6 ms·
Get into security, specifically web app security pentesting. You'll thank me later.
by bashwizard 6y ago
Get into security, specifically web app security pentesting.
You'll thank me later.
- thatcodingdude 6y agoThis and the servers/linux stuff is the most interesting part of my job. I do have my doubts about being able to get into it since I suppose you really have to master low level dev (which I don't) and I don't think I can get a job as self-taught in this field.
- bashwizard 6y agoWhy not try it out by start messing around with it and get a feel for it? But to answer your question: no, you don't. You already have more than enough prerequisites for an easier transition. https://pentesterlab.com https://pentesterlab.com https://portswigger.net/web-security https://portswigger.net/web-security Have fun! Edit: I'm completely self-taught and I've been working in the field for a few years. No dev or even IT background prior to getting into network pentesting and web app pentesting.
- thatcodingdude 6y agoNeat, thanks for the advice. Pentesting got a spot on mr. learning list's wild ride.
- frenchman99 6y agoIf you like devops and security, have a look at SRE (Site Reliability Engineering) positions. Companies look for software engineers to fill these positions. And you'll work on security related stuff. Not necessarily pen-testing per se, but network security, operational security, etc. Also, teams with SRE expertise most likely use modern tech because SRE itself is a rather new way of managing infrastructure. So you'll probably be able to get your hands dirty with lots of cool tech.
- thatcodingdude 6y agoNice, thought you needed sysadmin background for SRE. I'll look into that, thanks.
- ta17711771 6y ago> I don't think I can get a job as self-taught in this field. Good security firms are the last ones to gatekeep over a degree or other paper.
- pakwa 6y agoCurious - why do you suggest this field?
- dencodev 6y agoI'm looking to go into this field too and would also like to hear why
- bashwizard 6y agoIt's a rapidly growing field that has more jobs than people. Meaning, at this point if you have a solid dev background and strong practical skills in security you're most likely going to make bank. While anecdoctally speaking, I know people who switched from senior dev positions at two of the FAANG companies to smaller security companies and basically doubled their income and making north of $500k/year.
- thatcodingdude 6y agoAny way to contact you for learning/career advice ?
- bashwizard 6y agoWhat I can share is my roadmap how I manage to break into the field without any prior professional IT experience. 1) Linux. Learn it and live in it. 2) Linux servers and databases. 3) CompTIA Network+ (only for the knowledge, didn't bother getting the cert) 4) CompTIA Security+ (same as above) 5) OSCP certification (not a golden ticken by any means but it helps to bypass HR) That's basically it. While going down that road I focused on hands-on practice by actually hacking into machines with the help of following resources: A) Hack The box (hackthebox.eu) B) PentesterLab (pentesterlab.com) I also really like Portswigger's Web Security Academy (portswigger.net) and Try Hack Me (tryhackme.com) but they weren't around when I was starting out but I would definitely check them out, especially if I was completely new to security today. All in all it took me roughly a year but get comfortable enough to start applying to junior pentesting positions and eventually I got hired. There are probably better and easier ways to do it but that's how I did it at least.