Live data from Hacker News

Ask HN: Starting a career in security at 40?

news.ycombinator.com

41–50 of 114 posts

Re: Ask HN: Starting a career in security at 40?

#41
post #35

You'll do fine. Don't waste time with certificates. They mean fuck all in the industry. Any job that cares about them is a job you don't want. Try to get some clarity about what part of security you want to work in. All the subfields are open to you. Do you want to do operations work? Do you want to exercise your software development muscles? Do you want to work offense or defense? My advice might be different depend…

Do you have any resources / direction to give to a software engineer who'd want to learn more about security?

As a full stack web engineer I feel like I know nothing about security (just like most people) and I'd love to have more knowledge about it, even maybe work on this.

I have a small design and engineering studio, and might be interested in getting into that kind of services, if I discover that I get interested in this enough.

Re: Ask HN: Starting a career in security at 40?

#42
post #4

I get the sense the biggest obstacle to your career pivot may be the circumstances of a typical 40 year-old. You probably have bills to pay and a lot of responsibilities that consume your non-work time. The transition to the roles you've mentioned may require a significant period of unpaid, expensive self re-training, and if you want that re-training to end any time soon, you will want to spend a lot of hours on it.…

This was my thought too. As you get older you tend to add more and more responsibilities: children, debts, and these require that you both work and don't work too much, meaning that the time you can truly spend on a new avenue is quite low. That's the true challenge, I think.

Re: Ask HN: Starting a career in security at 40?

#43
post #35

You'll do fine. Don't waste time with certificates. They mean fuck all in the industry. Any job that cares about them is a job you don't want. Try to get some clarity about what part of security you want to work in. All the subfields are open to you. Do you want to do operations work? Do you want to exercise your software development muscles? Do you want to work offense or defense? My advice might be different depend…

Does this still ring true for someone with no experience in the industry?

I figure a certification is an effective "proof of expertise" when there's no employment history to back you up.

Re: Ask HN: Starting a career in security at 40?

#44
post #35

You'll do fine. Don't waste time with certificates. They mean fuck all in the industry. Any job that cares about them is a job you don't want. Try to get some clarity about what part of security you want to work in. All the subfields are open to you. Do you want to do operations work? Do you want to exercise your software development muscles? Do you want to work offense or defense? My advice might be different depend…

Does this still ring true for someone with no experience in the industry? I figure a certification is an effective "proof of expertise" when there's no employment history to back you up.

I think what he means with certifications is that they'll get you the jobs you don't really want.

For example, CEH (Certified Ethical Hacker) is a certification you'll see in a lot of job postings. The thing is, if you know this field, you know that this certification is worthless; it's just an expensive piece of paper. So, if you get a job that requires you to be CEH, it's telling a lot about the company itself, you don't want to work there.

Same goes for the other certs, CISSP is OK but it doesn't really prove you can actually do useful work, and the jobs that require them are not the most interesting ones. The other popular one is OSCP, which I think is quite OK. It shows a minimal level of competence.

But I tend to agree with the feeling that certification in this field do more harm than good. What we need is more professionalism and good engineering.

EDIT: To clarify my point on OSCP, it is good in the sense that they force you to do hands on work. But, it is very narrow and most of what you learn are "tricks". An OSCP holder is proven to know what a pentest it, how to go about with it, and has a lot of sometimes useful tricks under his belt. It will not tell you whether someone really knows how applications and systems works.

Re: Ask HN: Starting a career in security at 40?

#45

Security has a large number of unfilled positions currently: https://cybersecurityventures.com/jobs/ https://www.forbes.com/sites/jeffkauflin/2017/03/16/the-fast... https://www.ziprecruiter.com/blog/cybersecurity-jobs-are-sky... and security jobs tend to be slightly higher paying than other IT positions. With some certifications and a few years of experience you have a good chance to be making a comparable salary to…

You can almost double your total comp overnight going from a devops/infra role to an infosec role. If you're in ops, get out of ops and go into security. More money, no on call rotation, better career trajectory.

Potentially, if you find that magic role and are qualified. I am too cautious to say you could 2x from a 6 figure salary without putting in a few years getting experience and proving yourself first. Not saying it isn't possible, but overnight is probably an exaggeration. If you're willing to travel and do consulting it's realistic, but it sounds like OP may not be willing to go that route.

Re: Ask HN: Starting a career in security at 40?

#47
post #35

You'll do fine. Don't waste time with certificates. They mean fuck all in the industry. Any job that cares about them is a job you don't want. Try to get some clarity about what part of security you want to work in. All the subfields are open to you. Do you want to do operations work? Do you want to exercise your software development muscles? Do you want to work offense or defense? My advice might be different depend…

Certifications are a way to bypass HR filters, and allow you to negotiate higher salaries. I agree that in terms of imparting actual skills and knowledge they are of minimal value. Being mentored by your peers, being involved in the community, and learning by doing are by far the best ways to learn Security. Certificates are relatively easy to earn and have high ROI in terms of salary and negotiating power in my experience.

Re: Ask HN: Starting a career in security at 40?

#48

Earlier quoted context omitted.

Does this still ring true for someone with no experience in the industry? I figure a certification is an effective "proof of expertise" when there's no employment history to back you up.

I think what he means with certifications is that they'll get you the jobs you don't really want. For example, CEH (Certified Ethical Hacker) is a certification you'll see in a lot of job postings. The thing is, if you know this field, you know that this certification is worthless; it's just an expensive piece of paper. So, if you get a job that requires you to be CEH, it's telling a lot about the company itself, you…

Agree on the other certs -- but have you actually looked at the requirements for OSCP?

I think it's a bit more in depth than you believe.

Re: Ask HN: Starting a career in security at 40?

#50
CERT First -> Get Security+ cert (Foundational cert, HR Filter, DoD Approved DoDD 8570)- buy some cheap used books off ebay,cert cost ~$300 Network -> Join local user InfoSec groups, follow netsec on Reddit, create a L/I profile - join security groups, RSS feeds - Krebs, Hacker News Continuing Ed -> Community college - 2 year AA degree in Computer Science/Infosec (WGU Online).
Post reply on HN