Live data from Hacker News

Thinking of a Cybersecurity Career?

krebsonsecurity.com

61–70 of 129 posts

Re: Thinking of a Cybersecurity Career?

#61
post #60

Earlier quoted context omitted.

I do not value CEH or OSCP at all. The candidate will need to demonstrate they can apply that skill against a real world situation. I wont be more likely to interview you by having these on your resume, but it may help a recruiter put it in front of me (though I will never tell them to look for these keywords)

> See my earlier comment regarding the relative strength of candidates with OSCP. Have you been through the course and exam yourself, or are you basing this on something else? If you've been through the experience, which parts of it contribute to you not valuing it?

I have not, and have no plan to take OSCP - though im familiar with it.

I'm relating the facts about candidates who applied to my roles with OSCP certifications. I did not hire any of them.

I do not specifically dislike OSCP, its that I do not value any of the certs merely because someone possesses them.

Certs are a marginal signal to me about your potential for discipline, may inform how deep I go on questioning, and thats it. Conversely, certs may lead to bias, particularly for some very lame ones.

I don't think it's very fair to weight letters on a resume so heavily, it's about what you can do in the role I have for you.

Having them is not something that will make a big difference to me.

Re: Thinking of a Cybersecurity Career?

#62

Earlier quoted context omitted.

Can you talk about your interview process? e.g. types of interviews, screens vs. on-sites, distributions, etc. What are the shortcomings that keeps a candidate from an offer in the final steps, e.g. the candidate passes screening interviews, but falls short on an on-site interview. What are the indicators you observe that differentiate a senior candidate? How do you go about evaluating entry-level and junior candidat…

We do a few screens, starting with general security discussion - something like: intro, light tech/coding - just to make sure we aren't completely wasting our time The main interview centers on software security, and is focused on real world scenarios. We avoid "explain this OWASP top 10 blah blah blah" kind of questions. The goal is to see if you can reach the outcomes we expect, regardless of how you may approach t…

What is your salary range for all of this? That really, really sounds like it's worth ~$200k.

Re: Thinking of a Cybersecurity Career?

#63
post #62

Earlier quoted context omitted.

We do a few screens, starting with general security discussion - something like: intro, light tech/coding - just to make sure we aren't completely wasting our time The main interview centers on software security, and is focused on real world scenarios. We avoid "explain this OWASP top 10 blah blah blah" kind of questions. The goal is to see if you can reach the outcomes we expect, regardless of how you may approach t…

What is your salary range for all of this? That really, really sounds like it's worth ~$200k.

its worth more than $200k cash + bonus. Not everyone will slay every interview and we will adjust accordingly, but you need to be close.

Re: Thinking of a Cybersecurity Career?

#64
This is a predictable pattern at this point:

1) Employers don't like the fact that the labour they require has skills that a lot of time to become competent at and the labour wants to be compensated accordingly.

2) They get universities to start offering degree programs tailored to churn out new graduates who are willing to work for entry level wages.

3) Employers complain that the grads who come out of these programs are unprepared to do the same job as the old guard.

Using Metasploit, Nessus, and nmap should be a 1 credit elective course in a CS degree. Not top billing.

Re: Thinking of a Cybersecurity Career?

#65

I think the cybersecurity (I hate the term cyber btw as it's usually used by people who don't know what they're talking about), is very focused on the 'think like a hacker' skillset right now. While I do agree this is important in various roles in the security realm, there are also many jobs where this doesn't really add value. A lot of work is about implementing things like MFA, role-based-access etc where knowledge…

The term "cyber" has been part of the information security lexicon and if you work in the industry you accept it as reality. Especially if you work for government or a government contractor. Claiming that people who use the word cyber don't know what they are talking about is just ignorance at this point.

Re: Thinking of a Cybersecurity Career?

#66
post #65

I think the cybersecurity (I hate the term cyber btw as it's usually used by people who don't know what they're talking about), is very focused on the 'think like a hacker' skillset right now. While I do agree this is important in various roles in the security realm, there are also many jobs where this doesn't really add value. A lot of work is about implementing things like MFA, role-based-access etc where knowledge…

The term "cyber" has been part of the information security lexicon and if you work in the industry you accept it as reality. Especially if you work for government or a government contractor. Claiming that people who use the word cyber don't know what they are talking about is just ignorance at this point.

> has been part

That seems to be the issue for me - many people using "cyber" are noticeably out of touch.

Re: Thinking of a Cybersecurity Career?

#67
post #64

This is a predictable pattern at this point: 1) Employers don't like the fact that the labour they require has skills that a lot of time to become competent at and the labour wants to be compensated accordingly. 2) They get universities to start offering degree programs tailored to churn out new graduates who are willing to work for entry level wages. 3) Employers complain that the grads who come out of these program…

Totally it's the same pattern over and over again we don't want to pay technical talent that can actually do stuff, and won't or can't train the people that are willing to work cheap.

Re: Thinking of a Cybersecurity Career?

#68
post #25

I think the cybersecurity (I hate the term cyber btw as it's usually used by people who don't know what they're talking about), is very focused on the 'think like a hacker' skillset right now. While I do agree this is important in various roles in the security realm, there are also many jobs where this doesn't really add value. A lot of work is about implementing things like MFA, role-based-access etc where knowledge…

> Being able to run metasploit and wireshark does not make one a hacker. By doing this, pentesters test for yesterday's hacks, not tomorrow's. Be careful here. This is bordering on elitism. Having someone come into a business and check for "yesterday's hacks" is better than no one doing any checks at all, therefore such skills are still valuable and worthwhile. In learning how networking works; how operating systems…

Low-quality consultant penetration tests that rely on scanner results are a bigger problem in our industry than elitism.

Re: Thinking of a Cybersecurity Career?

#69
I’m in Georgia Techs online MS in cybersecurity program and have argued these points a few times. Most of the cybersecurity classes are just CS classes. I think it was just a money grab to repackage their existing CS degree into a more marketable package.

I’ve argued that we should have some type of network and OS hardening classes. There is a required network security And secure computer communication class but they are much more about programming vs implementation. The counter arguments I get are that what I’m suggesting is more aligned with a vendor cert. But a lot of cyber security is doing the hardening of os and proper user access.

A lot of the cyber students end up switching to the policy track instead of the information security track. They are admitting students with almost no prior CS experience. They get away with only having to take an intro to cyber security CS class. Their remaining classes are all management classes marginally related to security.

I’m going to use this article to backup my arguments that there is more to cybersecurity than programming.

Re: Thinking of a Cybersecurity Career?

#70
post #55

CyberSecurity, the domain that doesn't recruit yet has a shortage. What cybersecurity is to most people is automated security scans. This can be done by interns with a week of training to run the tools. (Interpreting and remediating the findings is another matter). Besides that, security is mainly about authentication. That's done by setting up LDAP, active directory, openid connect and co, and integrating in applica…

> CyberSecurity, the domain that doesn't recruit yet has a shortage. Yes, they are 100% lying about this. Any time you see an article about skills shortage, it's complete bullshit. It is cheap for them to create the illusion of a skills shortage via articles and blog spam. What they really want is people to spend their own money on training vs. them training their own talent. Then, once you've spent your money on tra…

> Yes, they are 100% lying about this. Any time you see an article about skills shortage, it's complete bullshit. It is cheap for them to create the illusion of a skills shortage via articles and blog spam. What they really want is people to spend their own money on training vs. them training their own talent. Then, once you've spent your money on training, you'll still run similar gauntlets in interviews that developers like to complain about.

This is so true. It is now common with most undergrads in India now, that they cannot even apply for a fresher job without such additional courses/certificates.

Training, learning and skill development budgets mobilized by CXOs for "other purposes"(may be for their vacation in the Swiss Alps that they promised to their spouse).

Post reply on HN