4 ms·
I went from lead dev (and head of development with 10 years experience) to security consultant about 6 months ago, as security was always a hobby of mine. If y
by howlett 9y ago
I went from lead dev (and head of development with 10 years experience) to security consultant about 6 months ago, as security was always a hobby of mine.
If you look at my previous comments I always say the same thing: get the OSCP certification. It will definitely get you an interview but the course is hard and demanding.
Also, get ready to take a paycut and a role downgrade as 4 years of pentesting have more value than 10 years of development.
Obviously you bring other skills to the table like better client communication and knowing how things work under the hood, but you'll have to take a step back before you take two steps forward.
I definitely recommend you go that way, but think hard before you do, and please be sure it's not because you're "bored".
Last but not least, prepare to travel to clients. Sure there is the "internet" and "vpn" but a lot of clients have internal apps need testing and do not give you remote access.
If you have any questions I'll be happy to help out.
- gdfer 9y agoThanks, helpful for sure. Yeah I'm not looking just because I'm "bored", I suppose it's a myriad of reasons but that is one of them. Why did you decide to make the change to security consultant? How were your security skills before you decided to make the change? You said it was a hobby, but for how long? I'm thinking I'll have to carve off time for a while to invest into learning the new hobby then see where I'm at in 6 months time.
- howlett 9y agoThe reason I switched was because pen testing is in really high demand and will stay that way for a few years to come. Also, I didn't want to get full time into management at this point. My security skills were average (hobby for about 10 years but mostly because I was a web developer) but like I said the OSCP did most of the work in terms of getting the interview and doing any technical test. The course itself took about 2 months, 6 hours every day after work, and fulltime weekends! My suggestion would be to do the OSCP course and if you like it then go for it. There is also vulnhub.com which has a lot of CTF VMs where you can practice (I personally dislike CTFs because I find them unrealistic).