You'll thank me later.
You'll thank me later.
https://portswigger.net/web-security
Have fun!
Edit: I'm completely self-taught and I've been working in the field for a few years. No dev or even IT background prior to getting into network pentesting and web app pentesting.
Also, teams with SRE expertise most likely use modern tech because SRE itself is a rather new way of managing infrastructure. So you'll probably be able to get your hands dirty with lots of cool tech.
Good security firms are the last ones to gatekeep over a degree or other paper.
While anecdoctally speaking, I know people who switched from senior dev positions at two of the FAANG companies to smaller security companies and basically doubled their income and making north of $500k/year.
1) Linux. Learn it and live in it.
2) Linux servers and databases.
3) CompTIA Network+ (only for the knowledge, didn't bother getting the cert)
4) CompTIA Security+ (same as above)
5) OSCP certification (not a golden ticken by any means but it helps to bypass HR)
That's basically it. While going down that road I focused on hands-on practice by actually hacking into machines with the help of following resources:
A) Hack The box (hackthebox.eu)
B) PentesterLab (pentesterlab.com)
I also really like Portswigger's Web Security Academy (portswigger.net) and Try Hack Me (tryhackme.com) but they weren't around when I was starting out but I would definitely check them out, especially if I was completely new to security today.
All in all it took me roughly a year but get comfortable enough to start applying to junior pentesting positions and eventually I got hired.
There are probably better and easier ways to do it but that's how I did it at least.