3 ms·
I think you guys are comparing apples to oranges > Certification in a field such as vulnerability research OSCP is basically tool-based network pen testing wi
by nulldev 9y ago
I think you guys are comparing apples to oranges
> Certification in a field such as vulnerability research
OSCP is basically tool-based network pen testing with a bit of outdated websec and buffer overflows thrown into the mix. It's not "vulnerability research" in any meaningful sense of the word. They have some other certs (OSCE) that might purport to target that domain, but idk much about them.
> As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications
So apparently OSCP won't get you a job at Matasano - but they're not the only game in town, and a lot of other security shops with less name recognition and lower standards do in fact use the OSCP as a positive signal.
No, it won't be l33t but it will be a job that they can use to transition to those fancy schmancy companies whose founders are HN regulars.
- tptacek 9y agoName a pentesting firm that cares about the OSCP.
- nulldev 9y agoThe pentesting team at SEI-CERT cares about it.
- raesene6 9y agoIn the UK OSCP can be used for CRT equivalency and I know that many/most pentesting companies care about CRT/CCT qualifications in the UK, if only because they're a requirement for doing work for some government departments, and also some financial services companies will use CREST certification as a check for testers doing work for them. So in that sense, they do care about OSCP.
- carterehsmith 9y ago> Name a pentesting firm that cares about the OSCP. Here: https://rhinosecuritylabs.com/company/ https://rhinosecuritylabs.com/company/ lists OCSP and CISSP and a bunch of other certs. So I guess they care about that. Now, how about you name the pentesting firm that does not list any certs.