Live data from Hacker News

Thinking of a Cybersecurity Career?

krebsonsecurity.com

31–40 of 129 posts

Re: Thinking of a Cybersecurity Career?

#32

As someone undertaking a Master's in Cybersecurity, that table is totally true. Most of my courses have a programming alternative for assignments yet the students alongside me have very little interest. I've been doing this a while so maybe I'm just an outlier as I've always been the guy who is the jack of all trades, but I can't help but see something unknown as something to learn.

Don't ditch programming. Knowing how programs are made will in some situations help you understand how they can be abused as well.

Re: Thinking of a Cybersecurity Career?

#34
post #28

In my experience, c level folks just want someone who can produce a dashboard or executive report with a bunch of green check marks that basically say “yay! We’re secure”. They don’t care about the why, how, if the check marks are actually meaningful, etc. This mindset is then reinforced by vendors selling security snake oil - the entire infosec domain is a shit show; if infosec practitioners ever want to be taken se…

There's the MITRE ATT&CK Framework https://attack.mitre.org/ which is gaining attention and seems very promising (although it of course isn't the golden answer to all questions, it goes a long way to cover the basics).

Re: Thinking of a Cybersecurity Career?

#35
post #32

As someone undertaking a Master's in Cybersecurity, that table is totally true. Most of my courses have a programming alternative for assignments yet the students alongside me have very little interest. I've been doing this a while so maybe I'm just an outlier as I've always been the guy who is the jack of all trades, but I can't help but see something unknown as something to learn.

Don't ditch programming. Knowing how programs are made will in some situations help you understand how they can be abused as well.

Of course not... after 11 years as a software engineer, it would be difficult to not do it.

Re: Thinking of a Cybersecurity Career?

#37
post #25

Earlier quoted context omitted.

> Being able to run metasploit and wireshark does not make one a hacker. By doing this, pentesters test for yesterday's hacks, not tomorrow's. Be careful here. This is bordering on elitism. Having someone come into a business and check for "yesterday's hacks" is better than no one doing any checks at all, therefore such skills are still valuable and worthwhile. In learning how networking works; how operating systems…

I know, but most of these "hacks" are identified by internal scans already. The pentest doesn't add much value then. The issue is more internal resistance to change in the management team. Like I said I know most companies already fail at the basics. But these are normally well known already, just not fixed due to political pressure. Having the security team's management be better at influencing would pre-empt these…

> I know, but most of these "hacks" are identified by internal scans already. The pentest doesn't add much value then. The issue is more internal resistance to change in the management team.

This sounds like management's fault for using a service they don't need yet. If there are glaring, obvious vulns that are repeatedly pointed out but aren't getting fixed then how useful is it to point out additional more subtle vulns? I understand the point you are trying to make about pentests telling you data you already know, but how many people are going to take the time to enumerate subtle vulns when there are basic ones that can be hit to great effect?

> Which is exactly what a serious adversary would be doing in a targeted hack!

I don't think it makes sense to worry about what a serious adversary could do when a moderately skilled one can already wreck you with known exploits.

Re: Thinking of a Cybersecurity Career?

#38
CyberSecurity, the domain that doesn't recruit yet has a shortage.

What cybersecurity is to most people is automated security scans. This can be done by interns with a week of training to run the tools. (Interpreting and remediating the findings is another matter).

Besides that, security is mainly about authentication. That's done by setting up LDAP, active directory, openid connect and co, and integrating in applications. A tremendous amount of setup and integration work for administrators/developers. (Not cyber security engineers)

There are cyber aspects around infrastructure and networking for sysadmin/devops/sre/developers. Setting up firewalls and 2FA in AWS, configuring TLS, upgrading OS and abandoned libraries. (Still, no permanent cyber security roles in sight)

Last is a couple of researchers finding vulnerabilities, concentrated in the likes of the NSA, NSO Group, project zero. Highly technical work that very few companies recruit for. These are full time jobs, offensive cyber security (vulnerability researcher) but extremely few in the world.

When I see people looking for cyber security engineers or trying to break into security. I can't help but think what do they mean by that? Just become a developer or a sysadmin/devops.

Re: Thinking of a Cybersecurity Career?

#39
post #25

Earlier quoted context omitted.

> Being able to run metasploit and wireshark does not make one a hacker. By doing this, pentesters test for yesterday's hacks, not tomorrow's. Be careful here. This is bordering on elitism. Having someone come into a business and check for "yesterday's hacks" is better than no one doing any checks at all, therefore such skills are still valuable and worthwhile. In learning how networking works; how operating systems…

I know, but most of these "hacks" are identified by internal scans already. The pentest doesn't add much value then. The issue is more internal resistance to change in the management team. Like I said I know most companies already fail at the basics. But these are normally well known already, just not fixed due to political pressure. Having the security team's management be better at influencing would pre-empt these…

So your point is "bad pentests are bad and provide no value". Yes. You are correct.

Re: Thinking of a Cybersecurity Career?

#40

I'm a senior level security leader and hiring manager. I focus on software security. Ask me anything about what I see, or don't, in candidates.

Can you talk about your interview process? e.g. types of interviews, screens vs. on-sites, distributions, etc. What are the shortcomings that keeps a candidate from an offer in the final steps, e.g. the candidate passes screening interviews, but falls short on an on-site interview. What are the indicators you observe that differentiate a senior candidate? How do you go about evaluating entry-level and junior candidates? Thank you!
Post reply on HN