The questions almost always come in the same order. First: “Can I really work in tech if I’ve never studied anything like this?” Next: “Where do I start?” And finally, the one that weighs the heaviest: “Isn’t it too late for me?”
If any of these three sound familiar to you, this article is for you. The short answer to all three is that yes, you can; that you start by choosing a specific area; and that no, it’s not too late. The long answer follows below.
The tech industry hires based on proven ability
The tech industry has one characteristic that sets it apart from almost any other: it hires based on demonstrable skills, not on traditional credentials. A company looking to fill a cybersecurity support position cares more about whether you can identify a vulnerability than about the name of the university on your diploma.
This doesn't mean that getting in is easy. It means that the path is different. Instead of a five-year college degree, entry into the field is typically based on specific technical training, an industry-recognized certification, and proof that you know how to do the job.
There is a second, less-discussed reason: demand exceeds the supply of trained talent. In cybersecurity—one of the areas where this gap is measured in the greatest detail—the figures from ISC2’s latest global workforce study paint a clear picture:
- The global workforce in this sector consists of 5.5 million professionals, with annual growth of nearly 8.7%.
- There are still 3.5 million unfilled job openings worldwide.
- 67% of organizations believe their security team is insufficient. To close that gap, the sector would need to grow by about 75%.
- Only between 20% and 25% of cybersecurity positions are held by women.
- Among professionals under 30, that percentage of women rises to 26%. It is a sign of generational change, and it is the gateway to the future today.
The World Economic Forum points in the same direction: in its report on the future of employment, networking and cybersecurity skills are among the three fastest-growing skills by 2030, along with artificial intelligence and technological literacy.
The paradox you need to understand before you begin
Here's a logical trap that's easy to fall into: "There's a shortage of millions of professionals, so finding a job must be easy." It isn't, and it's worth understanding why.
What the global study shows is not just that there is a shortage of people—it is that there is a shortage of specific skills within organizations. Companies need talent, but for those without prior experience, the real obstacle is not a lack of job openings, but the gap between what they know how to do and what the job requires.
That changes the question we should be focusing on. It shifts from “Is there a market?” to “How do I make myself employable in that market?” Everything that follows in this article addresses the second question.
Your previous education isn't a liability—it's a competitive advantage
There is a more subtle version of the same myth: “I didn’t study technology, so I’m starting at a disadvantage.” In a multidisciplinary field, one’s original education often becomes a distinguishing factor. Here are some specific examples:
- Law intersects with privacy, data protection, regulatory compliance, governance, and risk.
- Administration and accounting are linked to risk management, governance, consulting, and program management.
- Human resources and education are linked to a culture of safety, awareness, internal training, and change management.
- Communication is linked to crisis management, awareness campaigns, and incident reporting.
These aren't far-fetched analogies: they're entry points that companies routinely use. Anyone with a background in customer service, a help desk, or any job where they've had to follow procedures and identify inconsistencies has real transferable skills.
The Four Pillars of a Solid Career Path
A career isn't built by taking random courses. It's built on four pillars that support one another.
1. Choose a specific area
The most common mistake when starting out is trying to learn everything. “Technology” isn’t a single profession—it’s a collection of very different professions. At She is Digital, where we currently offer cybersecurity training, we develop skills to protect systems, data, and networks from threats. This requires analytical thinking and attention to detail. In this case, advanced programming skills aren’t required for entry-level roles.
2. Training with international certification
When you don't have work experience or a degree, certification serves a specific purpose: it translates what you know into a language that companies already understand and trust.
A Cisco certification in cybersecurity—or an AWS or IBM certification in cloud computing—isn’t just a piece of paper to show off. It’s a verifiable standard that a recruiter can assess without even knowing you. More than 2,500 women in the program have earned certifications in these three areas, and in many cases, that certification was what landed them their first interview.
3. Social-emotional skills
This pillar is often underestimated, yet it is the one that most often determines whether someone is hired. Communicating clearly, working as a team, asking for help in a timely manner, accepting feedback without falling apart, and dealing with the frustration of a problem that isn’t solved on the first try.
In technical teams, where work is almost always collaborative, these skills aren’t just a bonus. They’re part of the job. At She is Digital , this pillar is integrated throughout the entire training program and is key during the employability phase.
4. Networking and Mentoring
A significant portion of job openings are filled through referrals before they are even posted. This isn’t discouraging—it’s a lesson. Building a network from your first day of training, participating in communities, maintaining an active LinkedIn profile, and seeking mentorship are actions that directly improve your employability.
Choosing an area is just the first step: the case of cybersecurity
Deciding, “I want to work in cybersecurity,” is much less limiting than it seems. Within the field, there are areas that bear little resemblance to one another: some revolve around coding, others around risk analysis, and still others around the legal framework. Understanding the full picture helps you avoid two common mistakes. The first is ruling yourself out before even trying, believing that the entire sector requires programming skills. The second is studying for months without knowing which specific role you’re preparing for.
These are the eleven areas that currently account for the majority of hiring, grouped into four categories.
Operations and Defense
SOC / Security Operations. Monitors environments and identifies potential attacks. It is the most common entry point into the industry for entry-level positions. Roles: SOC Analyst, Security Analyst, Incident Analyst, Detection Engineer.
Incident Response. What happens after an attack has occurred: investigate, contain, eliminate, and recover. Roles: Incident Responder, IR Analyst, Crisis Manager.
Digital Forensics. Investigating digital evidence and reconstructing what happened. Roles: Forensics Analyst, Digital Investigator.
These are the eleven areas that currently account for the majority of hiring, grouped into four categories.
Technical and Offensive Profile
Ethical Hacking / Penetration Testing. Testing systems for vulnerabilities before criminals do. This is the area where programming and technical knowledge are most important. Roles: Penetration Tester, Ethical Hacker, Red Team, Application Security.
IAM — Identity and Access Management. Who you are, what you can access, and whether you should continue to have that access. Roles: IAM Analyst, Identity Engineer, PAM Specialist, IAM Architect.
Cloud Security. Protecting infrastructure that has been migrated to the cloud. Skills: AWS, Azure, GCP, identity, networking, containers, DevSecOps. Roles: Cloud Security Analyst, Cloud Security Engineer, Cloud Security Architect.
Governance, Risk, and Business
GRC — Governance, Risk, and Compliance. Policies, controls, auditing, and frameworks. One of the most interesting paths for less technical professionals. Roles: Cyber Risk Analyst, GRC Analyst, IT Auditor, Compliance Analyst.
Privacy. GDPR, LGPD, and local data protection laws. This is where law, processes, technology, and business converge. Roles: Privacy Analyst, Data Protection Specialist, Privacy Consultant, DPO.
Cyber Resilience. It’s not just about preventing an attack, but also: if one occurs, can we continue to operate and restore business operations? Roles: Business Continuity, Disaster Recovery, Crisis Management, Backup & Recovery.
Intelligence and Emerging Fields
Threat Intelligence. Who is attacking, why, and how. It combines technology, research, analysis, and intelligence. Roles: Threat Intelligence Analyst, Cyber Threat Researcher.
AI Security. Artificial intelligence governance, model and data protection, agent security, risks, and attacks on models. It is the newest area on the map and the one growing the fastest. Roles: AI Security Analyst, AI Governance Specialist, Model Risk Analyst.
Four of these eleven areas can be accessed without making a reservation
GRC, privacy, cyber resilience, and entry-level roles in a SOC don’t require coding skills. They require analytical thinking, attention to detail, sound judgment, and the ability to document effectively. All of these skills can be developed, and there are industry-recognized certifications for each of them.
Programming is important for some career paths, but it is not the core competency in governance, risk, compliance, privacy, IAM, awareness, crisis management, business continuity, third-party management, auditing, or consulting. These are entire fields with real job openings where the entry requirement is something else entirely.
Don't choose the field first—choose the type of problem you like to solve
There's a more useful way to make this decision than reading job descriptions. Instead of asking yourself, "Which field is better?", ask yourself what kind of problems you enjoy solving. Four profiles cover almost the entire spectrum:
- "I like to investigate." SOC, Incident Response, Threat Intelligence, Forensics.
- "I like to build things." Cloud Security, architecture, DevSecOps, IAM, security engineering.
- "I like to attack and test." Penetration testing, Red Team, application security, vulnerability management.
- "I like business, processes, and people." GRC, privacy, risk, auditing, consulting, awareness, cyber resilience.
In other words: don't choose cybersecurity first and then the role. Figure out what kind of problems you like to solve, and let that guide you to the right field.
What Job Postings Really Ask For
An academic study from 2025 analyzed more than 12,000 cybersecurity job postings to identify which skills are actually in demand. The results are divided into two columns, and neither works without the other.
Most Common Technical Skills: networking, operating systems, cloud computing, security fundamentals, identity management, SIEM, threats, and vulnerabilities.
The most frequently cited social-emotional skills were: communication, critical thinking, curiosity, problem-solving, teamwork, organization, and the ability to learn. Communication and project management were among the most frequently mentioned skills across the entire group.
The bottom line is that the profile they are looking for is not the most technically skilled person in the group, but rather someone who combines a technical foundation with the ability to explain, coordinate, and foster learning.
The factor that many people overlook: English
Technical documentation, research, vulnerability bulletins, certifications, training, and a large part of the communities operate in English. You don’t have to wait until you’re fluent to get started—but you do need to get started. Adding English to your technical training significantly expands the range of job openings you can apply for, including remote positions at companies outside the region.
How to Gain Experience When You Don't Have a Job Yet
This is the crux of the problem for those just starting out: they ask for experience to get that first job. The solution isn't to wait—it's to build a track record.
The most common ways to do this:
- In-house labs. A testing environment set up on your computer or in the cloud.
- Practice platforms. TryHackMe and Hack The Box let you solve real-world challenges with step-by-step guidance.
- CTFs. Capture-the-Flag competitions, which are also a great way to meet people in the industry.
- Analysis of hypothetical incidents. Choose a real-world case and document how you would have investigated it.
- Personal and volunteer projects. Helping a small organization organize its access controls or backups counts as experience.
- GitHub. The place where that work is visible and dated.
- Case studies, communities, and events. They add both network and context at the same time.
What matters isn't just doing it, but documenting it. The difference shows up in the interview. Saying "I took a course" carries much less weight than saying, "I set up a lab, simulated this problem, investigated the incident, and documented what I found."
Fundamentals Before Tools, and a Certification Pathway
A common mistake is to start with the latest tools without the foundation that supports them. Before choosing any platform, it’s important to understand:
- Networks
- Operating Systems
- Identity and Authentication
- Vulnerabilities and Threats
- Risk and Controls
- Cloud Basics
A structured introductory course is valuable precisely for that reason: it organizes that foundation rather than leaving it as a collection of scattered tutorials.
When it comes to certifications, it’s important to understand their purpose. They don’t replace experience: they structure the learning process and help your resume get past the initial screening. The typical path starts with two options designed for those without prior experience:
- Cisco CCST Cybersecurity. Fundamentals, network and device security, vulnerabilities, and incident management. Prepares you for roles as a technician or analyst.
- ISC2 Certified in Cybersecurity (CC). No experience required. Covers security principles, business continuity and recovery, access control, network security, and operations.
Next, depending on the path you choose, come Security+, CCNA, or CCNP; Microsoft, AWS, or Azure security certifications; and later on, CISSP, CISM, or CRISC.
Find the Right Door
Many female candidates miss out for a reason that could easily be avoided: they search for just one keyword on job boards. If you type “Cybersecurity Analyst” and nothing else, you’re only seeing a tiny fraction of the job openings you could apply for.
You may also want to look for: Junior Security Analyst, SOC Analyst, IAM Analyst, GRC Analyst, Risk Analyst, IT Audit, Privacy Analyst, Cloud Analyst, Network Analyst, Service Desk, NOC Analyst, and Technology Risk.
Sometimes the first step toward a career in cybersecurity is right next to cybersecurity itself. A help desk or network support position provides real-world operational experience and often paves the way for an internal move into the field in less than two years.
Your professional identity is built before you need it
You shouldn't wait until you're looking for a job to start using LinkedIn. Start earlier: follow professionals and companies in your field, participate in communities, share what you're learning, comment on discussions, connect with people, and document your progress.
You don't have to post expert content. Something as simple as "This week I was studying IAM and learned something interesting" is enough. That's what quietly builds the reputation that will later speak for you.
Artificial Intelligence as an Accelerator, with a Clear Limit
Those starting out today have an advantage that previous generations didn’t have: a tutor available 24 hours a day. AI can be used to explain concepts, create exercises, simulate interviews, review resumes, interpret logs, study English, design labs, simulate incidents, compare career paths, and prepare for certifications.
The limit is just as important: don't delegate your reasoning. A valued professional isn't someone who simply uses the tool, but someone who knows how to use it and question the answer they receive.
What a Realistic Plan Looks Like
A plan that works isn't ambitious. It's sustainable. It's helpful to look at it on two scales.
The First 90 Days
Days 0–30. Foundations. Complete the current training, understand the fundamentals, choose an area of interest, organize your LinkedIn profile, and start learning technical English.
Days 31–60. Practical work. Set up a lab, carry out small projects, study for certification, participate in communities, talk with professionals in the field, and document what you’ve learned.
Days 61 through 90. Job market. Get certified, update your resume and LinkedIn profile, practice interviews, apply for job openings, network, and look for internships or entry-level programs.
All 12 months
Months 1 through 3. Exploration and decision-making. Try the free introductory content in all three areas. Don't try to master anything—just figure out which one comes most naturally to you and which one bores you. At the end of the quarter, choose one.
Months 4 through 8. Intensive technical training. This is where a structured program comes in. Studying on your own is possible, but dropout rates are high without guidance. This stage concludes with certification in your chosen field.
Months 9–10. Evidence. Build three or four projects of your own—no matter how small—and document them. A working website, a vulnerability analysis of a test environment, an architecture deployed in the cloud. This is your portfolio, and it makes up for the work experience you don’t have yet.
Months 11–12. Active job search. Industry-specific resume, complete LinkedIn profile, consistent applications, and preparation for technical interviews. This is a high-volume phase: the first rejections are part of the process, not a sign that the plan has failed.
The equation to keep in mind
Knowledge + practice + certification + communication + networking = employability.
None of these elements alone guarantees an opportunity. Together, they significantly increase your ability to compete for one. If you had to break down the coming year into eight decisions, they would be these: master the fundamentals; choose one starting path—not ten; complete an entry-level certification; gain hands-on experience; study English every day; learn how to use AI; build your network before you need it; and apply for job openings even if you don’t meet 100% of the requirements.
The market data, area map, and recommendations in this section are adapted from the “Career Ecosystem” session that Fabio Isaguirre, Kyndryl’s Cyber Resilience & Connectivity Leader in Brazil, presented to the program participants.
True stories of women who started from scratch
Melissa, from Mexico, and Cárita, from Brazil, joined the program with no prior experience in technology. Irlanda also followed a similar path. Their testimonials are available on the program’s channel, and it’s worth watching them before deciding if this is right for you:
- Melissa (Mexico): https://youtu.be/Ei1rP-hDqrw
- Cárita (Brazil): https://youtu.be/SJObCKcaR24
- Ireland (Mexico): https://youtu.be/mBlnbLQn6ZI
What they have in common is that they've decided to take the first step.
Learn more about the program and find out if it's the next step in your career.