Noah Heroldt, a junior in cybersecurity in Indianapolis, grew up with an interest in computers: "I was basically a 'user' for a really long time, and that was it." Before he decided on college, he already knew he wanted to go into a field that would expand his knowledge base.
His father discovered that Purdue is a participant in the federal CyberCorps Scholarship for Service program. Heroldt toured Indianapolis during his junior year of high school and met Feng Li, now head of the School of Applied and Creative Computing. Li asked Heroldt if he knew about Kali Linux, an operating system used for penetration testing.
"I went home that day [and] searched for it," Heroldt said. "I didn't know hacking could be used as a career. From there I was kind of dead-set, locked in on, 'this is what I want to do.'"
Heroldt spent the next 10 months teaching himself the fundamentals of networking and ethical hacking. Through no small amount of self-training, he was able to arrive at college with a meaningful head start.
"That raw curiosity that sparked after my conversation with Doctor Li fueled a fire that has done me so much good throughout my college career," Heroldt said. "I learned a lot of what I know now outside of class, just on my own time, being curious about how things worked."
"I truly believe that anyone can learn anything these days as long as you have a connection to the internet. It's one of the reasons why I started my YouTube channel. I learned so much from the cyber community online and I wanted to do my part and give back, laying my knowledge down for future learners who might just pick this up on a whim, which is basically what I did."
While it can be difficult for a freshman to begin immediately applying what they've learned, Heroldt managed it. He secured a cybersecurity internship at a distribution company during the summer of his freshman year. The company was happy to keep him on, which meant that he was able to get almost two years of on-the-ground experience in a small, efficient IT team. This work gave Heroldt exposure to almost every facet of the company's IT and cybersecurity infrastructure during that time.
"I got exposed to almost every single facet of their infrastructure, and I didn't get pigeonholed into one single area of their IT or security system," Heroldt said. "If I didn't know [something], I'd ask questions... I would just learn it and try again. I think that's because it was a super lean team-basically five people. So there was no busy-work or anything like that, since they actually wanted substantial help. I was constantly challenged because there were real problems to solve, and if I ran into a roadblock then my coworkers were very willing to step in and teach me so that I could do it myself going forward."
Heroldt was confident enough in his experience to dedicate 2025 to earning professional credentials. "2025 was like the Year of the Certifications for me," he said. He passed the Practical Junior Penetration Tester (PJPT) and Practical Network Penetration Tester (PNPT) exams, offered by TCM Security. He then targeted the Offensive Security Certified Professional (OSCP) certification.
Offsec's OSCP certification has become an industry standard, and Heroldt explained that this particular test comes with a notable difficulty spike that causes many newcomers to fail on their first try. The OSCP certification requires candidates to hack a simulated network within 24 hours and write a comprehensive report within the next 24 hours. Heroldt passed the exam on his first attempt.
"I really believe it's the time crunch that usually feeds into students failing," Heroldt said. "Especially on that first try, people oftentimes feel constantly stressed and underprepared. I think these 'human failures' are the main factor in first-time fails more so than technical failures."
Heroldt approaches these grueling, multi-day exams with a strict strategy. He uses several tools to stay mentally healthy and agile throughout the length of the most demanding certifications. Heroldt's primary strategy is to use the Pomodoro Technique; he uses a timer to enforce short breaks every 25 or 50 minutes.
"A lot of people will just try to grind it out and go eight hours straight, no food, no water, no breaks," Heroldt said. "If you take breaks and you treat it like a normal day, then it becomes a lot less stressful, it becomes a lot easier, and your mind is just a lot clearer."
Heroldt started documenting his progress on YouTube two years ago. He initially started the channel (NTH Security) to record his solutions to Capture the Flag cybersecurity challenges. Since then, the channel has evolved into a platform where he answers questions, reviews certifications, and mentors other students.
Heroldt treats his YouTube content as an extension of his own education.
"Teaching is one of the best ways to learn something, and I don't want to just be teaching blindly," Heroldt said. "I always try to make sure that I'm doing something factually, making sure it's right before I make a video on it."
Heroldt plans to discuss artificial intelligence in the cybersecurity industry in future videos. The topic is not only relevant in the big picture; it became personally relevant to Heroldt when he discovered that one of his many certifications was marked by an AI grader. "There's definitely a wide range of opinions about how appropriate it is to use AI for something like that," Heroldt said.
Heroldt views AI as a useful tool for spotting data patterns, but he warns against using it to skip the difficult parts of the educational process.
"I think friction is where learning happens," Heroldt said. "When you try everything you know in a Capture the Flag challenge and you get stuck, that is friction. If I truly can't find a solution in the two and a half years of notes that I have... then that's when I'll considering turning to AI. And at that point, if it can help me learn something really novel, that is what sticks with me. But I'm always looking for that novelty anyway, regardless of where I get to learn it."
Additional information