The key is to demonstrate your passion for the industry. This can bypass experience sometimes. You have to do things on your own time to demonstrate that you're obsessed with this stuff, get certs, write articles, find exploits......whatever it is, do it and keep doing it. You've got to go into interviews professional, but energized. For example, I had a network admin/engineer background (12 years) and was hired as a senior pen testing consultant because I convinced them I knew what I was talking about. It can be tricky but it can be done. A good company will recognize passion and know that the upside for someone with passion is far superior to someone who is just luke warm.
Most of the interviews I've had they've explicitly told me "I can tell you're very passionate" or "you're doing the right things (in order to try to get the experience)", but they still say we're looking for someone with more experience. Guess I just haven't found the right company yet.
when I was breaking into the industry I offered to work for free and no one would take me on. So I ended up doing certificated to get some expierence.
I am doing unpaid work for a startup, I'm not getting a lot of experience, but it's better than nothing.