Live data from Hacker News

Flush times for hackers in booming cyber security job market

reuters.com

21–30 of 76 posts

Re: Flush times for hackers in booming cyber security job market

#21

I am totally into this field as a bystander. When many people would watch late night TV or listen to music or a podcast, I'll scour YouTube for defcon and CCC talks I haven't seen yet. I am good with python, Javascript, web and graphic design, technical writing, all kinds of stuff. I live in rural neighbor-island Hawaii and the only tech jobs I ever see out here are military, which I deeply respect but don't think wo…

Try the military. It's usually better than people imagine.

Re: Flush times for hackers in booming cyber security job market

#22
post #17
post #3

Low to mid 100k is very realistic in my experience. A lot more can be made with the right skills.

So standard software engineer salary in the USA?

Yes, like all tech jobs that pretend to be in demand.

Security is usually worse than regular engineering, because it tend to be a succession of short quick gigs.

Re: Flush times for hackers in booming cyber security job market

#23
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

it's like everything in a big company. every round of red team on my team's applications we just sit and laugh as they find nothing, yet we serve data to billions of customers every hour, from a myriad of complex entry points. nobody cares, and when I mention that on my self reviews it looks like I am padding it.

then the other teams only handle requests from the ios app they own, and red team finds tons of amateur attacks that work. they spend a quarter fixing it, and boast that they worked with the red team to patch hundreds of vulnerabilities. and everyone is promoted.

but that is not new. it always happened with teams that causes outages, or teams that miss out obvious revenues stream for years. remedial action for some reason is always rewarded in troubled big corps.

Re: Flush times for hackers in booming cyber security job market

#24
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

I used to work for a pentest company and everytime we engage with a customer, we discover a lot of problems and security issues which we document and submit to the customer.

We discover after a while that another company gets a contract 10x our price fixing the issues we discovered

Re: Flush times for hackers in booming cyber security job market

#25

I am totally into this field as a bystander. When many people would watch late night TV or listen to music or a podcast, I'll scour YouTube for defcon and CCC talks I haven't seen yet. I am good with python, Javascript, web and graphic design, technical writing, all kinds of stuff. I live in rural neighbor-island Hawaii and the only tech jobs I ever see out here are military, which I deeply respect but don't think wo…

Try the military. It's usually better than people imagine.

Military are the best at exploiting cybersecurity skills for their advantage

Re: Flush times for hackers in booming cyber security job market

#26
post #5

How can I get into this field? I used to love doing pen-testing when I was a teenager, and paid for my first car out of bug-bounties. Unfortunately, I got distracted by girls and booze at university and didn't keep it up, now I work in sigh enterprise C#/WPF land.

Daniel Miessler has a good general guide: https://danielmiessler.com/blog/build-successful-infosec-car... tptacek, who posts often on HN, also has some wise words: https://krebsonsecurity.com/2012/06/how-to-break-into-securi...

There are so many sources of information and learning grounds available now - bug bounties, certifications, war games, online tutorials, blogs, conferences etc.

I would suggest choosing a particular area of interest to begin with and deep-diving on that subject. Look for mentors or perhaps someone to knowledge share / skill exchange with.

You could do pretty well with a base in C#. Through pentest engagements, I've come across quite a few C# apps in my time and even with my limited knowledge of the language, found some interesting vulnerabilities ;)

Edit: Added tptacek link

Re: Flush times for hackers in booming cyber security job market

#27
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

[deleted]

Re: Flush times for hackers in booming cyber security job market

#28

What are some realistic salary ranges for people in this field? And is it largely on site work, or is it more common as a remote consultant?

Regarding onsite/remote, I think it depends on what you choose to specialise in. Most of the web application assessments I conduct are remote but there is still demand for onsite work.

Re: Flush times for hackers in booming cyber security job market

#29
post #18
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

It's because internal econometrics are resulting in perverse incentives. Defensive security is a cost center without clear, deterministic metrics for success. Let's say you pay X on defensive security (which is an oversimplification when you're talking about a cultural change, but that cultural change involves people learning how to pay attention to security, and paying attention is a form of man-hours, for which a c…

You probably meant Economics rather than Econometrics. Economics concerns itself with incentives and payoffs, whereas Econometrics is the statistical study of economic systems. Apologies for the pedantry

Re: Flush times for hackers in booming cyber security job market

#30
post #5

How can I get into this field? I used to love doing pen-testing when I was a teenager, and paid for my first car out of bug-bounties. Unfortunately, I got distracted by girls and booze at university and didn't keep it up, now I work in sigh enterprise C#/WPF land.

Didn't we all. (Similar story:) )

Don't regret the good times for one second, but do get very jealous of people on HN talking about all the exciting tech they're using and awesome work environment. I am actively taking steps to move to a better company, but my god I'm finding Cracking The Interview Code a slog.
Post reply on HN