4 ms·
Not OP, but if you work for a big company the goal of penetration testing runs counter to the goals of the other departments. The more bugs you find, the more t
by kkirsche 4y ago
Not OP, but if you work for a big company the goal of penetration testing runs counter to the goals of the other departments. The more bugs you find, the more that means someone else looks “bad”, so it can become hard to move up in seniority if you don’t have a good leader above you to properly align the interests of both parties so it’s collaborative rather than antagonistic
- InitialBP 4y agoNot an issue I experienced at my old company (a consultancy) but this is a huge factor on security teams that I think is often overlooked. "Old" style security teams often have a "you (wrote bad code|bad config|picked bad libraries), now go fix it" attitude that really doesn't do them any favors. A big part of being on any security team is building rapport with other teams and making sure that the security team is seen as a part of the company and not "the assholes who make us do extra work." Anecdotally it seems like the more the other teams have a strong relationship with security - the more likely they are to consult the team early on and get some input on design decisions and recommendations that reduce the overhead of fixing vulns later on.