Live data from Hacker News

Ask HN: Starting a career in security at 40?

news.ycombinator.com

81–90 of 114 posts

Re: Ask HN: Starting a career in security at 40?

#81

First of all: what in particular do you find interesting of the security field? Are you more interesting in the offensive or defensive side? I guess that given your background, the smoothest transition will be to something like application security engineer/devops security. There is a trend where companies are hiring developers who also know security, to be part of the dev team. So any bug that has an impact in secur…

Appreciate the reply! With regards to what do I find interesting, honestly I would put offensive at the top of the list but I do have interests in the defensive side as well as the malware analysis. I am, what I believe, a "problem solver" by nature so I enjoy the idea of being given some unknowns and being told to go figure it out.

You should be aware that you just described three very different roles --- "offensive security" (scanner jockey -> netpen -> appsec -> vuln research / red team), defensive security (secops -> seceng -> security management), and malware analysis (malware analysis -> malware analysis -> still more malware analysis).

For you, the most important question might be how much you enjoy coding.

Re: Ask HN: Starting a career in security at 40?

#82
post #80

Earlier quoted context omitted.

I'm just one data point but I'm a hiring security manager and if someone had OCSP it would mean nothing to me.

~Same. I expect in the most charitable case it means about as much to infosec hiring managers as bootcamps do to developer hiring managers.

What are you looking for in that case? I mean, in the absence of previous experience doing the same thing.

The way I look at it, people come into technical security either from operations or development backgrounds, but it's hard to distinguish someone who has the required skills from their years in dev or ops from those who have managed to do their core work so without going into the relevant details; their CVs are going to look pretty much the same.

A hobbyist might have practiced on some CTFs or vulnerable machine challenges, but unless they haven't e.g. won some bug bounties or gotten some CVE disclosures, then that won't be really visible on a job application. If certifications aren't considered relevant by security hiring managers, what is?

Re: Ask HN: Starting a career in security at 40?

#83
post #41
post #35

You'll do fine. Don't waste time with certificates. They mean fuck all in the industry. Any job that cares about them is a job you don't want. Try to get some clarity about what part of security you want to work in. All the subfields are open to you. Do you want to do operations work? Do you want to exercise your software development muscles? Do you want to work offense or defense? My advice might be different depend…

Do you have any resources / direction to give to a software engineer who'd want to learn more about security? As a full stack web engineer I feel like I know nothing about security (just like most people) and I'd love to have more knowledge about it, even maybe work on this. I have a small design and engineering studio, and might be interested in getting into that kind of services, if I discover that I get interested…

Look for a local group such as Security BSides - go to the meetups, get to know other professionals, learn from them, and get involved with their events.

Re: Ask HN: Starting a career in security at 40?

#84
post #80

Earlier quoted context omitted.

~Same. I expect in the most charitable case it means about as much to infosec hiring managers as bootcamps do to developer hiring managers.

What are you looking for in that case? I mean, in the absence of previous experience doing the same thing. The way I look at it, people come into technical security either from operations or development backgrounds, but it's hard to distinguish someone who has the required skills from their years in dev or ops from those who have managed to do their core work so without going into the relevant details; their CVs are…

We hire resume-blind, based on work-sample challenges.

https://latacora.com/careers/

Re: Ask HN: Starting a career in security at 40?

#85

Earlier quoted context omitted.

Appreciate the reply! With regards to what do I find interesting, honestly I would put offensive at the top of the list but I do have interests in the defensive side as well as the malware analysis. I am, what I believe, a "problem solver" by nature so I enjoy the idea of being given some unknowns and being told to go figure it out.

Of course, you're welcome. I forgot to address the salary question. Six figure jobs are common in this industry, but experience is required to get those jobs. I don't personally know of anyone that did the change at your age, but a good thing is that (unless you want to go enterprise or government) the industry is not to demanding on formalities, a lot of people don't even have degrees. It's a field where it's easy t…

I can easily offer an existence proof for "six figure jobs" in security that do not require previous experience in security to obtain. I don't think we're that far out of the mainstream.

(We're not competing with FAANGs for compensation, but that's not what "six figures" means).

Re: Ask HN: Starting a career in security at 40?

#86
post #73

Earlier quoted context omitted.

Certifications are a way to bypass HR filters, and allow you to negotiate higher salaries. I agree that in terms of imparting actual skills and knowledge they are of minimal value. Being mentored by your peers, being involved in the community, and learning by doing are by far the best ways to learn Security. Certificates are relatively easy to earn and have high ROI in terms of salary and negotiating power in my expe…

This is what everyone who voluntarily paid for a certificate tells themselves. As a hiring manager (for ~10 years now) in software security who talks to a lot of other hiring managers, I am pretty confident that the supposed ROI for certification is not there. Also: if you're dealing directly with HR filters when trying to get a job somewhere, you're already playing to lose. A much higher ROI would be gained by learn…

The value of a (good) certification is that Rumsfeld’s Law applies: you don’t know what you don’t know. Even if you never finish the programme you will at least pick up an idea of what you need to learn, the common vocabulary etc.

Re: Ask HN: Starting a career in security at 40?

#87
post #86
post #73

Earlier quoted context omitted.

This is what everyone who voluntarily paid for a certificate tells themselves. As a hiring manager (for ~10 years now) in software security who talks to a lot of other hiring managers, I am pretty confident that the supposed ROI for certification is not there. Also: if you're dealing directly with HR filters when trying to get a job somewhere, you're already playing to lose. A much higher ROI would be gained by learn…

The value of a (good) certification is that Rumsfeld’s Law applies: you don’t know what you don’t know. Even if you never finish the programme you will at least pick up an idea of what you need to learn, the common vocabulary etc.

If you want to pay for a forcing function, that's fine, but be clear with yourself that that's all you're really paying for.

Certainly I would push back hard on the idea that a certification of any sort is something you need to obtain a first job in the field.

Re: Ask HN: Starting a career in security at 40?

#88
I had a hard time getting a job in Java and web development because I had C on Hp nonstop experience. I found it difficult to come to terms with this. I had a decade of experience but I still couldn't get a job in web development. From your post it appears to be more prevalent. Why does this happen in the IT industry? Is it because the tools used are very different?

Re: Ask HN: Starting a career in security at 40?

#89
post #3

Earlier quoted context omitted.

> Having implementation experience (via webdev) in addition to the bug bounty experience was a plus when I was interviewing. Hiring manager here. Assuming you successfully demonstrated these skills during the interview process, the pay cut probably shouldn't have happened.

A minor pay cut can happen for various reasons. There is not enough information to say it should or shouldn't have happened.

Absolutely true, hence the assumptions. It also assumes the OP's prior pay wasn't atypically high e.g. to fill a very specific need such as self driving computer vision refinement.

I wouldn't consider a 10-15% dip a "minor" one, though. That's consistently tens of thousands of dollars in the top ten US metro markets for these roles.

Re: Ask HN: Starting a career in security at 40?

#90
post #80

Earlier quoted context omitted.

~Same. I expect in the most charitable case it means about as much to infosec hiring managers as bootcamps do to developer hiring managers.

What are you looking for in that case? I mean, in the absence of previous experience doing the same thing. The way I look at it, people come into technical security either from operations or development backgrounds, but it's hard to distinguish someone who has the required skills from their years in dev or ops from those who have managed to do their core work so without going into the relevant details; their CVs are…

Things that would count:

You wrote a compiler, kernel, emulator, firmware, or boot loader.

You wrote a small demo, such as 4096-byte or 512-byte. Like this: https://en.wikipedia.org/wiki/Demoscene

You have hand-optimized code via assembly language.

You have debugged software with a JTAG device or a digital logic analyser.

Post reply on HN