How to get a cyber security job in India with no experience: a 90-day plan

"No experience" is not the blocker most people think it is. Indian SOC teams hire freshers every quarter. What they will not hire is a candidate who cannot describe a single investigation from start to finish.
This is a 90-day plan built around that one gap.
4.8 million
Unfilled cyber security roles worldwide — the demand is real
ISC2 Cybersecurity Workforce Study 2024
68%
Breaches with a human element, the work entry-level analysts handle daily
Verizon DBIR 2024
90 days
Realistic time from zero to interview-ready if you work at it consistently
Cyber Shikshaa mentor guidance
Days 1–30: foundations you will actually be asked about
Skip the 40-hour "complete ethical hacking" playlists. Interviewers ask about a narrow set of things:
- Networking: TCP/IP, DNS, HTTP, ports, what a proxy log and a firewall log each contain.
- Operating systems: Windows event logs (4624, 4625, 4688), Linux auth logs, process trees.
- Identity: authentication vs authorisation, MFA bypass patterns, privilege escalation basics.
- The attack lifecycle: MITRE ATT&CK tactics as a vocabulary, not a memorisation exercise.
Build a home lab: a Windows VM, a Linux VM, and a free SIEM tier (Splunk Free, Elastic, or Microsoft Sentinel on a trial subscription). Generate your own failed logins and look at them.
The rule for this month
Every concept you learn must end in a sentence you could say in an interview. "I know Sysmon" is worthless. "I used Sysmon event 1 to build a process tree and found the parent was winword.exe" gets you shortlisted.
Days 31–60: three artefacts that replace experience
Employers substitute artefacts for experience when the artefacts look like real work.
- An incident write-up. Simulate a phishing-to-execution chain in your lab. Write it up in the structure a SOC uses: what triggered, what you checked, what you concluded, what you would contain, what you would recommend. One page.
- A detection you wrote. A Sigma rule or a KQL/SPL query that catches something specific, with the false positives you found and how you tuned them out.
- A short walkthrough video or blog post. Two minutes explaining the above out loud. This trains the exact muscle the interview tests.
Publish all three. A GitHub repository and a LinkedIn post is enough. Recruiters in India do search this.
Days 61–75: certification and applications in parallel
Pick one certification and finish it. For SOC-track freshers, CompTIA Security+ or Microsoft SC-200 both map cleanly to job descriptions. CEH is widely recognised by Indian HR filters but is weaker as proof of skill. See the full comparison in best cyber security certifications for freshers in India.
While you study, apply. Volume matters, but targeting matters more:
- Managed security service providers (MSSPs) hire L1 analysts in batches — they are the most reliable first door.
- GCCs of banks and global product firms hire freshers into monitoring and GRC.
- Do not ignore IT support roles inside security-heavy organisations; internal moves into the SOC after 9–12 months are common.
Ask for referrals directly. A short, specific message — "I built this detection, I am applying to your L1 opening, would you be willing to refer me?" — works far better than a connection request with no context.
Days 76–90: interview reps
This is where candidates who did everything else still fail. The L1 interview is mostly scenario questions:
- A user clicked a phishing link. What do you do first?
- You see 200 failed logins followed by one success. Walk me through it.
- How would you tell a true positive from a false positive here?
The right answers have a shape: contain first, preserve evidence, check the adjacent data source, state what you would escalate and to whom. Read what actually happens in an L1 SOC interview round and 20 scenario questions Indian SOC interviewers ask, then rehearse out loud until the structure is automatic.
Frequently asked questions
Can I get a security job without a technical degree?
Yes. GRC, security operations and identity administration all hire non-CS graduates regularly. Strong written English is a genuine advantage in GRC.
Are internships worth taking at low or no pay?
A paid internship at a real MSSP or GCC, yes. An unpaid "cyber security internship" that only issues a certificate, no. Judge it by whether you will touch real alerts.
How many applications should I expect to send?
Freshers commonly send 100+ before their first offer. Track them, and treat every rejection round as free interview data.
Next steps
Follow the study order in the cyber security roadmap for beginners in India and structure your applications with the fresher resume guide.
[Take a free 5-question AI mock interview](/free-mock-interview) and find out today which of the scenario answers you can already deliver cleanly.