So many people come talk to me because they are overwhelmed or discouraged by the job market. If that is you, you are not alone.
Cybersecurity is already a much wider field than many beginners realize. The roles, skills, and paths into this work can look completely different from one another. Add AI changing how work gets done, compressing some roles, expanding others, and moving expectations underneath all of us, and it can feel like we are trying to plan careers from the middle of a tornado.
I cannot tell you exactly where that tornado is going to land. But I can tell you one thing I think is worth making time for while we are in it.
Build something.
Building Is the Skill That Raises All Ships
Certifications matter. Learning Python, JavaScript, SQL, or another language can matter. Webinars can teach you something. Meetups can introduce you to people who change your career. And yes, keep applying for the roles you want.
Do all of those things.
But none of them should stop you from carving out some of your time to build.
Building is the skill that raises all ships: certifications, coding, and job hunting all matter, but building makes you better at all of them at once.
When you build, you have to turn an idea into something real. You make decisions. You get stuck. You research. You solve problems. You discover what you do not know. You learn tools because you actually need them instead of because a course told you they would be on the test.
Your skills do not have to be perfect before you start. That is part of the point. A builder can show up to a conversation with ideas, real results, lessons learned, and the enthusiasm that comes from solving an actual problem. Employers can notice that.
We have a saying in the GRC Engineering Club: The work works.
Building is exactly what we mean. Put your head down and do the work, and the benefits start stacking up. Your technical skills advance because you are using them. You interview better because you have real problems, decisions, mistakes, and results to talk about. Your understanding of GRC Engineering gets deeper because you are no longer only reading about the ideas. You are trying to make them work. And that experience tends to create more enthusiasm for the work because you can see what is possible.
A certification tells someone you studied something. A project gives you something to talk about.
Yes, You Can Vibe Code
There is no shame in vibe coding.
AI has lowered the barrier to getting an idea out of your head and into something you can see, test, break, and improve. Use that.
GRC professionals should be especially interested in this moment because many of us have spent our careers understanding requirements, processes, risks, controls, and how systems should behave. Those are useful building skills. AI gives more of us a way to translate those ideas into working prototypes without first spending years becoming software engineers.
AJ Yawn, founder of the GRC Engineering Club, said something that has stuck with me: "right now the most important language for software development is English."
That should encourage all of us.
You still need to learn what the code is doing. You still need to test it, question it, secure it, and eventually understand enough to recognize when the machine is confidently sending you in the wrong direction. But you do not need permission to start.
Start With Your Own Corner of the Internet
If you have no idea what to build first, build your portfolio.
Not a PDF resume converted into a website. Build a little corner of the internet that you own and maintain. Put your work there. Document what you are learning. Add a project. Improve the design. Connect a domain. Learn how deployment works. Break something and figure out how to fix it.
Maintaining even a small website is a microcosm of what it takes to build and maintain much larger systems. There is source code. Version control. Dependencies. Infrastructure. Security. Accessibility. Content. Testing. Deployment. Bugs. Updates. Users. Decisions about what is worth fixing now and what can wait.
Club members should have access to a portfolio template and resources to help get started. If you need help finding them or getting moving, reach out to chapter leadership. This is exactly the kind of thing we should be helping each other do.
You Are Going to Get Stuck
At some point the command line is going to make your eyes bleed. I wrote an entire article about that because I have been there.
You will encounter a language you do not know. You will get an error that makes absolutely no sense. You will run out of tokens at the worst possible moment. Your AI assistant will insist the problem is fixed when you can clearly see that it is not. Something that sounded like a 20-minute change will eat an evening.
Good.
Not because frustration is fun, but because figuring out what to do next is the skill.
And you do not have to figure it all out alone. That is exactly what community is for. Ask the question. Show somebody the error. Bring the half-working project to a meetup. Tell us what you were trying to make. Let somebody who has already fought that battle point you in the right direction.
Then keep going.
This Is Your Pep Talk
The job market may be difficult. AI may keep changing the expectations. There will always be another certification you could earn, another course you could take, another language somebody says you need to learn, and another job application you could submit.
Keep learning. Keep applying. Keep showing up.
But build too.
Build before you feel ready. Build badly and make it better. Build something small enough to finish. Then maintain it. Put it where other people can see it. Talk about what you learned. Help the next person build theirs.
Come back and read this again when you need the reminder.
Now go build. And remember to stay encouraged and connected.