Live data from Hacker News

Ask HN: Starting a career in security at 40?

news.ycombinator.com

91–100 of 114 posts

Re: Ask HN: Starting a career in security at 40?

#91
post #73

Earlier quoted context omitted.

Certifications are a way to bypass HR filters, and allow you to negotiate higher salaries. I agree that in terms of imparting actual skills and knowledge they are of minimal value. Being mentored by your peers, being involved in the community, and learning by doing are by far the best ways to learn Security. Certificates are relatively easy to earn and have high ROI in terms of salary and negotiating power in my expe…

This is what everyone who voluntarily paid for a certificate tells themselves. As a hiring manager (for ~10 years now) in software security who talks to a lot of other hiring managers, I am pretty confident that the supposed ROI for certification is not there. Also: if you're dealing directly with HR filters when trying to get a job somewhere, you're already playing to lose. A much higher ROI would be gained by learn…

Thank you for sharing your experience. I think there is a lot of truth in what you said. It is probably very situation dependent - in my case getting that first cert and paying out of pocket is how I broke in from IT Ops and got my first security consulting gig. The resulting pay bump paid for the cost of the cert in 6 months. For all certs thereafter I've had my employers pay for it as part of a benefits package. Obviously this is only a single data point, but many of my colleagues have similar stories so I feel like it can't be completely unique to me. YMMV.

Re: Ask HN: Starting a career in security at 40?

#92
How does the job market for security work compare to the job market for machine learning? Is the security work more interesting? My reason for asking is that I'm sort of in the same boat. I've got a PhD in Math (not crypto or stats related) and have been doing back end C++ work for a while now. Looking for a move to greener pastures.

Re: Ask HN: Starting a career in security at 40?

#93

Earlier quoted context omitted.

What are you looking for in that case? I mean, in the absence of previous experience doing the same thing. The way I look at it, people come into technical security either from operations or development backgrounds, but it's hard to distinguish someone who has the required skills from their years in dev or ops from those who have managed to do their core work so without going into the relevant details; their CVs are…

Things that would count: You wrote a compiler, kernel, emulator, firmware, or boot loader. You wrote a small demo, such as 4096-byte or 512-byte. Like this: https://en.wikipedia.org/wiki/Demoscene You have hand-optimized code via assembly language. You have debugged software with a JTAG device or a digital logic analyser.

Why would those things count more or less than other things? It seems more like a list of things you think are neat but trying to guess what a resume-reader might think is neat seems like a game with very poor returns.

Re: Ask HN: Starting a career in security at 40?

#94
post #93

Earlier quoted context omitted.

Things that would count: You wrote a compiler, kernel, emulator, firmware, or boot loader. You wrote a small demo, such as 4096-byte or 512-byte. Like this: https://en.wikipedia.org/wiki/Demoscene You have hand-optimized code via assembly language. You have debugged software with a JTAG device or a digital logic analyser.

Why would those things count more or less than other things? It seems more like a list of things you think are neat but trying to guess what a resume-reader might think is neat seems like a game with very poor returns.

Well, those things fit the job I posted: https://news.ycombinator.com/item?id=18358038

The common feature is low-level experience. Somebody should be comfortable with assembly and related things.

It's true that not all security jobs are the same of course, so there will be plenty of places wanting other stuff, but I don't know about those.

Re: Ask HN: Starting a career in security at 40?

#95
There are plenty of unfilled positions in security. Typically, a large SaaS company will have have several security teams: application (Product Security), Infrastructure Security, Network Security, Device security (company laptops, phone, etc.), Red team/penetration testing team, Response team, CIRT (external facing), etc. With your experience, it looks like Infrastructure team might be a good entry. No need for certifications.

Re: Ask HN: Starting a career in security at 40?

#96
post #93

Earlier quoted context omitted.

Why would those things count more or less than other things? It seems more like a list of things you think are neat but trying to guess what a resume-reader might think is neat seems like a game with very poor returns.

Well, those things fit the job I posted: https://news.ycombinator.com/item?id=18358038 The common feature is low-level experience. Somebody should be comfortable with assembly and related things. It's true that not all security jobs are the same of course, so there will be plenty of places wanting other stuff, but I don't know about those.

Ah that makes sense but then those things would be useful when applying for your specific job rather than things that would be useful when looking to make a specialization switch and are wondering whether certifications are useful.

Re: Ask HN: Starting a career in security at 40?

#97

I come from a similar background as you and I've done CISSP from (ISC)2. I always thought it would be useless as I thought that I can't learn new stuff because I am sysadmin/SRE/shitty dev. What I observed from a sysadmin/SRE perspective vs pure security team is that we speak 2 different languages. We often clashed with them and it brought frustrations on both sides. The material cover in CISSP is very broad and not…

Which book did you get?

Re: Ask HN: Starting a career in security at 40?

#98

Earlier quoted context omitted.

Shout-out to everyone who's ever worked for a large to mid-size ISP, that has acquired and eaten/digested a smaller ISP which has already existed for 12, 15 or 20 years... So much weird legacy gear in weird locations, doing weird things. So many SDH circuits and OC-whatever transport systems.

HAHA Are you me? This is sounds creepily familiar..

Seems to be an endemic problem, maybe if zayo buys everyone else noone will experience it again.

Re: Ask HN: Starting a career in security at 40?

#99
post #35

You'll do fine. Don't waste time with certificates. They mean fuck all in the industry. Any job that cares about them is a job you don't want. Try to get some clarity about what part of security you want to work in. All the subfields are open to you. Do you want to do operations work? Do you want to exercise your software development muscles? Do you want to work offense or defense? My advice might be different depend…

I generally agree with you on your points, but I'll share an anecdote.

I once had a friend ask me about getting a certificate in an unrelated field from one of those ultra for-profit schools they advertise during the day on TV. I told her it was basically worthless and that places that cared about that cert and those schools probably weren't worth working at.

Long story short, she went ahead and got the cert from the money mill, got a job at a place that cared about it, and despite my personal distaste for it all, she ended up loving the job and is very happy there a decade later. So...YMMV.

So I think it's hard to categorically say the OP will hate those places when in fact they might find them perfectly suitable. Some people just really like the kind of work those places do and are perfectly happy having a handful of 3-5 letter certification acronyms after their name on their business card.

As the question of whether they're worth the paper they're printed on and if those companies that care about those things are worth the air that comes out of their central heating, I have to say I personally agree with you. They probably aren't helping humanity or the security field any and I keep far far away myself.

But to your other point, the security field is tremendously huge and honestly a lot of it is paperwork pushing certification, compliance and accreditation stuff.

Re: Ask HN: Starting a career in security at 40?

#100
post #74
post #48

Earlier quoted context omitted.

Agree on the other certs -- but have you actually looked at the requirements for OSCP? I think it's a bit more in depth than you believe.

OSCP covers a significant part of my actual subfield in security, and I think it's pretty silly.

Well that's no good, I'd been told by others in the field it was a good cert. Guess I won't waste my time with it.
Post reply on HN