Live data from Hacker News

Flush times for hackers in booming cyber security job market

reuters.com

11–20 of 76 posts

Re: Flush times for hackers in booming cyber security job market

#11
post #5

How can I get into this field? I used to love doing pen-testing when I was a teenager, and paid for my first car out of bug-bounties. Unfortunately, I got distracted by girls and booze at university and didn't keep it up, now I work in sigh enterprise C#/WPF land.

Didn't we all.

(Similar story:) )

Re: Flush times for hackers in booming cyber security job market

#12
I am totally into this field as a bystander. When many people would watch late night TV or listen to music or a podcast, I'll scour YouTube for defcon and CCC talks I haven't seen yet. I am good with python, Javascript, web and graphic design, technical writing, all kinds of stuff. I live in rural neighbor-island Hawaii and the only tech jobs I ever see out here are military, which I deeply respect but don't think would be a good culture fit for me. I've just transitioned to working part time and intend to dive in to some open source projects with my extra time. Is there a good path of entry for someone with a deep natural curiosity about the field, self-trained in coding but with no industry connections or much in the way of related professional experience?

Re: Flush times for hackers in booming cyber security job market

#13
post #5

How can I get into this field? I used to love doing pen-testing when I was a teenager, and paid for my first car out of bug-bounties. Unfortunately, I got distracted by girls and booze at university and didn't keep it up, now I work in sigh enterprise C#/WPF land.

How'd you get into enterprise C#/WPF land?

Just sort of fell into it. Did an internship at university in $genericbigcorp and didn't bother looking for other/better jobs at graduation. (To be fair they paid a generous joining bonus - well £2000 "generous" to my broke 21 year old self).

Re: Flush times for hackers in booming cyber security job market

#14
post #4

I advise companies on tech security, and talent is very much needed. What's surprising (at first glance) is that the security talent need is very strong in UI/UX/CX. For example, security is needed to gradually escalate a user's own identity verification -- think of things like two-factor auth and multi-factor auth, that can phase in (or ramp up) when a user's actions enter a gray area of risk. Some examples: when a…

>What's surprising (at first glance) is that the security talent need is very strong in UI/UX/CX. Which technologies specifically?

>Which technologies specifically?

I think that's part of the issue, security minded folks are often very analytical and come from CS backgrounds and the demand is for people who understand how design interacts with technology to, in this case, create secure methods of actually using a technology.

So, to answer your question, none. It's about the mindset of the designer.

Re: Flush times for hackers in booming cyber security job market

#15

I am totally into this field as a bystander. When many people would watch late night TV or listen to music or a podcast, I'll scour YouTube for defcon and CCC talks I haven't seen yet. I am good with python, Javascript, web and graphic design, technical writing, all kinds of stuff. I live in rural neighbor-island Hawaii and the only tech jobs I ever see out here are military, which I deeply respect but don't think wo…

Fastest way would be OSCP cert.

Re: Flush times for hackers in booming cyber security job market

#16
post #5

How can I get into this field? I used to love doing pen-testing when I was a teenager, and paid for my first car out of bug-bounties. Unfortunately, I got distracted by girls and booze at university and didn't keep it up, now I work in sigh enterprise C#/WPF land.

Source code review is in high demand. Many companies are happy to train a developer on how to do it.

Re: Flush times for hackers in booming cyber security job market

#18
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

It's because internal econometrics are resulting in perverse incentives.

Defensive security is a cost center without clear, deterministic metrics for success. Let's say you pay X on defensive security (which is an oversimplification when you're talking about a cultural change, but that cultural change involves people learning how to pay attention to security, and paying attention is a form of man-hours, for which a cost can be calculated). If you don't get attacked, is it because the X you paid is high enough to deter/foil attackers, or could you have paid less and achieved the same result? If you are attacked and the attackers get past your defenses, is it because the X you paid wasn't enough, or if you had spent more, would the attackers have succeeded anyway, because of their relative power and motivation? For defensive security, it's very, very hard to justify to bean counters that X was the correct amount of money spend, no matter what the real outcome is, because it's hard to understand X's affect on that outcome.

Pentests which result in tickets/issues/etc. are much easier to justify. The company spent X on the pentest, and it got Y feedback in return. Simple, and effective, at least in the short-term.

It's part of the overall challenge that organizations face when they become metrics-driven. People choose the path of least resistance, so if you ask people to measure data, they'll measure the data that's easiest to measure. Data that's harder to measure - culture and social attitudes - becomes "not a priority" to measure.

Re: Flush times for hackers in booming cyber security job market

#19
post #4

I advise companies on tech security, and talent is very much needed. What's surprising (at first glance) is that the security talent need is very strong in UI/UX/CX. For example, security is needed to gradually escalate a user's own identity verification -- think of things like two-factor auth and multi-factor auth, that can phase in (or ramp up) when a user's actions enter a gray area of risk. Some examples: when a…

>What's surprising (at first glance) is that the security talent need is very strong in UI/UX/CX. Which technologies specifically?

For example some keywords: rapid web/mobile prototyping, info visualization, split test planning, throttle rollouts, accessibility areas, i18n/l10n, risk management, compliance verification, pattern recognition, time series analysis, threat modeling of web usage, relevance ranking, bloom filters, HIPAA/FERPA/SOX/ISAE etc., client-side cryptography, graylisting, social proof verification, identity theft mitigation, etc.

Re: Flush times for hackers in booming cyber security job market

#20
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

In theory you could take advantage of this by starting a company that hires people from the blue side at a premium and create products with top notch security.

Unfortunately I am not sure if currently consumers care that much about security of their products relative to convenience, price, and eye candy.

But in theory those who spend lots on red side will end up having a more expensive product and a bad reputation, so perhaps investing more on blue will win in the long run.

Post reply on HN