the career changer lands an entry-level analyst position based on demonstrated competence despite non-traditional path.

    Your First 90 Days: Practical Milestones

    The first two weeks establish foundation. Obtain access to all necessary systems, tools, and documentation. Attend new hire orientation and security team introduction. Review organizational security policies and incident response procedures. Meet your assigned mentor and schedule regular check-ins. Shadow senior analysts during alert triage without making independent decisions. Document everything you don’t understand for later clarification.

    Weeks three through six build guided competence. Handle five to ten tickets daily with escalation support. Achieve 80%+ alert classification accuracy. Attend all team meetings and note recurring themes. Complete assigned training modules or certification study milestones. Identify one process improvement opportunity based on observed inefficiencies. Establish rapport with two to three senior team members beyond your formal mentor.

    Weeks seven through twelve develop independence. Increase ticket volume to fifteen to twenty daily. Achieve 90%+ classification accuracy and sub-twenty-minute average resolution time. Escalate complex incidents appropriately with clear documentation. Pass Security+ certification or reach defined study milestone. Present findings from one small project or investigation. Begin identifying specialization area based on interest and organizational need. Document common procedures for future reference.

    These milestones aren’t universal—organizational context varies significantly. Use them as benchmarks, not rigid requirements. If you’re ahead of schedule, excellent. If you’re behind, diagnose why: inadequate organizational support, knowledge gaps requiring focused study, unrealistic expectations, or normal learning curve variation. Adjust accordingly.

    The Path Forward

    Learning cybersecurity skills on the job remains the most common path into the field. Formal education provides structure. Certifications provide credibility. But practical competence develops through repetition, feedback, and applied problem-solving in real environments with real consequences.

    Your non-traditional background is a strength, not a deficit. Healthcare professionals bring clinical assessment methodology. Financial analysts bring risk quantification experience. Teachers bring communication clarity. Military veterans bring operational discipline. These capabilities transfer directly to security operations, threat analysis, and incident response. The technical specifics—SIEM platforms, network protocols, operating system internals—can be learned. Problem-solving approaches and professional discipline cannot.

    The organizations worth working for invest in your development. They provide structured onboarding. They assign mentors. They maintain documentation. They normalize question-asking. They set realistic performance expectations. They sponsor certification. They create space for learning while working. During your job search, evaluate employers as carefully as they evaluate you.

    Start with one action today. Join TryHackMe and complete the first learning path. Register for a Security+ study group. Update your resume emphasizing transferable skills. Reach out to a cybersecurity professional for an informational interview. Attend a local security meetup. The entry barrier is lower than you think. The learning curve is manageable. The career outcome is achievable.

    The nurses who became threat hunters proved the path exists. Now walk it yourself.

    Share this article

    Enjoyed this article?

    Subscribe to Professor Simon's weekly newsletter for practical insights, career guidance, and leadership lessons delivered every Friday.

    A confirmation email will be sent. If you don't receive it, please check your spam or junk folder.

    No spam. Unsubscribe anytime.

    Prefer to Listen?

    Listen to Professor Simon’s IT & Cybersecurity Podcast for practical conversations about cybersecurity careers, certifications, security leadership, and real-world lessons from the field.

    Listen on Spotify