Live data from Hacker News

Ask HN: How did you get started in Network Security/Penetration Testing?

news.ycombinator.com

61–69 of 69 posts

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#61
post #34

Earlier quoted context omitted.

I didn't really find it that difficult to move from security consulting/research/code audits => dev/researcher at security vendors => machine learning engineer. So I don't know how we decide whose anecdote wins here :p

Simple. If you value your career as a dev, you won't become a pentester. :) There's no upside except intellectually. Being a dev pays more and gives you more options going forward. That's a harsh way to frame it, but it's also accurate. (I'm speaking from experience FWIW.) In other words, you could have become an ML engineer anyway. No reason to risk it by becoming a pentester.

I found security to be more financially rewarding than dev work (in the US) by asking developers at places I worked how much they were paid.

I wouldn't really recommend being a pentester either, but there is plenty of need for people who understand security and can code to write software.

It seems like you're having a tough time, and maybe ageism is a factor here, but none of what you're saying really meshes with my experience.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#62
post #42
post #8

I had an oppressive computer teacher in high school and I liked to pull pranks. It started out with simple password guessing, then phishing, then trojaned USB autoruns, SAM hash dumping, and password cracking, then some wifi sniffing... I never thought of what I was doing as hacking at the time (2001-2002). I just wanted to use the computer lab to play video games, and show up my jerk of a teacher. In my senior year…

I feel like it is difficult to get hired right out of college into a pentesting/netsec role without a bunch of certs and CTFs (which you do mention in your career guide). Even then it just looks like just another qualifying tick in the checklist. Right now I'm thinking a dev job for a couple years, then move into security (which looks like what some recommend). What do you suggest one can do to show that they have th…

Easy! Develop software. Don't limit yourself to scripts and small utilities. Work on something substantial, preferably low-level and closely related to the operating system or hardware. If you play CTF, show me the tooling you wrote to prepare, and the process you use to review your past performance and plan your next game. Our biggest ask during our hiring process is a code sample of some kind. If you're talking about finding bugs, show me that you didn't just get lucky, that you know how to make the process reliably produce a known outcome.

Sidenote, I think the dev job for ~2 years out of college then moving to security is a smart move. You're 100x more effective as a security engineer if you have a strong background in development. I'll say that we definitely prefer to hire software developers and teach them security.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#63
post #37

I decided I wanted to get verbally assaulted by engineering teams I was reporting findings to day in and day out. Who would have thought, I managed to make a career out of it! (ps, if you do go down this route, try to find a job at a company with a good security culture. starting one from scratch is walking a road of broken glass)

Corollary: Don't try to fix a company with bad culture. You can't change enough of it as a low level employee. Quit, and find somewhere better.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#64
A bunch of comments here warn that you may become unemployable in software engineering as a result. A so-called "security lifer".

I think that's a little silly. I work for one of the top security consulting firms and it's just not my or anyone else I know's reality. In fact, the total opposite seems to be true. We have talented code reviewers and tool writers move on to work at tech companies all the time. These people are still interested in security and from what I've heard, they end up working on or even leading some really cool software engineering projects.

I suppose if you woke up one day and decided that you're no longer interested in security at all, it may be difficult to pivot back if you stopped writing code. But that does not sound like the typical person who was originally interested in both security and code. Most security consultants I know who came from writing code really excel in security doing code review, architecture review, tool dev, etc. and those are all things that can translate back into software engineering experience on a resume.

Of course some people's experiences will differ. There are plenty of employers out there who are biased or looking for a very specific background. But these cases are far from the norm. Perpetuating the whole "security is a dead-end, life-long job" narrative is spreading needless FUD and prevents the industry from maturing.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#65
post #63
post #37

I decided I wanted to get verbally assaulted by engineering teams I was reporting findings to day in and day out. Who would have thought, I managed to make a career out of it! (ps, if you do go down this route, try to find a job at a company with a good security culture. starting one from scratch is walking a road of broken glass)

Corollary: Don't try to fix a company with bad culture. You can't change enough of it as a low level employee. Quit, and find somewhere better.

Working on it.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#66
post #62
post #42

Earlier quoted context omitted.

I feel like it is difficult to get hired right out of college into a pentesting/netsec role without a bunch of certs and CTFs (which you do mention in your career guide). Even then it just looks like just another qualifying tick in the checklist. Right now I'm thinking a dev job for a couple years, then move into security (which looks like what some recommend). What do you suggest one can do to show that they have th…

Easy! Develop software. Don't limit yourself to scripts and small utilities. Work on something substantial, preferably low-level and closely related to the operating system or hardware. If you play CTF, show me the tooling you wrote to prepare, and the process you use to review your past performance and plan your next game. Our biggest ask during our hiring process is a code sample of some kind. If you're talking abo…

Thanks! This is great advice.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#67

I can tell you how not to do it. I'll never forget the funniest interview I ever had. I interviewed with this company called Deja vu Security. http://www.dejavusecurity.com/ I explicitly told them, via email, I have ZERO experience pen testing, or anything related to hacking. I'm a terrific software engineer looking to pivot into this market, would take a salary cut to get my feet wet and be mentored. Would this be p…

Hey anon_dev_123456, This is Adam Cecchetti CEO of Deja vu Security. Over the last 2 years Deja has spent a lot of time refining our hiring processes, but occasionally an experience like this does slip through the cracks. We are always looking for candidates that are smart individuals, interested in security, and can code, any security experience is of course a plus. If you reach out to my email adam at dejavusecurity dot com I'd be happy to discuss what happened with your call and any other feedback you'd be willing to share.

Thanks, Adam

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#68
post #12

Earlier quoted context omitted.

Hey man this is really inspiring. I've been thinking about switching from web dev to security. How do you like it in comparison?

Right now I am happy as a freelance software engineer. I wasn't looking for a new job (I wanted the KNOW), but I _was_ looking for validation among business-types. I also have a few certs from AWS, and attaining those created the validation I needed in Devops/cloud (so it can be worth it for career growth). Honestly, I just got tired of being THAT developer who willingly shirked his security duties. I always let some…

That helps thanks for the reply!

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#69

I can tell you how not to do it. I'll never forget the funniest interview I ever had. I interviewed with this company called Deja vu Security. http://www.dejavusecurity.com/ I explicitly told them, via email, I have ZERO experience pen testing, or anything related to hacking. I'm a terrific software engineer looking to pivot into this market, would take a salary cut to get my feet wet and be mentored. Would this be p…

Damn, I love their Blender render homepage
Post reply on HN