4 ms·
A LOT of shops require OSCP to even get an interview. I know for a large number of them that OSCP is indeed a hard no go if you do not have it. Unless your pla
by Beached 6y ago
A LOT of shops require OSCP to even get an interview. I know for a large number of them that OSCP is indeed a hard no go if you do not have it.
Unless your plan is to go it your own, and either start your own business or go black hat, OSCP is indeed good advice.
- g_p 6y agoOut of interest, are these larger, and more "corporate" focused shops? I have directly worked with a range of client companies, and none cared about certs (even government!) I'm wondering if OSCP is an "easy resume filter" in a time of online job applications being easier than ever before, rather than something they have a business need for, as their clients demand it?
- Beached 6y agoThe clients dont care, the shops care. The shop that will hire the pen tester onto their staff are the ones that do the filtering of applicants based off certs. The reality is that OSCP is very hands on focused in training and examination. For the most part, based in real world skills and tools. Certs like CEH, Sec+ do jack shit for real world application, and focus you into memorizing things. At least passing the OSCP means you are competent in at least the basic tool set usage and application in an lab environment, which is more than most can say. Sure, you can be a competent pen tester without it, many are. but when you are staring down 100 resumes, where people spend more time making their resumes look good than they spend on polishing their skills, OSCP actually does its job in creating a known baseline of skills better than most other certs. (What certs are supposed to do) Rarely have I seen clients care about the pen tester having OSCP. It has always been the employer that has cared.
- tptacek 6y agoI'm sure there are a bunch of marginal firms that require certification, but that's a strong tell that you don't want to work there. Pursuit of certification is not good advice.
- vsareto 6y agoOSCP kinda sucks because the pentesting industry kinda sucks (I have OSCP). Things are different now since there's a ton of guides and videos specifically for it. Long term, you're better off being a developer and getting into security that way. Plus you're going to learn to program as a pentester anyway. The job market and day-to-day and salary is also much better. It is hilarious how necessary/important security is but pentesters seem to get low salaries and have high barriers to entry.
- tptacek 6y agoI think this is true of netpen work, which is heavily commoditized, but much less true of vuln research and appsec, which are the fields you're shooting for by learning to code. I generally agree that developer -> security is the right way to go.