Career switch to cyber security from IT support or network admin
If you are in IT support, desktop administration, network operations or system administration, you are not starting from zero. You are starting from the position most fresher candidates are trying to fake: you have touched production, handled users, and fixed things while someone was waiting. The switch is a reframing exercise plus two or three genuine gaps.
What already transfers
From IT support / service desk
- Ticket discipline: triage, prioritise, document, escalate. That is SOC workflow.
- Password resets, MFA issues, account lockouts — the everyday surface of identity security.
- Phishing reports from users. You have already seen real ones.
- Talking to non-technical people under pressure, which most security teams struggle with.
From network administration
- Firewall rules, VLANs, routing, VPNs, DNS, proxies — the vocabulary of network security.
- Packet-level troubleshooting. Very few freshers can read a capture; you can.
- Change control and the habit of thinking about blast radius.
From system administration
- Active Directory, group policy, patching, backups, hardening.
- Log locations and what normal looks like — the single hardest thing to teach a new analyst.
The gaps you genuinely need to close
- Adversary thinking. You know how systems fail. Now learn how they are made to fail: phishing to foothold, credential theft, lateral movement, persistence, exfiltration.
- Detection tooling. A SIEM (Sentinel, Splunk, QRadar or Elastic) and how to query it. Endpoint detection concepts if you can get access.
- Frameworks. MITRE ATT&CK for describing attacks, the incident response lifecycle for describing process, and at least a passing familiarity with ISO 27001 or NIST CSF if you lean towards GRC.
- The security vocabulary. Interviewers listen for it. Saying "we contained the host and preserved evidence" lands differently from "we took it off the network".
Pick the door closest to your current job
- Service desk → SOC L1. The most natural move; the workflow is the same shape.
- Network admin → network security / firewall engineer. You may skip the fresher band entirely here.
- Sysadmin → IAM, endpoint security or cloud security. Your AD and hardening experience is directly billable.
- Anyone with strong documentation habits → GRC. Underrated and less crowded.
Rewrite your resume as a security resume
Do not lead with "seeking a challenging opportunity". Lead with what you have handled that a security team cares about:
- Replace "handled user tickets" with the volume, the categories, and the escalation path you owned.
- Call out every phishing, malware, account-compromise or access-review task you touched — by name.
- Name the tools: AD, Intune, Fortinet, Palo Alto, Cisco ASA, Zscaler, whatever you actually used.
- Add a Security section: your lab, your write-ups, your certification in progress.
Two-thirds of your interview will come from your existing experience if you present it in security language.
Use your current job as your lab
This is the switcher's unfair advantage. Inside your current role you can:
- Volunteer for the phishing triage queue.
- Ask to sit with the security team during an incident.
- Take ownership of patch compliance reporting or access reviews.
- Offer to write the runbook nobody has written.
Six months of that is a genuine internal transfer case, and internal transfers are the most common successful route into security in Indian enterprises.
Handle the two questions you will definitely be asked
"Why do you want to move to security?" Do not say "growth" or "it is booming". Say what you saw: the incident you helped with, the phishing wave you watched land, the access review that shocked you. Concrete beats ambitious.
"What have you done about it?" This is where your lab, your write-ups and your certification progress come in. An answer without evidence sounds like a wish.
Do not take a pay cut you do not need to
Switchers often assume they must restart at fresher pay. Frequently they do not — especially network and system administrators moving into adjacent security roles, where the experience is directly relevant. Research your target role's current range on live job boards before you name a number, and argue from the experience you are bringing, not the title you are leaving.
Next step
Your experience is real; the language and the pressure are new. Take the free 5-question AI mock interview in your target role and hear how your existing work sounds when you have to explain it as a security story.