Ask HN: Starting a career in security at 40?
51–60 of 114 posts
Re: Ask HN: Starting a career in security at 40?
#52Earlier quoted context omitted.
You can almost double your total comp overnight going from a devops/infra role to an infosec role. If you're in ops, get out of ops and go into security. More money, no on call rotation, better career trajectory.
Potentially, if you find that magic role and are qualified. I am too cautious to say you could 2x from a 6 figure salary without putting in a few years getting experience and proving yourself first. Not saying it isn't possible, but overnight is probably an exaggeration. If you're willing to travel and do consulting it's realistic, but it sounds like OP may not be willing to go that route.
Re: Ask HN: Starting a career in security at 40?
#53- Do the Matasano security challenges - Talk to tptacek (tqbf on twitter): they almost certainly have pointers and opinions
Re: Ask HN: Starting a career in security at 40?
#54I did good work, but expertise was thin on the ground. I discovered that while I like the subject matter a great deal, I didn't like is the chain of responsibility at that organization.
At one point I felt like I couldn't leave because the system would come off the rails if I wasn't there and I harbored some resentment. If you can find a place where you're working in an advisory capacity you won't run into that problem.
Are you seeing job openings where you are taking a big pay cut to work in security? That didn't used to be the case. I used to lament that the problem with my platonic ideal for QA people is paradoxical; the sort of person whom I would cherish as a QA person could spend a year retraining as a security auditor and make more money than me instead of 70% of what I'm making.
Re: Ask HN: Starting a career in security at 40?
#55Now that you've done your share of sysadmins, SRE and software developer, you can see how things can fail. That's the heart of security. As tptacek advises, choose an area of security to focus on and go down that path for awhile. You'll find you will want to go further or jump to another path, but security is a great thing. The world is going to need more security-aware people and you can be at the forefront of it.
My current security focus is holistic defence of data flowing from customer to company. The whole SDLC lifecycle. It's fun but super challenging because it focuses on changing human mindsets and behaviour, but my Dev and ops skills are essential to my technical success.
And certs are useless on their own. Don't do certs unless you can specifically get something out of it. Your work experience is much more valuable than a cert at this point.
Re: Ask HN: Starting a career in security at 40?
#56You'll do fine. Don't waste time with certificates. They mean fuck all in the industry. Any job that cares about them is a job you don't want. Try to get some clarity about what part of security you want to work in. All the subfields are open to you. Do you want to do operations work? Do you want to exercise your software development muscles? Do you want to work offense or defense? My advice might be different depend…
Do you have any resources / direction to give to a software engineer who'd want to learn more about security? As a full stack web engineer I feel like I know nothing about security (just like most people) and I'd love to have more knowledge about it, even maybe work on this. I have a small design and engineering studio, and might be interested in getting into that kind of services, if I discover that I get interested…
Re: Ask HN: Starting a career in security at 40?
#57Earlier quoted context omitted.
I think what he means with certifications is that they'll get you the jobs you don't really want. For example, CEH (Certified Ethical Hacker) is a certification you'll see in a lot of job postings. The thing is, if you know this field, you know that this certification is worthless; it's just an expensive piece of paper. So, if you get a job that requires you to be CEH, it's telling a lot about the company itself, you…
Agree on the other certs -- but have you actually looked at the requirements for OSCP? I think it's a bit more in depth than you believe.
Security skills are just not something you tend to pick up in 4 hours flat.
source: have both OSCP and OSCE, and I work in the industry
Re: Ask HN: Starting a career in security at 40?
#58You'll do fine. Don't waste time with certificates. They mean fuck all in the industry. Any job that cares about them is a job you don't want. Try to get some clarity about what part of security you want to work in. All the subfields are open to you. Do you want to do operations work? Do you want to exercise your software development muscles? Do you want to work offense or defense? My advice might be different depend…
Or is there a better way to learn the various tools?
Edit: I have also completed some of the challenges on http://cryptopals.com/ a while back to get better with developing Python code.
Re: Ask HN: Starting a career in security at 40?
#59Re: Ask HN: Starting a career in security at 40?
#60You don't need a SANS class, they can teach you a lot but there are places for newbies that get more for much less. It's better to get a job and see what they need you to do on a daily basis, then choose a SANS class to get better at that specific skill. I'd just put your resume in now as a sysadmin and see what happens. We hire plenty of people with devops/sysadmin backgrounds and teach them as we go.
Certifications are pretty much not required. Some are seen as a joke and will actually get you weeded out if they are on your resume.
Compliance is very... very dull and is seen as a joke to serious security folks because the bar is set very low. I would say avoid this completely if you want to enjoy coming to work. (Sorry for compliance folks out there)
Six figures is common for a lot of people on here. Security makes more than some software devs depending on your skill level and company. I don't know what you do now, but you would most likely be matched or higher depending on how strong your skills are.
I'd say the hardest thing is you always have to learn new technology and keep up to date with the latest trends. CI/CD pipelines, containerization, blockchain (rolls eyes), cryptography, different cloud environments, smart phones, cars, etc. You will almost definitely encounter something you have never seen before and need to learn as much about it as possible in order to secure it.