Help desk to cybersecurity in 12 months is realistic if you do three things in parallel: earn Security+ in the first quarter, spend the middle six months volunteering for every security-adjacent task your current employer will let you touch, and build a small body of documented proof (a home lab, a scan-and-remediate writeup, a policy you drafted) that you can point to in an interview. The people who fail this transition are not the ones who lack talent. They are the ones who study for a cert in isolation, never touch a security task at work, and then apply cold to 200 postings with a resume that still says “reset passwords.”
You already troubleshoot, talk to angry users, and know what Active Directory looks like from the inside, which puts you ahead of a new grad with no work history. The plan below assumes a standard help desk job and eight to ten hours a week of outside effort.
Months 1 to 3: Security+ and the vocabulary shift
Security+ (SY0-701) is the first move because it is the recruiter filter, it is the DoD 8140 baseline for a large share of federal and contractor security roles, and it teaches you the vocabulary that lets you recognize security work when it walks past your desk. The exam is roughly $439 direct as of 2026, and the 8-week Security+ study plan covers exactly how to structure the study from zero.
Give yourself up to twelve weeks rather than eight if you are working full time. During these months, also do one thing at work: start reading every ticket that touches an account lockout, a phishing report, or a malware alert as a security event, and keep a private log of what you saw and how it was resolved. That log becomes interview material later.
- Weeks 1 to 10: Security+ study, one domain at a time, practice questions from week 4 onward.
- Weeks 10 to 12: sit the exam. Schedule it early so the date forces the studying.
- Ongoing: the security event log. Date, symptom, root cause, who fixed it, what control would have prevented it.
Months 3 to 4: make yourself the security person on the help desk
Every help desk has security work that nobody owns. Your job in this window is to own it, visibly and without being asked twice. The specific tasks to volunteer for, roughly in order of how easy they are to get:
- Phishing triage. Ask to be the first look on user-reported phishing. Learn to read headers, check sender domains, and write a two-line disposition. This is tier 1 SOC work with a different title.
- Account lifecycle. Offboarding checklists, stale account reviews, group membership cleanups. This is access control (the AC family in NIST 800-53, if you want to speak the language later) and it is the single most-audited area in any organization.
- Patch and vulnerability follow-up. If someone runs a vulnerability scanner, ask to be the person who chases the remediation tickets. You will learn what CVSS scores mean, why the same five machines never get patched, and how to document an exception.
- Documentation. Offer to write or update the procedure for any of the above. Written procedures are the currency of GRC and ISSO work, and nobody else on the help desk wants the job.
The wry reality: the security team is understaffed, tired, and would love to hand off the boring parts. Boring parts are how you get in. I have watched help desk technicians become the de facto junior security analyst by being the only person who reliably closed the vulnerability tickets.
Months 4 to 7: the home lab and the first proof project
By now you have Security+ and some hands-on at work. The next gap is demonstrable technical proof outside of tickets. Build a home lab. It does not need to be elaborate: a laptop or desktop with 16 GB of RAM running two or three virtual machines is enough. The Wazuh SOC analyst home lab walkthrough gets you a working SIEM, a Windows endpoint, and a Linux endpoint in a weekend.
Then produce one complete project with a written report. My recommendation for help desk people specifically, because it maps to what you already know:
- Stand up a Windows VM joined to a small domain (or standalone if you must).
- Run a vulnerability scan against it with a free scanner. Export the results.
- Pick five findings. For each, document the finding, the risk in plain English, the fix, and the evidence that the fix worked (a before and after scan, a screenshot with hostname and timestamp).
- Track the five items in a simple POA&M-style spreadsheet: finding, owner, milestone, due date, status, closure evidence.
- Write it up as a two-page report a manager could read.
That single project demonstrates vulnerability management, remediation, evidence discipline, and documentation, and it is worth more in an interview than a second certification.
Months 6 to 8: pick the lane and the second cert (maybe)
Around the halfway mark, decide which kind of security job you are aiming for. (If you want cloud security, add an AZ-900 or AWS Cloud Practitioner and rebuild part of the lab in a free cloud tier.)
SOC analyst or security operations
Lean on the home lab. Add detections in Wazuh, learn to read Sysmon logs, and get comfortable with one scripting language enough to parse a log file. A second cert is optional here; CySA+ is the natural one if your employer will pay for it, but a strong lab writeup beats CySA+ with no lab.
GRC analyst, compliance, or ISSO
Lean on the documentation and access control work. Read NIST 800-53 Rev 5 at the family level and write implementation statements for five controls based on your own employer (anonymized) or your lab. Learn what a POA&M is, what a risk register is, and what an assessor asks for. No second cert needed for entry; Security+ already satisfies the DoD 8140 baseline for the bulk of ISSO postings.
Whichever lane you pick, do not collect a third certification before you have a job. Certifications open the door; proof gets you through it.
Months 8 to 10: engineer the internal transfer
The single highest-probability route from help desk to security is an internal move at your current employer, because they already trust you, the hiring manager has already seen your work, and internal candidates skip the 300-applicant pile. Treat it as a campaign, not a hope.
- Tell your manager, on purpose. By month 6, your manager should know you are aiming for security. Good managers help; indifferent ones at least will not be surprised. Frame it as “I want to grow into security here,” not “I want to leave the help desk.”
- Get a coffee with the security lead. Ask what their team’s biggest annoying backlog is. Offer to take a piece of it. Follow through. Do this twice and you are a known quantity.
- Ask about the cert budget. Companies with a training budget will often pay for CySA+, a SANS course, or a cloud cert for someone who has already shown initiative. Free money for your resume.
- Watch the internal postings and ask before they post. Security teams often know a headcount is coming months ahead. If you have asked, you will hear about it first.
- Have your proof ready. Your event log, your remediation project, the procedures you wrote. When the conversation happens, you want to hand over evidence, not promises.
If your employer has no security team at all, skip ahead to the external search. Otherwise do the internal campaign first. It is faster, and the worst case is a manager who now knows exactly why you left.
Months 9 to 12: the external search, done correctly
External applications should start no later than month 9 even if the internal route looks promising. Target the titles that actually hire from help desk: SOC analyst I, security analyst (junior), information security analyst, IT security specialist, GRC analyst, compliance analyst, vulnerability management analyst, and, on the federal side, ISSO I or cybersecurity analyst on contractor postings.
Rewrite the resume before you send it anywhere. Every help desk bullet gets translated into its security equivalent. “Reset user passwords” becomes “Managed account lifecycle and access requests for 400 users, including offboarding verification.” “Removed viruses” becomes “Performed malware triage and remediation on endpoints, escalating confirmed incidents to the security team.” Both are true. One of them gets read.
The 6-month plan for getting a cybersecurity job with no experience covers the application mechanics in detail; the short version is that ten targeted applications with a tailored resume beat a hundred blind ones, and a referral from anyone at the company changes your odds more than any other single factor.
The federal and cleared shortcut
If you are a US citizen, there is a route I rarely see help desk technicians consider, and I think it is the single best-kept advantage in this transition: DoD contractor and federal cybersecurity roles. Contractors supporting the Department of Defense need people who hold the DoD 8140 baseline certification (Security+ qualifies for a wide range of positions) and can obtain a Secret clearance. Help desk experience plus Security+ plus US citizenship and a clean record is a sponsorable candidate for those postings.
The clearance is the moat. Once a contractor sponsors your investigation and it is adjudicated, you hold something a bootcamp graduate cannot buy, and cleared security roles pay a premium over their commercial equivalents at every level. The federal and DoD route into cybersecurity explains how sponsorship works, who hires people without an existing clearance, and what the timeline looks like.
One more angle: DoD contracts routinely run their own help desks, and those help desk positions often require Security+ and a clearance. Taking a cleared help desk job is a legitimate two-step. Twelve months of cleared help desk work with a Security+ makes the move to a cleared ISSO or SOC role a very short hop, and you get the clearance investigation done on someone else’s dime.
What the 12 months look like on one page
- Months 1 to 3: Security+. Start the security event log.
- Months 3 to 4: volunteer for phishing triage, account reviews, patch follow-up, and documentation.
- Months 4 to 7: home lab with a SIEM. Complete one scan-remediate-document project with a written report.
- Months 6 to 8: pick SOC, GRC, or cloud. Deepen in that direction. Second cert only if the employer pays.
- Months 8 to 10: internal transfer campaign. Manager, security lead, cert budget, early word on headcount.
- Months 9 to 12: external applications with a translated resume. Federal and cleared postings included.
The timeline slips for two reasons: the cert takes longer than planned (fine, add a month) or the volunteering never happens because it felt awkward to ask (not fine, that is the part that separates you from the pile). If you are at month 8 with Security+ and nothing else, the fix is not another cert. It is asking the security lead tomorrow for their worst backlog.
If you want this plan expanded into a week-by-week roadmap with the study schedule, the lab builds, the project templates, and the application targets in one place, Zero to Hired is the version I built for exactly this transition, and it costs less than a single practice exam voucher.


Leave a Reply