You'll do fine. Don't waste time with certificates. They mean fuck all in the industry. Any job that cares about them is a job you don't want. Try to get some clarity about what part of security you want to work in. All the subfields are open to you. Do you want to do operations work? Do you want to exercise your software development muscles? Do you want to work offense or defense? My advice might be different depend…
Ask HN: Starting a career in security at 40?
71–80 of 114 posts
Re: Ask HN: Starting a career in security at 40?
#72Edit: That similarly applies to the "current salary" discussion. Six figures could be a lot, or very poor.
Re: Ask HN: Starting a career in security at 40?
#73You'll do fine. Don't waste time with certificates. They mean fuck all in the industry. Any job that cares about them is a job you don't want. Try to get some clarity about what part of security you want to work in. All the subfields are open to you. Do you want to do operations work? Do you want to exercise your software development muscles? Do you want to work offense or defense? My advice might be different depend…
Certifications are a way to bypass HR filters, and allow you to negotiate higher salaries. I agree that in terms of imparting actual skills and knowledge they are of minimal value. Being mentored by your peers, being involved in the community, and learning by doing are by far the best ways to learn Security. Certificates are relatively easy to earn and have high ROI in terms of salary and negotiating power in my expe…
Re: Ask HN: Starting a career in security at 40?
#74Earlier quoted context omitted.
I think what he means with certifications is that they'll get you the jobs you don't really want. For example, CEH (Certified Ethical Hacker) is a certification you'll see in a lot of job postings. The thing is, if you know this field, you know that this certification is worthless; it's just an expensive piece of paper. So, if you get a job that requires you to be CEH, it's telling a lot about the company itself, you…
Agree on the other certs -- but have you actually looked at the requirements for OSCP? I think it's a bit more in depth than you believe.
Re: Ask HN: Starting a career in security at 40?
#75You'll do fine. Don't waste time with certificates. They mean fuck all in the industry. Any job that cares about them is a job you don't want. Try to get some clarity about what part of security you want to work in. All the subfields are open to you. Do you want to do operations work? Do you want to exercise your software development muscles? Do you want to work offense or defense? My advice might be different depend…
Do you have any resources / direction to give to a software engineer who'd want to learn more about security? As a full stack web engineer I feel like I know nothing about security (just like most people) and I'd love to have more knowledge about it, even maybe work on this. I have a small design and engineering studio, and might be interested in getting into that kind of services, if I discover that I get interested…
Re: Ask HN: Starting a career in security at 40?
#76You'll do fine. Don't waste time with certificates. They mean fuck all in the industry. Any job that cares about them is a job you don't want. Try to get some clarity about what part of security you want to work in. All the subfields are open to you. Do you want to do operations work? Do you want to exercise your software development muscles? Do you want to work offense or defense? My advice might be different depend…
How would you practice this craft? Is practicing on pentesting websites (like https://www.hackthebox.eu/ ) a good idea? Or is there a better way to learn the various tools? Edit: I have also completed some of the challenges on http://cryptopals.com/ a while back to get better with developing Python code.
https://trailofbits.github.io/ctf/
Cryptopals is great! :) If you've gotten all the way through set 6 and are interested in a first software security gig, get in touch. Those challenges have been a pretty excellent predictor for us.
Re: Ask HN: Starting a career in security at 40?
#77Allow me to disagree with tptacek a little: The OffSec Penetration Testing with Kali Linux (OSCP certification) is excellent and outstanding and cheap. https://www.offensive-security.com/information-security-trai... While the course itself is $800, you'll most assuredly need another 60 days of lab time for the certification. I think all-in-all it cost me $1,500 for everything. The course material is excellent and wid…
I'm just one data point but I'm a hiring security manager and if someone had OCSP it would mean nothing to me.
Re: Ask HN: Starting a career in security at 40?
#7840 is a great time. In fact, I went down a similar path. Now that you've done your share of sysadmins, SRE and software developer, you can see how things can fail. That's the heart of security. As tptacek advises, choose an area of security to focus on and go down that path for awhile. You'll find you will want to go further or jump to another path, but security is a great thing. The world is going to need more secur…
Is your goal creating a development process that leads to a secure system, or securing a system made by an existing process? How much code do you write? Maybe some tasks you've enjoyed or a typical day would be great.
I say this because, while I've never had or wanted a title that included security, as a dev I often find myself looking at "holistic defense of data flowing" and attempting to improve the situation. A role based on that concept is interesting.
Re: Ask HN: Starting a career in security at 40?
#79Earlier quoted context omitted.
You can almost double your total comp overnight going from a devops/infra role to an infosec role. If you're in ops, get out of ops and go into security. More money, no on call rotation, better career trajectory.
>no on call rotation In my experience that hasn't been true at all, but the rest is definitely accurate.
Re: Ask HN: Starting a career in security at 40?
#80Allow me to disagree with tptacek a little: The OffSec Penetration Testing with Kali Linux (OSCP certification) is excellent and outstanding and cheap. https://www.offensive-security.com/information-security-trai... While the course itself is $800, you'll most assuredly need another 60 days of lab time for the certification. I think all-in-all it cost me $1,500 for everything. The course material is excellent and wid…
I'm just one data point but I'm a hiring security manager and if someone had OCSP it would mean nothing to me.