Capstone and Career Coaching, Week 13

Run an incident as a team, then get a straight answer about the job market.

March 25, 2025

The last week has two halves. The first is a capstone exercise. The second is the conversation about what happens after the program ends.

Neither one involves a terminal, and both are harder than they sound.

The Capstone: Run the Incident

A tabletop exercise is an incident played out as a discussion. You get an evolving scenario, incomplete information, and pressure, and the group has to make decisions.

It is deliberately not technical, because the decisions that go wrong in real incidents are usually not technical. When do you tell customers. Who is authorized to take a production system offline. Do you pay. Who talks to the press. What do you do when the person who knows the system is on a plane.

Students who are strong on tools often struggle here, and that is the useful part. Incident response is a coordination problem wearing a technology costume.

Certifications: The Map, Not the Territory

The course gives an honest ranking rather than a list. Entry level certifications such as CompTIA Security+ get you past resume filters and teach vocabulary. Practical certifications such as OffSec OSCP prove you can actually do something, because the exam is a real lab. Management certifications such as CISSP matter later and require documented experience.

The thing nobody tells beginners is that a stack of certifications with no demonstrated work is a recognizable pattern to hiring managers, and not a good one. Full detail in our certification roadmap.

Flow diagram of the final week: a tabletop incident exercise, then certifications, portfolio, hiring and the first ninety days.
The Last Week

Proof of Work: Your Home Lab and Portfolio

A home lab is the cheapest credibility available. It costs an old computer and some time, and it gives you things to talk about that are specifically yours.

What matters is not the size of the lab, it is what you did in it and whether you wrote any of it down. A short, clear writeup of a problem you solved is worth more than a screenshot of a rack. See building a home lab for a build plan.

Getting Hired

Resume review is direct. Most security resumes bury the interesting part under a list of tools. The fix is to lead with things you did and what happened as a result.

Interview practice covers the questions that actually get asked: walk me through what happens when you type a URL into a browser, tell me about an investigation, how would you explain risk to someone who does not work in technology, and what would you do first if you joined a team with no asset inventory.

The first 90 days section is the least comfortable one. New security hires often arrive expecting to fix things and spend three months learning where everything is and who owns it. Knowing that in advance makes it much less discouraging. More in getting hired in cyber security.

Staying Current Without Drowning

The field moves, but slower than the noise suggests. Fundamentals stay fundamental. What changes is the surface: new platforms, new tooling, and the current attacker fashion.

The graduation advice is to pick a small number of reliable sources, follow the actual advisories for the products you run, and ignore most of the rest. Reading every headline is not a security practice, it is a hobby that feels like one.

Learn This at HackRange

The program ends here, but the alumni network and the lab access do not. Most of what people learn after graduation comes from staying in the conversation.