Skip to main content
studojo
Studojo Research · September 2026

The Cybersecurity Internship Report:
Stop Collecting Certificates

Students entering security are handed a reading list of acronyms and told to collect them. Most buy the expensive ones first, apply exclusively to technology companies, and never build the one thing that separates a shortlisted application from a rejected one. The field is hiring. The standard approach to entering it is close to backwards.

ScopePrimarily United States data · Entry level and internship cybersecurity roles
Report typeSector / Cybersecurity
PublishedSeptember 2026
Prepared byStudojo Research
$57,115
average annual pay for a cybersecurity intern in the United States. Entry level roles run roughly $50,000 to $85,000
Indeed and aggregated salary data, 2026
Security+
the correct first certificate, alongside ISC2 CC. CISSP, CISM and OSCP are not entry level and do not help you get an internship
Certification requirement analysis across entry level postings, 2026
55%
of hiring managers now use internships specifically to build their talent pipeline, which makes the internship the main door in
Employer hiring intent surveys, 2026
1
The certificate order most students get wrong
One of these is the first one. The famous ones are not.

CompTIA Security+ is the most common baseline requirement across entry and mid-level security postings, and ISC2's Certified in Cybersecurity sits alongside it as a genuine starting credential. Between them they cover what an entry-level posting is actually screening for.

CISSP, CISM and OSCP are not entry-level certificates, and treating them as the next rung is the expensive mistake. CISSP carries a multi-year professional experience requirement before you can even hold the full certification. OSCP is a demanding practical exam aimed at working penetration testers. Buying either as a student is money and months spent on a door that is not yet in front of you.

The practical rule is that one baseline certificate clears the screening filter, and the second one adds very little. After Security+, additional certificates have sharply diminishing returns compared with what the next section covers.

US cybersecurity pay, annual US dollars
Key insight: get one baseline certificate, then stop. The second certificate is almost always worth less than the first project you could have built in the same time.
If a training provider is selling you CISSP as a route into your first security job, that is a signal about the provider rather than about the field.
2
What actually outperforms a certificate
Demonstrable skill, which means a home lab you wrote about

The consistent finding across 2026 hiring guidance is that demonstrable skill, meaning a home lab plus a documented portfolio, outperforms certifications alone. That phrase is doing a lot of work and most students only hear the first half.

A home lab on its own proves nothing to a stranger, because they cannot see it. What converts is the documentation: a short write-up of what you built, what you were trying to detect or break, what happened, and what you concluded. Ten of those is a portfolio. It is also the only thing in your application that a hiring manager cannot get from anyone else, because everyone else has the same certificate.

The tooling expectation at entry level is modest and specific. Familiarity with Wireshark, a Linux distribution such as Kali, and enough scripting to automate something small. You are not expected to arrive expert. You are expected to have actually touched the tools.

Where a student's first year of effort is usually spent, against where it pays off
Key insight: the lab is the work, the write-up is the evidence. A lab nobody can read about does not exist as far as your application is concerned.

"Demonstrable skill, a home lab plus a documented portfolio, outperforms certifications alone."

Consistent finding across 2026 entry level security hiring guidance
Write up the failures too. A post explaining what you expected, what actually happened, and why you were wrong reads as genuine investigation. A page of clean successes reads as a tutorial you followed.
3
The roles are not where students look
Every industry has a security function. Technology companies are the crowded one.

Cybersecurity internship opportunities exist across virtually every industry, not just technology. Government agencies, healthcare systems, banks, insurers, utilities and major retailers all run security functions and all hire interns into them.

Almost every student application goes to technology companies and to the handful of named security vendors. This is the same queue problem that shows up in every field: the best-known employers receive applications from everyone, while a hospital network or a regional bank receives a fraction of that volume for work that is frequently more hands-on.

Regulated industries are worth particular attention. Healthcare and finance carry compliance obligations that force them to maintain real security capability regardless of the hiring market, which makes their demand steadier than a technology company's.

Key insight: your odds are set as much by which queue you join as by how strong you are. The hospital and the utility are hiring, and almost nobody applied.
Healthcare systems. Compliance obligations force continuous security investment, and patient data makes the work consequential from day one.
Government and public sector. Structured intern programmes, defined timelines, and in some roles a security clearance path that becomes durable career leverage.
Banking, insurance and utilities. Regulated, permanently staffed security functions with far shorter applicant queues than technology companies.
Retail and logistics at scale. Large payment and supply chain surfaces, genuine incident volume, and very little student competition.
Search by the function rather than the industry. Filtering job boards for security analyst intern surfaces employers that never appear on a list of top cybersecurity companies.
4
What the internship is actually worth
The pay, and the thing that matters more than the pay

Cybersecurity interns in the United States average around $57,115 a year, and entry-level security roles land roughly between $50,000 and $85,000 depending on the role, the metro and whether a clearance is involved. Intern pay generally sits below the entry-level band, as it does in most fields.

The number that should matter more to you is that 55 percent of hiring managers now use internships specifically to build their talent pipeline. That reframes the internship from a summer of experience into the primary hiring channel for the field.

Clearance is worth understanding early if you are in the United States. Roles requiring one pay at the top of the band, partly because the pool of cleared candidates is small and slow to grow. An internship in a government agency or a cleared contractor can start that process years before it would otherwise begin.

Key insight: if more than half of hiring managers use internships as their pipeline, then the internship is not a step toward the career. It is the entrance.
Compare offers on what you will touch, not only on the rate. A summer with real incident exposure at a hospital is worth more to your second job than a higher-paying summer writing documentation.
5
The twelve week plan
What to do between now and applications if you are starting from nothing

The sequence matters more than the intensity. One baseline certificate, then a lab, then write-ups, then applications aimed outside the obvious employers. Doing these in a different order is what produces a student with three certificates and no interviews.

Most entry-level postings also expect enrolment in a relevant programme and foundational knowledge of networking and operating systems. If your degree already covers those, do not re-learn them through a paid course. That is the second most common way students spend a term on something that changes nothing.

Key insight: a student with one certificate and ten written-up investigations beats a student with three certificates and nothing to show, essentially every time.
Weeks 1 to 6: one certificate. Security+ or ISC2 CC. Not both, and definitely not CISSP. This clears the screening filter and nothing more, which is all it needs to do.
Weeks 3 to 10: build the lab, in parallel. A few virtual machines, a network you can break, Wireshark, a Linux distribution, and a small script that automates something tedious.
Weeks 6 to 12: write up eight to ten investigations. Short posts. What you tried, what happened, what you concluded, what you got wrong. This is the portfolio, and it is the differentiator.
Weeks 10 onward: apply outside the crowd. Hospitals, utilities, banks, government, retail. Same function, far shorter queue, frequently more hands-on work.
Put the write-ups somewhere with a link you can paste into an application. A portfolio a recruiter has to ask for is a portfolio that does not get read.
→
What This Means For You
Prioritised action list
One certificate, then stop. Security+ or ISC2 CC clears the filter. CISSP, CISM and OSCP are not entry level and buying them early wastes both money and months.
Build a lab, then write about it. Demonstrable skill beats certifications alone, but only the documented part is visible to a stranger reading your application.
Apply where nobody else does. Hospitals, utilities, banks, government and retail all run security functions. Almost every student application goes to technology companies instead.
Treat the internship as the entrance. 55 percent of hiring managers use internships to build their pipeline, which makes it the main hiring channel rather than a stepping stone.

Reach the security teams that never post.

Studojo finds the person running security at employers outside the obvious list, and helps you put your write-ups in front of them.

Find Roles →