5 ms·
This was fascinating! If I could do it all over again, I'd have gone into the US Foreign Service. Maybe not to places like North Korea (which we don't have a pr
by stuff4ben 2y ago
This was fascinating! If I could do it all over again, I'd have gone into the US Foreign Service. Maybe not to places like North Korea (which we don't have a presence in anyways), but I'd have loved to travel the world. Maybe in the next life...
- unixhero 2y agoSure, if you could get in. I tried for 5 years in a row to get into my country's service. It failed. Pivoted to information security, hey at least I am a millionaire now.
- M5x7wI3CmbEem10 2y agomay I ask if you have any career advice?
- jawilson2 2y agoTry 5 years to get into foreign service, then pivot to IS?
- unixhero 2y agoUnless you have broken software and hardware since the 1990s or 1980s, and then gotten a degree in management or engineering, my path is hard to replicate. But I certainly can offer some advice: 1. Be hardcore and really interested in security. Read everything. Deep diving into networks, software, vulnerability, risk management. 2. Get a CISSP certifiaction, then maybe an ISO 27001 cert and then also something juicy from SANS (I have none of these). 3. Get an AWS or a public cloud of your choice certification Also * Cia triad * Mitre attack framework * Cis controls * Nist framework * Ise 62443 * Zero trust framework from NIST Get work experience, projects, situations, grow and evolve
- tptacek 2y agoIf you're interested in someone else's take on this: don't get a CISSP, and ISO 27001 is generally something a company gets, not a person.
- unixhero 2y agoTrue, it would be more toward security leadership in things like CISO roles or equivalent. Yet if one takes them, they will certainly help.
- tptacek 2y agoAgain, just in case you're interested in a second take on this, no.
- iJohnDoe 2y agoWhy no? CISSP is often requested on job postings for cybersecurity.
- tptacek 2y agoThey're disproportionately requirements for the worst, lowest-status jobs in cybersecurity, and many of the best known and "highest placed" practitioners in the industry (not just in vuln research and xdev but also in management) don't have one.
- hollerith 2y agoWhat does "xdev" mean, please?
- kasey_junk 2y agoExploit development
- trallnag 2y agoWhat currency
- bozey07 2y ago> Maybe not to places like North Korea (which we don't have a presence in anyways) Sure they don't ;)
- jrockway 2y ago> Maybe in the next life... I told myself this about an important decision. I thought about it more and decided I didn't really believe in that (proof: what do you remember from your last life), so just did it in this one. No regrets!
- pasquinelli 2y agoyou'll eventually forget this life too, so i'm not sure about your proof ;)
- kevindamm 2y agoA consistent, but perhaps incomplete, model.
- Xeyz0r 2y agoJust do IT!
- shagie 2y agoOn one of my flights out of... I forget if it was SJC or SFO - but it was one of them... I sat next to someone in uniform and we got to talking. He was a former dentist who joined the military and was studying in Monterey his fifth foreign language https://www.dliflc.edu https://www.dliflc.edu