Live data from Hacker News

Flush times for hackers in booming cyber security job market

reuters.com

71–76 of 76 posts

Re: Flush times for hackers in booming cyber security job market

#71
post #8

What saddens me is that, while red team pen testing is a very "hot" (high employer demand, high salaries) job market, people don't generally care about the blue team. It's easy to get a pentesting gig that pays well, but employers don't ask for/value people with the competence to build/maintain secure applications/networks/solutions in my experience. Instead they pay for recurring pen tests which results in internal…

The company I work for is aggressively hiring blue teamers. The core of our product is essentially a security product, so we need someone who has at least some professional engineering experience as you would be responsible for helping to lead teams building certain parts of our infrastructure and product. Someone who can hop onto code reviews that deal with sensitive areas would be fantastic.

We're located in Boulder but for the right candidate we'd consider remote, although that might involve relatively frequent travel.

cGhpbGlwLmRldWNobGVyQGp1bXBjbG91ZC5jb20= for contact

Re: Flush times for hackers in booming cyber security job market

#72

Earlier quoted context omitted.

Assuming the company is voluntarily hiring them, and not being required by a contract or law that needs an independent 3rd party for auditing purposes, it seems like the pentesting company would do an even better job on the inspection if they had a good chance of getting repair work down the line for every issue they found. If they make up a bunch of minor things that don't matter, you can ignore those and focus on t…

It's simply bad practice to have the people that are involved in the 'checking' making money or being involved in the 'fixing' in any way shape or form. You'll see this in almost every situation that is somehow related to auditing.

Like colleges.

Re: Flush times for hackers in booming cyber security job market

#73
post #4

I advise companies on tech security, and talent is very much needed. What's surprising (at first glance) is that the security talent need is very strong in UI/UX/CX. For example, security is needed to gradually escalate a user's own identity verification -- think of things like two-factor auth and multi-factor auth, that can phase in (or ramp up) when a user's actions enter a gray area of risk. Some examples: when a…

I work in infosec as a security engineer, I agree with this more than anything else anyone has posted about the state of the security industry on HN, ever.

For security being a human problem, I have yet to meet infosec types with strong backgrounds in human factors or product design. Nearly everyone came to this industry from netsec/IT/SOC work, or low-level programming, and neither group has a decent understanding of the usability issues that plague the security posture of common users. What works for a CLI junkie with deep systems knowledge absolutely fails people who barely know how to navigate their Android phone.

If anyone's interested in attempting to solve some of these design pattern issues, please reply here or DM me on Twitter. I'd love to actually get a group of people together trying to come up with standard, secure UX paradigms that can be referenced by others.

Re: Flush times for hackers in booming cyber security job market

#74

Earlier quoted context omitted.

I would not waste time and money on certifications.

As someone not in the field, but curious of getting in, could you explain why not?

There is a bias against certifications by some (but by no means all) professionals in InfoSec, since it is a heavily "hands-on" field. There is more emphasis on demonstrating actual ability through CTFs, bug bounties, published exploits, etc.

However, unlike Certified Ethical Hacker, CISSP, and other "mile wide, but inch deep" certs, the OSCP is a heavily hands-on certification that tests actual ability. No knowledgeable employer would discriminate against you for earning it.

And CISSP or CISSM are valuable if you're applying for a management job. For government defense-sector jobs, they are often required.

Re: Flush times for hackers in booming cyber security job market

#75
post #5

How can I get into this field? I used to love doing pen-testing when I was a teenager, and paid for my first car out of bug-bounties. Unfortunately, I got distracted by girls and booze at university and didn't keep it up, now I work in sigh enterprise C#/WPF land.

How'd you get into enterprise C#/WPF land?

That's the path of least resistance. Just passively accept calls and interviews via recruiters, and next thing you know you're in the enterprise. It's what happens when you don't have a plan.

Re: Flush times for hackers in booming cyber security job market

#76
post #49
post #30

Earlier quoted context omitted.

Don't regret the good times for one second, but do get very jealous of people on HN talking about all the exciting tech they're using and awesome work environment. I am actively taking steps to move to a better company, but my god I'm finding Cracking The Interview Code a slog.

Same here...and then add on that I'm actually over 40...and oh boy, does that code get tougher to track. Funny how in some circles deep and long experience in tech is respected...but companies often look at me and ask "What will you do for me lately?"...and look at my age, and likely assume that I'm slowing down; when just the opposite is happening, i'm speeding up in terms of complexity of tech i'm diving into. Weir…

Try it at 50. It's not a good field to be in at either of these ages unless you are in technical mgmt, architecture or direction.
Post reply on HN