4 ms·
How can I get into this field? I used to love doing pen-testing when I was a teenager, and paid for my first car out of bug-bounties. Unfortunately, I got dis
by jomkr 9y ago
How can I get into this field?
I used to love doing pen-testing when I was a teenager, and paid for my first car out of bug-bounties.
Unfortunately, I got distracted by girls and booze at university and didn't keep it up, now I work in sigh enterprise C#/WPF land.
- devwastaken 9y agoHow'd you get into enterprise C#/WPF land?
- IIAOPSW 9y agoStart as a pen tester then get distracted by girls and booze.
- chrisbennet 9y agoYou say that like its a bad thing. ;-)
- deleted 9y ago[deleted]
- jomkr 9y agoJust sort of fell into it. Did an internship at university in $genericbigcorp and didn't bother looking for other/better jobs at graduation. (To be fair they paid a generous joining bonus - well £2000 "generous" to my broke 21 year old self).
- OpenDrapery 9y agoThat's the path of least resistance. Just passively accept calls and interviews via recruiters, and next thing you know you're in the enterprise. It's what happens when you don't have a plan.
- unixhero 9y agoDidn't we all. (Similar story:) )
- jomkr 9y agoDon't regret the good times for one second, but do get very jealous of people on HN talking about all the exciting tech they're using and awesome work environment. I am actively taking steps to move to a better company, but my god I'm finding Cracking The Interview Code a slog.
- mxuribe 9y agoSame here...and then add on that I'm actually over 40...and oh boy, does that code get tougher to track. Funny how in some circles deep and long experience in tech is respected...but companies often look at me and ask "What will you do for me lately?"...and look at my age, and likely assume that I'm slowing down; when just the opposite is happening, i'm speeding up in terms of complexity of tech i'm diving into. Weird; but i feel your pain!
- fundabulousrIII 9y agoTry it at 50. It's not a good field to be in at either of these ages unless you are in technical mgmt, architecture or direction.
- ohm 9y agoSource code review is in high demand. Many companies are happy to train a developer on how to do it.
- janfry 9y agoDaniel Miessler has a good general guide: https://danielmiessler.com/blog/build-successful-infosec-career/ https://danielmiessler.com/blog/build-successful-infosec-car... tptacek, who posts often on HN, also has some wise words: https://krebsonsecurity.com/2012/06/how-to-break-into-security-ptacek-edition/ https://krebsonsecurity.com/2012/06/how-to-break-into-securi... There are so many sources of information and learning grounds available now - bug bounties, certifications, war games, online tutorials, blogs, conferences etc. I would suggest choosing a particular area of interest to begin with and deep-diving on that subject. Look for mentors or perhaps someone to knowledge share / skill exchange with. You could do pretty well with a base in C#. Through pentest engagements, I've come across quite a few C# apps in my time and even with my limited knowledge of the language, found some interesting vulnerabilities ;) Edit: Added tptacek link
- secu 9y agoI'm in my late 20s and got into the field professionally just a couple years ago. Prior to that I had been working as a software developer. I believe what helped was a handful of personal projects related to security: reverse engineering firmware, finding bugs in web apps. Also I emphasised the parts of my software development work that had some overlap, such as debugging Windows kernel drivers, and doing security reviews of network services we were writing and deploying. Now I'm doing full-time vulnerability research and writing software to help do that. Much more enjoyable and pays better too.
- tetrep 9y agoYou don't need a college degree to do pentesting. I don't think anyone credible in the industry cares where you got your education, as long as you know what you're doing (or in the case of juniors, are able to learn).