Live data from Hacker News

Ask HN: How do you start a career in software security?

news.ycombinator.com

11–17 of 17 posts

Re: Ask HN: How do you start a career in software security?

#11

Security consultant checking. Candidates with some form of experience are often preferred. But the beauty of infosec is that that experience can be pretty much anything, it does not have to be relevant work or school experience. Have some bug bounties, CVE's or exploits to your name, you'll get an interview. Have a certificate like OSCP to your name, you'll get an interview. Do writeups of Vulnhub machines and that m…

> Have a certificate like OSCP to your name, you'll get an interview.

That's the way I personally moved to security and can't recommend it enough. It's a bit expensive but you definitely get your money's worth.

Re: Ask HN: How do you start a career in software security?

#12
Don't be afraid to shake things or the industry but always stay on the bright side. The line is very thin between: I am trying to help and improve security in contrast with I am threatening you. Some people or Business could feel threatened depending on the wordings used when approaching them.

Re: Ask HN: How do you start a career in software security?

#13
post #11

Security consultant checking. Candidates with some form of experience are often preferred. But the beauty of infosec is that that experience can be pretty much anything, it does not have to be relevant work or school experience. Have some bug bounties, CVE's or exploits to your name, you'll get an interview. Have a certificate like OSCP to your name, you'll get an interview. Do writeups of Vulnhub machines and that m…

> Have a certificate like OSCP to your name, you'll get an interview. That's the way I personally moved to security and can't recommend it enough. It's a bit expensive but you definitely get your money's worth.

Well, it's a bit of an out of pocket expense for sure, but it is in my opinion the security course where you get most bang for your buck.

Re: Ask HN: How do you start a career in software security?

#14
post #5

The reason you haven't found companies hiring graduates for security is partly because security, like most specializations, generally skews towards more experienced candidates, and partly because it's a relative niche. I'm happy to help you via email if you'd like to get in touch. Practically speaking, my advice would be to pursue bug bounties, read as much as you can in the field and implement security measures in c…

I know this is a broad question, but what skill set are security firms looking for in graduates/juniors? I have a year of experience in software development on a security product, and have done some basic security vulnerability assessments, but I'm not sure if that's enough to get hired somewhere else.

Re: Ask HN: How do you start a career in software security?

#15
post #11

Security consultant checking. Candidates with some form of experience are often preferred. But the beauty of infosec is that that experience can be pretty much anything, it does not have to be relevant work or school experience. Have some bug bounties, CVE's or exploits to your name, you'll get an interview. Have a certificate like OSCP to your name, you'll get an interview. Do writeups of Vulnhub machines and that m…

> Have a certificate like OSCP to your name, you'll get an interview. That's the way I personally moved to security and can't recommend it enough. It's a bit expensive but you definitely get your money's worth.

In terms of security certificates, it is actually on the cheaper end. SANS/GIAC have a lot of certificates but run much more expensive, like $5k+

Re: Ask HN: How do you start a career in software security?

#16

Security consultant checking. Candidates with some form of experience are often preferred. But the beauty of infosec is that that experience can be pretty much anything, it does not have to be relevant work or school experience. Have some bug bounties, CVE's or exploits to your name, you'll get an interview. Have a certificate like OSCP to your name, you'll get an interview. Do writeups of Vulnhub machines and that m…

> Have some bug bounties, CVE's or exploits to your name, you'll get an interview.

That assumes you hear of positions, and apply. I do auditing for fun in my spare time, and have reported issues in software as diverse as Emacs, evilvte, GNU Readline, gforge, oping, and NCSA Mosaic 2.1 (!).

Brief list - https://steve.fi/Security/Advisories/

In all that time I've never once received an unsolicited offer/mail about "security". I do receive unsolicited contact from recruiters every other month or so, on the topic of Perl/Ruby/C++/etc.

(Interestingly I stopped getting recruiter mails from people asking about C++ when I moved a couple of personal github repositories into an organization of which I'm the main active member. I suspect that means recruiters are crawling github now.)

Post reply on HN