3 ms·
I think the only qualification for "security engineer" these days is changing your LinkedIn job description to "security engineer". Unlike SWEs, there isn't rea
by rhexs 4y ago
I think the only qualification for "security engineer" these days is changing your LinkedIn job description to "security engineer". Unlike SWEs, there isn't really any sort of standard leetcode bar for them, which is both a pro and a con.
Lot of snake oil in the field at the moment.
- nonameiguess 4y agoThat seems the opposite of true. They have pretty standardized certifications in the field. CISSP is much more consistent and predictable and known than random sampling of leetcode questions. Of course, you don't need to score 100% on the exam to pass it, and not being familiar with the content of the exam, I'm not vouching for it or anything. But it is effectively the equivalent of something like a CPA or CFA that Software Engineering has no analog of.
- qzx_pierri 4y agoAs someone who recently left a security job at a very prestigious and well known organization.. The person you're replying to isn't wrong. Certifications only prove that you took the time to memorize a set of concepts. > CISSP is much more consistent and predictable and known than random sampling of leetcode questions Even the CISSP is just a test of memorization - The ISC2 cert prep book is 10 miles long, but only about 5 feet deep (if that makes any sense). Being a good security engineer comes with experience and knowledge of basic scams such as caller ID spoofing (something I did to my friends as a bored 6th grader). Being a good security engineer is having a keen eye for small changes and being skeptical about EVERYTHING. Any security engineer worth their salt would never discuss anything containing PII on an inbound phone call.
- antonvs 4y ago> Any security engineer worth their salt would never discuss anything containing PII on an inbound phone call. Yeah. Clearly "security" means something different to him than it does to us.
- nobody9999 4y ago>Even the CISSP is just a test of memorization - The ISC2 cert prep book is 10 miles long, but only about 5 feet deep (if that makes any sense). Except passing the (broad, but shallow) test isn't the real reason why CISSP is a decent certification. Passing the exam is just the first part. You then need to document at least five years of professional infosec experience[0] and have one or more current CISSP holders recommend you[1]. Experience and the approval of your peers are much better predictors of value/knowledge than a test. That's not to say that every CISSP cert holder is a rock star, but it's a lot more than just passing a test. [0] https://www.isc2.org/Certifications/CISSP/experience-requirements https://www.isc2.org/Certifications/CISSP/experience-require... [1] https://www.isc2.org/Endorsement https://www.isc2.org/Endorsement
- wglb 4y agoThere is much doubt about the correlation of CISSP certificate holders and good security engineers.
- giaour 4y agoIf you spend time working in a field that requires a CISSP (like most info sec roles in the US government), you will meet plenty of people who crammed for a test but are otherwise completely incompetent. I would not recommend viewing the CISSP as anything other than an attestation that someone can memorize a few concepts for a test.
- briandear 4y agoWhat the heck is a “standard leetcode bar?” Who does leetcode to prove their worth as an SWE? I know plenty of leetcode aces that couldn’t work on a real world application if their lives depended on it. Leetcode might test the ability to write some academic algorithm from some college textbook, but it doesn’t test real world. There is a reason many top companies don’t use Leetcode or HackerRank: zero prediction of real world skill or systems thinking.
- staticassertion 4y agoI've been a SWE and Seceng. Interviews are extremely similar and extremely easy in both cases. The bar for both is kind of a joke, and it's very much made up.