3 ms·
So, take this with a grain of salt because I do not actually work in the security industry. My understanding of security researchers is limited to an academic
by stuffaandthings 10y ago
So, take this with a grain of salt because I do not actually work in the security industry.
My understanding of security researchers is limited to an academic setting. Many PhD students, masters students, professors, etc at my school were technically security researchers. Usually this consists of a lot of theoretical exploration. Check out this paper, I think it's pretty accurate to what a security researcher does: https://www.tau.ac.il/~tromer/acoustic/ https://www.tau.ac.il/~tromer/acoustic/
So that's the academic side. Companies like Google, Microsoft, Red Hat, etc. will also hire Security Researchers where your job is a bit more open ended and focused on outside-the-box work (finding new vulnerabilities, testing software, maybe some offensive security work).
Please correct me if I'm wrong, but my understanding of a netsec person is someone who's job is to implement and maintain secure systems. While this can definitely involve experimentation, it seems like more of a defensive approach to security.
A job description might say things like: "Protect critical systems from attacks", "incident response", "disaster recovery".
I think a Security Engineer is much closer to a Security Researcher, but in a more 'applied' way... for example, as a security engineer at Dropbox your job might be to actually implement (write code for) cryptographic communication between the client and server. So, to me, a Security Engineer is much closer to a software engineer. Whereas a Security Researcher is much closer to an academic.
I hope this helps clarify things. There are other great responses on this thread.
Also, I completely understand public sector not being a good fit.