Live data from Hacker News

Ask HN: Starting a career in security at 40?

news.ycombinator.com

71–80 of 114 posts

Re: Ask HN: Starting a career in security at 40?

#71
post #35

You'll do fine. Don't waste time with certificates. They mean fuck all in the industry. Any job that cares about them is a job you don't want. Try to get some clarity about what part of security you want to work in. All the subfields are open to you. Do you want to do operations work? Do you want to exercise your software development muscles? Do you want to work offense or defense? My advice might be different depend…

I second this. I moved from systems engineering to the security field without issue. Security organizations now more than ever need a full spectrum of developers, system engineers/sysadmins and operations folks. You likely already have all the skills you need to find a decent position somewhere. Your existing skills should translate quite well.

Re: Ask HN: Starting a career in security at 40?

#72
I'd recommend noting down your area. You're going to get a lot of advise, and it's probably very good advice in general. But as someone not in the US, a lot of what I'm reading does not reflect my local market.

Edit: That similarly applies to the "current salary" discussion. Six figures could be a lot, or very poor.

Re: Ask HN: Starting a career in security at 40?

#73
post #35

You'll do fine. Don't waste time with certificates. They mean fuck all in the industry. Any job that cares about them is a job you don't want. Try to get some clarity about what part of security you want to work in. All the subfields are open to you. Do you want to do operations work? Do you want to exercise your software development muscles? Do you want to work offense or defense? My advice might be different depend…

Certifications are a way to bypass HR filters, and allow you to negotiate higher salaries. I agree that in terms of imparting actual skills and knowledge they are of minimal value. Being mentored by your peers, being involved in the community, and learning by doing are by far the best ways to learn Security. Certificates are relatively easy to earn and have high ROI in terms of salary and negotiating power in my expe…

This is what everyone who voluntarily paid for a certificate tells themselves. As a hiring manager (for ~10 years now) in software security who talks to a lot of other hiring managers, I am pretty confident that the supposed ROI for certification is not there. Also: if you're dealing directly with HR filters when trying to get a job somewhere, you're already playing to lose. A much higher ROI would be gained by learning how to seriously pursue a targeted role.

Re: Ask HN: Starting a career in security at 40?

#74
post #48

Earlier quoted context omitted.

I think what he means with certifications is that they'll get you the jobs you don't really want. For example, CEH (Certified Ethical Hacker) is a certification you'll see in a lot of job postings. The thing is, if you know this field, you know that this certification is worthless; it's just an expensive piece of paper. So, if you get a job that requires you to be CEH, it's telling a lot about the company itself, you…

Agree on the other certs -- but have you actually looked at the requirements for OSCP? I think it's a bit more in depth than you believe.

OSCP covers a significant part of my actual subfield in security, and I think it's pretty silly.

Re: Ask HN: Starting a career in security at 40?

#75
post #41
post #35

You'll do fine. Don't waste time with certificates. They mean fuck all in the industry. Any job that cares about them is a job you don't want. Try to get some clarity about what part of security you want to work in. All the subfields are open to you. Do you want to do operations work? Do you want to exercise your software development muscles? Do you want to work offense or defense? My advice might be different depend…

Do you have any resources / direction to give to a software engineer who'd want to learn more about security? As a full stack web engineer I feel like I know nothing about security (just like most people) and I'd love to have more knowledge about it, even maybe work on this. I have a small design and engineering studio, and might be interested in getting into that kind of services, if I discover that I get interested…

Start here:

https://trailofbits.github.io/ctf/

Re: Ask HN: Starting a career in security at 40?

#76
post #35

You'll do fine. Don't waste time with certificates. They mean fuck all in the industry. Any job that cares about them is a job you don't want. Try to get some clarity about what part of security you want to work in. All the subfields are open to you. Do you want to do operations work? Do you want to exercise your software development muscles? Do you want to work offense or defense? My advice might be different depend…

How would you practice this craft? Is practicing on pentesting websites (like https://www.hackthebox.eu/ ) a good idea? Or is there a better way to learn the various tools? Edit: I have also completed some of the challenges on http://cryptopals.com/ a while back to get better with developing Python code.

Start here:

https://trailofbits.github.io/ctf/

Cryptopals is great! :) If you've gotten all the way through set 6 and are interested in a first software security gig, get in touch. Those challenges have been a pretty excellent predictor for us.

Re: Ask HN: Starting a career in security at 40?

#77
post #61

Allow me to disagree with tptacek a little: The OffSec Penetration Testing with Kali Linux (OSCP certification) is excellent and outstanding and cheap. https://www.offensive-security.com/information-security-trai... While the course itself is $800, you'll most assuredly need another 60 days of lab time for the certification. I think all-in-all it cost me $1,500 for everything. The course material is excellent and wid…

I'm just one data point but I'm a hiring security manager and if someone had OCSP it would mean nothing to me.

Same. To some extent the presence of certs is a lacks-clue indicator to me. That's not fatal (lots of great hires really understand security but know nothing about the industry) but it starts my evaluation of you off at 'greenhorn'.

Re: Ask HN: Starting a career in security at 40?

#78

40 is a great time. In fact, I went down a similar path. Now that you've done your share of sysadmins, SRE and software developer, you can see how things can fail. That's the heart of security. As tptacek advises, choose an area of security to focus on and go down that path for awhile. You'll find you will want to go further or jump to another path, but security is a great thing. The world is going to need more secur…

If you don't mind, I would love to know how "changing human mindsets and behaviour" and "Dev and ops skills ... technical success" go together for you!

Is your goal creating a development process that leads to a secure system, or securing a system made by an existing process? How much code do you write? Maybe some tasks you've enjoyed or a typical day would be great.

I say this because, while I've never had or wanted a title that included security, as a dev I often find myself looking at "holistic defense of data flowing" and attempting to improve the situation. A role based on that concept is interesting.

Re: Ask HN: Starting a career in security at 40?

#79

Earlier quoted context omitted.

You can almost double your total comp overnight going from a devops/infra role to an infosec role. If you're in ops, get out of ops and go into security. More money, no on call rotation, better career trajectory.

>no on call rotation In my experience that hasn't been true at all, but the rest is definitely accurate.

Secops people have on-call rotations. Pretty much nobody else does.

Re: Ask HN: Starting a career in security at 40?

#80
post #61

Allow me to disagree with tptacek a little: The OffSec Penetration Testing with Kali Linux (OSCP certification) is excellent and outstanding and cheap. https://www.offensive-security.com/information-security-trai... While the course itself is $800, you'll most assuredly need another 60 days of lab time for the certification. I think all-in-all it cost me $1,500 for everything. The course material is excellent and wid…

I'm just one data point but I'm a hiring security manager and if someone had OCSP it would mean nothing to me.

~Same. I expect in the most charitable case it means about as much to infosec hiring managers as bootcamps do to developer hiring managers.
Post reply on HN