4 ms·
If I'm a competent enough services and web developer wanting to move into infosec, what else could I be doing to get my foot in the door besides collecting cert
by Scuds 9y ago
If I'm a competent enough services and web developer wanting to move into infosec, what else could I be doing to get my foot in the door besides collecting certs, as ostensibly shite as they are?
- dsacco 9y agoBug bounties. Andddd that's it, you're done. Find a few in recognizable companies, and jobs will simply come to you. I'm not going to engage in the debate about what certifications should be in the industry, but I'm happy to show which option is most advantageous for your particular needs right now: * Certifications mostly do not teach you anything that you, as a competent web developer, cannot learn from the same five textbooks tptacek, others and myself recommend in these threads. * Certifications cost money. * Certifications optimize for companies and roles that disproportionately do not pay highly. * Many certifications require upkeep. Let's contrast with bug bounties: * Bug bounties grow your real-world, hands on experience. * Bug bounties do not cost you anything (in fact, you can get paid!). * Bug bounties cover a much more diverse and up to date set of security flaws than certifications. * Bug bounties optimize for companies and roles that will respect you more highly, pay you far better and aggressively try to hire you after you find more than, let's say, two serious vulnerabilities in recognizable companies. * Bug bounty recognitions do not expire.
- djcapelis 9y agoThis is the best hot take I've seen on how to deal with certifications in security so far. This is an excellent suggestion.