Live data from Hacker News

Thinking of a Cybersecurity Career?

krebsonsecurity.com

41–50 of 129 posts

Re: Thinking of a Cybersecurity Career?

#41
post #19
post #13

Earlier quoted context omitted.

I used to do interviews for pentesters at an old job, and I was suprised as well. I think it's because CyberSecurity is relatively new, so companies have no idea how to hire for it, and end up hiring whoever can talk the best. I interviewed a lot of people with titles like "Senior Cybersecurity Engineer" who had no security knowledge beyond how to run an automated scan against an IP range, and put the findings it pri…

That's also the kind of report that management would like to hear instead of the real report, which should say things like "every single person on teams X-Z should use a password manager and 2-FA for everything they access both in business and in private". Security is a bother at best, and disruptive at worst. It's a tough sell, and it's so much easier to point at some badly configured network devices.

> Security is a bother at best, and disruptive at worst.

Yep, the devs where I work actually went to my manager and said that me reporting security findings that need to be remediated is messing up their timeline, so they wanted all testing to be put on hold until the app was already in production. Luckily my manager pushed back and said that if they don't want their timeline messed up by constantly having to remediate findings, they should stop including basic vulnerabilities in their code.

Re: Thinking of a Cybersecurity Career?

#42

Earlier quoted context omitted.

I know, but most of these "hacks" are identified by internal scans already. The pentest doesn't add much value then. The issue is more internal resistance to change in the management team. Like I said I know most companies already fail at the basics. But these are normally well known already, just not fixed due to political pressure. Having the security team's management be better at influencing would pre-empt these…

> I know, but most of these "hacks" are identified by internal scans already. The pentest doesn't add much value then. The issue is more internal resistance to change in the management team. This sounds like management's fault for using a service they don't need yet. If there are glaring, obvious vulns that are repeatedly pointed out but aren't getting fixed then how useful is it to point out additional more subtle v…

Well, the issue is that these vulnerabilities can't be hit to great effect, because they're usually well understood and mitigated by other means (see the admins being very conscious of email malware). In many cases the pentesters cheat by asking for special permissions or for someone to click something they wouldn't normally have done. Just so they can be seen to 'have found something'.

I think a targeted adversary is more worrying because they usually are driven by high gains, which means something that's a big risk to the company. Like strategic information that can cripple the company. Whereas a more moderate adversary will usually trigger a ransomware campaign on some low-secured laptops or something which can be mitigated in a day or 2 by restoring backups. Big interruption yes. Company-killer no.

Also an advanced adversary will usually operate unseen altogether and penetrate the highest levels of security. A ransomware attack is much more obvious. I would view them as different things altogether. An advanced adversary might use the same techniques for their initial access but due to the many layers of security this won't be enough to reach the most critical information.

Re: Thinking of a Cybersecurity Career?

#43
post #39

Earlier quoted context omitted.

I know, but most of these "hacks" are identified by internal scans already. The pentest doesn't add much value then. The issue is more internal resistance to change in the management team. Like I said I know most companies already fail at the basics. But these are normally well known already, just not fixed due to political pressure. Having the security team's management be better at influencing would pre-empt these…

So your point is "bad pentests are bad and provide no value". Yes. You are correct.

Which is exactly why I was saying pentesters should be more inventive :) The level of external pentesters I've seen, has not exceeded the "scriptkiddie" level.

Re: Thinking of a Cybersecurity Career?

#44
post #39

Earlier quoted context omitted.

So your point is "bad pentests are bad and provide no value". Yes. You are correct.

Which is exactly why I was saying pentesters should be more inventive :) The level of external pentesters I've seen, has not exceeded the "scriptkiddie" level.

> The level of external pentesters I've seen, has not exceeded the "scriptkiddie" level.

You get what you pay for. I've taken part in security audits that delivered 0days - but they weren't cheap.

Re: Thinking of a Cybersecurity Career?

#45
post #36

Earlier quoted context omitted.

A follow-up: how much do you value OSCP?

Hopefully the answer will be "A LOT more than CEH", but I wanted to test the waters. :P

I do not value CEH or OSCP at all. The candidate will need to demonstrate they can apply that skill against a real world situation. I wont be more likely to interview you by having these on your resume, but it may help a recruiter put it in front of me (though I will never tell them to look for these keywords)

Re: Thinking of a Cybersecurity Career?

#46
post #25

Earlier quoted context omitted.

> Being able to run metasploit and wireshark does not make one a hacker. By doing this, pentesters test for yesterday's hacks, not tomorrow's. Be careful here. This is bordering on elitism. Having someone come into a business and check for "yesterday's hacks" is better than no one doing any checks at all, therefore such skills are still valuable and worthwhile. In learning how networking works; how operating systems…

I know, but most of these "hacks" are identified by internal scans already. The pentest doesn't add much value then. The issue is more internal resistance to change in the management team. Like I said I know most companies already fail at the basics. But these are normally well known already, just not fixed due to political pressure. Having the security team's management be better at influencing would pre-empt these…

> But these are normally well known already, just not fixed due to political pressure.

This is just not true. Plenty of developers don't really know much about these. Juniors are basically glad they done the task or tend to focus on like two risks they know. And from experience, many seniors sorta kinda vaguely heard about these.

The fault is absolutely not just in management. And even management that is at fault is often acting on advice or with validation of developers who don't care about these much.

Many companies don't know how to even run internal scans. Even when they have interest in it.

Re: Thinking of a Cybersecurity Career?

#47

CyberSecurity, the domain that doesn't recruit yet has a shortage. What cybersecurity is to most people is automated security scans. This can be done by interns with a week of training to run the tools. (Interpreting and remediating the findings is another matter). Besides that, security is mainly about authentication. That's done by setting up LDAP, active directory, openid connect and co, and integrating in applica…

This. So much this.

Unless you’re going the vulnerability/malware research, reverse engineering, or something equally specialized don’t paint yourself into a corner and limit your options with over specific signaling.

And realize that the above are tough roles to get paid for. There aren’t many of them, you have to have intense technical skills across many domains to be effective. All things considered you are unlikely to be able to make as much money as a developer (with just a little business savvy) putting in the same amount of effort.

Don’t get me wrong, I’m still an old hacker at heart and infosec has a lot of amazing aspects of it. It is one of the last holdouts of the old community-driven cultures around computing, but know what you’re getting into with open eyes. Recruiters and businesses have been working hard to commoditize it for years, and will continue to. In addition it’s been a “hot” job track for a while now, similar to “devops” a few years ago, so you’ll find a lot of folks in it without a particular interest or understanding beyond the surface level resume fodder.

Re: Thinking of a Cybersecurity Career?

#48
Cybersecurity, as a field, is in desperate need of identifying different roles within it. These roles are notionally understood within the field, but what they are called and what exactly they do hasn't really crystallized quite yet. You still see job postings for "Cyber-security SME" or whatever and the organization has almost no idea what exactly they want out or the person they hire. So they end up with bored, highly skilled, reverse engineers and pentesters running automated scans, or overwhelmed "security guys" who's career was running compliance checklists being asked to build a defensive intelligence platform.

I call this the "Cyber Dash" problem where there's many different kinds of Cyber- but the industry hasn't figured out what those are, what to call them, what they do, and what the requirements are beyond maybe a handful of roles.

Re: Thinking of a Cybersecurity Career?

#49

I'm a senior level security leader and hiring manager. I focus on software security. Ask me anything about what I see, or don't, in candidates.

Can you talk about your interview process? e.g. types of interviews, screens vs. on-sites, distributions, etc. What are the shortcomings that keeps a candidate from an offer in the final steps, e.g. the candidate passes screening interviews, but falls short on an on-site interview. What are the indicators you observe that differentiate a senior candidate? How do you go about evaluating entry-level and junior candidat…

We do a few screens, starting with general security discussion - something like: intro, light tech/coding - just to make sure we aren't completely wasting our time

The main interview centers on software security, and is focused on real world scenarios. We avoid "explain this OWASP top 10 blah blah blah" kind of questions. The goal is to see if you can reach the outcomes we expect, regardless of how you may approach them. I don't care if you can explain SQLi to me, you should be able to approach exploiting it on a live system.

We will:

* Give you a sample system and ask you to threat model it. Maybe you will use STRIDE, maybe you wont, but we hope you will find some threats using structured techniques.

* Ask you about secure systems you have designed, why you made the choices you made, and how you would make them differently today. We want to know if you have a methodology, a structured approach, and experience.

* Expose you to vulnerable code implementations, and running systems. We hope you will discover vulnerabilities.

* Show you examples of our systems, and ask you how you would secure them. We want to understand if you can see, and discuss security architecture.

* Role play developer interaction scenarios. Can you handle soft skills?

* Have you done any of this at scale? Do you understand how to make it work for 10, and 1000 developers? Explain your experience, how would you do it differently?

I can go on, but again the emphasis is evaluating whether or not you can do the tasks we need you to do, with a high degree of quality in whichever way works best for you, while also being able to completely ignore your resume if we want.

It is extremely difficult for us to consider hiring junior candidates, and we frequently encounter candidates with no deep experience. While it is unfair to expect candidates to have spent time at home treating this as a passion project, those are the ones im going to hire because they can deliver the outcomes in an interview. To combat the hiring difficulty, we have arrived at this approach which allows us to send candidates through the machinery quickly, with low bias.

Re: Thinking of a Cybersecurity Career?

#50
post #6

It's important to note that while there are a lot of skills which can be useful, it's fairly rare to find a job which requires them all. For example, if you have a mobile application specialist, they probably don't need to worry about, say, VLAN configuration on a regular basis. It's quite likely that even if they do know it, the lack of use will result in them not showing that knowledge well in an interview situatio…

Totally agree, it's not really possible for a hacker or security specialist to excel at all categories. Some people become an expert in web injection, others in buffer overflows, network attacks or crypto. The field has become way too wide for one person to have expert knowledge in everything.
Post reply on HN