In partnership with

Hey everyone, welcome back.

This issue is all about one thing: proof. The market is full of certified people, so the ones getting hired are the ones who can show they can actually do the work. We'll dig into why 75% of junior roles now demand hands-on experience, and exactly how to build that proof when you have none yet.

I've also got something new for you. I've built a free Cyber Career Path Explorer that maps 8 ways into cyber and the real salary climb from entry to senior. On top of that, there's a breakdown of what makes a portfolio earn interviews instead of getting ignored, this week's video where I review real beginner portfolios, and the news worth your time.

Let's get into it.

📊Stat of the Week

75% of junior cybersecurity roles now require hands-on experience.

Source: Cyberbit, Same Job, New Skills 2026 report, an analysis of nearly 1,000 cybersecurity job postings across North America, Europe, APAC and the Middle East.

Entry-level no longer means entry. Certifications still open doors, but employers are screening for people who can show they have actually done the work, not just studied it. That one shift should change how you spend your next month.

Last week Palo Alto Networks confirmed attackers were already exploiting a fresh flaw in its GlobalProtect VPN software, well after the patch had landed. That is the job now. The gap between a vulnerability going public and someone weaponising it has collapsed to hours. Employers know it, and it is why they have quietly stopped hiring for what you know and started hiring for what you can prove you can do. If you are sitting on two or three certs and still not getting interviews, this issue is for you.

Your certs got you noticed. Your proof gets you hired.

Here's the thing. The market is not short on certified people. It is short on people who can prove they can do the work.

I see it every week. Two candidates apply for the same SOC role. Both have Security+. One lists the cert and a line that says "passionate about cybersecurity." The other links to a short write-up of a home lab, showing how they detected and investigated a simulated phishing attack, screenshots and all. Same cert. Only one gets the call. Every single time.

The data backs this up. That Cyberbit analysis found 83% of all cybersecurity roles now require hands-on experience, and 75% of junior roles demand it too. They call it the Junior Paradox. You need experience to get the job, but you need the job to get experience. It feels rigged. It is not. You just have to manufacture the proof yourself, before anyone pays you to.

The same research found 94% of postings asked for tool proficiency, things like SIEM and EDR, not theory about them. Studying the concept of a SIEM is not the same as showing you have pulled logs, written a detection, and explained what you found. Proof of work is simply you closing that gap in public.

Here is how to build it, starting this week.

  1. Pick one role and one tool. Do not try to cover everything. Want SOC work? Spin up a free Splunk or Elastic instance. Aiming at GRC? Build a sample risk register or map a small business against the Essential Eight. One role, one artefact. Depth beats breadth.

  2. Do a small project and document it like a case. Detect something, investigate something, or fix something. Then write it up the way you would brief a manager: what you did, what you found, what you would do next. The write-up matters as much as the work, because it shows how you think.

  3. Put it where a recruiter can find it in ten seconds. A GitHub repo, a simple blog, a LinkedIn post with screenshots. If I have to dig for your proof, I will not. Make the link impossible to miss on your resume and your profile.

  4. Repeat until you have three. One project looks like luck. Three looks like a habit. Three small, well-documented projects will out-compete a wall of certs with no evidence behind them nearly every time.

When I place candidates, the ones who move fastest are almost never the most qualified on paper. They are the ones who made it easy for me to picture them doing the job, because they had already started doing it. And right now, a project that touches AI security, even something as simple as testing a chatbot for prompt injection, will get you noticed faster than almost anything else.

Recruiter's Take: When I shortlist for an Australian SOC or GRC role, I spend about thirty seconds on a resume before I decide. A link to one documented project pulls me in faster than a second or third certification ever will. Australian hiring managers are practical people. Show them you can do the thing, in their language, and you have already won half the interview. Build the proof, then point straight at it.

New Free Tool: The Cyber Career Path Explorer

Here's the catch with building proof: you have to know which role you are building it for. So I built something to fix that.

The Cyber Career Path Explorer maps 8 real ways into cyber, from IT Support right through to Cloud Security Engineering, and shows the honest salary climb from entry to senior in Australian dollars. It is built from 15 years of recruiting across Australia and the UK, and it is completely free.

Here is the entry to senior climb across all 8 paths:

  • IT Support (breaking in): $60k, then $95k, up to $195k

  • SOC Analyst (operational): $80k, then $125k, up to $225k

  • GRC Analyst (governance and risk): $80k, then $140k, up to $270k

  • Penetration Tester (offensive security): $85k, then $155k, up to $275k

  • IAM Analyst (identity and access): $95k, then $145k, up to $275k

  • Incident Responder (DFIR): $115k, then $170k, up to $300k

  • Security Engineer (build and defend): $120k, then $160k, up to $290k

  • Cloud Security Engineer (cloud and DevSecOps): $115k, then $190k, up to $340k

Pick your starting role, see where it leads, and choose the path worth building your proof of work for. Explore all 8 paths free here.

Global HR shouldn't require five tools per country

Your company going global shouldn’t mean endless headaches. Deel’s free guide shows you how to unify payroll, onboarding, and compliance across every country you operate in. No more juggling separate systems for the US, Europe, and APAC. No more Slack messages filling gaps. Just one consolidated approach that scales.

  • Attackers are already exploiting Palo Alto's GlobalProtect VPN flaw (CVE-2026-0257). Palo Alto confirmed live exploit attempts on 29 May, well after the patch shipped. The window between disclosure and attack is now hours, and employers are crying out for people who can triage and act on CVEs fast. Vulnerability management is a hands-on skill you can practise this week.

  • A new trick called "ChatGPhish" turns AI summaries into phishing. Researchers showed how a poisoned web page can hijack ChatGPT's trust in links and images to leak user data. AI security is the fastest-moving skill in the market. If you can speak to prompt injection and AI attack surfaces, you stand out from a stack of identical applicants.

  • Ransomware just hit a regional Victorian newspaper. The Brain Cipher group listed Shepparton's The Adviser on its leak site, claiming more than 350GB of stolen data, with a deadline of 2 June. Cyber is not just a big-city, big-corporate problem here. Demand for incident response and GRC skills across regional Australia keeps climbing.

  • Over 2,000 "vibe-coded" apps were found leaking sensitive data on the open web. A new report identified hundreds of thousands of AI-built web assets, many deployed with no access controls at all. This is a brand-new attack surface, and spotting misconfigurations like these is exactly the kind of proof-of-work project that gets a junior noticed.

Anatomy of a portfolio that gets interviews

Let's be honest. Most beginner portfolios are not skipped because the projects are weak. They are skipped because a recruiter cannot tell, in ten seconds, what the work proves. Fix that one thing and you are ahead of almost everyone.

What gets your link ignored:

  • A bare GitHub link with no README and no context.

  • A wall of certificates with nothing that shows what you can actually do.

  • Raw config files or screenshots with no explanation of the problem or the result.

  • "Currently learning..." with no finished outcome to point to.

What gets you the interview:

  • Every project opens with one line: what this proves, and for which role.

  • A short writeup covering the problem, what you did, and what you found.

  • Screenshots or output that a non-expert can follow.

  • Three focused projects, not thirty half-finished ones.

🎥 Video of the Week

I Reviewed Beginner Cybersecurity Portfolios: What Gets Interviews?

I sat down and went through a stack of beginner cybersecurity portfolios to work out what actually earns an interview and what makes a recruiter close the tab. The pattern was clear: most beginner portfolios do not fail because the projects are bad, they fail because the recruiter cannot quickly see what the work proves. If you are building a portfolio for SOC, GRC, IAM, cloud security, or any entry-level cyber role, this one shows you how to turn your labs, tools, GitHub projects, and writeups into evidence a hiring team actually understands.

New videos every week on cybersecurity careers, certifications, and what recruiters actually want.

⚡ Quick Wins

  1. Open a free tier of Splunk, Elastic, or Microsoft Sentinel today and load one sample log set. Spend twenty minutes running three searches. That is your first artefact in motion.

  2. Rewrite your LinkedIn headline from a title you want to a proof point you have. "Built a home SOC lab detecting phishing in Splunk" beats "Aspiring Cybersecurity Professional" every time.

  3. Pick one CVE in the news this week, the PAN-OS GlobalProtect flaw is a good start, and write three sentences explaining what it is, who it affects, and how you would mitigate it. Then post it.

🎯 Weekly Challenge

Build one documented mini-project this week. Pick a single tool, complete one small task in it: detect a simulated attack, write one detection rule, or map a business against the Essential Eight. Then write a one-page case study covering what you did, what you found, and what you would do next. Open it with a single line that says what it proves, publish it on LinkedIn or GitHub, and add the link to your resume before Friday. Thirty to sixty minutes of focused work, one link, and a recruiter reads you completely differently.

🎓 From the Desk: Cybersecurity Job-Ready Blueprint

If this issue lit a fire under you to start building proof, the Blueprint is the structured version of exactly that. It is a step-by-step guide built from 15+ years of placing candidates into cybersecurity roles, and it covers the exact path from zero to job-ready: which certs to get first, how to build proof of work, how to write a resume that gets past ATS, and how to approach applications like a recruiter. Get the Cybersecurity Job-Ready Blueprint here.

Thanks for reading. As always, keep levelling up your career.

Best wishes
Luke
Career Coach | Cybersecurity Recruiter

Subscribe here to get The Career Compass every fortnight.