Live data from Hacker News

Flush times for hackers in booming cyber security job market

reuters.com

61–70 of 76 posts

Re: Flush times for hackers in booming cyber security job market

#61

Earlier quoted context omitted.

Conflict of interest.

Assuming the company is voluntarily hiring them, and not being required by a contract or law that needs an independent 3rd party for auditing purposes, it seems like the pentesting company would do an even better job on the inspection if they had a good chance of getting repair work down the line for every issue they found. If they make up a bunch of minor things that don't matter, you can ignore those and focus on t…

It's simply bad practice to have the people that are involved in the 'checking' making money or being involved in the 'fixing' in any way shape or form.

You'll see this in almost every situation that is somehow related to auditing.

Re: Flush times for hackers in booming cyber security job market

#62
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

This will change with time. I have thought, studied, talked, and written extensively on this general theme. What comes to mind to frame it for you is my "four principles:" [a]

1. Compromise is inevitable 2. Default-allow products always fail 3. 1 and 2 are not opinion or marketing spin, just simple truths 4. As an industry, we are still learning 1 and 2

Security is slowly shifting from an administrative IT function to an operational function. In IT, the business value comes from the products and people are a tax required to administer the products. In security operations, the business value comes from the people, products are just tools in their toolbag. [c]

Keep walking this dog and you realize basic IT activities for core infrastructure are critical for security, to the point the CIO will report to the CISO -- unless the CIO steps up. [b]

So - in short - your frustrations are accurate, but the winds are shifting. Companies will incresingly value top people for their internal staff/blue teams. It's going to take a few more years, but I believe it is inevitable.

[a] - https://www.linkedin.com/pulse/my-four-cybersecurity-princip... [b] - https://www.linkedin.com/pulse/cio-report-ciso-j-j-guy [c] - https://www.linkedin.com/pulse/cio-report-ciso-why-j-j-guy

Re: Flush times for hackers in booming cyber security job market

#63
post #5

How can I get into this field? I used to love doing pen-testing when I was a teenager, and paid for my first car out of bug-bounties. Unfortunately, I got distracted by girls and booze at university and didn't keep it up, now I work in sigh enterprise C#/WPF land.

You don't need a college degree to do pentesting. I don't think anyone credible in the industry cares where you got your education, as long as you know what you're doing (or in the case of juniors, are able to learn).

Re: Flush times for hackers in booming cyber security job market

#64

What are some realistic salary ranges for people in this field? And is it largely on site work, or is it more common as a remote consultant?

Central Texas 5 yrs experience, 95k when bonuses and 401k match are thrown in.

Re: Flush times for hackers in booming cyber security job market

#65
post #18
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

It's because internal econometrics are resulting in perverse incentives. Defensive security is a cost center without clear, deterministic metrics for success. Let's say you pay X on defensive security (which is an oversimplification when you're talking about a cultural change, but that cultural change involves people learning how to pay attention to security, and paying attention is a form of man-hours, for which a c…

Isn't a result of pentest a direct measure of defensive security as well?

Re: Flush times for hackers in booming cyber security job market

#66
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

I'm hiring for blue team at Akamai. We've picked up some fantastic early-career people into our training program; also looking for mid-career architects, senior architects.

https://akamaijobs.referrals.selectminds.com/jobs/senior-lea...

https://akamaijobs.referrals.selectminds.com/jobs/security-a...

https://akamaijobs.referrals.selectminds.com/jobs/manager-in...

Re: Flush times for hackers in booming cyber security job market

#67
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

This. Not interested in pen testing at all, just want to build things that don't suck from a security perspective. Happy to break things along the way to gain perspective, and I like to know how things work, but I'm a software engineer who likes security. A builder, not a breaker, by nature.

Re: Flush times for hackers in booming cyber security job market

#68
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

Honestly, as someone who is leaving "blue-team" network security work for a "DevOps" production team (I know, I know), it's really a mixed bag. I've done blue-team for 2 companies now and honestly the job is more project management than anything else. I found that I was very rarely actually getting hands-on with technology. When implementing a new piece of security tech, we were simply directing other teams to perform most of the the actual technical work (this was the case at both of my "security engineering" jobs). I didn't get any of the satisfaction of building anything, solving problems etc.

The other big thing to note is that a lot of companies have security teams solely to meet audit requirements. If you find yourself on a team like that, you'll be spending a lot of time just gathering evidence for audits, remediating findings and writing policy. I really loved security intellectually, but in practice, the blue-team side of things wasn't my cup of tea.

Re: Flush times for hackers in booming cyber security job market

#70

Earlier quoted context omitted.

OSCP, red teaming, possibly CISM or CISSP for upward mobility.

I would not waste time and money on certifications.

As someone not in the field, but curious of getting in, could you explain why not?
Post reply on HN