← Back to list

They Said It Was “Entry Level.” It Required 5 Years of Experience.

An honest account of trying to break into cybersecurity from Nairobi, with no connections, no pedigree, and a lot to prove.

Lutsaibarry · 2026-05-12 10:46 · 0 claps · 3.9 min read
#cybersecurity-careers #career-advice #technology #african-technology #career-change
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

A personal story

A personal story

They Said It Was “Entry Level.” It Required 5 Years of Experience.

An honest account of trying to break into cybersecurity from Nairobi, with no connections, no pedigree, and a lot to prove.

I remember the exact moment I felt the walls close in.

I was sitting at my desk, probably 11pm, Nairobi humming outside my window, and I had just spent three hours crafting what I thought was a solid job application. I had a diploma. I had certifications. I had built a home lab, spent weekends on TryHackMe, read documentation for fun. I hit submit.

The job was listed as entry level.

The requirements asked for five years of experience, a CISSP, and prior SOC lead responsibility.

I sat there wondering if I was reading the same job description as the people who wrote it.

The lie hiding in plain sight

Here is the thing nobody tells you when you decide to get into cybersecurity: the industry has a vocabulary problem. “Entry level” does not mean what it means everywhere else. In most fields, entry level means you are new. You are learning. You are being given a chance.

In cybersecurity, entry level often means: we want someone junior enough to pay a junior salary, but experienced enough to do a senior job.

I saw this pattern over and over. Junior analyst roles demanding OSCP. Graduate positions requiring hands-on incident response leadership. Internships listing SIEM administration as a mandatory skill. I started screenshotting the worst ones. Not out of bitterness — out of disbelief.

And the cruel irony? The only way to get experience is to get a job. The only way to get the job is to have experience.

What I did instead of giving up

I want to be honest here. I almost did give up. Not dramatically I did not quit overnight. It was quieter than that. I started questioning whether I had chosen the wrong field. Whether Kenya was the wrong country. Whether I was the wrong person.

But I kept building anyway. Not because I had a plan. Because I did not know what else to do.

I set up a full SOC environment at home. VMware, Splunk, Wazuh, simulated attacks using MITRE ATT&CK techniques. I broke things deliberately and fixed them. I wrote down everything. I put the projects on GitHub not because anyone asked but because I needed proof — for myself as much as anyone else — that the work was real.

I took freelance clients on Upwork. Small businesses, startups, people who needed someone to configure their SIEM and could not afford a big firm. I was not making much. But I was getting reps. Real environments. Real stakes. Real documentation.

And I started GuardZen a cybersecurity service for SMEs. Less a business at first, more a forcing function. Having a name, a structure, a thing I was building, kept me accountable when the job market made me feel invisible.

The internship(job simulation) that changed the framing

When I got the PwC internship in Risk and Consulting, something shifted not just in my CV, but in how I understood the problem.

Sitting in those sessions, reviewing SOX controls, conducting gap assessments, writing findings reports I realised something. I already knew how to do most of this. The gap was not technical. The gap was credentialed proof. The industry does not just want competence. It wants validation from names it already trusts.

That is a systems problem, not a you problem.

And once I understood that, I stopped trying to become what job descriptions demanded and started being precise about what I had actually built.

What nobody talks about when they say “get certified”

Certifications help. I will not pretend otherwise. My CompTIA Security+ opened doors. My ISO 27001 Lead Auditor cert gave me language that resonated in risk and compliance conversations. They are real signals.

But the certification industrial complex has convinced a generation of aspiring security professionals that if they just collect enough badges, doors will open. That is not quite true.

Certifications tell an employer you know the concepts. Your projects tell them you can use them. Your communication tells them you can work with humans. You need all three, and most advice stops at the first one.

The people I have seen break in — genuinely break in, not just scrape by — are the ones who combined structured learning with messy, real, documented practice. TryHackMe rooms. Home labs. Client work. Blog posts. GitHub repositories that show how they think.

The certificate is the cover. The lab is the story.

To the person staring at that door right now

If you are in Nairobi, or Lagos, or anywhere that is not Silicon Valley or London, and you are trying to break into this industry — I see the specific weight you are carrying. You are doing it without the alumni network. Without the name-brand university on your CV. Without someone who already knows the hiring manager.

You are building in public and nobody is watching yet.

Keep building.

The irony of cybersecurity is that the skills that actually matter in the job methodical thinking, documentation discipline, the ability to hold your nerve when an incident is unfolding are not the skills the job description tests for. They are the skills you build in the silence, alone at your desk, when nobody is grading you.

The door will open. Sometimes you will pick the lock. Sometimes you will find a window. Sometimes you will build something people need badly enough that they come looking for you.

But it opens. I promise you it opens.

Barry Lutsai is a Cybersecurity Analyst at Daraja Plus and founder of GuardZen, a cybersecurity-as-a-service initiative for SMEs in Kenya. He holds CompTIA Security+ and ISO 27001 Lead Auditor certifications and is currently pursuing CySA+ and EC-Council CSA.


메타데이터
post_id
c05bc03ecb2b
slug
they-said-it-was-entry-level-it-required-5-years-of-experience-c05bc03ecb2b
url
https://medium.com/@lutsaibarry/they-said-it-was-entry-level-it-required-5-years-of-experience-c05bc03ecb2b
canonical_url
https://medium.com/@lutsaibarry/they-said-it-was-entry-level-it-required-5-years-of-experience-c05bc03ecb2b
author_url
https://medium.com/@lutsaibarry
status
ok
fetched_at
2026-06-23 03:48:11