Skip to main content

Where to find entry-level cybersecurity jobs: 6 places to look

Compare six places to find entry-level cybersecurity jobs, check employer requirements, and build a shortlist with practical search examples.

Updated by

JW
Jack WalshOct 2, 2026 · 9 min read

Hi, I'm Jack, the owner of Cybersecurity Jobs List, and co-founder of Himalayas (himalayas.app) and Cavuno (cavuno.com). Across all my platforms, I work with application security daily: dependency vulnerability scanning, secure authentication, API security, and data protection across hundreds of thousands of users. My technical background is in computer science (UNSW), where he studied security engineering and computer networks, and worked as a research assistant on VR experiments that were published in the Journal of Experimental Psychology. I also work with cybersecurity hiring data every day, tracking which companies are posting, what certifications actually appear in listings, how salaries differ by sub-discipline and clearance level, and where the talent gaps are widest. That combination of security practice, engineering at scale, and daily immersion in the hiring data is what shapes the content on this site. I'm currently based in Sydney, Australia.

Share this post

Illustration of a job seeker examining vacancy cards beside a laptop and a map.
Conceptual illustration created for Cybersecurity Jobs List.

You can find entry-level cybersecurity jobs through LinkedIn, Handshake, specialist boards such as ISACA's Career Center, technology job sites, Cybersecurity Jobs List and employers' own careers pages. Start with two sources that suit your target role, then check each promising vacancy against the employer's full description.

The useful question is whether you could do the advertised work and meet the requirements. A junior label helps you find a lead, but it doesn't settle that decision.

This guide focuses on US-oriented searches, with platforms that also serve other markets. We checked the sources on 3 October 2026. Access, filters and vacancies can change. These are six complementary places to look, rather than a ranking based on hiring success.

Six places to find entry-level cybersecurity jobs

Where to lookUseful starting pointWhat to check
LinkedInBroad searches across employers and related titlesFull requirements behind the experience label
HandshakeEarly-career and school-connected opportunitiesInstitution, graduation and qualification restrictions
ISACA Career CenterIT audit, risk and assurance searchesSeniority and whether the work matches your background
Built InTechnology-employer discoveryResponsibilities inside an entry-level collection
Cybersecurity Jobs ListA focused cybersecurity searchEmployer requirements, location and current application route
Employer careers pagesChecking a vacancy before applyingExact requisition, eligibility, shifts and application status

LinkedIn: describe the work and location you want

LinkedIn's current search guidance describes an AI-powered search that accepts your requirements in ordinary language. Its interface is changing, so older instructions for finding a particular filter may not match your account.

Try a specific query such as Junior security analyst roles in Chicago that accept help desk experience. This is a suggested search, not a promise that every result will meet it. Read the experience and duties sections yourself.

LinkedIn currently lists experience-level, date-posted and Remote filters among those available. Check its help page if a control is missing; don't rely on an old screenshot of the classic search interface.

Use the Jobs page to explore a title family, then look up promising employers directly. Keep the employer's job ID when one is supplied so you can recognize the same vacancy elsewhere.

Handshake: check which opportunities your account can access

Handshake is worth checking for early-career opportunities, especially when you have a connection to a participating school. Its search documentation makes an important distinction: school-connected users can access jobs and collections targeted to their institution, while people who register without a school see jobs posted to the broader network.

Some postings also have qualification restrictions. You may not be able to see or apply for every role another student can access.

Search by title or keyword and location, then choose the appropriate job type. Keep internships separate from full-time searches. A promising security internship can still be unsuitable if it requires current enrollment or a graduation date outside your window. Our cybersecurity internship guide explains how to check program eligibility before preparing an application.

The ISACA Career Center gives you another place to search for work involving IT audit, risk and assurance. It has keyword and location search, but its listings span levels of experience.

Try terms that describe the work you want to do, such as IT audit associate, technology risk analyst or security compliance analyst. Treat these as search ideas. They don't establish that a particular vacancy is junior, and an analyst title can still carry substantial experience requirements.

Look for duties you can connect to evidence from your background: checking records against a requirement, documenting exceptions, organizing evidence or explaining a process. Read how much independent judgment the employer expects. Supporting an audit and owning an organization's audit program are different starting points.

Built In: use the collection to discover employers

Built In's entry-level cybersecurity collection is a useful place to find technology employers to investigate. During our review, that collection also displayed staff and management roles. The collection heading therefore wasn't enough to establish junior eligibility.

Open the description and check who owns the work. A role that expects you to lead architecture decisions, manage a team or set a security strategy deserves a different assessment from one with supervised investigation or review tasks.

When you find an employer doing work that interests you, check its careers page for other openings. The first result you encounter may be too senior while a different role at the same organization fits your experience. Don't assume such a role exists; look for an actual posting.

Cybersecurity Jobs List: keep a focused search alongside the broader sites

Cybersecurity Jobs List is our own board. Use it as a focused source of security roles alongside a broader platform, then assess the full description and employer application page.

Start with the role you can explain most clearly. For example, SOC analyst listings can help you compare alert-investigation work. That collection includes different levels, so check the requirements before treating a result as an entry-level opportunity.

Keep a note of relevant employers and the duties they ask for. If you're still deciding which kind of work to target, our guide to getting into cybersecurity covers preparation and role choice. This search guide is the next step once you have a direction.

Employer careers pages: check the exact role before applying

Go from the employer's own website to its careers section, then match the title, location and job ID where available. The application system may use a different domain; following the employer's careers link gives you a route you can trace.

A live example shows why the details matter. On 3 October, Foresite's SOC Analyst posting described an Analyst I role accepting 0–2 years across SOC, security, IT operations or help desk/NOC work, and encouraged recent cybersecurity graduates to apply. It required on-site shifts in Overland Park, including scheduled weekend and holiday coverage. It asked for SIEM fundamentals, offered Chronicle training, and required Security+ or an equivalent within 90 days of hire if not already held. Scripting appeared under nice-to-have skills.

Our reading: this was worth assessing for a candidate with relevant foundations who could work those shifts. It wasn't a remote opening or a job with no skill expectations. Reopen the posting before applying; its availability and requirements may change.

Search beyond one job title

Build searches around a kind of work, then vary the title. Keep your location requirement consistent at first so you can see whether the wording changes the results.

The examples below are starting queries, not standardized job levels. Add your city, region or eligible country using the site's search controls.

Work to exploreSearch ideasRead for
Investigating alertsSOC analyst I; junior security analyst; security operations traineeSupervision, shifts, investigation expectations
Reviewing accessIdentity access analyst; access management analystRoutine access work versus owning identity architecture
Checking controls and evidenceIT audit associate; technology risk analyst; security compliance analystSupporting reviews versus leading audits or programs
Building experience in ITHelp desk analyst; NOC technician; IT supportRelevant duties and a worthwhile role in its own right

The last row contains adjacent IT roles. They aren't automatically cybersecurity jobs or guaranteed stepping stones. Consider them when the work itself suits you and could build experience you want. Our help desk to cybersecurity guide shows how to connect support work with security responsibilities without exaggerating your experience.

Change one part of a search at a time. If a narrow title produces little useful work, try its related title before removing your location or experience constraints. Otherwise, you can end up with more results and no better options.

Decide which vacancies deserve an application

Read each promising posting in three passes. First, check whether you can accept the stated location, work arrangement and schedule, and whether you meet explicit eligibility requirements. Treat an unstated condition as unknown. A remote label alone doesn't establish that the employer can hire in your country.

Next, separate required qualifications from preferences. Read the wording and when a requirement must be met. A credential required after joining is different from one required when you apply. Don't silently convert a mandatory requirement into a preference because the rest of the job looks appealing.

Then connect the main duties to evidence you could discuss. That might be employment, coursework, volunteering or a clearly labeled personal project. Explain what you did and what you still need to learn. Use our cybersecurity resume examples to turn that evidence into application material.

Three fictional shortlist decisions

These invented examples illustrate the screening process; they aren't current vacancies.

  • An analyst advert accepts support experience and offers supervised investigations. You have a year on a help desk and can explain a relevant troubleshooting case. If you meet its other requirements, it belongs on your application shortlist. Prepare the case rather than claiming you have already worked in a SOC.
  • A remote trainee advert requires residence in a country where you don't live. The title fits, but the stated location requirement doesn't. Leave it off your shortlist unless the employer clarifies that another arrangement is possible.
  • A junior-labelled advert requires several years leading incident response. You have coursework and lab exercises. The duties and mandatory experience make this a poor match for an entry-level application, despite the label. Search for supported investigation work instead.

You don't need a percentage score for matching a posting. Record the requirement you meet, the evidence you have and any unresolved condition that could change your decision.

Turn the search into a repeatable routine

Choose one broad source and one source suited to your target work. Review their results, verify promising vacancies on employer pages, and keep a single shortlist. Revisit employer pages you've already identified rather than rebuilding your search from scratch each time.

Copy these fields into a note or spreadsheet:

  • Employer, title, job ID and original posting link
  • Location, work arrangement and shifts
  • Required experience and other eligibility conditions
  • Closing date, if the employer states one
  • Evidence you can offer for the main duties
  • Missing information and your next action
  • Application date and current status

Record the same requisition once, even if several sites show it. Mark a missing deadline as “not stated” rather than guessing. A useful search session can finish with one well-assessed role; there's no need to invent an application quota.

Common questions

Can I find cybersecurity jobs with no professional experience?

Look for postings that explicitly accept graduates, trainees or relevant project experience, then check the skills they still require. “No professional experience” and “no preparation” are different conditions. Apply based on the description and your evidence rather than a search-result label.

Do I need to be a student to use these sources?

This list isn't limited to student programs. Handshake's school connection changes which opportunities you can access, and individual internships may require enrollment. Check the conditions of each posting; don't assume an early-career role is restricted to current students.

Should I search only for remote jobs?

Use remote-only searches if that is a firm requirement for you, and check eligible locations and schedules within each result. If you can also accept local work, run a separate search for it. Keeping the searches separate makes it easier to assess the options you could take.

Start with current cybersecurity listings, choose a role to investigate, and fill in the shortlist fields from its employer posting before you spend time tailoring an application.

Related posts