Building Your Security Portfolio
Proof Beats Promises
Security hiring managers get many applications that all say "passionate about cybersecurity". What sets you apart is evidence: things you built, investigated and wrote that show how you think. A portfolio is that evidence, and you can build one for free from anywhere, including Lagos, Kano or Kigali.
1. GitHub: Your Public Workshop
Create a GitHub profile with a short bio and a few well-organised repositories:
- Home lab documentation: how you built a lab (VirtualBox with Kali and a vulnerable VM, or a small Wazuh or Splunk setup), with diagrams and lessons learned.
- Scripts and tools: a Python port scanner, a log parser that finds failed logins, a hash checker. Small but clean, with a README.
- Detection ideas: Sigma rules, SIEM queries or a write-up of how you would detect a specific attack.
- Notes and cheat sheets for certifications and labs.
Rules: write clear READMEs, keep secrets out of your repos, and never upload real client data or anything you are not allowed to share.
2. CTF Write-ups and Lab Reports
Capture the Flag (CTF) events and training platforms are the best way to practise safely: TryHackMe, Hack The Box, picoCTF, OverTheWire, Blue Team Labs Online, LetsDefend.
Turn each challenge into a short write-up:
- Goal: what was the task?
- Approach: what did you try first, and why?
- Steps: commands and screenshots.
- Result: what you found or learned.
- Defence: how the vulnerability could be fixed or detected.
Publish on GitHub, a blog or Medium. The "Defence" part shows maturity that many beginners skip.
Ethics: on Hack The Box, only publish write-ups for retired machines and follow the platform's rules. Never spoil active challenges or competitions.
3. Bug Bounty and Vulnerability Disclosure
Many organisations invite researchers to report flaws: bug bounty programmes pay for valid findings, and vulnerability disclosure programmes (VDPs) accept reports without payment. Platforms include HackerOne, Bugcrowd and Intigriti.
Start carefully:
- Read the scope and rules of each programme. Test only what is listed, and never access other users' data or disrupt services.
- Begin with VDPs and beginner-friendly programmes, learn the common bug classes (XSS, IDOR, misconfiguration) and study public disclosed reports.
- Write clear, reproducible reports (Lesson 4 of the last module). Duplicates and "informative" results are normal at first, so be patient.
- Do not publish a finding before the company allows it.
Even a few accepted reports or Hall of Fame mentions are strong evidence for a CV.
4. Certifications and Learning Trail
List your certificates and in-progress learning (see the previous lesson). Add platform profiles: a public TryHackMe or HTB badge page shows consistent effort.
5. Your CV and LinkedIn
CV tips
- One or two pages. Lead with a short summary, then skills, projects and certifications, then education and experience.
- Describe projects with impact: "Built a Wazuh lab monitoring 4 hosts and wrote detections for SSH brute force and malware persistence".
- Tailor keywords to the job advert: SIEM, log analysis, incident response, Nmap, Wireshark, MITRE ATT&CK.
- Include links to GitHub and your write-ups.
- A clear headline such as "Aspiring SOC Analyst | Security+ | TryHackMe top 5%".
- Share what you learn: short posts about labs and lessons. Follow security teams and recruiters. Connect with local and international professionals.
6. Getting Your First Job
- Target the right roles: SOC analyst (Tier 1), IT support with security duties, junior security analyst, GRC analyst, graduate and internship programmes at banks, fintechs, telcos and consultancies.
- Start where you are. IT support, network or system administration and software development are common routes into security. Volunteer for security tasks in your current job.
- Network: attend local meetups and conferences, join communities, ask for feedback on your write-ups, and find a mentor.
- Prepare for interviews: be ready to explain how the internet works, the CIA triad, common attacks and how you would triage an alert. Bring examples from your labs.
- Show integrity. Security roles involve trust and often background checks. Never boast about illegal activity, and never test systems without permission.
- Be patient. Entry-level roles are competitive, and many people apply many times. Each application and interview teaches you something.
A Nigerian and Global Perspective
Local employers value candidates who understand the regulatory and payments environment as well as the technology, so mention exposure to PCI DSS, data protection law (Nigeria Data Protection Act 2023, GDPR) and mobile money or card systems if you have it. At the same time, a public portfolio makes you visible to international employers, who hire remotely on evidence and communication. Balance both: build local credibility, and publish work the whole world can see.
Try It: Portfolio Scorecard
In the editor on the right, tick what you already have. The scorecard shows your readiness and suggests the next single step. Come back and update it as you grow.
Try it yourself
Key Takeaways
- A portfolio is evidence of skill. It can be built free from anywhere with GitHub, lab write-ups and small tools.
- Write up CTFs and labs with goal, approach, steps, result and defence. Only publish retired machines and follow platform rules.
- Bug bounty and VDPs are legal only within a programme's scope and rules. Start with beginner-friendly ones and never disclose early.
- Tailor your CV with project impact statements and keywords, keep LinkedIn active and link to your work.
- Target Tier 1 SOC, junior analyst, GRC and IT-plus-security roles, network with the community, stay honest and be patient. Balance local credibility with a public portfolio that international employers can see.
Quick Quiz
1.What is the best way to make a CTF or lab write-up valuable to a hiring manager?
2.You want to try bug bounty as a beginner. Which approach is correct?
3.Which is a realistic way to move into security if you currently work in IT support or software development?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx