Live data from Hacker News

Thinking of a Cybersecurity Career?

krebsonsecurity.com

81–90 of 129 posts

Re: Thinking of a Cybersecurity Career?

#81
post #18

As with most positions, the largest obstacle to getting a job in security is overcoming the HR Gatekeepers. The hiring system is broken. Those who successfully attained job are those who generally have networked their way around the first line HR personnel. Get your name out there so that hiring managers know who you are. Blog, go to meet-ups, make friends, do capture-the-flags, create a website, create a Git repo, a…

TBH while a lot of people say the shortage is a myth, I am not so convinced. I wouldn't personally hire most people in infosec because I think the industry has the wrong idea of what the career should look like.

Most people in infosec have no coding skills. That isn't their fault, they aren't told it's important. I think it is, so I won't hire them. That just cut out the vast majority of candidates with a single criteria, and I believe a lot of the criteria is broken.

Re: Thinking of a Cybersecurity Career?

#82
post #13

Earlier quoted context omitted.

I used to do interviews for pentesters at an old job, and I was suprised as well. I think it's because CyberSecurity is relatively new, so companies have no idea how to hire for it, and end up hiring whoever can talk the best. I interviewed a lot of people with titles like "Senior Cybersecurity Engineer" who had no security knowledge beyond how to run an automated scan against an IP range, and put the findings it pri…

And yet here I am with half a decade actual experience in 'Cyber Security', can write passable Golang, C, C++, Python, hands on, real world knowledge and experience of threat actors and APT TTPs, for Blue team threat hunting, IDS/IPS signature creation, incident response... etc. And I can't even get a callback from any other company, because I don't check the "Bachelor degree required" box. Fucking, awesome.

That's very surprising. I don't have a degree and at Dropbox, the last company I worked for, dropouts were more common than those who held a bachelors.

Maybe there's something else going on?

Re: Thinking of a Cybersecurity Career?

#83

I think the cybersecurity (I hate the term cyber btw as it's usually used by people who don't know what they're talking about), is very focused on the 'think like a hacker' skillset right now. While I do agree this is important in various roles in the security realm, there are also many jobs where this doesn't really add value. A lot of work is about implementing things like MFA, role-based-access etc where knowledge…

> Being able to run metasploit and wireshark does not make one a hacker. By doing this, pentesters test for yesterday's hacks, not tomorrow's.

Funny enough, this thought process shows a failure to understand process and internal influencing. Quite often, the things found by a basic pen-test are known internally. Research will reveal long, boring discussions that end with someone like Bill dismissing things as not important and the risk acceptable.

What the paid-for report does it makes the risk visible, documented, and something the company may have to show to customers or partners. Now it's gone from something that can be shrugged off to something expensive and embarrassing. Bill has to explain why his opinion should matter more than those of the biggest customers. Now it's something that is much easier to prioritize.

Big management often doesn't value unpleasant or critical feedback from below. Once it's advice that's been paid for, its value jumps. After all, if you're not going to listen then why did the company pay the big bucks for it?

Re: Thinking of a Cybersecurity Career?

#84
post #83

I think the cybersecurity (I hate the term cyber btw as it's usually used by people who don't know what they're talking about), is very focused on the 'think like a hacker' skillset right now. While I do agree this is important in various roles in the security realm, there are also many jobs where this doesn't really add value. A lot of work is about implementing things like MFA, role-based-access etc where knowledge…

> Being able to run metasploit and wireshark does not make one a hacker. By doing this, pentesters test for yesterday's hacks, not tomorrow's. Funny enough, this thought process shows a failure to understand process and internal influencing. Quite often, the things found by a basic pen-test are known internally. Research will reveal long, boring discussions that end with someone like Bill dismissing things as not imp…

>What the paid-for report does it makes the risk visible, documented, and something the company may have to show to customers or partners.

Only if there's a lawsuit and it shows up on discovery. Otherwise there isn't really anything preventing it from being buried.

Re: Thinking of a Cybersecurity Career?

#85
post #84
post #83

Earlier quoted context omitted.

> Being able to run metasploit and wireshark does not make one a hacker. By doing this, pentesters test for yesterday's hacks, not tomorrow's. Funny enough, this thought process shows a failure to understand process and internal influencing. Quite often, the things found by a basic pen-test are known internally. Research will reveal long, boring discussions that end with someone like Bill dismissing things as not imp…

>What the paid-for report does it makes the risk visible, documented, and something the company may have to show to customers or partners. Only if there's a lawsuit and it shows up on discovery. Otherwise there isn't really anything preventing it from being buried.

Sometimes it crops up in vendor review or similar. I've definitely found myself reviewing pen-test reports for exactly that reason without a lawsuit or discovery.

Needless to say, having a bad pen-test report and then burying it would look extremely bad.

Re: Thinking of a Cybersecurity Career?

#86
post #25

I think the cybersecurity (I hate the term cyber btw as it's usually used by people who don't know what they're talking about), is very focused on the 'think like a hacker' skillset right now. While I do agree this is important in various roles in the security realm, there are also many jobs where this doesn't really add value. A lot of work is about implementing things like MFA, role-based-access etc where knowledge…

> Being able to run metasploit and wireshark does not make one a hacker. By doing this, pentesters test for yesterday's hacks, not tomorrow's. Be careful here. This is bordering on elitism. Having someone come into a business and check for "yesterday's hacks" is better than no one doing any checks at all, therefore such skills are still valuable and worthwhile. In learning how networking works; how operating systems…

Also, metasploit isn't used just for yesterdays hacks, it's great for ever your 0days to manage sessions and do some of the repetitive/boring leg work for you

Re: Thinking of a Cybersecurity Career?

#87
post #44

Earlier quoted context omitted.

> The level of external pentesters I've seen, has not exceeded the "scriptkiddie" level. You get what you pay for. I've taken part in security audits that delivered 0days - but they weren't cheap.

Good point. I'm not sure how much we pay for these as they're not commissioned by me. But knowing the company it's not going to be too much :)

Most pentesters / offensive security professionals have to operate with their hands tied behind their backs. Management generally has no interest in a real report of what happens if someone actually tried to break in. Generally speaking pentests are often so limited in scope and what is allowed to be engaged that you might have a group of people perfectly capable of robbing you unable to show you how because the company doesn’t want to know the truth.

Re: Thinking of a Cybersecurity Career?

#88

I feel like it's hard to teach cybersecurity formally. It deals with hacking and by nature the spirit of hacking is hard to teach. I have learnt cybersecurity as a hobby and have competed with our university team in some online well known attack/defense style competitions (we sucked) and a lot of this stuff is really hard to formalize. I guess you could teach the basics like overflows, aslr, stack canaries, basic ass…

Sounds like they need to bring apprenticeships to the field.

Re: Thinking of a Cybersecurity Career?

#89
post #67
post #64

This is a predictable pattern at this point: 1) Employers don't like the fact that the labour they require has skills that a lot of time to become competent at and the labour wants to be compensated accordingly. 2) They get universities to start offering degree programs tailored to churn out new graduates who are willing to work for entry level wages. 3) Employers complain that the grads who come out of these program…

Totally it's the same pattern over and over again we don't want to pay technical talent that can actually do stuff, and won't or can't train the people that are willing to work cheap.

Step 4, in the US at least, is to lobby for more H1B bodies.

While they may or may not have the skills that are actually needed, the H1B system makes feudal servants bound to the corporation.

Re: Thinking of a Cybersecurity Career?

#90
post #72
post #25

Earlier quoted context omitted.

> Being able to run metasploit and wireshark does not make one a hacker. By doing this, pentesters test for yesterday's hacks, not tomorrow's. Be careful here. This is bordering on elitism. Having someone come into a business and check for "yesterday's hacks" is better than no one doing any checks at all, therefore such skills are still valuable and worthwhile. In learning how networking works; how operating systems…

> Be careful here. This is bordering on elitism. Be careful about the soft bigotry of low expectations. A generation has grown up thinking that skill/knowledge elitism is a real thing and that it's oppressive. Instead we should learn to identify people who do difficult things, recognise how they do difficult things well, systematically emulate their methods as we attempt difficult things, and constantly work at the e…

What part of my response led you to believe I inferred we shouldn't learn difficult things? I'm simply try to show that people who haven't mastered the industry are still valuable.
Post reply on HN