I currently work as a Technical Support Engineer and recently applied for a Security Analyst role internally. I’m curious what you think would be a fair salary for the position based on the job description, my resume, and my experience. I was offered $78,000.
I feel like I have a strong IT foundation and several transferable skills that line up well with this position.
Based on the responsibilities, does this seem like a legitimate entry-level cybersecurity role where I’d actually gain valuable security experience and be able to build toward more advanced security positions? Or do the responsibilities sound somewhat inflated/generic, where the actual day-to-day work may not provide much meaningful cybersecurity experience?
How can I counter-offer? Would it make sense to mention that I plan to get my Security+ within the next 6 months and potentially negotiate a salary increase once I obtain it? If so, what would be a reasonable amount to ask for?
Before signing an offer, what questions should I ask the hiring manager to make sure I understand the actual day-to-day responsibilities, what security tools I’ll be working with, and how much hands-on cybersecurity experience I’ll actually get?
Job Description:
This is an entry-level security role focused on supporting the organization’s day-to-day cybersecurity operations while working under the guidance of more experienced security professionals. The position would provide exposure to areas such as security monitoring, vulnerability management, incident response, security assessments, and other operational security activities.
The role would also involve helping identify and investigate potential security threats, assisting with audits and security assessments, responding to security incidents, and helping ensure the organization follows established security policies, standards, and compliance requirements.
Key Responsibilities:
- Help implement and maintain various security controls and processes.
- Monitor security alerts and events and escalate potential issues when necessary.
- Assist with vulnerability scanning and keeping track of remediation efforts.
- Participate in security assessments, audits, and testing.
- Follow established security policies, procedures, and industry standards.
- Apply cybersecurity concepts and techniques while working with senior team members.
- Document security-related activities, findings, and remediation work.
- Work with other internal teams on security-related projects and initiatives.
- Assist with the intake, initial triage, and tracking of security incidents.
- Handle security-related tickets and other operational tasks.
- Coordinate with technical teams to help address and remediate security issues.
- Assist with implementing, configuring, and maintaining security tools and technologies.
Skills & Qualifications:
- At least 2 years of experience in cybersecurity, IT operations, or a related area.
- Basic understanding of networking, systems, and network security concepts.
- Some familiarity with security technologies such as SIEM platforms and vulnerability scanning tools.
- Basic knowledge of incident response and security incident management.
- Strong analytical, troubleshooting, and problem-solving abilities.
- Good communication and ability to work effectively with others.
- Experience working in an enterprise IT environment and supporting technology operations or service delivery.
- Experience with ticketing, incident management, and SLA-driven support processes.
- Basic knowledge of Windows, servers, and networking.
- Ability to communicate and coordinate with both technical and non-technical teams.
Preferred Qualifications:
- A bachelor’s degree in cybersecurity, information security, computer science, or a related area.
- Entry-level security certifications such as CompTIA Security+ or CEH.
- Some experience or exposure to cloud security.
- Experience assisting with enterprise technology deployments or system integrations.
- Experience in healthcare, regulated industries, or other environments where compliance and information security are important.
How My Qualifications Compare:
- I have 3+ years of experience internally with the company as a Technical Support Engineer, along with 2 years of previous Help Desk experience.
- I have the CompTIA A+ and Network+ certification.
- I’m not currently familiar with security-specific tools such as SIEM platforms or vulnerability scanners, but my current role has given me transferable skills, including analyzing logs, troubleshooting system issues, and identifying potential problems.
- I’m familiar with incident response processes because incident management is part of my current role.
- My position as a Technical Support Engineer requires strong analytical, troubleshooting, and problem-solving skills.
- I have strong communication and teamwork skills and regularly collaborate with different technical teams to resolve issues.
- I have experience working in enterprise IT environments supporting system operations and service delivery, which is a major part of my current job.
- I’m familiar with incident tracking, ticketing systems, and SLA-based support models.
- I have a basic understanding of Windows systems, server environments, and networking fundamentals.
- I have experience working in healthcare IT.
Where I Fall Short / Preferred Qualifications:
- I don’t have a degree in Information Security, Computer Science, or a related field. My degree is in Biology.
- I don’t currently have the CompTIA Security+, but I would like to obtain it within the next 6 months.
- I don’t have hands-on experience with security tools such as SIEM platforms, vulnerability scanners, EDR, or other dedicated security technologies.
- I don’t currently have experience working in cloud security environments, although this is an area I would be very interested in gaining experience in.
- I’m transitioning into cybersecurity, so I don’t have several years of dedicated cybersecurity experience yet.