Career changer based in Portugal. Five years in industrial IT and automation — PLCs, SCADA, industrial networks, robotics — currently employed as an IT technician. Targeting SOC Analyst L1 or junior cybersecurity analyst, remote in the EU or hybrid regionally.
Certifications: ISC2 CC and CompTIA Security+ (passed recently), TryHackMe SOC Level 1 path nearly finished at top 2% globally, plus Cisco Networking Academy and Fortinet NSE 1–3. I also publish write-ups of my investigations on GitHub — full methodology, not just answers.
Roughly 35 security-titled applications in five weeks. Twelve rejections overall, zero interviews from the security side specifically. Every rejection that gave a reason said the same thing: not enough professional experience.
CV below, anonymised. I'd genuinely rather be told something is wrong than be told it looks fine.
**What I'm trying to work out:**
1. **Is the OT/ICS angle a real differentiator, or am I overselling it?** I lead on it because most people entering security don't have hands-on time in industrial control environments. But I don't know whether hiring managers actually value that for an L1 SOC seat, or whether it just makes me read as an automation guy who did some courses.
2. **Is "zero professional security experience" simply fatal at L1 in the current market**, regardless of how the CV reads? If it is, I'd rather know and change the plan than keep polishing a document that was never the problem.
3. **The TryHackMe numbers** — top 2%, 140+ rooms. Does anyone hiring actually weight that, or is it filler?
4. **The skills section** — I list a lot of tools. Does that read as breadth, or as someone padding a list with things they touched once in a lab?
Portuguese market, so local conventions differ somewhat from US norms — content and structure feedback is more useful to me than formatting conventions.
—
# SOC ANALYST L1 · CYBERSECURITY ANALYST
Career changer from industrial IT, automation and OT — 5+ years technical experience
ISC2 Certified in Cybersecurity (CC) • CompTIA Security+ • TryHackMe SOC Level 1 (nearing completion)
*[contact details and profile links removed] • Northern Portugal • Remote (EU) or Hybrid (regional)*
## PROFESSIONAL SUMMARY
Cybersecurity-focused IT professional with 5+ years of experience in industrial, networking, and technical support operations, now transitioning into a Security Operations Center (SOC) Analyst L1 role. ISC2 Certified in Cybersecurity (CC) and CompTIA Security+ certified, with the TryHackMe SOC Level 1 (SAL1) path nearing completion (top 2% global rank, 140+ rooms completed). Hands-on experience in SIEM and log analysis, endpoint and network monitoring, and phishing and incident analysis, developed through TryHackMe, Cisco Networking Academy, and Fortinet NSE training. Combines strong Windows/Linux administration and networking fundamentals with genuine OT/ICS and industrial-control-systems experience — a distinctive asset for organizations securing industrial and critical-infrastructure environments. A structured, root-cause approach to troubleshooting in live production environments translates directly into disciplined, methodical alert triage and incident investigation.
## TECHNICAL SKILLS
– **Monitoring & Detection Tools:** Splunk, Sysmon, Microsoft Sentinel, SIEM, EDR, SOAR
– **SOC Analysis Practices:** Alert Triage, Log Analysis, Endpoint Investigation, Incident Investigation & Reporting, Phishing Analysis, Threat Intelligence
– **Security Frameworks:** MITRE ATT&CK, Cyber Kill Chain, OWASP Top 10
– **Security Fundamentals:** Access Control, Authentication, Network Security, Endpoint Security, Vulnerability Management, Incident Response, Threat Detection
– **Offensive Security / Testing Tools:** Wireshark, Nmap, Tcpdump, VirusTotal, CyberChef, Metasploit, Burp Suite, Hydra, Gobuster, SQLMap, John the Ripper
– **Networking:** TCP/IP, IPv4, DNS, DHCP, VLAN, Ethernet, Industrial Ethernet, SSH, SMB, HTTP/HTTPS, VPN, Cisco IOS, Network Troubleshooting
– **OS & Administration:** Windows 10/11, Windows Server, Linux, Ubuntu, Kali Linux, Active Directory, NTFS Permissions, Windows Command Prompt, Event Viewer, Sysinternals, Microsoft 365
– **Scripting & Databases:** Python, PowerShell, Bash, SQL, SQL Server, PHP, JavaScript
– **Industrial / OT:** PLC Programming, Siemens TIA Portal, SCADA, ICS, OT, Modbus TCP, Industrial Automation, KUKA, ABB Robotics, Electrical Control Systems, Equipment Commissioning
## HANDS-ON LABS & CYBERSECURITY PRACTICE
– TryHackMe — top 2% global rank, 140+ rooms completed, 90+ day streak, 30+ badges earned. Completed the Pre Security and Cyber Security 101 paths, and nearing completion of SOC Level 1 (SAL1), with practical rooms covering SIEM and log analysis (Splunk, Wazuh, Microsoft Sentinel), endpoint and network monitoring, and phishing and incident analysis — building repeated, hands-on practice investigating alerts and identifying indicators of compromise.
– CompTIA Security+ — globally recognized, ISO/ANSI-accredited, DoD 8140-approved certification covering core security concepts, threats and vulnerabilities, security architecture, and security operations.
– Cisco Networking Academy — 7 completed courses across cybersecurity and networking fundamentals: Introduction to Cybersecurity, Networking Basics, IT Customer Support Basics, Networking Devices & Initial Configuration, Endpoint Security, Network Defense, and the Junior Cybersecurity Analyst Career Path.
– Fortinet NSE 1–3 — foundational network security and threat landscape training.
## PROJECTS & WRITE-UPS
– Security Investigation Write-Ups — a public portfolio of hands-on investigations, each documenting full methodology (evidence gathering, tool-based analysis, root-cause findings) rather than just the final answer, spanning multiple security domains and growing continuously as new rooms are completed. Published on a personal GitHub repository. *[link removed for this post]*
## PROFESSIONAL EXPERIENCE
**Information Technology Technician — Industrial IT, Automation & Technical Support**
*Industrial Manufacturing Group (3 business units) | Jan 2026 – Present*
– Support 8 production lines equipped with 16 pick-and-place robots and associated PLC/automation systems, troubleshooting connectivity, automation faults, and reliability issues using structured, root-cause methodologies — the same disciplined triage process used in SOC alert investigation.
– Designed, built, and programmed a custom PLC monitoring board — including all electrical wiring and component integration — to independently measure gas and water consumption against utility billing; the investigation uncovered a significant billing discrepancy.
– Installed an industrial machine with no existing documentation, independently troubleshooting the PLC program, wiring, and missing components to bring it into full operation.
– Currently designing the electrical schematic for a new PLC control panel being built from the ground up to add a new path to an existing production line.
– Technologies: PLC Systems, Robotics Systems, SCADA, Industrial Ethernet, Modbus TCP, TIA Portal, Electrical Control Systems, Windows, Linux, Networking Fundamentals, Office.
**Technical Department Technician**
*Water-Treatment Equipment Company | Jun 2025 – Nov 2025*
– Diagnosed and repaired electrical and mechanical equipment faults, replacing components to restore functionality and minimize downtime; served as the technical escalation point for customer-support calls requiring deeper technical explanation.
**Robotics, Automation and Industrial Control Technician**
*Industrial Engineering Research Institute | Oct 2021 – May 2025*
– Delivered complex, safety-critical technical work across robotics, additive manufacturing, and materials testing — demonstrating rigorous, evidence-based analysis directly transferable to security investigation.
– Installed and commissioned 2 industrial robot systems (ABB and KUKA) for automated manufacturing and testing applications.
– Commissioned 2 PLC systems: one for an Industry 4.0 solution feeding key production parameters to a live monitoring dashboard, and one to operate a custom-built electromagnetic oven.
– Completed specialized manufacturer training to safely operate advanced equipment, including a metal powder-bed laser fusion system and two mechanical-testing systems.
– Produced technical reports and supported researchers and partner companies with ongoing Master's and PhD research studies.
– Technologies: Robotics Systems, KUKA, ABB, PLC Commissioning, Industry 4.0 Dashboards, Metal Powder-Bed 3D Printing, Mechanical Testing Equipment, CAD Software, Arduino, Industrial Automation, Windows, Linux, Office.
**Earlier Experience**
*2014 – 2019*
– Restaurant Manager, independent restaurant (2014–2019): managed daily operations, staff coordination, inventory, and customer service in a fast-paced environment (CCTV systems, billing software).
– Programming Intern, health-sector startup (Sep–Dec 2014): software programming and database updates using SQL and PHP.
## CERTIFICATIONS & TRAINING
– 2026 — Certified in Cybersecurity (CC), ISC2
– 2026 — CompTIA Security+
– 2026 — Fortinet NSE 1–3 Cybersecurity
– 2026 — Cisco: Introduction to Cybersecurity; Networking Basics; IT Customer Support Basics; Networking Devices & Initial Configuration; Endpoint Security; Network Defense; Cyber Threat Management; Junior Cybersecurity Analyst Career Path
– In progress — TryHackMe SOC Level 1 (SAL1, nearing completion); Cyber Security 101; Pre Security
## EDUCATION
– 2019–2021 — Technological Specialization Course in Robotics, Automation and Industrial Control — national vocational training institute
– 2013–2014 — Technological Specialization Course in Programming and Web Applications — private university
## LANGUAGES
– Portuguese C2 · English C1 · Spanish B2
Source: r/resumes · by /u/IncognitoRegards