From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…
This is me. There's nothing more boring than those positions. (Or to me, unethical than working for the US government) I'd much rather create something that benefits the world. Maybe the partial solution is bug bounties? As much as I'd hate those positions, I actively poke around for holes in websites for fun. I love when I have to do business with a small poorly run website, seems you can always find something they…
I’ll be a little more nuanced. I’m very appreciate of the hard work nist does posting best practices and guidelines on privacy, zero-trust, crypto, and other things. The SP series of publications are well respected and do lift the entire industry up to some minimum standard. In some cases they actually move things forward by a lot (like the AES competition)