Prática de Shadowing: How I Would Start Cybersecurity in 2026 (If Starting From Zero) - Aprenda a falar inglês com vídeo

Criando lição...
1
If I had to start my cybersecurity career from absolute zero in 2026, knowing everything I know now as a recruiter, this is exactly what I do.
2
And I'm going to be brutally honest with you that most people are still doing this completely wrong.
3
Look, I've seen the pattern play out over and over.
4
Someone gets excited about cybersecurity, they drop thousands on a bootcamp or a certification, study for months and then nothing, crickets.
5
No interviews, no callbacks, just rejection after rejection.
6
Why?
7
Because they skip the fundamentals that actually get you hired.
8
Hey everyone, my name is Luke Goff.
9
I've been recruiting now for almost 15 years and I also coach people how to break into this industry.
10
In my most popular video, I shared the five -step roadmap that no one talks about.
11
Now today, I'm taking that framework and showing you exactly how I'd apply if I was starting fresh in 2026.
12
With the updated tools, the current job market realities and the insider knowledge I've gained from seeing what actually works.
13
By the end of this video, you'll have a very clear step -by -step action plan that will put you months ahead of everyone else starting out.
14
I've been really looking forward to doing this video.
15
So grab a coffee, a notepad and pen, and let's get straight into it.
16
Let's get you hired into cybersecurity.
17
Okay, section one.
18
Week one to two, map the battlefield, but be smart.
19
Here's what I'd do differently in 2026.
20
Most people skip this step entirely, or they spend five minutes Googling cybersecurity jobs and call it done.
21
That's a mistake that could cost you lots of time.
22
If I was starting fresh, here's my exact two -week plan.
23
Week one, role research.
24
I'd spend 30 minutes every single day on LinkedIn, and Indeed or whatever job site there you have in your region.
25
Not applying for roles, just reading.
26
I'd open 10 different cybersecurity job descriptions each day and ask myself one question.
27
Does this day -to -day actually excite me?
28
Here's what I'd be looking for.
29
SoC analyst roles.
30
Am I pumped about hunting threats in log files?
31
GRC analyst positions.
32
Does the idea of building security frameworks and ensuring compliance sound interesting to me?
33
For cloud security jobs, environments.
34
Now, I'd keep a simple notes document and jot down, this sounds cool or this sounds boring.
35
No judgment, just real honesty.
36
Now, in week two, this is reality check conversation.
37
Here's the move most people miss.
38
I'd reach out to three people actually doing these roles.
39
A simple LinkedIn message.
40
Now, you can watch this back on about to say if you want to use this, but this is a basic message you could put.
41
Hey there, I'm exploring cybersecurity and your background in really like.
42
Now you'd be shocked how many people say yes.
43
Honestly people like talking about themselves.
44
People like talking about what they do and helping others.
45
And those 15 minute conversations would save me from wasting months on the wrong path.
46
Imagine if you were thinking of going to become a pen tester.
47
You spoke to someone and you really didn't like the sound of it.
48
Now if you hadn't have done that you wouldn't have known
49
and could have spent months preparing for something you weren't going to enjoy.
50
The advantage in 2026 is use chat gpt or equivalent
51
them identify common skills and requirements across different roles copy
52
and paste 10 job descriptions and ask the ai what are the top five skills
53
that appear most often it's a tip there that will save you
54
so much time now by the end of week two i'd know my lane and
55
that clarity would make every step after this 10 times more
56
effective okay moving on to section two month one build your foundation using free resources
57
so right you've picked your direction so now here's where most buy expensive certifications.
58
Don't do it yet.
59
If I was starting out in 2026, here's my month one foundation building plan.
60
Week one to two, work on IT fundamentals.
61
I'd watch Professor Messers, for example, free Comp Tier A plus videos on YouTube.
62
Not to take the exam, just to understand how computers, how operating systems and how hardware actually work.
63
This is your baseline.
64
30 minutes a day, an hour a day if you've got more time taking notes.
65
Week three to four, deep dive.
66
Now this I can tell you is non -negotiable.
67
You must understand networking.
68
Every single cyber attack happens across a network in some way.
69
This is where I'd actually start studying for the Comp Tier Network Plus certifications.
70
Now I know I said don't do certifications yet but the Comp Tier Network Plus I'd start looking into it.
71
Why?
72
Because Network Plus helps you understand the fundamentals of networking and this is absolutely key to every single role in cyber security.
73
So whether you're or your managing compliance frameworks.
74
It all happens across networks.
75
I'd use Professor Messer's free Network Plus course and take proper notes on the OSI model,
76
the TCP, what DNS, what DHCP and firewalls actually do.
77
I'd look at subnetting basics and network security concepts.
78
Once again, I'm not saying you need to rush out and take the exam immediately, but using the Network Plus Certification Path as a structured learning
79
guide is probably the single best way to get the networking knowledge.
80
That's absolutely essential.
81
actual exam but the knowledge itself is non -negotiable.
82
The advantage in 2026 is there's platforms like Code Academy, Free Code Camp and YouTube.
83
They've all gotten so much better.
84
You can learn faster, free, things that people couldn't even do five years ago.
85
Now let me know in the comments, are you currently studying networking fundamentals or did you skip straight to certifications? Be honest.
86
Okay, section three, month two.
87
This is where you get your hands dirty and build your portfolio.
88
So This is where you separate yourself from 90 % of other beginners because most people never do this step.
89
Once again, if I was starting fresh, here's exactly what I'd build.
90
Week one, I'd set up my home lab.
91
I'd download VirtualBox, which is free.
92
I'd install Windows Server, which is also free, and build a mini network on my laptop.
93
This may sound intimidating, but there are dozens of free YouTube tutorials
94
that walk you through it step by step and very clear for you to follow and understand.
95
how systems talk to each other.
96
Now, then moving on to week two or three, I would start looking at try hack me and hack the box.
97
I'd sign up for try hack me.
98
There's a free tier and it's fine to start with.
99
And I'd work through these specific rooms, Linux fundamentals, network services, and intro to offensive security.
100
Those three rooms are what I would do first.
101
Now, every single room I complete, I'd write a short blog post or a LinkedIn article documented what I did and what I learned.
102
This is And this will help you stand up down the line when you come to apply for roles.
103
Week four, my first practical project.
104
So this would be my real first project that I've done.
105
I'd set up a basic SIEM tool, which is security information and event manager for anyone watching this who's unsure of that.
106
I would use Splunk 3 or Elk Stack, feed it some sample logs and practice detecting suspicious activity.
107
I'd then once again, I'd document the whole thing on GitHub with screenshots and a write -up.
108
I would say how I built my first SIEM lab.
109
by how much this will help you.
110
The advantage in 2026 will be that free scene tools, cloud platforms with three tiers, AWS Azure and platforms like TriHackMe,
111
these all didn't exist years and years ago.
112
You can build a portfolio that would have cost you thousands right now for free.
113
Now, why does this matter for recruiters?
114
Well, when I'm hiring, I see hundreds of resumes that say CompTier Security Plus certified.
115
Great, that really is.
116
It's important to have that.
117
But the plus.
118
That's the person that gets interviewed first every single time.
119
Okay, section four, month three.
120
Immerse yourself and build real connections in the cyber community.
121
Month three is about becoming part of the broader cyber world.
122
Cyber security is one of the most welcoming industries I've seen, but you have to show up.
123
If I was starting in 2026, here's exactly what I'd do.
124
Week one to two, I'd get active online.
125
I'd follow 20 to 30 cyber security professionals SOC analysts, cloud security engineers.
126
I'd then engage.
127
I'd comment on posts with very genuine questions.
128
I'd also share what I'm learning with my own posts.
129
An example could be on LinkedIn, just completed my first try Hack Me Room on network enumeration and here's what I learned.
130
People will start reading that.
131
People will start commenting.
132
You will become more known in your network.
133
Week three, find my local scene.
134
So I'd start looking up the local cyber security Even if I felt like I didn't know enough, I'd go.
135
Because jobs are filled through connections before they've ever posted online.
136
I find so many people for jobs through my network, not just people applying for jobs.
137
So bear that in mind.
138
Week four, I'd then start consuming content.
139
Now, I'd pick one cybersecurity podcast.
140
An example could be Darknet Diaries.
141
This is brilliant for storytelling.
142
And one newsletter.
143
Obviously, this YouTube channel's newsletter, which goes without saying.
144
But seriously, choose a newsletter to stay current on industry trend.
145
Virtual meetups and Discord communities mean you can network globally without even leaving your house.
146
Join the TriHackMe Discord, the Cyber Defenders community, wherever your people are.
147
A tip from a recruiter's insight here.
148
The number of times I've hired because they were referred by someone in the community is huge.
149
Showing up really matters.
150
Excuse me.
151
Okay, section five, month four.
152
This is now when you get your certification.
153
So month four, now and only now would I get certified.
154
Now, there's a chance you would have completed your Network Plus already.
155
So I know that does contradict myself slightly.
156
But if you haven't, do your Network Plus.
157
If you've done it already, great.
158
But here's what I would do next.
159
Absolutely no questions asked, I would do the CompTIA Security Plus.
160
The Security Plus is still the gold standard entry level certification in cybersecurity.
161
It's recognized globally.
162
It covers all fundamentals across different security domains and it's what hiring managers look for when screening candidates.
163
I can tell you that it's still the number one certificate hiring managers look for for entry -level cyber professionals.
164
This would be the certification I do or I would do regardless of which path I eventually chose.
165
Now why Security Plus?
166
Apart from it being globally recognised in the gold standard, it validates that you understand all the basics,
167
threats, attacks, vulnerabilities, You learn operations and incident response,
168
governance risk and compliance basics.
169
It's also vendor neutral, which means the knowledge applies everywhere.
170
Whether you end up in cloud, GRC or SOC work, it doesn't matter.
171
Now this, after I've done Security Plus, is when I would choose my specialization path.
172
So by now, you may have an idea about what specific path you want to go down in cyber.
173
So I'd take a moment to think about this
174
and think about what really excites me based on everything I've learned in the previous three months.
175
relevant certifications for my chosen direction.
176
Now I'm going to give you a few examples here.
177
So if SOC Analyst is my choice, I might look at the CYSA +, which is CompTIA Cybersecurity Analyst Plus.
178
Or I'd even start looking at exploring vendor -specific tools like Splunk certifications.
179
Being honest, I'd probably do both of those.
180
If cloud security was my path.
181
Now I can tell you that I'm not telling you necessarily to do cloud, but as a recruiter, it is a booming area and it will continue to grow.
182
So cloud is definitely something I probably would look into.
183
But if at the AWS Certified Security Specialty, the Azure Security Engineer Associate, also known as the ACED 500,
184
or the Google Cloud Professional Security Engineer.
185
Now, depending on which cloud platform is most in demand in my target area, being completely honest with you, I'd probably look at AWS, but there are all three of those are good options.
186
Here's the key.
187
By month four, I've already done the labs, I've built the projects, I've built portfolios, and I've joined the community.
188
Security Plus isn't demonstrated through hands -on work that I've documented.
189
The advantage of 2026 is there's more pathways than ever with
190
vendor specific certifications carrying serious weight alongside the traditional comp tier stack.
191
Okay section six month five and six this is when I'd start applying and get hired.
192
This is the exciting part this is where all the work you've done comes to this.
193
So month five and six is about execution and here's my exact strategy on what I would do.
194
Week one I'd to you here.
195
If you see something that you struggle with, reach out to me.
196
I offer career coaching on exactly this.
197
Part of my course and what I do is I can optimize your resume and LinkedIn to make sure it stands out, it's written correctly, it's ATS friendly,
198
and it gives you the best position possible to secure that interview.
199
I'll leave the description below.
200
But I'd make sure that my LinkedIn headline says exactly what I'm aiming for.
201
An example could be aspiring SOC analyst, CompTIA Security +, Home Lab Projects and SIEM and Threat Detection.
202
So you've got your name, LinkedIn like a recruiter and hire a manager, straight away they're seeing this is what this person does, this is what they've done.
203
It jumps out.
204
Now my resume would focus on my projects, not just my certifications.
205
So each bullet point would show impact.
206
For example, one bullet point built and configured a home seam lab using Splunk to detect and analyze network anomalies.
207
Make sure that you've highlighted what you've done in bullet points and it's clear to see.
208
Week two to six, this is when I'd start doing very targeted applications.
209
I'd start applying to five to qualified for.
210
Don't just start sending your CV off to any role that says SOC or cyber.
211
Don't do that.
212
Be more targeted.
213
I'd be looking for junior SOC analyst roles, cyber security analysts or even IT security analysts.
214
And here's the move.
215
For every application, I'd find the hiring manager on LinkedIn or the best person possible I could reach out to.
216
And I'd send a very short, genuine message.
217
I can tell you now 90 % and probably 95 % of people don't do this.
218
They just send their resume in.
219
I'll give you an example of what you could say here.
220
So feel free to replay this, I would put, hi, John, I've just applied for the SOC analyst role.
221
I've been building hands -on experience through home labs and try Hackme, and I'd love to bring that energy to your team.
222
A very simple message like that will go so far.
223
Hiring managers and businesses would love the fact that you've been proactive
224
and reached out to them where you haven't just sent your CV, and it could be the difference between you and another candidate on what makes you get that interview.
225
Another advantage of 2026 is remote work has opened up opportunities globally.
226
to opportunities in your city anymore.
227
So there you have it.
228
If I was starting cybersecurity in 2026 from absolutely zero, that is the exact path I would do.
229
It may sound tedious.
230
It may sound five or six months before I apply for a job.
231
I get that.
232
But do it right.
233
Do it correctly.
234
It's the path I've seen work and it's the path I would do.
235
So let's recap.
236
Month one, map my path and build foundations.
237
Month two, get hands on with labs, projects, portfolios.
238
Month three, immerse LinkedIn network, network on X, wherever the community is.
239
Month four, get certified to validate my skills.
240
And month five and six, this is when I would start applying strategically and hopefully land the role I'm after.
241
This isn't just theory.
242
This is the exact framework.
243
I've seen work many, many times.
244
And then the demand for cybersecurity professionals, honestly, is through the roof.
245
But companies want people who can actually do the job, not just pass the test.
246
If I could give you one more bit of advice, it's this.
247
Certifications are great.
248
Don't get me wrong.
249
You need them make sure you build portfolios, home labs, projects alongside it, certifications and real hands -on experience.
250
If this roadmap was helpful, and I really hope it was, hit that subscribe button and turn on notifications so you don't miss what's coming next.
251
And here's my question for you.
252
Where are you right now in your cybersecurity journey?
253
Are you just starting out or are you already building home labs?
254
Drop it in the comments.
255
I read every single one.
256
Also, the community can learn from each other.
257
So put those examples below.
258
I really am appreciating everyone's support.
259
Thank I do.
260
I love helping people and I want to say thank you to my community.
261
So thanks for watching.
262
Always keep levelling up your career and I'll see you all in the next video.
263
Thank you.
264
Thank you you Thank you.
265
you

Contexto & Antecedentes

O vídeo apresentado por Luke Goff oferece uma visão interessante sobre como iniciar uma carreira em segurança cibernética em 2026, desde o zero. Goff, que atua como recrutador há quase 15 anos, compartilha sua experiência e conhecimento, destacando erros comuns que candidatos cometem ao tentar entrar no setor. Com ênfase em uma abordagem metódica, Luke nos guia por um plano prático que não só facilita a compreensão do mercado, mas também promove uma prática efetiva de conversação em inglês através do shadowing.

Top 5 Frases para Comunicação Diária

  • “Does this day-to-day actually excite me?” - Uma pergunta crucial para avaliar seu interesse em diferentes funções.
  • “I’d spend 30 minutes every single day on LinkedIn.” - Uma boa dica sobre como dedicar tempo ao aprendizado e à pesquisa.
  • “People like talking about themselves.” - Uma observação valiosa sobre interação social que pode ser usada na prática de conversação em inglês.
  • “This sounds cool or this sounds boring.” - Um método simples de classificar suas emoções sobre diferentes cargos.
  • “It would save me from wasting months on the wrong path.” - Reflete a importância do diálogo na escolha de uma carreira.

Guia de Shadowing Passo a Passo

Para aproveitar ao máximo o conteúdo do vídeo e aplicar técnicas de shadow speak em suas práticas de conversação em inglês, siga este guia de shadowing:

  1. Escolha uma seção do vídeo: Selecione um trecho de 2 a 5 minutos para começar. Os detalhes sobre pesquisa de funções ou conversas com profissionais são ótimos pontos de partida.
  2. Assista e ouça atentamente: Preste atenção na entonação, pronúncia e ritmo de Luke. Tente absorver não apenas as palavras, mas também a emoção por trás delas.
  3. Reproduza o que ouviu: Pause o vídeo e repita o que ele disse em voz alta. Use a técnica de shadowing em inglês ao tentar imitar a maneira como ele se expressa.
  4. Registre seus erros: Faça anotações sobre onde você teve mais dificuldade. Isso ajudará a identificar áreas que precisam de mais prática.
  5. Conversação prática: Depois de praticar o shadow speech, tente usar as frases e expressões aprendidas em conversas reais ou com colegas. Considere conversar com pessoas que trabalham em segurança cibernética para aplicar o que aprendeu.

Implementar essas etapas não apenas reforçará seu inglês, mas também lhe dará um entendimento mais profundo dos tópicos abordados no vídeo. Essa é uma excelente estratégia para integrar o aprendizado linguístico com o desenvolvimento profissional na área de segurança cibernética.

O que é a Técnica de Shadowing?

Shadowing é uma técnica de aprendizado de idiomas com base científica, originalmente desenvolvida para o treinamento de intérpretes profissionais. O método é simples, mas poderoso: você ouve áudio em inglês nativo e repete imediatamente em voz alta — como uma sombra seguindo o falante com 1-2 segundos de atraso. Pesquisas mostram melhora significativa na precisão da pronúncia, entonação, ritmo, sons conectados, compreensão auditiva e fluência na fala.