32 ms·
The article focuses exclusively on the technical side. No, certifications are not required. Sure, they will get your resume higher on the list. Security is muc
by kafrofrite 6y ago
The article focuses exclusively on the technical side. No, certifications are not required. Sure, they will get your resume higher on the list.
Security is much more than simply breaking stuff. You need to understand the fundamentals, CIA triad, risk, misunderstandings that arise from the fundamentals, issues that generally arise with security due to the context etc. Debunk also some common myths around security. Fundamentals can land you in tables that technical skills won't. It is one thing to land bugs and another to be able to sit in a meeting with a guy from engineering and reason with his team and reach an agreement. Generally, working with non-security folks is hard and knowing the fundamentals helps. This also requires soft skills. Know your limits and be honest about them. Also, it is good to listen to people and their concerns. Generally, soft skills are super important in security because in most cases your opening statement is going to be one of the following:
- I found some bugs that I want to discuss with you.
- You did X which violated that policy and it rang an alarm in SOC.
- We have this issue and I came up with this plan to build this to address it.
Being able to calm the other side is crucial or you risk derailing the conversation. Also, being able to write code helps a lot. As a matter of fact, I forced team-members to work for other teams for two months. Not only they brought skills back, my team now had an understanding of their work and potential pain points.
Being able to understand the pain of the other side and also come up with solutions (incl. writing code)
If I started again, I'd do the following:
1) Understand the fundamentals and the limitations
2) Build stuff. It helps relate with people.
3) Break stuff. It's fun and useful to understand what went wrong.
4) Have a broad knowledge but focus on specific fields. Some people like defending, some people like attacking, some like building stuff.
5) As every job, it has its laundry list and boring tasks that people need to make. Yes, Excel spreadsheets are a thing in infosec.
6) Don't focus too much on certifications.
Worthy reads
[1] https://www.freecodecamp.org/news/so-you-want-to-work-in-security-bc6c10157d23/ https://www.freecodecamp.org/news/so-you-want-to-work-in-sec...
[2] https://lcamtuf.blogspot.com/2016/08/so-you-want-to-work-in-security-but-are.html https://lcamtuf.blogspot.com/2016/08/so-you-want-to-work-in-...
Edit: Saw this[3] comment. That comment reminded me of something. We've had, time and time, candidates with certificates that could do exploit stuff but couldn't use SSH. One of my first hiring questions was "How do you use SSH" and "How do you delete files from the terminal". I wasn't sure whether this guy was making fun of me or my resume sucked. Apparently, the guy was fed up with people not knowing to use a system that he started asking such questions regardless if you had a Ph.D. in Computer Science.
[3] https://news.ycombinator.com/reply?id=25814333&goto=item%3Fid%3D25812025%2325814333 https://news.ycombinator.com/reply?id=25814333&goto=item%3Fi...