3 ms·
Alright so lots of people are saying certs aren’t worth it here. But as someone desperately trying to pivot from software development (5 year exp) to anything s
by dilDDoS 6y ago
Alright so lots of people are saying certs aren’t worth it here. But as someone desperately trying to pivot from software development (5 year exp) to anything security related (which I find far more interesting), how are you supposed to do that without certs? I’ve done CTF events and performed well, I’ve done HTB for well over a year at this point, and the only time I’ve ever heard back from a company regarding an (offense) security position was basically just to see if I could be persuaded to do software development for their company instead. It’s extremely frustrating.
- tidepod12 6y agoThe annoying truth is that offensive security roles, despite being the "sexy" face of security, are in much less demand compared to defensive security roles. There are some very prestigious pentesting or research shops that pay a lot for highly-skilled offensive security professionals, but they are rare. The average company treats offensive security as an entry-level position meant to attract newbies to security with the "sexy hacker role" before pushing them into more in-demand positions like application security. For context, many of the large companies I consult for have ~5 people max on their red teams, while having 100+ on the rest of their security teams (the "blue" teams). There just relatively aren't that many offensive security positions available. If you really want to do security, then my advice is to either look at some dedicated security consulting shops that do penetration testing (and be prepared to take a pay cut), or alternatively use your software development experience to pivot into an application security role. From there, you might find it easier to get involved with some offensive security efforts through that.
- g_p 6y agoIf you're doing well at CTFs and HTB and similar, I guess you are now at the point where you should start to look at networking. Clearly given world circumstances right now, in-person networking events are not likely to be happening, but it's likely that there's a local community in your area with security people. They might still be doing virtual events, having some speakers etc. Get yourself known. I have been able to get junior people straight out of college/university into roles by getting them into the "networks". There's a worldwide shortage of security people, caused partly by the inability of the people who need them to efficiently hire them (other causes include wanting top-level skills for bottom level pay, and blaming lack of people for their own lack of willingness to pay). The more you get known in your local security community, the better. After a while, perhaps they'll be interested in a talk from you about something as well - it gets you seen and known, and it's much easier to break into security when you're known.
- radditone 6y agoThis is good advice. Go to your local security meetups, network, meet people. Chances are most of the people you talk to are hiring or know people who are hiring. Get yourself a blog, write about your security research, write about your experiences with CTFs. Showing that you care about security enough to do it in your own time is worth more than any cert.
- g_p 6y ago> Chances are most of the people you talk to are hiring or know people who are hiring. Definitely this. And if they like you, and their company isn't hiring, they might even be able to get them to hire you. Good and enthusiastic security people are hard to come by, so you take the ones you can get, if times are good and you think you might need more soon! And even if they aren't hiring, chances are they will be able to make a personal introduction to someone who is hiring - at least in the local networks I've been involved in, there's more demand than there is supply, so people are generally pretty willing to help you make connections with the right people. And at the back of their mind, they will also be thinking how they can always go to you in future to get out of their current place(!)
- capeterson 6y agoDo you have a MS? If you were interested in government cybersecurity work, you could do something like SFS (https://www.sfs.opm.gov/ https://www.sfs.opm.gov/) and get a MS with a pretty much guaranteed gov't job at the end of it. It's also a good program if you want to get working for FFRDC's. edit: They also give a ~$25k-$35k stipend plus tuition, security certs, books, etc. It's a pretty solid deal IMO.
- Beached 6y agoPeople saying certs aren't worth it are only looking at half the picture. EVERYONE knows most certs suck, and the few that are good are drowned out by the volume of half ass shitty certs that are just money grabs. But certs are an unfortunate necessity in a world where fresh college graduates without a days worth of experience in IT or Security are pre-filtering resumes. Certs ARE worth it, to get past HR. I always tell everyone who wants to get into security that the first infosec job is the hardest to get, and for that, you need to play the HR game, and that means a couple certs. You need to sit down in front of the hiring manager for an interview to get the job, your hiring manager will know your cert means nothing, almost guaranteed he never even asks you about any of them. Your resume means everything to get in front of the manager, then your resume means jack shit to the manager. It is stupid, but is the world we live in. You can get hired into infosec without the certs though, and that's know the hiring manager or know someone on the team you are applying for. Hiring managers can tell HR "I want to interview Joe Somebody, he said he will apply this week", and in security, id say more than 50% of the hires are indeed that. So to do this, go to the local professional meetups that meet monthly, go out for beers with the people, go to the local conferences and make friends with many people already in the industry, maybe do a talk at the meetups or local conference. Then when a position opens up at a place where there is someone you know, you now can get an interview. But you really should be doing both at once. Most competent developers or IT people can pass Sec+ blindfolded, you most certainly do not have to take the class, at MOST skim the study guide book once, and your almost guaranteed to pass. It is a joke, everyone in the industry knows it, yet if you could dramatically increase your chances of getting an interview while you are taking the time to develop those relationships, what idiot wouldn't?
- radditone 6y agoI've heard this a lot before and I'm sure its true in a lot of cases. But I've been in security over a decade, and have hired at smaller boutique pentest companies, and multi billion dollar companies. In all cases, the CVs/resumes come straight to us, they never go via HR.
- g_p 6y agoI can sympathize with the comment, and know for a fact it's true in a lot of fields, including ones it shouldn't be done in due to similar skills niches. Despite this, as you say, I've usually seen CVs/resumes come straight to the hiring team - the first thing an effective security lead does ensure there's no pre-screening on CVs, as they want to see the "unconventional" CVs as much as the conventional ones. There's also companies that actively have their techies go out and fly the flag, post on the /r/netsec or HN hiring thread, and give a point of contact straight to a personal or team mailbox.
- guidovranken 6y agoI don't have any certs (apart from malformed X509 files..) so I can't speak of their effectiveness. What has worked for me is having a strong presence in open source. I just show people one of my projects like [1] and nobody asks about certs or education, ever. I spend most of my free time on these projects so cultivating a sizeable project might not be a suitable route for anyone who has a life outside of computers, though having some kind of publicly available utility where a prospective employer can check out your coding style and skills is probably a decent way to stand out amidst a sea of applicants. [1] https://github.com/guidovranken/cryptofuzz https://github.com/guidovranken/cryptofuzz