Live data from Hacker News

Flush times for hackers in booming cyber security job market

reuters.com

1–10 of 76 posts

Re: Flush times for hackers in booming cyber security job market

#4
I advise companies on tech security, and talent is very much needed.

What's surprising (at first glance) is that the security talent need is very strong in UI/UX/CX.

For example, security is needed to gradually escalate a user's own identity verification -- think of things like two-factor auth and multi-factor auth, that can phase in (or ramp up) when a user's actions enter a gray area of risk.

Some examples: when a user signs in from a new location, or a user does an especially large money transfer, or a user resumes an account that's been dormant for years, etc.

The UI/UX/CX is especially necessary to 1) explain to the user that there's a security issue, 2) how the user can fix it, and 3) how to improve backend systems to handle users who ask for help.

Re: Flush times for hackers in booming cyber security job market

#6
post #5

How can I get into this field? I used to love doing pen-testing when I was a teenager, and paid for my first car out of bug-bounties. Unfortunately, I got distracted by girls and booze at university and didn't keep it up, now I work in sigh enterprise C#/WPF land.

How'd you get into enterprise C#/WPF land?

Re: Flush times for hackers in booming cyber security job market

#7
post #4

I advise companies on tech security, and talent is very much needed. What's surprising (at first glance) is that the security talent need is very strong in UI/UX/CX. For example, security is needed to gradually escalate a user's own identity verification -- think of things like two-factor auth and multi-factor auth, that can phase in (or ramp up) when a user's actions enter a gray area of risk. Some examples: when a…

>What's surprising (at first glance) is that the security talent need is very strong in UI/UX/CX.

Which technologies specifically?

Re: Flush times for hackers in booming cyber security job market

#8
What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal tickets/issues/BUGs, while the development/operation practices are kept the same.

Re: Flush times for hackers in booming cyber security job market

#9
post #5

How can I get into this field? I used to love doing pen-testing when I was a teenager, and paid for my first car out of bug-bounties. Unfortunately, I got distracted by girls and booze at university and didn't keep it up, now I work in sigh enterprise C#/WPF land.

How'd you get into enterprise C#/WPF land?

Start as a pen tester then get distracted by girls and booze.
Post reply on HN