- Do the Matasano security challenges - Talk to tptacek (tqbf on twitter): they almost certainly have pointers and opinions
I am waiting for his seminal thoughts on this actually...really.
31–40 of 114 posts
- Do the Matasano security challenges - Talk to tptacek (tqbf on twitter): they almost certainly have pointers and opinions
I am waiting for his seminal thoughts on this actually...really.
The certification discussion usually raises hackles among security people. I've been in infosec for over 20 years, so take from this what you will. Question is what kind of work you plan to do. If you are contracting, most public sector contracts are awarded on a points scoring system that gives points for certifications. Given the value of a given contract (e.g. say, ~$200k for a year) paying for a $5k-$10k option o…
Earlier quoted context omitted.
Senior network engineer for an ISP here, when you have a network that spans a number of states and provinces, it inevitably develops a huge attack surface. Designing security features into the network is part of modern network architecture, the two are inseparable these days. There's obvious concerns about endpoint security (individual servers, VMs, etc) and then different considerations for network security of routi…
As someone who used to be a senior engineer for an ISP, shout-out to all the STBs with hard coded admin creds :-)
What I would think about if I were you (was so 15 years ago - started as systems engineer in telco, although has been playing around with systems since childhood) is to try and capitalize on knowledge you’ve got - pick entrypoint to secuirty market as ‘security for X’, where X is the type of systems you’ve been administrating. This way, you’ll have a solid base of problem domain experience, and will be able to easily associate new learning material and new work challenges with experience you’ve already got.
Security is a huge domain of knowledge - being able to bite it with digestible chunks is crucial not to turn into another checklist drone or certified skript kiddie.
Don't waste time with certificates. They mean fuck all in the industry. Any job that cares about them is a job you don't want.
Try to get some clarity about what part of security you want to work in. All the subfields are open to you. Do you want to do operations work? Do you want to exercise your software development muscles? Do you want to work offense or defense? My advice might be different depending on the answers to those questions, but no matter what you want to do, you should be fine.
I had a strong reverse engineering background from the software development projects I'd worked on professionally, and had dabbled in security-related things in my free time, so certifications weren't required.
It has been a pay increase rather than a pay cut, but I think that was partly due to moving location. I've had two jobs so far, and no shortage at all of offers when I was looking.
Having significant prior software development experience has been useful. About half of my work so far has been writing tools to assist vulnerability research, and the other half analyzing and discussing security bugs with the developers responsible for making the fix, so having this background has helped in both of these. But it depends what area of security you're aiming for.
I would say go for it, put your resume out there, if you've done anything at all even tangentially related to security in your working life then you have a good chance.
To be honest, I didn't think I had a chance compared to all the elite hackers and researchers who've been doing this sort of thing for years, and was surprised it all worked out.
Go for it! The agism counter-wind is still weak at 40.
I write resumes and consult to job seekers on search strategy topics. I've worked with several clients this year who have transitioned from more traditional IT/admin roles into security - for experienced pros I'd say that IT/admin types are the most common background (as opposed to software dev) for those seeking to enter infosec. The value of certs depends a bit on the cert, and to be honest I don't typically see th…
Earlier quoted context omitted.
As someone who used to be a senior engineer for an ISP, shout-out to all the STBs with hard coded admin creds :-)
Shout-out to everyone who's ever worked for a large to mid-size ISP, that has acquired and eaten/digested a smaller ISP which has already existed for 12, 15 or 20 years... So much weird legacy gear in weird locations, doing weird things. So many SDH circuits and OC-whatever transport systems.