Earlier quoted context omitted.
I used to work for a pentest company and everytime we engage with a customer, we discover a lot of problems and security issues which we document and submit to the customer. We discover after a while that another company gets a contract 10x our price fixing the issues we discovered
Sounds like a missed opportunity to at least get a referral fee for resolution.
Flush times for hackers in booming cyber security job market
51–60 of 76 posts
Re: Flush times for hackers in booming cyber security job market
#52Re: Flush times for hackers in booming cyber security job market
#53What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…
My experience is inconsistent with yours. In my 12 years of experience in the security industry, I have found that the blue teams (engineers who develop, maintain and secure network, data and applications) have higher demand and higher salaries than the red teams or pen-testing teams. My experience is limited to security software development in e-banking, e-commerce, network security and data security domains in tech…
We had the Red team come in and while pentesting share his screen with us all. Another Red team member explained what he was doing and after an attack was launched and we would see if our tools detected the activity. If they didn't, we went out to find out why. This was huge. It showed us where we needed to tune some things and where we needed newer and/or different tools.
This isn't the only way we get pen tested. They do their annual "regular" pentest. The Purple team thing was awesome though. We learned a ton. Since I happen to own most of our tools and am secondary on the ones I don't own, I have learned a tremendous amount and I've been in IT for 20 years.
Re: Flush times for hackers in booming cyber security job market
#54Earlier quoted context omitted.
My experience is inconsistent with yours. In my 12 years of experience in the security industry, I have found that the blue teams (engineers who develop, maintain and secure network, data and applications) have higher demand and higher salaries than the red teams or pen-testing teams. My experience is limited to security software development in e-banking, e-commerce, network security and data security domains in tech…
Thanks for sharing this. You mention banking - protecting money seems like a much higher incentive for blue team than say, the security of a forum or online game server.
I think there needs to be greater punishment for companies that lose customer information. Only then will the incentives be large enough for something to be done.
Re: Flush times for hackers in booming cyber security job market
#55What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…
> results in internal tickets/issues/BUGs, while the development/operation practices are kept the same.
You could not be more accurate; this also applies to groups that maybe started out as corporate infosec (virus protection, simple application scanning, etc...) and were never really tightly coupled with engineering. We have identified essentially identical authorization issues in a pre-release version of one of our products two or three times this year, which was also present in the last 3rd party pentest of the same product before my time (which was pretty scathing). Its incredible.
Re: Flush times for hackers in booming cyber security job market
#56Re: Flush times for hackers in booming cyber security job market
#57Earlier quoted context omitted.
Thanks for sharing this. You mention banking - protecting money seems like a much higher incentive for blue team than say, the security of a forum or online game server.
Unfortunately not at the FIs I have worked for. Their approach seems to be "give the illusion of security while covering any actual losses with insurance". I think there needs to be greater punishment for companies that lose customer information. Only then will the incentives be large enough for something to be done.
Re: Flush times for hackers in booming cyber security job market
#58Earlier quoted context omitted.
Sounds like a missed opportunity to at least get a referral fee for resolution.
Conflict of interest.
If they make up a bunch of minor things that don't matter, you can ignore those and focus on the important ones. I suppose if you don't have any in-house expertise at all to evaluate what they say, the conflict would be more important?
Re: Flush times for hackers in booming cyber security job market
#59What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…
I used to work for a pentest company and everytime we engage with a customer, we discover a lot of problems and security issues which we document and submit to the customer. We discover after a while that another company gets a contract 10x our price fixing the issues we discovered
Re: Flush times for hackers in booming cyber security job market
#60What are some realistic salary ranges for people in this field? And is it largely on site work, or is it more common as a remote consultant?
Junior: $120k base. $10-15k annual bonus.
Mid: $150k base. $20-30k annual bonus.
Senior: $180k base. $30k annual bonus.
Slightly skewed towards consulting; notch it up a bit to account for stock grants in addition to the bonus if you're thinking of something like Google, Facebook or Amazon. Sometimes the consulting firm pays separate bonuses for research time and bench projects that result in something useful or beneficial for the firm's brand.
That's based on my own experience and talking with probably well over a hundred people in the industry about their salary by now.
You can do remote, I've been remote almost my entire career thus far. Remote is more likely in consulting than it is at one of the reputable internal security teams, but it's not uncommon at smaller tech companies.