
Sign up to save your podcasts
Or


Car salesman to Tier 2 SOC analyst in six months sounds almost impossible. Gilbert Sanchez did it after 956 applications, Network+ and Security+, practical cybersecurity projects, tailored resumes and persistent follow-up.
In this episode of Cyber Careers, Gilbert explains why he left car sales, how he structured his career change and what finally helped him stand out. We also discuss the failed interviews, the follow-up email that mattered and the parts of his approach that other career changers should not copy blindly.
Gilbert's result was exceptional. It is an individual case study, not a typical outcome or guaranteed timeline.
In this episode:
Why Gilbert left car sales for cybersecurity
How he approached Network+ and Security+
What he learned from submitting 956 applications
How projects, labs, GitHub and tailored resumes supported his job search
Why communication, networking and follow-up mattered
What it is like starting directly in a Tier 2 SOC analyst role
Connect with Gilbert Sanchez:
YouTube: https://www.youtube.com/@GilbertSanchz
LinkedIn: https://www.linkedin.com/in/gilbertesanchez/
X: https://x.com/gilbertsanchz
Resources:
Pocket Prep IT and Cybersecurity practice: https://pocketprep.sjv.io/2RYKo0
Cybersecurity Job-Ready Blueprint: https://lukegoughcoaching.com/cybersecurity-job-ready-blueprint/
Work with Luke: https://lukegoughcoaching.com/coaching/
The Career Compass newsletter: https://lukegoughcoaching.com/newsletter/
Watch the video interview on YouTube: [ADD PUBLIC YOUTUBE EPISODE URL]
Affiliate disclosure: I may earn a commission if you use some of the links above, at no extra cost to you.
Chapters:
00:00 From Car Sales to Cyber
06:31 Why Cybersecurity
13:15 Study Strategy
17:34 956 Applications
26:56 Projects and Interviews
34:36 Tier 2 and Lessons
About Cyber Careers:
Cyber Careers with Luke Gough gives practical cybersecurity career advice from a recruiter's perspective. Subscribe or follow the show for interviews, job-search guidance and realistic advice on building a career in cybersecurity.
No cybersecurity experience? These cybersecurity projects for beginners can give recruiters the proof they need to take your application seriously.
In this episode of Cyber Careers with Luke Gough, Luke breaks down how to build practical cybersecurity experience without already having a cyber job. From the recruiter side of the table, he explains which projects, labs and portfolio pieces actually help, how to document them properly, and how to turn them into clear evidence on your resume.
Luke covers:
Why certifications are rarely enough by themselves
The three proof points beginners should build
Project ideas for SOC, GRC, IAM and cloud security
What recruiters want to see in a project write-up
How to turn labs into stronger resume bullets
Where to host your portfolio
A practical 30-day evidence-building plan
Four common beginner questions in the podcast Q&A
If your resume currently says “home lab” or lists a platform without explaining what you did, this episode will show you how to make that evidence useful.
Projects discussed include Splunk and Windows event log analysis, phishing analysis, risk registers, Essential Eight and ISO 27001 control mapping, user access reviews, least privilege, onboarding and offboarding risks, and cloud account hardening.
Chapters
00:00 Evidence beats certificates
00:54 Cyber Careers introduction
01:09 What cybersecurity evidence means
01:51 The recruiter resume test
02:37 What does not count as evidence
03:34 Three proof points to build
03:50 Projects for SOC, GRC, IAM and cloud
04:50 How to document a project
05:32 Stronger cybersecurity resume bullets
06:38 Your 30-day evidence plan
07:44 Communication is evidence
08:42 Bonus Q&A
10:20 Build one project and keep going
Links and resources
Submit a question for a future episode: https://tally.so/r/816lNl
Work with Luke through 1-on-1 cybersecurity career coaching: https://lukegoughcoaching.com/coaching/
Visit Luke Gough Coaching: https://lukegoughcoaching.com
Join The Career Compass newsletter: https://thecareercompass-newsletter.beehiiv.com/
Connect with Luke on LinkedIn: https://www.linkedin.com/in/luke-gough
Subscribe on YouTube: https://www.youtube.com/@Luke-Gough?sub_confirmation=1
Follow Luke on X: https://x.com/Avidityrecruit
Listen on Apple Podcasts: https://podcasts.apple.com/au/podcast/cyber-careers-with-luke-gough/id1896616557
Email the podcast: [email protected]
Follow Cyber Careers with Luke Gough wherever you listen so you do not miss the next episode.
Do you need a cybersecurity degree to get a job, or are certifications and projects enough?
In this episode of Cyber Careers with Luke Gough, Luke breaks down the degree question from the recruiter side of the table. He explains why university study can help, why it is not absolutely essential for every cybersecurity job, and why certifications plus projects are often the evidence hiring managers need to see.
Luke covers:
Why a cybersecurity degree can help but is not mandatory for every path
Why certifications and projects are valuable hiring signals
How a project portfolio shows what a candidate can actually do
Why the strongest combination is degree plus certs plus portfolio
How to think about bachelor's degrees, master's degrees and other university options
Why job ads should guide your decision before enrolling
The practical evidence recruiters still need to see
How to think about cost, time, debt and opportunity cost without quoting university prices
The decision framework Luke would use before committing to major study
Submit a question for a future episode: https://tally.so/r/816lNl
For 1-on-1 cybersecurity career coaching, visit https://lukegoughcoaching.com
In this episode of Cyber Careers with Luke Gough, Luke breaks down the difference from the recruiter side of the table. He explains what each role actually does, who each path tends to suit, what evidence recruiters look for, and how to decide which path to aim for first.
Luke covers:
Why SOC is not the default path for everyone
Why GRC is not the easy non-technical fallback
What SOC analysts actually do day to day
What GRC analysts actually do day to day
How the work style differs between operations and assurance
Which backgrounds often transfer into each path
What projects and resume evidence help each pathway
Why Australian GRC can involve the Essential Eight, ISM, ISO 27001, third-party risk and financial-services regulation
A 30-day test to choose your first lane without overcommitting
Submit a question for a future episode:
https://tally.so/r/816lNl
Luke Gough YouTube channel
https://www.youtube.com/@Luke-Gough
For 1-on-1 cybersecurity career coaching, visit https://lukegoughcoaching.com
Cybersecurity certifications can be useful. They can also waste a lot of your money and time.
In this episode of Cyber Careers with Luke Gough, Luke breaks down how recruiters actually view certifications and why the right cert depends on your target role, not whatever certification is trending online.
Luke covers:
Why Security+ is still the strongest foundation for many entry-level candidates
When Network+, ISC2 CC, CySA+, BTL1, SC-200, AZ-500, ISO 27001, CISA, CRISC, CISM, eJPT, PNPT and OSCP make sense
Why CISSP is usually a mid-to-senior career credential, not an entry-level shortcut
Why CEH and mystery bootcamp certificates can be overhyped
The cert-stacking trap that keeps candidates busy but does not always get them interviews
The decision framework Luke would use before spending money on another certification
The core message is simple: certifications help when they send the right signal for the role you want. They do not replace practical evidence, projects, labs, commercial experience, or a clear resume.
If you are trying to decide what to study next, start with the job you want. Look at real job ads, identify the repeated requirements, choose one relevant certification, then build proof that you can apply what you learned.
Listen on Apple Podcasts: https://podcasts.apple.com/au/podcast/cyber-careers-with-luke-gough/id1896616557
You can also search Cyber Careers with Luke Gough on Spotify or Apple Podcasts.
Submit a question for a future episode: [email protected] or fill out a form at https://tally.so/r/816lNl
For career advice and how to break into Cybersecurity:
https://www.youtube.com/@Luke-Gough
For 1-on-1 cybersecurity career coaching, visit https://lukegoughcoaching.com
You're applying for cybersecurity roles, sending out your resume, and hearing nothing back. No recruiter calls. No interviews. Sometimes not even a proper rejection.
In this episode of Cyber Careers, Luke Gough breaks down the biggest cybersecurity resume mistakes he sees from the recruiter side of the table. He explains how resumes actually get screened, what recruiters look for in the first few seconds, and why a decent candidate can still get skipped if the right evidence is not obvious.
Luke covers:
Why your resume is not a full career history
How recruiters and hiring teams scan cybersecurity resumes
Why a generic professional summary hurts you
How to make your target role clear
Why responsibilities are weaker than evidence
What to include if you do not have cyber work experience yet
How to use projects, labs, GitHub, LinkedIn, and portfolio links properly
Why tailoring your resume matters more than sending hundreds of generic applications
If you are trying to break into cybersecurity, move from IT into cyber, or improve your callback rate, this episode will help you tighten the signal before you send your next application.
Submit a question for a future Cyber Careers episode: https://tally.so/r/816lNl
Cyber Job-Ready Blueprint: https://lukegoughcoaching.com/cybersecurity-job-ready-blueprint/
Starting from zero in cybersecurity can feel noisy: too many certifications, too many job titles, and too much conflicting advice.
In this first episode of Cyber Careers with Luke Gough, Luke breaks down the practical 2026 roadmap he would follow if he had to start again from scratch. This is not a shortcut or a "get hired in 30 days" promise. It is a realistic path for beginners who want to understand the market, build the right foundations, create evidence, and apply with a clearer strategy.
In this episode, you will learn:
- How to map the cybersecurity job market before choosing a lane
- Why networking fundamentals matter, even if you are aiming for SOC, GRC, IAM, or cloud security
- How to build practical evidence through labs, projects, and write-ups
- Why networking and visibility matter before you need a job
- Where certifications like Security+ fit into a realistic beginner plan
- How to apply smarter with a targeted resume, LinkedIn profile, project evidence, and follow-up messages
The podcast-only Q&A also covers:
- Whether help desk is required before cybersecurity
- Why Security+ is useful but usually not enough on its own
- How long it may realistically take to break into cybersecurity
- How career changers can position previous experience
- What to do this week if you are starting from zero
Chapters:
0:00 - Introduction
2:44 - Part 1: Map the Battlefield (Weeks 1-2)
10:06 - Part 2: Build the Foundations (Month 1)
14:22 - Part 3: Build Evidence (Month 2)
18:48 - Part 4: Build Connections (Month 3)
22:32 - Part 5: Get Certified Strategically (Month 4)
26:51 - Part 6: Apply Smart (Months 5-6)
31:02 - The Full Roadmap Recap
32:32 - Q&A: Podcast-Only Section
32:50 - Q1: Do I need help desk first?
34:17 - Q2: Is Security+ enough to get hired?
35:33 - Q3: How long does it take?
37:12 - Q4: What if I'm older or changing careers?
39:27 - Q5: What should I do this week?
Host: Luke Gough
Show: Cyber Careers with Luke Gough
Have a cybersecurity career question for a future episode?
Submit it here: https://tally.so/r/816lNl
You can also email me at [email protected].
From the publisher's feed