Live data from Hacker News

Ask HN: How can I get into cyber security research?

news.ycombinator.com

31–40 of 47 posts

Re: Ask HN: How can I get into cyber security research?

#31
Great question!

For context, I transitioned from publishing top academic papers in security to building & growing a visual graph AI startup where, for one of our bigger customer bases, we work with top enterprise & military security teams. We're actively hiring here so some quick responses based on what I look for and have seen:

* Red team makes sexy headlines, but it's the blue team who gets the seat on the board. Think prioritizing areas like detection, hardening, new protocols, thorough fuzzing, SDLC, vs finding bugs with a security flavor. Red team does have its niche, as pen testing + compliance audits form an important services industry, but the research opportunities are more limited.

* Education: Cybersecurity fundamentals are super approachable and CS ugrads who did systems courses already have the harder basics: networking, OS, and compilers. Cyber-specific coursework mostly just revisits the harder fundamentals with a "gotcha" perspective. For more modern AI-ish roles, a classical math/cs background is typical.

* Industrial education: Interestingly, SOC/IR/Hunt are NOT taught in school. Likewise, industrial experience in AI/data engineering/software can often be way more valuable than university-flavor, so career pivots are doable.

It can be hard to do R&D within a regular operational security team. However, early-stage vendors like us inherently have to do it, and we work with top enterprise/tech/mil teams who in turn do research internally & through us. US, esp DC-area with clearance (ex: drugs can be problematic), opens a lot of doors. If anyone is like that for cyber AI or sec eng, either US or Australia, we're def looking for senior, and aim to have mid/junior later in the year :)

Re: Ask HN: How can I get into cyber security research?

#32

Do you want to work for a government contractor? If so, they're always looking to expand and hire more great minds. Many people who are technically skilled but relatively new to RE/VR get hired because it's such a niche field and they teach on the job. If you don't want to work for a government contractor, gl;hf because most of the money lies in alphabet agency contracts and the vulnerabilities WILL be weaponized and…

This is a much harder field to break into if you're not a US citizen / eligible for clearance. It's frustrating comparing the jobs available in/around VA/MD/DC to the ones available in other countries.

Re: Ask HN: How can I get into cyber security research?

#33
post #17

1. Browse through major findings in USENIX security conferences and make note of major authors and their affiliations. 2. Think about what challenges are generally faced in the field in whatever capacity you're interested in (network security, hardware security, etc.) and what organizations (public/private/solo hacker groups) are actively working towards addressing these challenges. 3. Do some work, reach out to peop…

USENIX? Lmao. Nothing of note happens there. Hilariously enough, nothing significant happens at BH or DEFCON either. There are other, much smaller conferences for the actual interesting, and novel things.

Any exemplars that come to mind?

I wouldn't be surprised as other posters have opined (and likely accurately) that industry/hacker groups have progressed past academia.

Re: Ask HN: How can I get into cyber security research?

#34

Do you want to work for a government contractor? If so, they're always looking to expand and hire more great minds. Many people who are technically skilled but relatively new to RE/VR get hired because it's such a niche field and they teach on the job. If you don't want to work for a government contractor, gl;hf because most of the money lies in alphabet agency contracts and the vulnerabilities WILL be weaponized and…

I work in this niche (finding/exploiting C/C++ bugs in operating systems and browsers). Here's the companies I know about: Raytheon, Mitre, L3Harris, Grayshift, Vigilant. Also NSA and CIA will train you if you don't already have the skills, but there's downsides: clearance required, no remote work, DC area only, low pay.

Re: Ask HN: How can I get into cyber security research?

#35
post #2

Could you give us a few examples of security research jobs? It seems pretty obvious that you’d need to go into a PhD program in cybersecurity to work on groundbreaking research. Perhaps you mean industry or implementation specific research?

We have 2 senior openings right now, and both feel representative in not requiring a PhD. We're pretty cutting edge here (end-to-end GPU acceleration, graph neural networks, win R&D competitions, ...), and our team is split pretty evenly on PhD vs not, so I likewise feel pretty comfortable writing this:

* Security AI : ugrad-level math ability (linear algebra, prob, stats, info theory, ...) is required, as well as experience with deep learning and operational AI problems. PhD more strongly suggests you can communicate & plan, such as for giving talks, pitching crazy projects, and writing DARPA grants... but not necessarily, nor required.

* Security engineer: We care more that someone has worked with big operational security systems, getting things like large & gnarly Splunk deploys and how tools like Spark, AI, Python, notebooks, and viz can seriously augment them. You don't learn that at school.

Re: Ask HN: How can I get into cyber security research?

#37
Lots of folks can make the hop from SRE to pentesting; much of the knowledge space - especially post-exploitation - is very similar! You have the advantage that you know how to operate on a production box without accidentally destroying or interrupting it. There are tools to learn, but I think you would find it to be an easy transition.

In more mature environments I would say up to 20-30% of a pentester's job can be finding bespoke vulnerabilities, 30+% is writing reports, so you get some good exposure to those; these are the exact skills you need in vulnerability research. If possible, request a ridealong with your company's pentesters in your environment, usually they love that: SREs know where the bodies are buried.

Research itself is a bit harder leap to get into straight from SRE; definitely far fewer junior roles. A lot of companies hire up researchers internally from their red and blue teams. Bug bounties are a way in without operational experience; without doing one or the other it's a bit of a tough sell. I would recommend a year or so on a red team and try to spend as much time as possible doing vuln-researchy things. Find some interesting things, communicate them effectively, and you will be well-poised to get into research.

Re: Ask HN: How can I get into cyber security research?

#39
post #34

Do you want to work for a government contractor? If so, they're always looking to expand and hire more great minds. Many people who are technically skilled but relatively new to RE/VR get hired because it's such a niche field and they teach on the job. If you don't want to work for a government contractor, gl;hf because most of the money lies in alphabet agency contracts and the vulnerabilities WILL be weaponized and…

I work in this niche (finding/exploiting C/C++ bugs in operating systems and browsers). Here's the companies I know about: Raytheon, Mitre, L3Harris, Grayshift, Vigilant. Also NSA and CIA will train you if you don't already have the skills, but there's downsides: clearance required, no remote work, DC area only, low pay.

If you find the right contractor or aim for a smaller subcontractor, the pay can be fairly lucrative if you haven't been poisoned by FAANG salaries.

Typically the game in the industry is work for a contractor, quit with a few of your best buds, open an LLC and sub back to the same customer/contractor with your billing rate doubled. Since you lack the overhead of a larger company, you can be a little entrepreneur with your specialization and get very rich very fast.

Re: Ask HN: How can I get into cyber security research?

#40
post #16

Earlier quoted context omitted.

Most of the actually groundbreaking and useful research in security happens out of necessity in the industry as opposed to in academia, where they seem to rediscover things that are widely known in the hacker community a few years later.

I would argue that the industry may stumble upon a security-related issue first. But stumbling, and being aware of something is not research. Anecdotally, I vividly remember industry people showing up in academic conferences, bragging how they knew everything about bit-flips already. They didn't. They just happened to know to be aware of the phenomenon, and smart enough to understand that it should have security impl…

A good amount of the industry has dedicated research departments these days. At least, the better consultancies have.

As for the bitflips example, are you talking about Rowhammer? That and the CPU side channel issues are the kind of area academia really tends to do great work on.

Where I find academia incredibly disappointing is in areas like covert channels - there's a fucking paper mill in Israel that keeps shitting out implausible "covert channel" research.

Also stuff like memory corruption techniques - academia seems to spend a lot of its time reinventing shit that has been done to death in industry or even has papers in Phrack.

Post reply on HN