9 ms·
may I ask if you have any career advice?
by M5x7wI3CmbEem10 2y ago
may I ask if you have any career advice?
- jawilson2 2y agoTry 5 years to get into foreign service, then pivot to IS?
- unixhero 2y agoUnless you have broken software and hardware since the 1990s or 1980s, and then gotten a degree in management or engineering, my path is hard to replicate. But I certainly can offer some advice: 1. Be hardcore and really interested in security. Read everything. Deep diving into networks, software, vulnerability, risk management. 2. Get a CISSP certifiaction, then maybe an ISO 27001 cert and then also something juicy from SANS (I have none of these). 3. Get an AWS or a public cloud of your choice certification Also * Cia triad * Mitre attack framework * Cis controls * Nist framework * Ise 62443 * Zero trust framework from NIST Get work experience, projects, situations, grow and evolve
- tptacek 2y agoIf you're interested in someone else's take on this: don't get a CISSP, and ISO 27001 is generally something a company gets, not a person.
- unixhero 2y agoTrue, it would be more toward security leadership in things like CISO roles or equivalent. Yet if one takes them, they will certainly help.
- tptacek 2y agoAgain, just in case you're interested in a second take on this, no.
- iJohnDoe 2y agoWhy no? CISSP is often requested on job postings for cybersecurity.
- tptacek 2y agoThey're disproportionately requirements for the worst, lowest-status jobs in cybersecurity, and many of the best known and "highest placed" practitioners in the industry (not just in vuln research and xdev but also in management) don't have one.
- hollerith 2y agoWhat does "xdev" mean, please?
- kasey_junk 2y agoExploit development
- tptacek 2y agoTo be fair: this is, like, a 2010 acronym, and I'm dating myself just by using it; I just have a dry-eye thing going today that's making screen time annoying and didn't want to type the words out. :)
- 2y ago