Live data from Hacker News

Thinking of a Cybersecurity Career?

krebsonsecurity.com

11–20 of 129 posts

Re: Thinking of a Cybersecurity Career?

#13

That's surprising to someone not in CyberSec that so few can do basic tasks of their job. I wonder how they declare the bar for basic or not.

I used to do interviews for pentesters at an old job, and I was suprised as well. I think it's because CyberSecurity is relatively new, so companies have no idea how to hire for it, and end up hiring whoever can talk the best. I interviewed a lot of people with titles like "Senior Cybersecurity Engineer" who had no security knowledge beyond how to run an automated scan against an IP range, and put the findings it printed out into a report for management.

Re: Thinking of a Cybersecurity Career?

#14
post #9

Krebs does not work in Cybersecurity, does not come from a position of knowledge or experience in Cybersecurity and his only skill relating to Cybersecurity is doxxing people. I could understand if this was "Thinking of a Cybersecurity journalism career" but there are better people to learn from.

Perhaps instead of going after the author you could go after his ideas? It seems like quite a well written essay imo

Re: Thinking of a Cybersecurity Career?

#15
I feel like it's hard to teach cybersecurity formally. It deals with hacking and by nature the spirit of hacking is hard to teach. I have learnt cybersecurity as a hobby and have competed with our university team in some online well known attack/defense style competitions (we sucked) and a lot of this stuff is really hard to formalize. I guess you could teach the basics like overflows, aslr, stack canaries, basic assembly, but in the end it's up to the hacker to string everything together to overflow a buffer, control the return pointer, leak the canary, string together a rop chain and pwn the system, and this takes a lot of tinkering and discovery rather than prior knowledge, although experience definitely helps. I guess it's also why some random high school teenager could be going up against the hacking team from Tencent in these competitions. And this is only for binary exploitation mind you. If you look at some of the crazy talks from defcon, the stuff they do draws upon a lot of random knowledge, and it comes down more to the act of piecing everything together than knowing anything before hand, hence the "hacking". And that's also why I love it :)

Re: Thinking of a Cybersecurity Career?

#16
As someone undertaking a Master's in Cybersecurity, that table is totally true.

Most of my courses have a programming alternative for assignments yet the students alongside me have very little interest.

I've been doing this a while so maybe I'm just an outlier as I've always been the guy who is the jack of all trades, but I can't help but see something unknown as something to learn.

Re: Thinking of a Cybersecurity Career?

#17
post #6

It's important to note that while there are a lot of skills which can be useful, it's fairly rare to find a job which requires them all. For example, if you have a mobile application specialist, they probably don't need to worry about, say, VLAN configuration on a regular basis. It's quite likely that even if they do know it, the lack of use will result in them not showing that knowledge well in an interview situatio…

>I think the cyber security industry is at the stage where the web was 15-20 years ago, where a company would hire a "webmaster" who did all the web related stuff, rather than getting a combination of people in different roles each specialising in one area

This is an interesting view. You really think so? The use case of the "web" /website industry is so much wider. I feel like cybersecurity companies are struggling a lot more to come up with an actual product and continues to be more of a consultancy type business. I know in China a lot of the smaller cybersecurity startups have eventually been folded into either alibaba or tencent cause it's so hard to come up with a product that people want to buy.

Re: Thinking of a Cybersecurity Career?

#18
As with most positions, the largest obstacle to getting a job in security is overcoming the HR Gatekeepers. The hiring system is broken. Those who successfully attained job are those who generally have networked their way around the first line HR personnel. Get your name out there so that hiring managers know who you are. Blog, go to meet-ups, make friends, do capture-the-flags, create a website, create a Git repo, and a home lab that you write about.

Re: Thinking of a Cybersecurity Career?

#19
post #13

That's surprising to someone not in CyberSec that so few can do basic tasks of their job. I wonder how they declare the bar for basic or not.

I used to do interviews for pentesters at an old job, and I was suprised as well. I think it's because CyberSecurity is relatively new, so companies have no idea how to hire for it, and end up hiring whoever can talk the best. I interviewed a lot of people with titles like "Senior Cybersecurity Engineer" who had no security knowledge beyond how to run an automated scan against an IP range, and put the findings it pri…

That's also the kind of report that management would like to hear instead of the real report, which should say things like "every single person on teams X-Z should use a password manager and 2-FA for everything they access both in business and in private".

Security is a bother at best, and disruptive at worst. It's a tough sell, and it's so much easier to point at some badly configured network devices.

Re: Thinking of a Cybersecurity Career?

#20

Very interesting article, but at the same time it depicts a very sad truth... [Disclaimer: also not a certified security professional, but I do follow the topic and practice it hands-on from time-to-time...] However I think there are multiple (sometimes non-overlapping) types of cyber-security professionals / roles: * the policy maker / enforcer -- which is what some companies want, and what the most well known peopl…

You might be grouping this in "policy", but I'd break out "compliance".

Getting a company certified under PCI, HIPAA, and friends is a specific and important role in cybersecurity that doesn't require advanced hands on technical knowledge.

Post reply on HN