4 ms·
None of those are necessary, though it depends on what your desired path is. Here’s one approach: 1) Find several local security meet-ups and get involved. Vo
by valiant-comma 7y ago
None of those are necessary, though it depends on what your desired path is.
Here’s one approach:
1) Find several local security meet-ups and get involved. Volunteer, talk, make friends. Network early and often, ask questions and learn.
2) Using the contacts and exposure developed above, find either an internship or contract role doing whatever security-related work you can find. You will (most likely) need to pay your dues, meaning it might be pretty basic security work to start with, but you’re looking for experience and further opportunity to grow your skills.
3) On the pentesting side, you’ll want to learn the target systems well (e.g., use them in practice), learn the common types of vulnerabilities and how to exploit them, and immerse yourself in opportunities to use your nascent skills (online challenges, capture-the-flag events, etc.). Read vulnerability reports published by other researchers, watch relevant videos, experiment on your own setups, and so forth.
4) As you feel more comfortable with your assessment skills, you might consider entering bug bounty programs.
Again, this is just one approach, there are many options depending on what works for you. Best of luck!
Edit: Line breaks.
- badrabbit 7y agoWhat you said sounds good but I have never heard of anyone that got into infosec this way.
- valiant-comma 7y agoThey exist; I’ve hired a few myself who’ve chosen this path. But it’s just one of many approaches to get into security as a career, and there are many. Along these lines, I highly recommend Rachel Tobac’s talk “The Path to Infosec is Not Always Linear”[1]. [1] https://www.youtube.com/watch?v=rWAeDVo8mXc https://www.youtube.com/watch?v=rWAeDVo8mXc
- relaunched 7y agoMy team has hired at least one that way and it's how we encourage others to develop skills.