Live data from Hacker News

Ask HN: Starting a career in security at 40?

news.ycombinator.com

1–10 of 114 posts

Ask HN: Starting a career in security at 40?

#1
For the security folks out there, what is the market like? How much weight is put on having some of the various certifications out there?

I have always had an interest in security, especially the red/blue team side of things as well as the forensics area. I have spent my entire career in the world of sysadmin/SRE/shitty dev however so nothing on my resume shows "security". The last couple of weeks I have been looking at some of the certification classes and... wow, they can get pretty crazy. The SANS online stuff is like $6k per course!

Being close to 40 and making six figures (not a brag, just using it for background) I am worried that it's too late to make the jump and still be able to provide for my family. It seems like a pretty big risk to drop multiple thousands on certifications only to start at a salary much lower than I currently have. I'm not willing to impact my family by taking a potential 50% pay cut. I realize there are risks with any kind of career change, I just want to make sure I'm not going into this blind.

Does it make sense to go after some of these certifications, even if they are not from SANS? Is the security world hiring and paying well these days? Am I looking for too much and should just except the fact that a major pay cut would be part of the process?

TIA

Re: Ask HN: Starting a career in security at 40?

#2
I made the switch from web development to security a few years ago and initially took a 10-15% pay cut. I didn't get any certs and wouldn't necessarily recommend them. Instead, I joined various bug bounty programs to get practical (and resume-lite) experience.

Having implementation experience (via webdev) in addition to the bug bounty experience was a plus when I was interviewing.

If you're in a tech hub like SF or NYC there is plenty of security work. But, yeah, I would expect some kind of a paycut since you are moving from a (potentially) senior position to an entrylevel position.

Re: Ask HN: Starting a career in security at 40?

#3

I made the switch from web development to security a few years ago and initially took a 10-15% pay cut. I didn't get any certs and wouldn't necessarily recommend them. Instead, I joined various bug bounty programs to get practical (and resume-lite) experience. Having implementation experience (via webdev) in addition to the bug bounty experience was a plus when I was interviewing. If you're in a tech hub like SF or N…

> Having implementation experience (via webdev) in addition to the bug bounty experience was a plus when I was interviewing.

Hiring manager here. Assuming you successfully demonstrated these skills during the interview process, the pay cut probably shouldn't have happened.

Re: Ask HN: Starting a career in security at 40?

#4
I get the sense the biggest obstacle to your career pivot may be the circumstances of a typical 40 year-old. You probably have bills to pay and a lot of responsibilities that consume your non-work time.

The transition to the roles you've mentioned may require a significant period of unpaid, expensive self re-training, and if you want that re-training to end any time soon, you will want to spend a lot of hours on it. Can you handle those two things?

Here's an interesting tale of someone younger than us who took a path into security from zero.[0]

[0] http://blog.mallardlabs.com/zero-to-oscp-in-292-days-or-how-...

Re: Ask HN: Starting a career in security at 40?

#5
You don't give enough information, "security" is meaningless as a solo term. You need to go into specifics at to what exactly you see yourself doing.

If we are talking threat intelligence/analytics then I would say that you're taking on a huge gambit that will most probably not pay off. These jobs will be amongst the first that will go away / automated and do not require deep skills. Certifications are a complete waste of money.

The jobs in security that have a future and pay well are research-related: vulnerability research, reverse-engineering, exploit development, toolset r&d. Certifications are (again) entirely useless. All you gotta do is prove that you have the skills necessary, which take years to acquire and even more years to master.

Personally, I would say don't bother. You are too old and too far behind.

Re: Ask HN: Starting a career in security at 40?

#6
I think anyone that understands how computers and networks work can make a good security engineer. The mindset for breaking things can be taught.

It isn't too late to do something that interests you, it may be painful taking lower pay or having to learn something that isn't directly related to your job.

Try it as a hobby first, attend some security related conferences, like most industries the security folks are kind and happy to share knowledge.

Re: Ask HN: Starting a career in security at 40?

#7
I come from a similar background as you and I've done CISSP from (ISC)2. I always thought it would be useless as I thought that I can't learn new stuff because I am sysadmin/SRE/shitty dev.

What I observed from a sysadmin/SRE perspective vs pure security team is that we speak 2 different languages. We often clashed with them and it brought frustrations on both sides.

The material cover in CISSP is very broad and not deep. I've done it on my own and I saved $6K. The book costs 80$ and it takes 3 to 6 months to complete. The exam is a real bitch though! Be sure to be very prepared.

In the end, it's the best moved that I've done in my career and I can now speak with the Security mafia.

Re: Ask HN: Starting a career in security at 40?

#8
In order of appearance of '?', here are my responses

1. Market is pretty hot and you will be get multiple choices to pick from the available offers 2. Certifications have very little to do with the job (Full Disclosure - I am currently maintaining CISSP, CCSP, GWAPT, GMOB certs ) That being said, sometimes HR/recruiter use these for filtering candidates. You can look at security+ certification to get a feel. 3. It will make sense even if its not from SANS because people who have done SANS know that a) SANS is very expensive b) its an open bool exam 3) Does not involve hands-on. For that matter, if you will go after coveted OSCP, then people will understand that you have hands-on skills.

4. You should get equivalent or more pay because the market is hot. Most of the earlier security professionals came from SysAdmin/Dev background. You have a better understanding of how systems/apps, so it will be easier to break them or identify vulnerabilities.

There are several blogs (e.g. https://tisiphone.net/category/security-education/) available to find a learning path for security, so check them out. Self learning is the biggest skill that you will need.

PS - Started my career in Information Security 9 years back, right after coming out of school

Re: Ask HN: Starting a career in security at 40?

#9
First of all: what in particular do you find interesting of the security field? Are you more interesting in the offensive or defensive side?

I guess that given your background, the smoothest transition will be to something like application security engineer/devops security. There is a trend where companies are hiring developers who also know security, to be part of the dev team. So any bug that has an impact in security will be fixed by this role. Also, the new architectural landscape (cloud everything) is really changing the game, and having expertise in these solutions from a security perspective is a very valuable skill.

I don't know of particular certifications for application security or "DevSecOps" that will help you. I know that for example, in your situation; CISSP is not useful. CISSP jobs are mostly boring.

If you're interested in the offensive side, then the OSCP certification is a good bet; it shows that you understand and are able to execute a simple pentest. It is a well regarded certification and It will mostly make up for your lack of professional experience in the subject.

In conclusion, you're making good money right now; unless you're really bored and unchallenged, I'll start getting into security as a hobbie, and see how can you apply what you learn on your current job. Maybe you can even change roles where you're at. But try to use your current experience and give it a security twist, so you can then build on your experience instead of trying to make up for the lack of it with bogus certifications.

Re: Ask HN: Starting a career in security at 40?

#10
Security has a large number of unfilled positions currently:

https://cybersecurityventures.com/jobs/

https://www.forbes.com/sites/jeffkauflin/2017/03/16/the-fast...

https://www.ziprecruiter.com/blog/cybersecurity-jobs-are-sky...

and security jobs tend to be slightly higher paying than other IT positions. With some certifications and a few years of experience you have a good chance to be making a comparable salary to your current one.

SANS tends to be on the high end of cost for certifications. Look into the following organizations for more options:

ISACA

ISC2

EC-Council

A background in IT and Dev is highly valuable for Security jobs. You will find that many of your current skills are applicable.

Look at job postings in Indeed, LinkedIn, etc. job sites for roles that interest you and look at the certifications and experience they ask for. That will help guide your investigation into what you need to qualify.

(I have been working in the security industry for the past 10 years in various capacities, caveat emptor etc.)

Post reply on HN