3 ms·
The best advice I can give you is to join a Security CTF team (your college may or may not have one, but there are others that are open to all). Internships an
by stuffaandthings 10y ago
The best advice I can give you is to join a Security CTF team (your college may or may not have one, but there are others that are open to all).
Internships and jobs will open up from being part of a CTF group. It's also A LOT of fun* (*opinion).
netsec might not necessarily be what you're looking for. A position as a Security Researcher is probably what you most fit into... finding the right recruiter can also help you out a lot.
Another (and honestly, easier to get into) security industry is the public sector. Intelligence agencies, military intelligence branches, etc. They'll hire you based on personality and potential, and will train you further. This (in my limited experience) usually means less pay.
Hope this helps. Good luck!
- alltakendamned 10y agoI like your CTF suggestion. But finding a job as a security researcher will be hard if you cannot show any experience.
- stuffaandthings 10y agoYou're absolutely right, but people are willing to consider CTF work as experience. If you can go into depth how you solved a problem, no one will question your conceptual understanding. I think it's definitely easier if your interviewer actually knows what security ctf's are.
- isnetsecforme 10y agoThanks for your reply. Can you please explain what you think differentiates someone working in netsec from security researcher? And where do you think a Security Engineer position would fit in? Thanks for the public sector advice. Although, I think I won't be a good fit. Thank you!
- stuffaandthings 10y agoSo, take this with a grain of salt because I do not actually work in the security industry. My understanding of security researchers is limited to an academic setting. Many PhD students, masters students, professors, etc at my school were technically security researchers. Usually this consists of a lot of theoretical exploration. Check out this paper, I think it's pretty accurate to what a security researcher does: https://www.tau.ac.il/~tromer/acoustic/ https://www.tau.ac.il/~tromer/acoustic/ So that's the academic side. Companies like Google, Microsoft, Red Hat, etc. will also hire Security Researchers where your job is a bit more open ended and focused on outside-the-box work (finding new vulnerabilities, testing software, maybe some offensive security work). Please correct me if I'm wrong, but my understanding of a netsec person is someone who's job is to implement and maintain secure systems. While this can definitely involve experimentation, it seems like more of a defensive approach to security. A job description might say things like: "Protect critical systems from attacks", "incident response", "disaster recovery". I think a Security Engineer is much closer to a Security Researcher, but in a more 'applied' way... for example, as a security engineer at Dropbox your job might be to actually implement (write code for) cryptographic communication between the client and server. So, to me, a Security Engineer is much closer to a software engineer. Whereas a Security Researcher is much closer to an academic. I hope this helps clarify things. There are other great responses on this thread. Also, I completely understand public sector not being a good fit.
- throwaway22417 10y agoWhat is your opinion on starting out with government contractors?
- stuffaandthings 10y agoI don't know enough to have a well formed opinion. I don'y know any contractors personally, and haven't read up on it much. Sorry!