How to Start a Cybersecurity Career in Malaysia With No Experience

By SuperJobs Team
Quick Answer: You can start a cybersecurity career in Malaysia with no work experience, but not with no evidence. A joint study by the Department of Skills Development (JPK), CIAST and CyberSecurity Malaysia, cited by the Communications and Digital Minister in August 2023 and reported by Free Malaysia Today, counted 15,248 cyber knowledge workers against a national requirement of 27,000 by end-2025. The practical entry route is a defensive role such as SOC analyst, GRC analyst or IT auditor, supported by free lab platforms and one affordable certification such as ISC2 CC at US$199 or CompTIA Security+ at a US$439 list price.
Two graduates apply for the same tier 1 monitoring seat in Cyberjaya. Both hold a computer science degree, neither has worked a day in security. One sends a CV listing subjects passed. The other sends a link to fifteen written investigations from a home lab, each showing the alert, the log evidence and the decision made. That gap in evidence, not in qualifications, decides most entry-level cyber hires in Malaysia.
A 2023 joint study by JPK, CIAST and CyberSecurity Malaysia put Malaysia's cybersecurity workforce at 15,248 against a stated requirement of 27,000 by the end of 2025, a shortfall of close to 12,000 people. The figures were announced at CyberDSA 2023 on 15 August 2023 and reported by Free Malaysia Today. They trace to a ministerial statement rather than to a published dataset: the joint study itself has not been released, and cybersecurity.my publishes no equivalent figure.
Malaysia's Cybersecurity Talent Gap
That 27,000 target date has now passed, and no updated national headcount has been published in its place. What has changed since 2023 is the legal pressure on employers. The Cyber Security Act 2024 (Act 854) was gazetted on 26 June 2024 and came into force on 26 August 2024, according to NACSA. It creates a National Cyber Security Committee, sets protection duties for National Critical Information Infrastructure (NCII), and regulates cyber security service providers through a licensing regime.
Two parts of that Act turn directly into headcount. NCII entities across the Act's eleven designated sectors, including government, banking and finance, healthcare, energy, water, transport, defence and communications, now carry standing obligations to assess risk, be audited and report incidents. Somebody has to do that work. Separately, NACSA's licensing programme covers managed security operation centre monitoring services and penetration testing services, which pushes buyers towards licensed providers and pushes those providers to staff up.
Policy funding is moving too. NACSA now lists the Malaysia Cyber Security Strategy 2025-2030, successor to MCSS 2020-2024, among its current strategic frameworks, after the Ministry of Digital told Bernama on 30 July 2025 that the document was being finalised. Cabinet approved the MyKriptografi Action Plan 2026-2030 on 28 November 2025. The Star reported on 30 November 2025 that RM30 million was allocated to strengthen national cybersecurity, covering digital trust for data, identity and critical infrastructure.
Here is the honest counterweight. A national shortage of cybersecurity professionals is not the same thing as a shortage of people willing to do cybersecurity. Shortage figures like this one count the whole profession, not entry-level seats, and the roles employers struggle hardest to fill are the mid and senior ones asking for five years of incident handling or an audit track record. Entry-level seats are genuinely competitive, and tier 1 postings in Kuala Lumpur routinely attract far more applicants than there are seats. The shortage helps you, but only after you have something to show. Start by seeing what is actually being advertised on information technology jobs in Malaysia before you spend a ringgit on training.
Entry-Level Roles: SOC Analyst, GRC Analyst, IT Auditor
Four job families reliably take people with zero security experience. Learn which one fits you before choosing a certification, because the certifications diverge sharply.
Security operations centre analyst (tier 1). You watch alerts from a SIEM, decide which are real, and escalate the ones that are. Shift work is normal, including nights, because attacks do not observe office hours. This is the single most common first security job in Malaysia and it is covered in depth in our SOC analyst career guide.
GRC analyst. Governance, risk and compliance work means mapping controls to standards such as ISO/IEC 27001, chasing evidence from system owners, tracking risk registers and preparing for audits. Act 854's assessment and audit duties have made this a growth area inside NCII entities. If you are organised, write clearly and do not want night shifts, GRC is often the easier door than a SOC.
IT auditor. Usually sits in an internal audit function or a professional services firm. You test whether controls actually operate, sample evidence and write findings. Accounting and finance graduates get hired into IT audit fairly often, which makes it one of the few security-adjacent roles where a non-technical degree is not a handicap.
Identity and access administrator. Provisioning accounts, running access reviews, cleaning up orphaned permissions. Unglamorous, and one of the fastest routes into a security team from an existing IT helpdesk job.
The helpdesk route deserves its own note. Plenty of Malaysian security engineers started on a service desk, spent eighteen months learning how the estate actually works, then moved sideways when a security vacancy opened internally. An internal move needs no cover letter and competes against nobody. If your applications for direct security roles are not landing, a service desk or NOC seat advertised under technology and software jobs is a legitimate two-year plan, not a defeat.
Free and Cheap Ways to Learn (TryHackMe, HackTheBox, Cisco)
Nothing in the first three months needs to cost money.
TryHackMe runs a free tier that gives limited access to learning paths, free rooms only, and a one-hour daily limit on its browser-based AttackBox. That free tier is enough to work through fundamentals for weeks. Premium is listed at €10.50 per month when billed annually, with a MAX tier at €17.99 per month billed annually, per TryHackMe's own pricing page in August 2026.
Hack The Box Academy lets you register and start for free. Its paid credential most relevant to a defensive career is the Certified Defensive Security Analyst, priced at US$490 on the HTB Academy site, roughly RM1,980. Treat that as a year-two purchase, not a first step.
Cisco Networking Academy publishes a free online Introduction to Cybersecurity course, which is a reasonable place to build vocabulary if terms like DMZ, hashing and least privilege are still fuzzy.
Google Cybersecurity Professional Certificate on Coursera runs nine courses in under six months at under ten hours a week, per Coursera's course page. Coursera lists it at US$49 per month after a seven-day free trial, so most learners finish for under US$300, about RM1,210, and financial aid is available. Coursera states that US$49 is United States and Canada pricing and that other countries may pay less, so a Malaysian card may be charged differently. It is structured coursework rather than a proctored exam, so read it as a positive signal on a fresh-graduate CV rather than a substitute for Security+.
One rule governs all of this. Practise only inside these platforms' own sandboxes, on virtual machines you own, or on systems you have written permission to test. Touching anything else is an offence under the Computer Crimes Act 1997, and a security team will not hire someone who does not understand that line.
Certifications Worth Getting: Security+, ISC2 CC, CEH and CISSP Associate
Buy one certification, not four. Security+ is the credential most often named in entry-level defensive job ads in Malaysia, reflecting CompTIA's position as the vendor-neutral baseline for SOC and GRC job descriptions. No published Malaysian survey counts certification mentions in job advertisements, so treat that as an observation from reading ads rather than a measured statistic.
| Certification | Body | Published cost, August 2026 | Approximate ringgit | Where it fits |
|---|---|---|---|---|
| Certified in Cybersecurity (CC) | ISC2 | US$199 exam, US$50 annual maintenance fee | About RM800, plus RM200 a year | Cheapest recognised entry credential |
| Security+ (SY0-701) | CompTIA | US$439 list, US$395 through an authorised reseller | About RM1,775, or RM1,600 | The default first cert for SOC and GRC roles |
| CySA+ V4 (CS0-004) | CompTIA | CompTIA publishes no exam price | Set by the reseller you buy the voucher from | Year two, after real alert-handling experience |
| Certified Defensive Security Analyst | Hack The Box | US$490 | About RM1,980 | Hands-on defensive exam, strong portfolio piece |
| Google Cybersecurity Certificate | Google via Coursera | US$49 a month, US and Canada pricing, under US$300 in total | Under about RM1,210 in total | Structured beginner coursework, not an exam |
| CEH (v13) | EC-Council | Training packages from US$1,699; no standalone voucher price published | From about RM6,870 | Appears in Malaysian ads, expensive for a first cert |
| CISSP (Associate status) | ISC2 | ISC2 publishes no price on its CISSP page | Not published | Pass now, hold Associate status until 5 years' experience |
Sources: the ISC2, CompTIA, EC-Council, Hack The Box Academy and Coursera pages, plus CompTIA authorised reseller Professor Messer for the Security+ list and voucher prices, all checked in August 2026. Neither CompTIA nor ISC2 publishes an exam price of its own. Ringgit figures are converted at USD/MYR 4.0421 as at 25 August 2026 and rounded, so recheck the rate on the day you pay and add your card's foreign transaction fee.
Two exam versions are moving under your feet, and this roadmap runs nine to eighteen months. CompTIA lists CySA+ V3, exam code CS0-003, as the retiring version: English learning products retire on 22 November 2026, the English exam on 22 December 2026, and translated exams on 23 March 2027. Buy CySA+ V4 instead, exam code CS0-004, which CompTIA launched on 23 June 2026 and runs to a maximum of 85 questions in 165 minutes. Security+ SY0-701 is still current, but CompTIA's own page notes that a version usually retires about three years after launch and gives an estimated 2026 retirement for this one, which launched on 7 November 2023. Check the live version on comptia.org before buying either a voucher or a study bundle, because both expire with the exam.
The ISC2 CC deserves a specific warning, because outdated advice about it is everywhere. ISC2's One Million Certified in Cybersecurity programme, which gave away free CC exams and free self-paced training, has closed to new enrolments as of 20 May 2026. If you were told the CC is free, that is no longer true. It now costs US$199 for the exam plus a US$50 annual maintenance fee once you pass, about RM800 and RM200 at the rate above.
CISSP works differently from the rest. You can sit and pass the exam before you have the required five years of experience, and ISC2 then grants you Associate status while you accumulate it. Passing it as a fresh graduate is an achievement, but it is a heavy, expensive, management-oriented exam, and no Malaysian employer will hand a graduate a senior role on the strength of Associate status alone. Security+ first. For how certification bodies and recognition work more broadly in the Malaysian market, see our guide to professional certifications in Malaysia.
Building a Home Lab and Portfolio
This is the part that substitutes for experience, and almost nobody does it properly.
A workable defensive lab runs on one machine with 16GB of RAM. Install VirtualBox or Hyper-V. Build a Windows virtual machine and a Linux virtual machine on a host-only network so nothing reaches the internet by accident. Turn on Sysmon and Windows event logging on the Windows box. Ship those logs into an open-source monitoring stack. On 16GB, use Wazuh; a standalone Security Onion install wants more memory than that before you add two virtual machines to the same host, so treat it as an upgrade rather than a starting point. You now have the same basic shape as a real SOC: endpoints generating telemetry, a collector, and a console showing alerts.
Then generate ordinary activity and watch what the logs say about it. Create a user, change a password, run a scheduled task, mount a network share, fail five logins in a row. Record what each action looks like in the event data. That exercise, repeated for a month, teaches the single skill tier 1 analysts are actually paid for, which is telling normal apart from suspicious.
Write every session up. Four hundred words each, in a fixed format: what you did, what the alert said, what the raw logs showed, what you concluded, what you would escalate. Publish them in a public GitHub repository with a clear README. Fifteen of those write-ups is a portfolio, and it answers the interview question that sinks most graduates, which is "tell me about a time you investigated something."
Capture the flag events add a second signal. Stick to defensive, forensics, log analysis and incident response categories, and to organised events run on the organiser's own infrastructure. Note the placings on your CV with dates.
Put the portfolio link in three places: the top of your CV, your LinkedIn headline area, and the first line of every application. Run the CV through the SuperJobs CV checker and tidy your profile with the LinkedIn optimizer first, because security teams read both.
Malaysian Companies Actively Hiring in Cyber
Rather than chase a list of logos, work out which categories of employer are legally obliged to keep security staff. Act 854's NCII sectors are the map.
Banks, insurers and payment firms. Banking and finance is a designated NCII sector, and it ran mature security functions well before the Act. Large local banking groups and the Malaysian arms of regional banks run their own security operations centres in Kuala Lumpur.
Telecommunications and utilities. Communications, energy and water are all NCII sectors. National telcos and grid operators carry in-house security teams and long-running graduate intakes.
Government and government-linked bodies. NACSA, CyberSecurity Malaysia and ministry digital units hire, though entry usually runs through public-sector recruitment rather than commercial job boards.
Licensed service providers. Because NACSA licenses managed SOC monitoring and penetration testing services, licensed providers are where much of the tier 1 volume hiring happens. Working at one exposes you to many client environments quickly, which is why so many Malaysian security careers start there.
Professional services and consulting. The large audit and advisory firms in Malaysia all run cyber and GRC practices with structured graduate intakes.
Global business services centres. Kuala Lumpur, Cyberjaya and Penang host regional security operations centres serving Asia-Pacific for multinational employers. These hire in cohorts and train from scratch more readily than most local employers.
Malaysian security product companies. Kuala Lumpur headquartered Securemetric Berhad, for instance, builds digital identity, authentication and cryptography products across ASEAN, and hires for engineering and support roles adjacent to security.
CyberSecurity Malaysia also runs the Global ACE certification scheme, which has a student membership tier. Check employer profiles on SuperJobs company pages, and if you are still studying, apply for internship positions, because a security internship converts to a graduate offer far more often than an external application succeeds.
Salary Ranges by Role and Years of Experience
| Role | Typical monthly salary in Malaysia |
|---|---|
| Network administrator | RM3,650 |
| Security manager | RM4,430 |
| Network and security engineer | RM4,550 |
| Security engineer | RM4,750 |
| Security consultant | RM6,000 |
| Cyber security analyst | RM6,900 |
| Risk manager | RM9,400 |
Source: JobStreet Malaysia career advice salary pages, accessed August 2026. JobStreet states these are drawn from full-time salary ranges disclosed by employers in its job ads.
Read that table with three caveats. First, these are blended figures across all experience levels, so a fresh graduate should not expect the cyber security analyst number in year one. Second, Malaysian security job titles are inconsistent, which is why "security manager" appears below "security engineer" here; the ad-disclosed sample for each title differs, and some "security" ads are for physical security. Third, location moves the number. JobStreet lists Sepang as the top-paying location for security analysts at RM6,880 a month, ahead of Kulai District at RM5,000.
Progression follows a recognisable shape. Years zero to two are tier 1 monitoring or junior GRC, where you are paid to be reliable and to escalate correctly. Years two to four bring tier 2 investigation, threat hunting or lead audit work, and this is where pay moves most in percentage terms, particularly if you add CySA+ or a hands-on defensive credential. Beyond that the split is between technical tracks such as incident response and detection engineering, and governance tracks leading to risk or compliance management. Compare advertised ranges on SuperJobs salary insights before you negotiate.
Frequently Asked Questions
Can I get a cybersecurity job in Malaysia with no experience?
Yes, but entry-level cyber roles in Malaysia are competitive and a degree alone rarely wins one. Employers substitute evidence for experience: a documented home lab, published investigation write-ups, capture the flag placings and one recognised certification such as CompTIA Security+ or ISC2 CC. Tier 1 SOC analyst, GRC analyst and IT auditor are the job families that most often accept candidates with no prior security employment.
Which cybersecurity certification should a Malaysian fresh graduate get first?
CompTIA Security+ is the credential most often named in entry-level defensive job ads in Malaysia, though no published Malaysian survey counts certification mentions, so treat that as an observation rather than a statistic. The SY0-701 exam has a US$439 list price, roughly RM1,775 at USD/MYR 4.0421 on 25 August 2026. If that is beyond your budget, the ISC2 Certified in Cybersecurity costs US$199 plus a US$50 annual maintenance fee and is recognised by many employers. Buy one, pass it, then gain experience before spending on a second certification.
How much does a cybersecurity analyst earn in Malaysia?
JobStreet Malaysia listed a typical monthly salary of RM6,900 for a cyber security analyst and RM4,750 for a security engineer as at August 2026, based on salary ranges disclosed by employers in job advertisements. These blend all experience levels, so fresh graduates in tier 1 monitoring roles usually start well below the analyst figure. Shift allowances for SOC work are paid on top of base salary.
Do I need a computer science degree to work in cybersecurity in Malaysia?
No. Governance, risk and compliance analyst and IT auditor roles regularly hire accounting, business, law and engineering graduates, because the core work is control testing, evidence gathering and clear writing. Technical monitoring roles are harder without networking and operating system fundamentals, but those can be self-taught through free platforms rather than a second degree.
Is TryHackMe or Hack The Box enough to get hired in cybersecurity?
Completing rooms alone is not enough, because a completion badge shows attendance rather than judgement. What converts is documentation. Write up each exercise with the alert, the evidence you examined, your conclusion and your escalation decision, then publish the collection publicly. Practise only inside these platforms' own environments or on machines you own, since unauthorised access to any other system is an offence under Malaysia's Computer Crimes Act 1997.
How long does it take to break into cybersecurity from zero in Malaysia?
Plan for nine to eighteen months of part-time preparation alongside study or another job. A realistic sequence is three months of free fundamentals, three months building and documenting a home lab, one to two months preparing for a single certification exam, then an active application period. Candidates who take a service desk or network operations role first often move into security internally within two years.
Take the Next Step
- See what employers are advertising right now across information technology jobs in Malaysia and technology and software roles.
- Still studying? Secure a security or IT internship placement, the highest-conversion route into a graduate cyber role.
- Compare certification costs and recognition in our guide to professional certifications in Malaysia.
- Map a two-year route from your current qualification with the career planner, then check your application documents with the CV checker.
?Frequently Asked Questions
Can I get a cybersecurity job in Malaysia with no experience?
Yes, but entry-level cyber roles in Malaysia are competitive and a degree alone rarely wins one. Employers substitute evidence for experience: a documented home lab, published investigation write-ups, capture the flag placings and one recognised certification such as CompTIA Security+ or ISC2 CC. Tier 1 SOC analyst, GRC analyst and IT auditor are the job families that most often accept candidates with no prior security employment.
Which cybersecurity certification should a Malaysian fresh graduate get first?
CompTIA Security+ is the credential most often named in entry-level defensive job ads in Malaysia, though no published Malaysian survey counts certification mentions, so treat that as an observation rather than a statistic. The SY0-701 exam has a US$439 list price, roughly RM1,775 at USD/MYR 4.0421 on 25 August 2026. If that is beyond your budget, the ISC2 Certified in Cybersecurity costs US$199 plus a US$50 annual maintenance fee and is recognised by many employers. Buy one, pass it, then gain experience before spending on a second certification.
How much does a cybersecurity analyst earn in Malaysia?
JobStreet Malaysia listed a typical monthly salary of RM6,900 for a cyber security analyst and RM4,750 for a security engineer as at August 2026, based on salary ranges disclosed by employers in job advertisements. These blend all experience levels, so fresh graduates in tier 1 monitoring roles usually start well below the analyst figure. Shift allowances for SOC work are paid on top of base salary.
Do I need a computer science degree to work in cybersecurity in Malaysia?
No. Governance, risk and compliance analyst and IT auditor roles regularly hire accounting, business, law and engineering graduates, because the core work is control testing, evidence gathering and clear writing. Technical monitoring roles are harder without networking and operating system fundamentals, but those can be self-taught through free platforms rather than a second degree.
Is TryHackMe or Hack The Box enough to get hired in cybersecurity?
Completing rooms alone is not enough, because a completion badge shows attendance rather than judgement. What converts is documentation. Write up each exercise with the alert, the evidence you examined, your conclusion and your escalation decision, then publish the collection publicly. Practise only inside these platforms' own environments or on machines you own, since unauthorised access to any other system is an offence under Malaysia's Computer Crimes Act 1997.
How long does it take to break into cybersecurity from zero in Malaysia?
Plan for nine to eighteen months of part-time preparation alongside study or another job. A realistic sequence is three months of free fundamentals, three months building and documenting a home lab, one to two months preparing for a single certification exam, then an active application period. Candidates who take a service desk or network operations role first often move into security internally within two years.