Live data from Hacker News

Ask HN: Starting a career in security at 40?

news.ycombinator.com

61–70 of 114 posts

Re: Ask HN: Starting a career in security at 40?

#61
Allow me to disagree with tptacek a little:

The OffSec Penetration Testing with Kali Linux (OSCP certification) is excellent and outstanding and cheap.

https://www.offensive-security.com/information-security-trai...

While the course itself is $800, you'll most assuredly need another 60 days of lab time for the certification. I think all-in-all it cost me $1,500 for everything.

The course material is excellent and wide-ranging and very hands-on. If you have a family, it's a serious investment of time. It put a serious dent into my night time hours for a couple months.

The OCSP certification is widely-respected and not just a "paper certification" like some of the others (c|eh). Lots of practical skills. Great stuff.

Re: Ask HN: Starting a career in security at 40?

#62

I started my career in security at 35, a few years ago. I had a strong reverse engineering background from the software development projects I'd worked on professionally, and had dabbled in security-related things in my free time, so certifications weren't required. It has been a pay increase rather than a pay cut, but I think that was partly due to moving location. I've had two jobs so far, and no shortage at all of…

Hello, can you provide an email address where I can contact you? I am very early in my career but it seems we've had similar paths and I would like to ask you some questions.

Re: Ask HN: Starting a career in security at 40?

#63
post #4

I get the sense the biggest obstacle to your career pivot may be the circumstances of a typical 40 year-old. You probably have bills to pay and a lot of responsibilities that consume your non-work time. The transition to the roles you've mentioned may require a significant period of unpaid, expensive self re-training, and if you want that re-training to end any time soon, you will want to spend a lot of hours on it.…

From the blog: "Know what you're getting yourself into, [OSCP] took me 292 days full-time"

Re: Ask HN: Starting a career in security at 40?

#66
post #61

Allow me to disagree with tptacek a little: The OffSec Penetration Testing with Kali Linux (OSCP certification) is excellent and outstanding and cheap. https://www.offensive-security.com/information-security-trai... While the course itself is $800, you'll most assuredly need another 60 days of lab time for the certification. I think all-in-all it cost me $1,500 for everything. The course material is excellent and wid…

I'm just one data point but I'm a hiring security manager and if someone had OCSP it would mean nothing to me.

Re: Ask HN: Starting a career in security at 40?

#67

First of all: what in particular do you find interesting of the security field? Are you more interesting in the offensive or defensive side? I guess that given your background, the smoothest transition will be to something like application security engineer/devops security. There is a trend where companies are hiring developers who also know security, to be part of the dev team. So any bug that has an impact in secur…

Appreciate the reply! With regards to what do I find interesting, honestly I would put offensive at the top of the list but I do have interests in the defensive side as well as the malware analysis. I am, what I believe, a "problem solver" by nature so I enjoy the idea of being given some unknowns and being told to go figure it out.

With that extra detail, it appears you are seeking the sort of job I posted in the hiring thread:

https://news.ycombinator.com/item?id=18358038

You say that "nothing on my resume shows "security"" and that is fine... look, the job posting doesn't say it either. Certifications don't count for anything. Most of us here don't show up with "security" or certifications on a resume.

That said, the skill you list as "sysadmin/SRE/shitty dev" (for "SRE" being either "software release engineer" or "site reliability engineering") probably isn't going to cut it. Something more low-level is usually needed. You almost need to be good at assembly language.

Re: Ask HN: Starting a career in security at 40?

#68
post #61

Allow me to disagree with tptacek a little: The OffSec Penetration Testing with Kali Linux (OSCP certification) is excellent and outstanding and cheap. https://www.offensive-security.com/information-security-trai... While the course itself is $800, you'll most assuredly need another 60 days of lab time for the certification. I think all-in-all it cost me $1,500 for everything. The course material is excellent and wid…

I'm just one data point but I'm a hiring security manager and if someone had OCSP it would mean nothing to me.

... why nothing to you?

Re: Ask HN: Starting a career in security at 40?

#69
post #61

Allow me to disagree with tptacek a little: The OffSec Penetration Testing with Kali Linux (OSCP certification) is excellent and outstanding and cheap. https://www.offensive-security.com/information-security-trai... While the course itself is $800, you'll most assuredly need another 60 days of lab time for the certification. I think all-in-all it cost me $1,500 for everything. The course material is excellent and wid…

I'm just one data point but I'm a hiring security manager and if someone had OCSP it would mean nothing to me.

You are probably looking for advanced people (or you might just be a shitty recruiter...). As a second data point I can tell that having OSCP can help you significantly in the beginning of your career (and for a reason, most entry-level certs are just complete bs and it's nice to have something to show off when you are lacking actual experience).

Re: Ask HN: Starting a career in security at 40?

#70
post #3

I made the switch from web development to security a few years ago and initially took a 10-15% pay cut. I didn't get any certs and wouldn't necessarily recommend them. Instead, I joined various bug bounty programs to get practical (and resume-lite) experience. Having implementation experience (via webdev) in addition to the bug bounty experience was a plus when I was interviewing. If you're in a tech hub like SF or N…

> Having implementation experience (via webdev) in addition to the bug bounty experience was a plus when I was interviewing. Hiring manager here. Assuming you successfully demonstrated these skills during the interview process, the pay cut probably shouldn't have happened.

A minor pay cut can happen for various reasons. There is not enough information to say it should or shouldn't have happened.
Post reply on HN