Image: d2908q01vomqb2.cloudfront.net · rights & removal
Part 1 – Cybersecurity journeys: I didn’t plan this
Reporting by AWS Security BlogRead the original at aws.amazon.com
Executive Summary
The content explores non-linear career paths into cybersecurity through the experiences of several individuals. Justin Knight began in warehouse fulfillment and self-taught security skills using online resources like YouTube, Kali VMs, and platforms like Hack the Box and TryHackMe before transitioning into a bug bounty role. Zlata Pavlova moved from a background in political science and service jobs, developing skills in Open Source Intelligence (OSINT) through marketing work, supporting penetration testing firms, and participating in OSINT investigations related to real-world cases. Arman Sadri navigated an unconventional path involving hacking as a teenager before utilizing structured programs like Year Up and mentorships to secure a position by demonstrating skill rather than traditional credentials.
These narratives collectively emphasize that entry into cybersecurity does not require a single predetermined route, degree, or formal training. The stories highlight the importance of curiosity, persistence, and the ability to apply learned skills in novel ways. The piece suggests that success comes from leveraging diverse, often unexpected experiences—ranging from manual labor and public service investigations to gaming and marketing—to build competence.
The central theme is the rejection of a straight-line approach to a specialized career, positioning curiosity and demonstrable action as more significant catalysts for entry than formal prerequisites. The featured individuals demonstrate that skills like sleuthing, problem-solving, and persistence can be translated into valuable security expertise regardless of initial background.
Facts Only
* Justin Knight started working in an Amazon warehouse doing fulfillment, scanning, packing, shipping, with no tech background or computer science degree around 2015 or 2016.
* Justin learned skills by using YouTube channels such as Daniel Messler, Stök, and NetworkChuck to self-teach fundamentals.
* Justin set up a Kali Virtual Machine and used Hack the Box and TryHackMe labs for practice.
* Justin transitioned into an IT role inside the warehouse, fixing broken laptop screens and replacing printers.
* Justin found a bug bounty role on LinkedIn.
* A hiring manager lowered role level requirements for Justin to make the jump into the role.
* Zlata Pavlova started with a degree in political science and worked in hospitality, restaurants, and retail before pursuing social media marketing.
* Zlata used her skills for contract work supporting penetration testing firms, including running social media and website maintenance.
* Zlata pursued OSINT (Open Source Intelligence) by supporting red team operations and conducting reconnaissance assessments.
* Zlata participated in Trace Labs competitions and volunteered on the National Child Protection Task Force, conducting OSINT investigations on cases involving real victims.
* Arman Sadri hacked into a major tech company as a teenager, around age 16 or 17, to steal hardware prototypes.
* Arman completed the Year Up program, which included an internship and teaching classes.
* Arman was placed in IT support (help desk) after Amazon offered him a job before the internship started.
* Arman participated in a mentorship program for security engineers with a two-year waitlist.
* Arman successfully passed a hiring challenge at the end of the program by finishing, leading to an offer when a role became available.
Full Take
The narrative structure effectively challenges the ingrained societal assumption that professional success follows linear, credentialed trajectories. The stories of Justin, Zlata, and Arman function as powerful counter-narratives against the notion that specialized fields require pre-existing academic or vocational alignment. The pattern observed is a deliberate juxtaposition of highly structured, formal systems (corporate environments, academic degrees) against emergent, pragmatic skill acquisition (self-teaching via YouTube, OSINT, practical challenges).
The underlying implication is a systemic barrier where legitimacy and opportunity are disproportionately assigned to those who follow established institutional pathways. Justin's success highlights how existing infrastructure (like open-source learning platforms) can bypass traditional gatekeepers, while Arman’s story underscores the necessity of extreme persistence when confronting past liabilities—waiting two years and mastering a challenge others failed—to overcome perceived ceilings. Zlata’s journey demonstrates that analytical capabilities derived from seemingly unrelated fields, like political science or marketing, are directly transferable to security-adjacent work through an aptitude for pattern recognition (OSINT).
This structure subtly promotes the idea that agency resides not in following a prescribed path, but in reframing experience through a lens of curiosity and persistent application. The suggested actions—using Hack the Box, Trace Labs, and self-directed learning—are effectively presented as bridges because they harness the innate human drive for investigation and mastery. The implicit threat this narrative counters is the rigid authority game embedded in traditional career guidance, suggesting that true capability is built through applied, messy experience rather than formal prequalification.
Bridge Questions: If institutional barriers are largely artificial, what other unacknowledged systems currently limit entry into high-demand technical fields? How can organizations effectively value the diverse, non-linear skill sets demonstrated by individuals like Justin and Zlata when hiring? What role does the narrative of "impostor syndrome" play in perpetuating these systemic limitations within the cybersecurity space?
From the original · AWS Security Blog
AWS Security Blog Part 1 – Cybersecurity journeys: I didn’t plan this If you’ve ever wondered whether your background qualifies you for a career in cybersecurity, you’re not alone — and you’re probably more prepared than you think. My name is Shannon Brazil, and I work in security communications at Amazon Web Services (AWS).Read the full story at aws.amazon.com
Sentinel — Human
The article functions as a compelling, experience-based narrative using personal anecdotes to illustrate the non-linear paths into cybersecurity, exhibiting strong human storytelling traits.
