5 ms·
I found critical flaws in systems 4 previous pen test companies didn't find. I found bugs in a security camera DVR platform for a big company, I found critical
by SecConsult 11y ago
I found critical flaws in systems 4 previous pen test companies didn't find. I found bugs in a security camera DVR platform for a big company, I found critical flaw on numerous custom web portals, I found all these bugs after they went through at least one pentest by another vendor. I usually don't miss bugs in pentest and/or source code analysis. When I analyze malwares, I usually do it quick and I analyze them extensively and write good and detailed reports. I'm 28 but I built my reputation over sometime with quality work. (very sorry if my post have bragging tone, I don't mean to, I just wanted to share)
- chatmasta 11y agoIt's clear that you do have value, and it's easy for you to prove it. But how did you get your foot in the door to even have the chance to prove it? Were you invited to pen test? Did you offer your initial service for "free" to prove your worth?
- SecConsult 11y agoFirst you need to work for established infosec companies. They get pentest projects every day, easily. You can't be like them day 1. So when you work through those companies and do pentest for a client, show yourself. In our team, maybe 10 people were working with me on pentest projects, but if you ask clients now after years, they probably ONLY remember my name, because they know and understand who did what. So after years and years of good reputation, it's super easy to expand your client base, do for yourself, ask for top $, reject offers might be a dream salary for some. But just like everything else, you start slowly and gradually "level-up"