Building a career in cyber security: A Q&A with Grayce Consultant Faisal
1. Tell us a little about yourself and your role as a Grayce Consultant.
I’m 23, based in Southampton and currently working as a Cyber Security Consultant within a large enterprise’s security operations, investigating alerts and closing out incidents day to day.
As a recent computing graduate, I came in from an IT helpdesk background, so a lot of my early placement has been about translating that troubleshooting mindset and university knowledge into security-specific investigation work.
2. What attracted you to the opportunity to join Grayce?
I wanted a structured way into security that didn’t just throw me in the deep end.
Grayce’s mix of a real client placement plus ongoing coaching and peer support felt like the right balance, and it fit my longer-term plan of building Cyber Security experience first as a deliberate stepping stone toward future technical roles.
3. What has been the biggest learning experience since starting your placement?
Realising how much of the job is judgement calls under time pressure, not just following a playbook, and deciding what’s genuinely worth escalating versus noise.
I’ve also had to get much better at writing up my findings clearly, since analysts after me rely entirely on my notes to pick up where I left off, and this attention to detail has stood out amongst the client environments.
4. How have your confidence and professional skills developed so far?
Handling live incidents and talking directly to more senior analysts has pushed me to trust my own analysis rather than second-guessing it.
I’ve also gotten more comfortable proactively asking questions and flagging gaps, leading to overall improvement in our service provided, along with good feedback from senior leaders giving me that confidence to continue improving.
5. What’s been your favourite part of working within a large organisation?
Getting exposure to people who’ve been in security for years and seeing how they think through problems, not just what they know.
It’s also given me a much clearer, more realistic picture of how security fits into a much bigger organisational machine than I’d seen before.
The client organisation is huge with many avenues to go down, which has given me a much cleaner picture of where I could eventually specialise.
6. How has Grayce supported your development during your placement?
Regular check-ins have given me space to talk through bigger career direction questions, rather than figuring it all out alone.
That structure has also been useful for keeping me accountable for the certifications and skills I’m building outside of my day-to-day work, helping me position myself for my future career.
7. What’s something you’ve learned that you didn’t expect before starting your career?
How much of security work is communication. Writing something a non-technical stakeholder can act on is often harder than the technical investigation itself. I also didn’t expect how much credibility and reputation come from being consistent in the small things, such as producing clear reports, rather than just delivering big wins.
8. What advice would you give to someone considering applying to Grayce?
Go in expecting to be a beginner again for a while, and treat that as the point rather than something to rush past.
Use the structure Grayce gives you, the check-ins and the peer network, along with actively utilising the useful training and certifications offered to improve your own career pathway.
