Cyber security is experiencing a significant skills shortage in New Zealand. MBIE has listed information security analysts as a role on the long-term skill shortage list, and the National Cyber Security Centre has publicly noted the gap between the security workforce available and the demand from government and private sector organisations. For people considering a career change, or starting out, the question is which path actually leads to employment.
This post covers the realistic entry points into cyber security in NZ, which certifications employers look for, and what self-study paths are worth your time.
---
Do You Need a Degree?
A computer science or information technology degree helps, but it is not a prerequisite for a cyber security career in NZ. The field has more practitioner-led certification pathways than almost any other area of technology, and employers increasingly value demonstrated skills over academic credentials.
That said, a degree reduces the time to your first role and opens doors to some government and defence-aligned positions that require formal qualifications. If you are already employed in IT — helpdesk, networking, system administration, development — a certification pathway is typically faster and more cost-effective than returning to study.
Entry-Level Certifications That NZ Employers Recognise
ISC2 CC (Certified in Cybersecurity)
The ISC2 CC is currently free to sit and is the most accessible formal entry-level credential available. It covers the foundations of information security — access controls, network security, incident response basics, and security governance. ISC2 is the body behind CISSP, one of the most respected senior certifications in the industry, so the CC carries brand recognition with NZ hiring managers.
Recommended for: anyone starting from a non-security background who needs a recognised credential quickly.
Google Professional Cybersecurity Certificate
Google's Professional Cybersecurity Certificate is delivered through Coursera, takes approximately six months of part-time study, and covers threat analysis, incident response, Python basics for security automation, and SIEM tools. Google certificates carry increasing credibility with NZ employers, particularly in cloud-forward organisations. The course includes hands-on labs in a browser-based environment.
Recommended for: career changers with no IT background who need structured self-study with practical components.
CompTIA Security+
Security+ is the most widely recognised entry-level security certification in the English-speaking world and is a common requirement for NZ government-adjacent roles. It covers network security, cryptography, threats and vulnerabilities, and identity management. The exam is vendor-neutral and globally portable.
Recommended for: anyone targeting government, defence, or corporate IT security roles in NZ.
Fortinet NSE 4
The Fortinet NSE (Network Security Expert) programme is a vendor-specific certification track. NSE 4 covers Fortinet's FortiGate firewall platform, which is widely deployed in NZ enterprise and government environments. It is not a general security certification, but it is highly practical and opens doors to network security and MSSP roles.
Recommended for: people targeting hands-on network security or managed security provider roles in NZ.
Practical Skills Employers Test At Interview
Certifications get you past the initial filter. Practical skills are what get you the offer. The skills NZ hiring managers consistently ask about at interview:
- Log analysis — can you read a firewall log, an event log, or a SIEM alert and explain what happened?
- Network fundamentals — TCP/IP, DNS, HTTP/HTTPS, VPN, firewall rules
- Incident response basics — what do you do when a user reports a suspicious email?
- Vulnerability concepts — what is a CVE, what is CVSS scoring, how do you prioritise?
- Cloud security basics — what does shared responsibility mean in AWS or Azure?
Most of these are learnable through free platforms. TryHackMe and Hack The Box both offer NZ-accessible, browser-based lab environments with structured learning paths. The TryHackMe SOC Level 1 path is a practical foundation for a SIEM or analyst role.
NZ-Specific Pathways
Ara Institute and NMIT offer information technology and cybersecurity programmes at diploma and degree level. These are practical routes for school leavers or people who prefer structured classroom environments.
NZQA-recognised cybersecurity qualifications are available through several providers. The NZQA framework provides portability and recognition for government-adjacent roles.
NZ Cyber Security Challenge — an annual competition run for students and early-career professionals that gets NZ employers' attention. Placing well in the challenge is a genuine CV differentiator for a first role.
CERT NZ and NCSC advisory roles — both organisations publish guidance and run outreach programmes. Volunteering for CERT NZ's community initiatives and attending ISANZ (Information Security Association of New Zealand) events builds the network that often leads to referrals.
The Security Awareness Side of the Industry
Not all cyber security careers require hands-on technical skills. Security awareness, governance, risk, and compliance (GRC) roles are growing faster than technical roles in many NZ organisations and typically require:
- Understanding of frameworks (NZISM, ISO 27001, Essential Eight, Privacy Act)
- Communication and training skills
- Project management
- Risk assessment basics
An ISC2 CC or Security+ plus practical experience running a security awareness programme is a competitive profile for a GRC analyst or security awareness manager role at a NZ mid-sized organisation or Crown entity.
Practical Starting Points
- Sit the ISC2 CC — it is currently free and takes 3-4 months of study
- Build hands-on skills through TryHackMe or Hack The Box alongside certification study
- Set up a home lab — a basic server running free SIEM software, a virtual network — is worth more at interview than two additional certificates
- Join ISANZ and attend meetups — the NZ security community is small and referrals matter
- Document everything publicly — a GitHub with your lab scripts, a blog, a LinkedIn that describes what you have built
SecureAZ is used by NZ organisations running security awareness programmes — understanding how a compliant awareness programme is built and run is practical experience relevant to both GRC and awareness roles.
External references: