Which certification actually helps for a first security role in India?
Foundational vendor-neutral certifications carry real weight at the screening stage because security teams use them to filter volume. Practical, hands-on certifications carry more weight in the interview itself. What does not work is collecting advanced management-oriented certifications with no operational experience behind them, since panels quickly find the gap between the credential and what you can actually investigate.
Will I have to take a pay cut to enter cybersecurity?
It depends on which door you use. Moving internally into your own organisation's security team usually protects your compensation and your context, which is why it is the path we push first. Entering a new company as an external junior analyst is where cuts happen, because you are priced as a beginner rather than as someone who already knows the estate you are defending.
Should I aim for SOC analyst or something like penetration testing?
SOC is the realistic entry point from service desk. Defensive operations hire at volume, and triage and escalation discipline transfer directly from your current work. Offensive security has a smaller entry market and expects demonstrable technical depth before a first role. Many people move from SOC into specialisation later, which is a far shorter route than trying to start there.
How do I get past resume screening with a helpdesk title?
By making the security content of your work explicit and measurable. Volume of phishing reports triaged, access reviews supported, incidents escalated, endpoint alerts handled. Screening filters on the vocabulary of the field, and most service desk resumes describe the same work in support vocabulary. This single rewrite is usually the difference between no responses and first-round conversations.