Live data from Hacker News

Flush times for hackers in booming cyber security job market

reuters.com

31–40 of 76 posts

Re: Flush times for hackers in booming cyber security job market

#31
post #5

How can I get into this field? I used to love doing pen-testing when I was a teenager, and paid for my first car out of bug-bounties. Unfortunately, I got distracted by girls and booze at university and didn't keep it up, now I work in sigh enterprise C#/WPF land.

I'm in my late 20s and got into the field professionally just a couple years ago. Prior to that I had been working as a software developer.

I believe what helped was a handful of personal projects related to security: reverse engineering firmware, finding bugs in web apps. Also I emphasised the parts of my software development work that had some overlap, such as debugging Windows kernel drivers, and doing security reviews of network services we were writing and deploying.

Now I'm doing full-time vulnerability research and writing software to help do that. Much more enjoyable and pays better too.

Re: Flush times for hackers in booming cyber security job market

#32

I am totally into this field as a bystander. When many people would watch late night TV or listen to music or a podcast, I'll scour YouTube for defcon and CCC talks I haven't seen yet. I am good with python, Javascript, web and graphic design, technical writing, all kinds of stuff. I live in rural neighbor-island Hawaii and the only tech jobs I ever see out here are military, which I deeply respect but don't think wo…

Hit some bounties. Earn some income and it generally looks good on a CV that you can deliver real world results. Just try and go deeper.

Re: Flush times for hackers in booming cyber security job market

#33
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

My experience is inconsistent with yours. In my 12 years of experience in the security industry, I have found that the blue teams (engineers who develop, maintain and secure network, data and applications) have higher demand and higher salaries than the red teams or pen-testing teams.

My experience is limited to security software development in e-banking, e-commerce, network security and data security domains in technology areas like cryptography, PKI, deep packet inspection, and network protocols. I know my experience may not be representative of the entire security industry and there is a possible selection bias too (i.e. I may have seen more demand for blue team engineers because I have belonged to blue teams myself), but I thought I should share my experience here to present the other side of the story.

Re: Flush times for hackers in booming cyber security job market

#35
post #18
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

It's because internal econometrics are resulting in perverse incentives. Defensive security is a cost center without clear, deterministic metrics for success. Let's say you pay X on defensive security (which is an oversimplification when you're talking about a cultural change, but that cultural change involves people learning how to pay attention to security, and paying attention is a form of man-hours, for which a c…

It's not only "internal". There isn't really a functioning market for "middleware" in much of software, creative areas excluded. I don't really believe that managers, users or anyone else is primarily responsible. At the end of the day most developers aren't very good at security and they aren't necessarily willing to pay for it either.

Re: Flush times for hackers in booming cyber security job market

#38
post #15

I am totally into this field as a bystander. When many people would watch late night TV or listen to music or a podcast, I'll scour YouTube for defcon and CCC talks I haven't seen yet. I am good with python, Javascript, web and graphic design, technical writing, all kinds of stuff. I live in rural neighbor-island Hawaii and the only tech jobs I ever see out here are military, which I deeply respect but don't think wo…

Fastest way would be OSCP cert.

OSCP, red teaming, possibly CISM or CISSP for upward mobility.

Re: Flush times for hackers in booming cyber security job market

#39

I am totally into this field as a bystander. When many people would watch late night TV or listen to music or a podcast, I'll scour YouTube for defcon and CCC talks I haven't seen yet. I am good with python, Javascript, web and graphic design, technical writing, all kinds of stuff. I live in rural neighbor-island Hawaii and the only tech jobs I ever see out here are military, which I deeply respect but don't think wo…

1) Schneier's advice from a few years ago is still accurate:

https://www.schneier.com/blog/archives/2012/07/how_to_become...

2) The Reddit NetSec FAQ has a good list of resources for beginners (and those starting to specialize):

https://www.reddit.com/r/netsec/wiki/start

3) Finally, each of these popular "Getting Started in Security" guides has a slightly different, but useful, opinion on the specifics of the path to take:

https://medium.freecodecamp.org/so-you-want-to-work-in-secur...

https://danielmiessler.com/blog/build-successful-infosec-car...

https://www.trustwave.com/Resources/SpiderLabs-Blog/Getting-...

https://tisiphone.net/2015/10/12/starting-an-infosec-career-...

Re: Flush times for hackers in booming cyber security job market

#40
post #20
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

In theory you could take advantage of this by starting a company that hires people from the blue side at a premium and create products with top notch security. Unfortunately I am not sure if currently consumers care that much about security of their products relative to convenience, price, and eye candy. But in theory those who spend lots on red side will end up having a more expensive product and a bad reputation, s…

The trouble with that is that b2b contracts will specify pen tests so you'll incur that cost anyway to demonstrate you don't have security holes.

"Regular pen test" is seen as demonstrating security, which is as little perverse because the results don't typically get published so you could be having the same issues year after year and look just as good as someone who gets a clean bill each time.

Post reply on HN