• Call: (301) 220 2802
  • Email: info@trainace.com

From Retail to Cybersecurity:
A Realistic 90-Day Roadmap

Cybersecurity Workforce

From Retail to Cybersecurity: A Realistic 90-Day Roadmap

  • August 13 2026
  • Paul Ricketts

Ask around at any cybersecurity conference, and you'll find the same thing: almost nobody there started as a computer person.

There's the retail manager who spent five years reading people and defusing situations before they turned into scenes. The nurse who handled protected records under HIPAA and never once let the paperwork slip. The logistics sergeant who held a clearance, ran a supply chain under deadline pressure, and reported up a chain of command without excuses. None of them wrote a line of code before thirty. All of them, it turns out, were already doing the job, just not with that name on it.

Cybersecurity has more than half a million unfilled jobs in the US right now. That's not a talent shortage employers are managing gracefully. It's a hole they're filling with whoever shows up ready to work, degree or no degree. Good for you if you're one of them. Less good if you were hoping this would be easy. It isn't. What follows is ninety days of real effort, not a hack.

You already have half of what you need

The thing stopping most career changers isn't ability. It's the idea that this field belongs to people who've been taking computers apart since they were twelve. That idea is nonsense, and the hiring numbers back that up. 58% of security teams say they're understaffed to the point of real risk. Employers aren't holding out for the perfect candidate anymore. They can't afford to.

What they're actually looking for, most of the time, has nothing to do with code:

Came from retail or customer service? You already know how people behave under stress and how to spot when something's off — that's most of what security awareness training and social engineering defense actually is.

Came from healthcare? You've lived inside compliance frameworks and handled data you weren't allowed to lose — that's GRC work, nearly unchanged.

Served in the military? Clearance eligibility alone puts you ahead of most applicants in the DC Metro area, before your discipline and chain-of-command habits even enter the conversation.

Ran projects or admin work? You already document things properly and manage stakeholders, which is most of what a security program coordinator does all day.

Nobody's short on people who are good with computers. Everyone's short on people who think clearly under pressure and don't cut corners. That skill comes from a hundred different careers, and yours probably taught it to you already.

The 90 days, no padding

Three phases, thirty days each. Here's what actually happens in each one. Not the polished version, the real one.

One honest note before we start: if you're doing this around a full-time job, call it 90 to 120 days, not 90 flat. Nobody studies at full speed after a nine-hour shift, and pretending otherwise just sets you up to feel like you're failing a plan that was never built for your life. Build it around your actual week.

Days 1–30: Figure out where you're going before you start walking

The first week isn't studying. It's deciding, because picking the wrong certification track is the single most expensive mistake people make here (expensive in months, not dollars).

Do an honest audit of what you actually bring. Healthcare background → GRC and compliance is your fastest lane. Military → federal and DoD roles are the clearest door in. Coming from somewhere more general → SOC analyst is the most accessible entry point.

Be honest about your technical experience too. If you're leaning towards a change to IT, you likely have some level of computer experience. That level of experience can determine whether you're ready to dive straight into Security+, or maybe you need to build up some of your technical skills with foundational certifications like CompTIA A+ and Network+.

Three certification paths worth knowing:

    • CompTIA Security+ — shows up in more DoD and federal postings than anything else. If you're not sure where to start in cybersecurity, this is where to start. However, if your IT experience is limited, you may need to work up to this by first earning CompTIA A+ and Network+.
    • Google Cybersecurity Certificate — cheapest and fastest way to find out if you actually like this before you commit real money and months to it.
    • CompTIA A+ and Network+ — start with this if you genuinely need more technical ground under you. Be honest with yourself here, not optimistic.

Pick one path and enroll somewhere with an actual deadline. Self-paced courses with no instructor and no due date have a graveyard's worth of half-finished accounts behind them. A schedule you can't quietly ignore works better for almost everyone.

Milestone: enrolled, with an end date on the calendar.

Days 31–60: The unglamorous middle

This is where it stops being exciting and starts being work. There's no way around that.

Put in 1.5 to 2 hours a day, real hours, not "I'll catch up on the weekend" hours (that plan rarely survives week three). Evenings and weekends are the plan if you're working full-time, not an emergency backup to it.

Get into labs, not just videos. TryHackMe, iLabs, whatever your program includes. Reading about a firewall rule and configuring one under time pressure are different skills, and the exam, and ultimately the job, only cares about the second one.

Start showing up publicly now, not after you're certified. The ISC2 Community, CompTIA forums, LinkedIn security groups. Don't hold back from posting your progress, ask a dumb question, follow people doing the work. Nobody's going to mock a career changer who's clearly putting in the hours. Your network starts today, not on your first day of work.

Milestone: 60–70% through the material, one full practice exam taken and survived.

Days 61–90: Stop preparing and start applying

Two things happen at once here: finishing the cert, and getting in front of employers. Don't wait for one to finish the other.

Run two or three full practice exams until you're consistently clearing 80%. Then book the real one immediately. A date on the calendar is the only thing that reliably beats the urge to "study just a little more first." Endless self-studiers rarely lack knowledge. They lack a deadline.

Meanwhile, start applying before the certificate even arrives. Most employers will talk to someone actively pursuing a cert, they're not waiting for a piece of paper any more than you should be. Hit SOC Analyst Tier 1, security-flavored helpdesk roles, IT support at security-focused shops. Apply while the material's still fresh in your head, not three months later when you've forgotten why you started.

Build something small to show, too. Write up one concept a week from your labs. A rough GitHub page or LinkedIn post that shows actual work beats a résumé line that just says "certified."

Milestone: exam booked, first applications out the door.

What that first job is actually going to look like

Let's not dress this up. Your first role won't be senior analyst. That's not a knock on you, nobody walks into any field at the top, and if a training program tells you otherwise, that's marketing, not honesty.

Here's where people like you actually land:

SOC Analyst Tier 1: watching alerts, triaging, escalating to someone with more scar tissue than you. $55,000–$70,000. Strong demand almost everywhere, especially DC Metro.

IT Support / Helpdesk with a security lean: the lowest rung, and honestly the best one if you have zero IT history to begin with. $40,000–$55,000. Not glamorous. But the path from here to security analyst is worn smooth by everyone who came before you.

Security Compliance Analyst: built for people coming out of regulated industries. Your healthcare or finance background carries real weight here; the cert just makes it official.

Federal / DoD roles: the sharpest shortage of all, and the clearest pipeline if you've got clearance eligibility. Security+ isn't a nice-to-have; it's frequently the actual requirement.

None of these is the destination. They're the door. Someone disciplined enough to earn a second cert and pick one lane tends to move faster here than in most fields. The shortage cuts both ways, and employers know it.

The only real question

You didn't come here for a pep talk. You came with one question: can I actually pull this off?

Yes. But only if you treat the next ninety days as a project with a deadline, not a vague intention you're carrying around. The shortage is real, structural, not going anywhere soon. The employers are there. The path is well-worn and employer-recognized. The only unknown left in this whole thing is you.

If you want somewhere to start, talk through your options with our experienced program managers. They can give you impartial advice on how to get started. TrainACE runs entry-level certification programs out of the DC Metro area, and we've been doing this for 25 years. We know exactly what it looks like to start from zero, because most of the people we train did.

The ninety days start whenever you decide they do. Nobody's waiting on you but you.

Leave Your Comment Here