Live data from Hacker News

Ask HN: Starting a career in security at 40?

news.ycombinator.com

11–20 of 114 posts

Re: Ask HN: Starting a career in security at 40?

#11

You don't give enough information, "security" is meaningless as a solo term. You need to go into specifics at to what exactly you see yourself doing. If we are talking threat intelligence/analytics then I would say that you're taking on a huge gambit that will most probably not pay off. These jobs will be amongst the first that will go away / automated and do not require deep skills. Certifications are a complete was…

He did say what he was interested in:

    I have always had an interest in security, especially the red/blue team side of things as well as the forensics area.
You should try replying to the actual post, not the one you constructed in your head.

Re: Ask HN: Starting a career in security at 40?

#12
It's a great time to be in security, definitely a job seeker's market. I've been in security for ~8 years now and don't have any certs and don't see a whole lot of value in them unless your employer/clients require them (some consultant or government shops do). I place a much higher value on knowing your stuff and being able to earn the respect of other engineering teams when helping them understand more secure ways to build what they're trying to build.

Some of the best security engineers I've known came from a network engineer or sysadmin background. So don't worry if you don't have a "masters in security". I'd spend some time thinking about the last large system you built. How would someone attack it? How would you detect those attacks? What would you do if they were successful? How could you have architected around those weaknesses? If doing that seems like fun, my team is hiring in Seattle, feel free to drop us a message at prodsec-recruiting@tableau.com

Re: Ask HN: Starting a career in security at 40?

#13
You're not likely to have much luck jumping straight into the R/B team pentesting or forensics world without either some practical experience or certification. With a firm tech background I can imagine you can re-train into a slightly lower position on the security totem pole pretty easily though. Certs can be a mixed bag - pretty much everyone knows they don't actually mean a whole hell of a lot other than a basic grasp of the concepts, but some places will still use them as HR filters. SANS exams can be helpful and are not particularly difficult, but as you said, are very expensive. I'm not really sure about current pay rates for sysadmin type work are, but I wouldn't expect that significant of a pay cut, if you encounter one at all.

Security as a field in general is definitely hiring, though. You'll almost certainly be able to get a job pretty much anywhere in a large variety of companies. For example, here in the Midwest there's a lot of health providers, insurance companies, and banks that have plenty of positions available at locally competitive rates (though bear in mind this exists outside the SV wage bubble) and they generally do not have any qualms about hiring older folks.

Re: Ask HN: Starting a career in security at 40?

#14

It's a great time to be in security, definitely a job seeker's market. I've been in security for ~8 years now and don't have any certs and don't see a whole lot of value in them unless your employer/clients require them (some consultant or government shops do). I place a much higher value on knowing your stuff and being able to earn the respect of other engineering teams when helping them understand more secure ways…

Senior network engineer for an ISP here, when you have a network that spans a number of states and provinces, it inevitably develops a huge attack surface. Designing security features into the network is part of modern network architecture, the two are inseparable these days. There's obvious concerns about endpoint security (individual servers, VMs, etc) and then different considerations for network security of routing/switching/WDM/millimeter wave equipment at POPs.

A lot of equipment used by ISPs is barely protected at all, from what I've seen of other peoples' networks. There's a lot of things out there like temperature monitoring devices, UPSes, rectifiers, HVAC controls, security card readers/relay controls, generator monitoring control systems that run ancient shitty software, which the vendor will never patch. People spend a lot of time isolating these things in special management networks because the cost of replacing a big rectifier system at an older POP cannot be justified.

I would say that for somebody that wants to get into a dedicated security role, without having specifically studied netsec stuff in detail, the best background to have is a mixed balance of first/second-tier NOC, network engineering, and general Linux/BSD sysadmin knowledge.

Re: Ask HN: Starting a career in security at 40?

#15

First of all: what in particular do you find interesting of the security field? Are you more interesting in the offensive or defensive side? I guess that given your background, the smoothest transition will be to something like application security engineer/devops security. There is a trend where companies are hiring developers who also know security, to be part of the dev team. So any bug that has an impact in secur…

Appreciate the reply!

With regards to what do I find interesting, honestly I would put offensive at the top of the list but I do have interests in the defensive side as well as the malware analysis. I am, what I believe, a "problem solver" by nature so I enjoy the idea of being given some unknowns and being told to go figure it out.

Re: Ask HN: Starting a career in security at 40?

#16
I was 36 when I got into security and have never looked back. The fastest, most lucrative route to security is through a role at a vendor. Start to get involved with security at your current job. Get to know the security team. Work on a project with them. Get to know the sales person from an up and coming vendor. Ask him/her abut an SE role. You can easily clear six figures.

Re: Ask HN: Starting a career in security at 40?

#17

It's a great time to be in security, definitely a job seeker's market. I've been in security for ~8 years now and don't have any certs and don't see a whole lot of value in them unless your employer/clients require them (some consultant or government shops do). I place a much higher value on knowing your stuff and being able to earn the respect of other engineering teams when helping them understand more secure ways…

Senior network engineer for an ISP here, when you have a network that spans a number of states and provinces, it inevitably develops a huge attack surface. Designing security features into the network is part of modern network architecture, the two are inseparable these days. There's obvious concerns about endpoint security (individual servers, VMs, etc) and then different considerations for network security of routi…

[deleted]

Re: Ask HN: Starting a career in security at 40?

#18
My career arch is much like yours but at the same time I grew up wearing a greyhat much like how my beard is becoming: black then with time white was added. Most employers value security and actively encourage any efforts in increasing their security posture. Are there not efforts in your current career to "scratch the itch" so to speak? I would agree with many that certs are worthless unless you intend to work as a third party auditor but being able to "talk the talk and walk the walk" matters more.

Re: Ask HN: Starting a career in security at 40?

#19

First of all: what in particular do you find interesting of the security field? Are you more interesting in the offensive or defensive side? I guess that given your background, the smoothest transition will be to something like application security engineer/devops security. There is a trend where companies are hiring developers who also know security, to be part of the dev team. So any bug that has an impact in secur…

Appreciate the reply! With regards to what do I find interesting, honestly I would put offensive at the top of the list but I do have interests in the defensive side as well as the malware analysis. I am, what I believe, a "problem solver" by nature so I enjoy the idea of being given some unknowns and being told to go figure it out.

Of course, you're welcome. I forgot to address the salary question. Six figure jobs are common in this industry, but experience is required to get those jobs. I don't personally know of anyone that did the change at your age, but a good thing is that (unless you want to go enterprise or government) the industry is not to demanding on formalities, a lot of people don't even have degrees. It's a field where it's easy to detect if someone really knows what he/she's talking about. And if someone is useful and helpful, nobody will really care your experience, academic history, etc.

If you're interested in stuff like malware analysis, then you could start doing it as a hobby and maintain a good blog where you explain all your analysis as you learn.

Re: Ask HN: Starting a career in security at 40?

#20

Security has a large number of unfilled positions currently: https://cybersecurityventures.com/jobs/ https://www.forbes.com/sites/jeffkauflin/2017/03/16/the-fast... https://www.ziprecruiter.com/blog/cybersecurity-jobs-are-sky... and security jobs tend to be slightly higher paying than other IT positions. With some certifications and a few years of experience you have a good chance to be making a comparable salary to…

You can almost double your total comp overnight going from a devops/infra role to an infosec role. If you're in ops, get out of ops and go into security. More money, no on call rotation, better career trajectory.
Post reply on HN