Live data from Hacker News

Flush times for hackers in booming cyber security job market

reuters.com

41–50 of 76 posts

Re: Flush times for hackers in booming cyber security job market

#41
Always cracks me up thinking about how much the press talks about cybersecurity being in demand then looking at the actual IOT and embedded cybersecurity market.

Everyone should be very, very scared about infrastructure/medical security and the effective lack of anyone doing anything about it.

I'm sure web/network pentesting is doing well though.

Re: Flush times for hackers in booming cyber security job market

#42
post #24
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

I used to work for a pentest company and everytime we engage with a customer, we discover a lot of problems and security issues which we document and submit to the customer. We discover after a while that another company gets a contract 10x our price fixing the issues we discovered

Sounds like a missed opportunity to at least get a referral fee for resolution.

Re: Flush times for hackers in booming cyber security job market

#43

I am totally into this field as a bystander. When many people would watch late night TV or listen to music or a podcast, I'll scour YouTube for defcon and CCC talks I haven't seen yet. I am good with python, Javascript, web and graphic design, technical writing, all kinds of stuff. I live in rural neighbor-island Hawaii and the only tech jobs I ever see out here are military, which I deeply respect but don't think wo…

I saw a talk by the founder of this company: https://radicallyopensecurity.com/

They're based in Amsterdam, but she said that a lot of their pentesters and engineers are remote (all over the world).

Might be worth reaching out!

Re: Flush times for hackers in booming cyber security job market

#44
post #23
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

it's like everything in a big company. every round of red team on my team's applications we just sit and laugh as they find nothing, yet we serve data to billions of customers every hour, from a myriad of complex entry points. nobody cares, and when I mention that on my self reviews it looks like I am padding it. then the other teams only handle requests from the ios app they own, and red team finds tons of amateur a…

>remedial action for some reason is always rewarded in troubled big corps. reply

>for some reason

I would go out on a limb to say it's definitional. A troubled Big Corp is troubled precisely because it focuses on the wrong thing.

Re: Flush times for hackers in booming cyber security job market

#45
post #41

Always cracks me up thinking about how much the press talks about cybersecurity being in demand then looking at the actual IOT and embedded cybersecurity market. Everyone should be very, very scared about infrastructure/medical security and the effective lack of anyone doing anything about it. I'm sure web/network pentesting is doing well though.

https://www.youtube.com/watch?v=pd91c5ZwSf0

Excellent talk from last year's HOPE about the vulnerability of medical devices - he even connects to some live

Re: Flush times for hackers in booming cyber security job market

#46

I am totally into this field as a bystander. When many people would watch late night TV or listen to music or a podcast, I'll scour YouTube for defcon and CCC talks I haven't seen yet. I am good with python, Javascript, web and graphic design, technical writing, all kinds of stuff. I live in rural neighbor-island Hawaii and the only tech jobs I ever see out here are military, which I deeply respect but don't think wo…

1) Schneier's advice from a few years ago is still accurate: https://www.schneier.com/blog/archives/2012/07/how_to_become... 2) The Reddit NetSec FAQ has a good list of resources for beginners (and those starting to specialize): https://www.reddit.com/r/netsec/wiki/start 3) Finally, each of these popular "Getting Started in Security" guides has a slightly different, but useful, opinion on the specifics of the path to…

Correct URL for Reddit NetSec FAQ: https://www.reddit.com/r/netsec/wiki/start

Re: Flush times for hackers in booming cyber security job market

#47
post #46

Earlier quoted context omitted.

1) Schneier's advice from a few years ago is still accurate: https://www.schneier.com/blog/archives/2012/07/how_to_become... 2) The Reddit NetSec FAQ has a good list of resources for beginners (and those starting to specialize): https://www.reddit.com/r/netsec/wiki/start 3) Finally, each of these popular "Getting Started in Security" guides has a slightly different, but useful, opinion on the specifics of the path to…

Correct URL for Reddit NetSec FAQ: https://www.reddit.com/r/netsec/wiki/start

Thanks for the correction - fixed the typo!

Re: Flush times for hackers in booming cyber security job market

#48
post #23
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

it's like everything in a big company. every round of red team on my team's applications we just sit and laugh as they find nothing, yet we serve data to billions of customers every hour, from a myriad of complex entry points. nobody cares, and when I mention that on my self reviews it looks like I am padding it. then the other teams only handle requests from the ios app they own, and red team finds tons of amateur a…

That's sad to hear. Possibly you could demonstrate "We defend against XXX attacks, compare that to the iOS app which defends against XX"

Re: Flush times for hackers in booming cyber security job market

#49
post #30

Earlier quoted context omitted.

Didn't we all. (Similar story:) )

Don't regret the good times for one second, but do get very jealous of people on HN talking about all the exciting tech they're using and awesome work environment. I am actively taking steps to move to a better company, but my god I'm finding Cracking The Interview Code a slog.

Same here...and then add on that I'm actually over 40...and oh boy, does that code get tougher to track. Funny how in some circles deep and long experience in tech is respected...but companies often look at me and ask "What will you do for me lately?"...and look at my age, and likely assume that I'm slowing down; when just the opposite is happening, i'm speeding up in terms of complexity of tech i'm diving into. Weird; but i feel your pain!

Re: Flush times for hackers in booming cyber security job market

#50
post #33
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

My experience is inconsistent with yours. In my 12 years of experience in the security industry, I have found that the blue teams (engineers who develop, maintain and secure network, data and applications) have higher demand and higher salaries than the red teams or pen-testing teams. My experience is limited to security software development in e-banking, e-commerce, network security and data security domains in tech…

Thanks for sharing this. You mention banking - protecting money seems like a much higher incentive for blue team than say, the security of a forum or online game server.
Post reply on HN