636-555-3226 wrote: » Certs are good for the basics, but even most SANS courses don't go deep. If you want to go deep, you're going to need to download and learn to use the tools themselves. If you want defensive hands-on skills (without a cert), download and install Security Onion at home. Run some VMs (with torrented pirated Windows that are likely pre-infected with something), and infect the heck out of them to create lots of malicious traffic going in & out of your house. If I'm hiring for a defensive security position and you've had security onion running in your house for the past year and have been doing your own incident response with that kind of stuff, major double extra super bonus points. Much better even than any SANS or Offensive Security certs since it shows you've got major hands-on technical chops and can start contributing to my department from the first hour you walk in the door. Then get that new job and make them pay $6k for your SANS classes.