Live data from Hacker News

Thinking of a Cybersecurity Career?

krebsonsecurity.com

91–100 of 129 posts

Re: Thinking of a Cybersecurity Career?

#91
If it can be done without a degree and largely by self study than most of it can be packaged into a course or a book with practice problems and labs that anyone with dedication can finish can complete and come out competent.

Maybe such a course that covers what's needed to get into that top 10% doesn't exist yet but I'm sure it can exist and I would gladly pay for such a course to attain the required mastery rather than explore the space haphazardly myself.

Do any professional security experts know of such a course? Are any of you willing to start one?

Re: Thinking of a Cybersecurity Career?

#92
post #75
post #25

Earlier quoted context omitted.

> Being able to run metasploit and wireshark does not make one a hacker. By doing this, pentesters test for yesterday's hacks, not tomorrow's. Be careful here. This is bordering on elitism. Having someone come into a business and check for "yesterday's hacks" is better than no one doing any checks at all, therefore such skills are still valuable and worthwhile. In learning how networking works; how operating systems…

Decent sysadmin should be able to setup automated scanning, know about OWASP, keep systems patched. That should be absolute baseline for sysadmin work. Checking for yesterdays hacks is valuable but that is called auditing and you should have checklist for that. Pentesting should be focusing on hacking and uncovering stuff that was not in audits like making custom exploits on the spot. Problem is that running scanners…

> Pentesting

I think I see the problem. You're assuming several things here. Firstly you're assuming that pentesting is the definition of cyber security when in fact it's one aspect of a huge area. Secondly you're implying that everyone wants to be a pentester. And finally I feel like you read the article and came to the conclusion it was only about becoming a pentester, when in fact it was about getting into a much larger field that contains maybe jobs with many different objectives.

Re: Thinking of a Cybersecurity Career?

#93
post #25

Earlier quoted context omitted.

> Being able to run metasploit and wireshark does not make one a hacker. By doing this, pentesters test for yesterday's hacks, not tomorrow's. Be careful here. This is bordering on elitism. Having someone come into a business and check for "yesterday's hacks" is better than no one doing any checks at all, therefore such skills are still valuable and worthwhile. In learning how networking works; how operating systems…

I know, but most of these "hacks" are identified by internal scans already. The pentest doesn't add much value then. The issue is more internal resistance to change in the management team. Like I said I know most companies already fail at the basics. But these are normally well known already, just not fixed due to political pressure. Having the security team's management be better at influencing would pre-empt these…

> I know, but most of these "hacks" are identified by internal scans already. The pentest doesn't add much value then.

As I said above in to another comment: pentesting isn't the job in the field and the article wasn't specifically aimed at pentesters.

> Which is exactly what a serious adversary would be doing in a targeted hack!

Sure, and that's when you bring in someone who can do the same for you but ahead of time before the bad guys get there. But to say someone who can't do that isn't in a cybersecurity position or has no value is wrong :)

Re: Thinking of a Cybersecurity Career?

#94

I'm a senior level security leader and hiring manager. I focus on software security. Ask me anything about what I see, or don't, in candidates.

I notice in your other replies you have several interview questions that seem to be targeted at previous experience. What kind of side projects, cybersecurity or just programming related, do you find the most appealing in a candidate?

Re: Thinking of a Cybersecurity Career?

#95
post #93

Earlier quoted context omitted.

I know, but most of these "hacks" are identified by internal scans already. The pentest doesn't add much value then. The issue is more internal resistance to change in the management team. Like I said I know most companies already fail at the basics. But these are normally well known already, just not fixed due to political pressure. Having the security team's management be better at influencing would pre-empt these…

> I know, but most of these "hacks" are identified by internal scans already. The pentest doesn't add much value then. As I said above in to another comment: pentesting isn't the job in the field and the article wasn't specifically aimed at pentesters. > Which is exactly what a serious adversary would be doing in a targeted hack! Sure, and that's when you bring in someone who can do the same for you but ahead of time…

I didn't say that! If you see my first post, I agree with you that in many 'cyber'security jobs other skills (like politics/influencing) are much more important and unfortunately often lacking in key people. I actually don't like the strong focus on the CEH/OCSP certs as most HR depts seem to apply them to all areas of security. Not just pentesting and auditing.

And especially for pentesters, I'd want them to have more initiative than just running through some standard textbook operations. At least that's what I've seen. But as another poster mentioned, what they do at this company is more like an audit, just under the flag of a pentest which sounds cooler.

Re: Thinking of a Cybersecurity Career?

#96
post #87

Earlier quoted context omitted.

Good point. I'm not sure how much we pay for these as they're not commissioned by me. But knowing the company it's not going to be too much :)

Most pentesters / offensive security professionals have to operate with their hands tied behind their backs. Management generally has no interest in a real report of what happens if someone actually tried to break in. Generally speaking pentests are often so limited in scope and what is allowed to be engaged that you might have a group of people perfectly capable of robbing you unable to show you how because the comp…

Indeed, what you describe sounds very typical!

Especially pre-Wannacry, since then things have improved somewhat, when top management woke up to the thought that these things do in fact actually happen.

Re: Thinking of a Cybersecurity Career?

#97
post #62

Earlier quoted context omitted.

What is your salary range for all of this? That really, really sounds like it's worth ~$200k.

its worth more than $200k cash + bonus. Not everyone will slay every interview and we will adjust accordingly, but you need to be close.

Really? Your interview sounds pretty par for the course. I did this work for ~$140k, but was not in the bay area. I knew I was underpaid but not THAT underpaid.

Re: Thinking of a Cybersecurity Career?

#98

I'm a senior level security leader and hiring manager. I focus on software security. Ask me anything about what I see, or don't, in candidates.

I notice in your other replies you have several interview questions that seem to be targeted at previous experience. What kind of side projects, cybersecurity or just programming related, do you find the most appealing in a candidate?

I love to hear about the tools people have created. There is almost always a good story about a problem and a solution.

However, this is not really what I mean. If you are interviewing for a role in software security, you should be current on the industry and ready to talk sources and research. At a minimum, you should have areas of interest that you are passionate about discussing, even if you are still ignorant about the deep details.

You wont do well if security is something you only do 9-5, but I don't want you working for me after hours.

Re: Thinking of a Cybersecurity Career?

#99
post #83

I think the cybersecurity (I hate the term cyber btw as it's usually used by people who don't know what they're talking about), is very focused on the 'think like a hacker' skillset right now. While I do agree this is important in various roles in the security realm, there are also many jobs where this doesn't really add value. A lot of work is about implementing things like MFA, role-based-access etc where knowledge…

> Being able to run metasploit and wireshark does not make one a hacker. By doing this, pentesters test for yesterday's hacks, not tomorrow's. Funny enough, this thought process shows a failure to understand process and internal influencing. Quite often, the things found by a basic pen-test are known internally. Research will reveal long, boring discussions that end with someone like Bill dismissing things as not imp…

This is a really good point. I have actually seen that happen.

I just wish we could get our own point across (at a level higher than myself) sometimes without having to do this :)

Re: Thinking of a Cybersecurity Career?

#100
post #62

Earlier quoted context omitted.

What is your salary range for all of this? That really, really sounds like it's worth ~$200k.

its worth more than $200k cash + bonus. Not everyone will slay every interview and we will adjust accordingly, but you need to be close.

It is sfbay. Senior security folks are at or above $200k in the majority of cases. As with all sfbay salaries, it is not representative of any other market.
Post reply on HN