#cyber-and-careers

1 messages · Page 5 of 1

pseudo creek
#

No I'm good

#

So you want to go to a community college to avoid taking a test? I mean that's not a bad plan but it still may not me as easy or as cheap as you think

warm hinge
#

dumb question

#

so....

#

@pseudo creekcan i get an associate degree from university? or it is a degree only from college?

pseudo creek
warm hinge
pseudo creek
#

An associate degree is basically a general studies degree with a few specific classes thrown in

warm hinge
pseudo creek
pseudo creek
#

So basically no matter your route, your first 2 years of college are general studies. History, English, math, science, social studies. Then the last 2 years of college are specific to your degree

#

Lots of people fulfill the first 2 years at a community college

warm hinge
#

hem....

#

bachelor takes 4 years at leats but if u go for associate first it will take only 2, based on points x h

pseudo creek
#

well because associate is the first 2 years of a bachelors but a bachelors is required at the minimum I believe for immigration to the US unless you pursue other means

#

and an associates isn't really valued much in the US, it is better than a high school diploma but it is also very generic

warm hinge
#

it is a pre-degree

pseudo creek
#

yes

warm hinge
#

we don't have that here

#

so at the start it hit me like tf is this?how to learn this etc

#

i was shocked

pseudo creek
#

like an associates seems equivalent to the UKs 16-18 year old education

warm hinge
pseudo creek
#

GSECs is what I think they call them?

pseudo creek
warm hinge
#

i don't have any idea

pseudo creek
#

nah just statement

warm hinge
#

also...

#

how to get associate degree? i mean about grades

#

they have GPA scales, but we have like number grade e.g 7/8 etc

#

do i need to meet the minimum req to earn an associate/bachelor?

#

user comment: Otherwise, if you are going to invest 2 years, you may be better off taking a masters degree in your present field or get an MBA. Though you generally need a GPA in your bachelors of 3.0 or better.

pseudo creek
#

you do, generally its a 2.0 out of 4.0

#

but if you plan to go for a masters, you'll need better grades than the minimum

warm hinge
#

lets do in my grade to undertsnand better😅

#

imagine i have 6 out of 10 in my diploma ok? will it be enough to go to a college/university in USA?

pseudo creek
#

no

#

but you'd have to talk to someone who specifically knows about how grades are done in your country

warm hinge
#

6 out of 10 is.... 60 out of 100

pseudo creek
#

which is pretty bad in US terms

warm hinge
#

but

#

in EU is not bad also

#

in USA there are people who are bad at school but then go to university

pseudo creek
#

that is why I'm saying, maybe college admissions would look at you differently being from Switzerland

warm hinge
#

my grades are not very high in my school

pseudo creek
warm hinge
#

u mean going for a associate degree (community college)

#

2 years to try to be good

#

because community college accept everyone while university not

pseudo creek
#

kind of, but you don't even need an associate degree, you just need to meet the requirements of the university

warm hinge
#

u mean this righT?

pseudo creek
#

so a community college accepts everyone within that community

warm hinge
pseudo creek
#

but basically a university can still reject you if you go to a community college

warm hinge
flat sedge
#

Community college also has a different goal than a 4 year university. Community colleges focus on vocational training, not preparing the student for further academia.

flat sedge
# warm hinge based on what? they need proof to reject

They don't, actually. Candidates can be rejected for not meeting minimum academic standards, but even good grades isn't a guarantee of admission. Most universities have a limited number of new students they can bring in each year.

pseudo creek
#

but you should also target a community college in the state of the university you want to go to

warm hinge
#

in switzerland we have 12 univerisity, in USA more than 4k

pseudo creek
#

and universities have quotas for foreign students / students on a student visa

#

we also have 330 million people

warm hinge
pseudo creek
#

our universities aren't empty

pseudo creek
pseudo creek
#

public universities reject thousands of people every year

warm hinge
#

imagine privates

warm hinge
pseudo creek
warm hinge
#

because?

#

bad grades?

pseudo creek
#

not meeting academic standards, the university being at capacity, and for foreign students, there is a hard quota of how many students they can accept

#

people can have great grades and a crappy entrance essay and be rejected

warm hinge
#

then mostly won't go to university....

pseudo creek
#

yes and most don't

warm hinge
#

so

#

i should have been born in USA

#

....

pseudo creek
#

even that won't guarantee you entrance to a university

warm hinge
#

....

#

so half of US citizens aren't graduated?

#

i mean most of them

#

don't have any degree

pseudo creek
#

yes most of them don't have a college degree

warm hinge
pseudo creek
#

but there are various options available, non traditional schools as an example or for profit schools which are less academically inclined if you pay $$$

pseudo creek
warm hinge
#

normal diploma i mean

pseudo creek
warm hinge
#

i think $ is most important xD

pseudo creek
#

there are 2 options in the US... you can 'test out' and get an equivalency diploma

warm hinge
#

they can close an eye

pseudo creek
#

but lots of people drop out of high school and test out either when they are young or later on

warm hinge
#

wait

#

ur saying i should leave my high school rn to go to finish in USA?

#

only 1 year before my diploma?

pseudo creek
#

oh no no no

#

you still need to get a student visa

warm hinge
#

my parents will do that

#

i just have decide what i want to do and how

pseudo creek
#

I mean you have to meet requirements to get a student visa

#

why do you want to come to the US?

warm hinge
#

and i would work there

pseudo creek
#

have you been here?

warm hinge
#

there are US citizens who comes to study here, why i can't go there then?

warm hinge
pseudo creek
#

I mean I'm just asking, lots of people have an idealized view of the US

warm hinge
#

@pseudo creeki would work here (dm)

#

u can get idea maybe

pseudo creek
warm hinge
#

ok

#

i thought i couldn't link

#

instead i can

pseudo creek
warm hinge
pseudo creek
#

in order to work for the Gov, you'll need to be a US citizen and go through extensive background checks. Now switzerland isn't a frenemy country but still ties to another country make it tricky to work for the NSA (CIA, FBI, etc)

warm hinge
#

most of whistleblower where from usa

#

e.g snowden

#

they do a background check etc

#

polygraph exam

pseudo creek
warm hinge
#

if it is all correct, why would be a problem?

warm hinge
pseudo creek
#

basically the background check includes finding out if you have ties to other countries...

warm hinge
#

if u don't have nothing to hide

#

it is ok

pseudo creek
#

no you don't understand

#

but look, I'm done

warm hinge
pseudo creek
#

a foreign national with an aim to work for the NSA is a big red flag

warm hinge
#

ah

#

i can get what u say

#

but if i will live there etc, won't be a red flag right?

#

once u get US citizen

pseudo creek
#

it will take years to become a US citizen but even not all US citizens are eligible for clearances / working for the gov

warm hinge
#

if u think am crazy or smtgh, i dont get it as an offense

wintry saddle
#

hellooo

cobalt reef
#

so i've almost finished a ba of IT, thinking of shifting towards security engineering.

any recommations for certs/courses i could pair with the ba with a sec ops/ security engineering focus?

was thinking CISSP is probably the one i've heard of the most hoping for some extra input tho or if the extra certs even worth chasing up

stoic cave
#

Foreign Nationals can get low level clearances but it's an extremely difficult process.

#

You'll also have to renounce your citizenship to your home country and you're going to put your family through a lot.

stoic cave
#

No

#

You have to swear your allegiance to the US. That goes for just getting a citizenship without a clearance too

#

I can tell you right now, you're not working for the NSA

#

I'm not trying to be rude, just realistic

clever rain
# cobalt reef so i've almost finished a ba of IT, thinking of shifting towards security engine...

@cobalt reef You might not be aware but there are experience requirements to get the CISSP (https://www.isc2.org/Certifications/CISSP/experience-requirements#:~:text=Candidates must have a minimum,year of the required experience.), even if you pass the test. Have you thought about what exactly you might want to do within security engineering? (Cybersecurity is a very broad field)

Do you qualify to take the CISSP exam? View the experience requirements.

stoic cave
cobalt reef
clever rain
# cobalt reef was under the impression security engineering was its own field of cyber and cov...

Bigger companies will have the role more defined; smaller companies likely will not. For example, I've held the title "security engineer" but also had to do GRC (Governance, Risk, Compliance) activities. In the real world, it really depends on the organization but the CISO mindmap by Rehman might help visualize the different areas: https://rafeeqrehman.com/2022/04/24/ciso-mindmap-2022-what-do-infosec-professionals-really-do/

Let me start with the quote from last year: Most people outside the Cybersecurity profession don’t fully realize and appreciate the complexity of a security professional’s job. Since 2012, CISO MindMap has been an effective educational tool and has enabled … Continue reading →

clever rain
cobalt reef
serene umbraBOT
#

Gave +1 Rep to @clever rain

cobalt reef
#

but essentially since i've done alot of programming informally before my degree and outside of work as well as a fair bit of penetration stuff simply for the fact i wanted to know how it worked was seeing if there was a way to combine them and from what i saw security engineering sort of fit that but ill look through the link you sent me

clever rain
# cobalt reef but essentially since i've done alot of programming informally before my degree ...

Sounds like you have the right mindset! The only other thing that I'd add besides focusing in on the area that you enjoy, is making sure that whatever you are doing is providing value to the organization. This way of thinking can become muddy very clearly if you work in a large vs small vs finance vs NPO vs healthcare etc. Whether "right" or "wrong", if whatever you are doing is consistently perceived as "blocking" the business/organization, then there will be struggle/conflict. Of course organizational leadership could be hard headed and fine to accept organizational ending risks so we might have to stand our ground (or leave) but whenever possible, saying "Yes" with conditions will likely get you much farther than flat out "No! We absolutely cannot do that because of <insert valid reason". This becomes a lot easier to do if you working in a part of security engineering that you enjoy while understanding how the organization works. Good luck my friend!

flat sedge
#

"Sure you can do <really dumb thing>. I need you to get sign off from your director all the up to VP for me to approve the change for SNMPv1 to be put on the public DMZ"

clever rain
# cobalt reef thanks that's a huge help and makes sense i got place into an "it management rol...

@cobalt reef one more final thought...I have degrees and a bunch of alphabet soup and so do most of the folks in my team. However, I hired almost 10 security engineers this year and not once did I screen CVs for certifications/degrees or ask if they have a degree or cert. Obviously this is anecdotal but it "feels" like many of the "good" organizations to work at don't care about certs as much as before (just my observation, I have no data to back up my statement). I'm probably opening up a huge can of worms here so to clarify: I'm not suggesting that certs are worthless (you absolutely have to have them to work for the DoD or consulting for example) but maybe focusing on projects, networking (like TryHackMe forums), and experience might lead to better opportunities and certs are just icing on the cake. Not sure if this helps but food for thought at least. EDIT: Clarified by adding "...I screen CVs for certifications/degrees"

cobalt reef
#

thanks for the help everyone

ill keep those things in mind you guys have cleared up alot for me

cobalt reef
stoic cave
#

I would say that virtualjj's case is unique. I would consider getting your security+ as it will likely make things easier paired with a degree.

#

Also, idk how I feel about not reading people's CVs. Those people put time and effort into preparing the document and to me at least, not taking a look is kind of not respecting their time. I do however see the flip side of not wanting to introduce bias.

#

I'm also assuming you said CV meaning resume.

cobalt reef
#

but ill most likely get a security+ cert to pair with my degree

stoic cave
#

Yes, so I think i pinged you earlier, but Sec+ is a fundamental cybersecurity cert

cobalt reef
#

given CISSP needs the formal work experience

stoic cave
#

CISSP has the work experience requirement

cobalt reef
stoic cave
#

Yes

#

Yes, that's the ping I was talking about

cobalt reef
#

oh okay

#

is there any other certs that i would need at this point or would a degree and sec+ be enough

stoic cave
#

I only had a degree* and a company took a chance

cobalt reef
#

oh okay awesome

stoic cave
#

But it would have been a lot easier if I had Sec+

#
  • because I have a clearance
cobalt reef
#

yeah that makes sense

earnest swift
# cobalt reef so i've almost finished a ba of IT, thinking of shifting towards security engine...

The CISSP is not not a very technical exam. I've heard it described as a "mile wide and an inch deep". I feel that the test teaches you language you need to be able to translate between management and security team. I think its a worthwhile certification and you will likely learn a lot, but I would look into it and make sure its the things that you want to be learning.

If you want see what training I used for passing the CISSP, check out the playlist below. FRSecure runs a CISSP Mentor Program every year and it is fantastic. https://www.youtube.com/playlist?list=PLETKkWHNA3qjMWR61bBseaI1J_3zP5tlp

earnest swift
stoic cave
earnest swift
clever rain
proud tangle
#

internally should be internal

thin cape
#

You are right but thats what i received by mail

proud tangle
#

Then I'm not sure what you're question is

warm hinge
# earnest swift If you are short on the required experience, you can still take the exam. When y...

The thing is, the CISSP title is what is most important about this cert, not ability to pass that exam. This is managerial cert, and 'associate of ISC2' does not do much for you really in this realm. If somebody wants some ISC2 certs, there are lower certs with lower experience requirement. Passing exam, and paying fees for years and not being able to use the cert is pointless imo, especially that it's not a cheap exam.

pseudo creek
#

(CISSP isn't a managerial cert in the US)

warm hinge
#

Well, yes, a lot of certs lost value in US :D Still, experience is most important part of this cert, and the title. What is the point of spending that money if you cannot even use the title?

pseudo creek
#

well I agree with that

#

CISSP in the US is good for people once they have been in cyber for a few years, want a promotion / higher responsibilities / etc

#

I don't recommend people get CISSP until they have the experience requirement

warm hinge
#

I know that some companies want it for entry level jobs, and I have no clue why. I think ISC2 needs to communicate better or something?

#

yeah, this

pseudo creek
#

you actually know they want it for entry level jobs or are you looking at mismarked jobs on LinkedIn/Indeed?

warm hinge
#

I saw with my own eyes CISSP for L1 helpdesk in big enterprise. I need to start taking screenshots. It's was definitely an exception, not rule.

#

I know that P&G demands having CISSP or doing it up 6 months from employment, regardless of the sec role you have there.

#

At least it's not prerequisite.

pseudo creek
#

well my company basically wants any mid level cyber person to have CISSP regardless of role

warm hinge
#

but yeah, mismarked jobs are the problem too

#

midlevel makes sense, it implies some decent exp

#

midlevel in sec is pretty far :)

pseudo creek
#

well like 5-7 years in

odd sparrow
#

about to apply to an infosec associate analyst job at a previous healthcare system I worked at, wondering what you guys think of my resume? i have a non-IT background and most my experience is in clinical pharmacy. currently pursuing other certs (Az-900, CySA, net+) and upgrading my computer to virtualize a home lab, but haven't started yet. if i should add, edit, or remove any sections to make it more impactful, any advice appreciated!

warm hinge
#

So, ok for cissp, exp fullfilled, but demanding it for entry roles or from people straight from college is not really great, imo. Idk... there are other certs to validate people's knowledge. Also, it's a different story when company pays for it too. Just people without exp, even if they pass exam, cannot call themselves cissp, so what is the point to require that?

#

I suck in resumes, so I back off in that. Check Blue Teams Labs Online, they have solid labs.

stoic beacon
# odd sparrow

i would remove tryhackme from the experience section, i don't think most places are gonna care about experience outside of a real world environment

warm hinge
#

but it may be worth to put into personal interests/projects

stoic beacon
#

that, and THM boxes are left insecure in some way so as to facilitate learning, whereas real life machines are much more limited in scope and rules of engagement. don't get me wrong, thm is a great resource for learning, but i don't think any company would consider it a valid reason to hire you

stoic beacon
pseudo creek
# odd sparrow about to apply to an infosec associate analyst job at a previous healthcare syst...

so your summary basically doesn't mention cyber until the last 3 words... Basically you should focus on saying you are looking at pivoting... like "Healthcare professional ... then you start talking about your interest in pivoting your career and focus on cyber after that or else you lost me"

"professional experience" - I would include some blurbs on how you work on a team, any leadership, etc. I'd drop the internship

"certifications and training" - keep security+ here but drop the other stuff and put in another section near the bottom

"skills" - I hate to say it but no one really cares if you can use Windows, macOs or office... if you can administrate that, its a different story. I'd build this out a bit include things like "vulnerability application testing using tools such as..."

"non-professional experience" - change this title to something like "personal development"

As you are probably aware, your resume is really lacking. Do you have a github or writeups or something you can share? Also, what is your overall goal, what type of position do you want?

warm hinge
# stoic beacon that, and THM boxes are left insecure in some way so as to facilitate learning, ...

Not a valid reason to hire, not, but it shows that you are interested in the topic and learn around. Of course it does not count as real work experience because it's a ctf, at the same time in 'personal development' it can help. It of course depends if hiring company cares about it. Imo, building virtualized environments, even small, treating them as real world projects, hardening and all, and documenting it well technically and from project management angle, may help.

stoic beacon
warm hinge
pseudo creek
stoic beacon
#

another tip; i personally make my resume as modular as possible so it's easier to specifically tailor to any job listing i apply to

#

customer service? emphasis on customer service experience, resolving issues quickly and efficiently, etc. security? emphasis on security, monitoring cctv and security centers, etc

odd sparrow
# pseudo creek so your summary basically doesn't mention cyber until the last 3 words... Basica...

I have a github, but only has a few simple python projects from guided videos and courses (like snake, pong, and jumper frog), nothing cyber related. Only writeup is a reddit post detailing how I passed the sec+

Overall goal is to pivot initially into an analyst role, and to work towards working in a blue team environment, specifically SOC, IRT, or forensics. I have an interest in cloud security as well

stoic beacon
serene umbraBOT
#

Gave +1 Rep to @outer swift

odd sparrow
#

would it be better to just remove the publications section since it's not IT/cyber related?

pseudo creek
pseudo creek
warm hinge
# odd sparrow I have a github, but only has a few simple python projects from guided videos an...

My 2 cents: Proficiency means high level of skill, basic or intermediate proficiency makes no sense. Also, don't mix systems and tools into one category. Pick few skills you know best, and focus on them. If you want to go to analysis, consider doing BTL1 - it has a practical exam. BTLO have a lot of investigations, and these are labs, not tutorials, so to some extent they show your skill too. Write few solid reports - employers love good documentation/report writing skills.
Check Jason's Blanchard (Banjo Crashland) job hunting videos on youtube. There is a lot of good advice there for people without experience.

pseudo creek
#

oh which reminds me... this is a pretty solid video on writing a better resume https://www.youtube.com/watch?v=uqhOlOdwavU&t=672s

Thanks to our sponsor, Snyk. You can check out the Snyk CTF at snyk.co/tcm

Sample resume template: https://github.com/hmaverickadams/Sample-Pentest-Resume


Pentests & Security Consulting: https://tcm-sec.com
Get Trained: https://academy.tcm-sec.com
Get Certified: https://certifications.tcm-sec.com
Mer...

▶ Play video
proud tangle
serene umbraBOT
#

Gave +1 Rep to @pseudo creek

odd sparrow
#

Thanks all for the insight, already modified the top couple sections to make it more applicable to the job and removed lots of fluff. Also touched up my github with an Azure Sentinel project I had worked on the side.

mellow bobcat
clever rain
# odd sparrow

@odd sparrow Many of the fine folks here have given some really good advice. Something else you can consider is that it might make sense to try and get a call/video conference with the hiring manager(s) to explain why you are pivoting before applying. Unfortunately, depending on the job description, hiring manager, and job applicant system, your CV/resume will likely get automatically tossed or passed over in favor of candidates that appear to be more qualified on paper. My take is you'd probably have a better chance by networking if possible. One huge advantage that you have is that you understand and have experience in the industry where in many cases, infosec folks do not. Without seeing the job description of the role you are applying for it's hard to give more specific advice but if you will be staying in healthcare, I'm guess showing/demonstrating that you are up to speed on HIPPA could get you far since healthcare is a highly regulated industry. If you haven't already, try to network with other infosec professionals working in the industry; perhaps you can share you insights on what it was like getting a phd and submitting peer-reviewed publications in exchange for the advice. (i.e. help others and they will be more inclined to help you) Just keep trying and don't get discouraged if folks say no. Just reading between the lines of your CV and what you've written here, you just need that one opportunity to get your foot in the door; if you can stick out a doctorate in pharmacy, I don't see you having much trouble being successful in cybersecurity!

stoic cave
#

Or your spouse is active duty?

glad dust
distant pier
shy quail
#

Hey everyone. I currently am in a job interview process for a junior penetration tester position and I have a question. Some backstory on me, I got into tryhackme a lot in the last 2 years and moved over into an IT position and started looking into getting some certs. Because I was hard focusing on certs I had to put offensive studying off for a bit. Fast forward to now and I now have my net+ and sec+ and am almost ready to take my cissp after studying for a while. Well as a shot in the dark I decided to apply for a penetration tester position at a company I would love to work for. I have gotten past the interviews to the assessment portion now. My question is, is it normal for a beginner to not be able to root an assessment given to you by a company? I have found a couple security issues and vulns but just can’t land an exploit to completion. I know I just need more training to get it but I just want to know if I’m just not ready yet?

pseudo creek
shy quail
serene umbraBOT
#

Gave +1 Rep to @pseudo creek

lean cypress
#

I need some help. What are roles called when an consulting attempts to get into a companies data center or office in person ? I know this is consulting, but what is the title specifically ? Thanks !

undone shore
#

Physical pentests aren't massively common.

lean cypress
serene umbraBOT
#

Gave +1 Rep to @undone shore

lean cypress
#

Anybody try Over the Wire ? Is it more advanced then most plaforms ?

pseudo creek
hybrid orchid
proud tangle
hybrid orchid
# proud tangle Ah nice. I think my problem is that I have no experience, so I'm finding it hard...

Start building your website resume RIGHT NOW with Hostinger!!: https://www.hostg.xyz/SHACM (get 10% off with code NETWORKCHUCK)

It's hard to get a job in IT. In this video, NetworkChuck will show you how you can get a job in information technology with no experience. Tired of getting passed up for Information Technology jobs? It’s probably yo...

▶ Play video
#

If you haven't had the chance to get that experience via a job so far, maybe you could "prove yourself" via home labs, walkthroughs, skill badges, course completions...

pseudo creek
#

home labs are great, they can show interest but also home labs these days can be using a cloud environment or virtualization environment. Building a portfolio overall is useful, use something like github, put your write-ups there, put any scripts/stuff you create related to cyber security there

#

but skill badges? course completions? those are much less useful

#

do not waste precious resume space with those

desert sonnet
#

Network Chuck is a cool guy and I like his content, but it seems much more focused on learning for fun and enjoyment than learning for roles imho

#

Obviously that's not a bad thing, and it's good for getting people interested, but a lot of his content is like "look at this cool thing, isn't it cool, play with it!" rather than comprehensive teaching stuff

cinder idol
#

Hey guys new to the discord! RN looking to change careers into cybersecurity. I have an associates and bachelors in nursing. I have no experience in the field and just looking for info. Has anyone had success in teaching themselves without doing a boot camp and finding a job?

rugged delta
# cinder idol Hey guys new to the discord! RN looking to change careers into cybersecurity. I ...

Cybersecurity is not an entry level field in the IT landscape but it is possible to learn a lot using TryHackMe and other resources like books and courses. If you go onto the THM blog, you can see lots of success stories of people migrating from other professional areas. A lot of people use THM to learn as they grow their skills and aim for certifications, either professional or academic but there are lots of paths to take.

Right now, there are two Humble Bundle collections of great cybersecurity books (linked below) that we frequently discuss in #bookclub, including the Tribe of Hackers collection which includes interviews with cybersec experts discussing their various roles and how to go about getting there. Cybersecurity is a fun journey and you should check out the links in #start-here and go on and try the Advent of Cyber, a set of beginner challenges leading up to Christmas

https://tryhackme.com/resources/success-stories
https://www.humblebundle.com/books/hacking-no-starch-press-books-2022
https://www.humblebundle.com/books/holiday-encore-become-cybersecurity-expert-wiley-books

lean cypress
proud tangle
# pseudo creek what? is that really what he says because... thats a bit yikes

Basically he says you should have a website to showcase personal projects, and provide the url on your resume. He recommends putting homelab stuff on your resume if you have no experience. The sample website he shows off had skill badges on the site. - Though, I'm not sure I'd even want to put skill badges on a website.

pseudo creek
wary siren
#

I guess it wouldn't hurt to put certain courses on your LinkedIn, for instance. Maybe not every single THM room/learning path you have ever done, but there are some courses that can at least add a note to your resume that you are involving yourself with it.
Now, will this help with recruiters? Probably not always, but you may once in a while raise interest and get contacted. From there you might be able to score an interview and then you can use it to empower your own narrative.

What I think is even better: set up a blog, go through courses and write about it. It shows your active involvement with these topics and writing is a seriously important skill in the business world.

#

Oh, and don't hesitate to promote your blog posts on LinkedIn. That's quite literally what this website is made for.

slate crag
#

Hello, good day.
I am a student and will very soon graduate from masters of cybersecurity.

I've been self-learning and focusing towards SOC L1 to get a job in that when I graduate, I've finished CyberDefense and SOC L1 pathes in THM.
I've also watched CEH and Pen+ on Udemy just to get an idea while focusing more on defensive-side.

  • I have 2 years work experience as IT Technician
  • Have 0 work experience in cybersecurity

Since I've finished all the blue team paths in THM, where should I head now? should I start trying to get a certificates like CySA+? but then I've always heard "Qualifications before Certifications"

Thanks

pseudo creek
slate crag
#

No I don't have the certificate Sec+ because it seems not to be needed here in "middle east" and I feel like having master's in Cybersecurity should just cover the need of it, but I've learnt it.
I've been applying recently, and yes I literally have the Splunk page open thinking to start with it.

pseudo creek
#

ahh ok, you mentioned CySA+ which I usually don't see comptia mentioned much outside the US. Also US based masters really wouldn't cover anything much in terms of an entry level cyber position but I don't know about masters outside of the US

slate crag
#

No my master didn't really cover the content of Sec+, I meant that Sec+ is kinda a start point and just learning it without getting the cert is enough, and that If I to get a certificate I should start higher on ones like CySA+ or others that on same level I don't know.

pseudo creek
#

that isn't a bad path if cysa+ is recognized in your country for jobs

slate crag
#

Ok thanks, I'll be looking to get started for either Splunk Certificate or CySA+/ISC2 certs.

thin merlin
#

I am alone anyone wanna come in my server

hardy snow
#

hey so I have just completed the eJPT certification and I was wondering what should be my next step, maybe eCPPT? OSCP? if someone could guide me a little thanks

hardy snow
#

probably pursue a job on pentesting? but not 100% sure, atm just want to keep learning

pseudo creek
#

what experience you have now? what country?

hardy snow
#

studying computer science, completed ejpt to focus on cybersec

#

oh, spain

thorny turtle
slate crag
thorny turtle
#

better if you get the Splunk

#

since a lot of SOC uses Splunk SIEM

slate crag
#

Alright, thanks.

pseudo creek
thorny turtle
#

not in the recruiting standing point

#

most recruiting tools scans your resume, not read by the human eye

pseudo creek
#

uhh ok if you say so, I'm not in the middle east but I do participate in hiring/interviews of cyber peers

#

they will be looking for CISSP, not for a random cert that I can't even tell you what its called

thorny turtle
#

I mean, i guess it depends on the company

pseudo creek
#

whats it called? do you know? because you called it ISC2 cert

thorny turtle
#

most places Ive seen, they put SEC+ and ISC2

#

CySA+ is like rarely mentioned

pseudo creek
#

I know our automatic resume filtering looks for certs by name, not by the provider

#

but also, we hand look at resumes too even if they were rejected sometimes

thorny turtle
#

But i can tell you @slate crag if you do get an interview, make sure you know your steps for incident response

#

how you would go about dealing with phishing emails

#

KPI

#

just basic security stuff

#

if you take either Sec+ or ISC2, they provide those knowledges

#

CySA+ is more technical than memorization

slate crag
#

Thanks a lot, appreciate this.. noted.

flat sedge
thorny turtle
#

SSCP

flat sedge
#

Thanks

thorny turtle
#

Do you have any certs in security? if not, i would first recommend SEC+

#

and then go for SSCP

#

SSCP is more advanced

#

Sec+ isnt too hard

slate crag
#

I have studied it but never done the exam, was aiming to start with a bigger one. Haven't seen anyone in my country who work in SOC have SEC+
So I thought to start with a bigger one

flat sedge
#

I have CISSP, thanks though.

slate crag
#

Most of them have certs from Microsoft/eLearningSecurity

flat sedge
#

I would not spend your own money on certs, unless it's to get a junior role. If you can, try to leverage your current job role and employer to pay for the certs so you can make the transition

slate crag
#

As mentioned above ^, I have 0 work experience in Cybersecuty (2yrs I.T Tech) and will graduate soon with a Master degree in Cybersecurity and have been self-studying on platforms like letsDefend/Cybrary/THM and now since I've finished blue team paths in THM recently

#

I was wondering my next move, was thinking of Splunk certificate

flat sedge
#

A M.Sc in CyberSec can actually be a detriment when you are starting out.

#

And will overqualify you for many entry level cyber roles.

slate crag
#

oh no

flat sedge
#

So you have 2 years of work experience in IT Tech? Can you elaborate on that

slate crag
#

I was in maintenance department for an I.T company, fix hardware/software for the company and clients..

#

Made sure everything is running

flat sedge
#

What does that mean? Did you do solder repair on broken boards? Replace malfunctioning equipment? Reinstall software? Write patches for software?

slate crag
#

yes except for writing patches

flat sedge
#

Ok, so that's a decent place to start from.

#

My advice would be to get an entry level sysadmin or network admin cert (CCNA, RHCSA, Linux+, et al) and transition to systems engineering or IT infrastructure

#

From there, it's a much easier transition to a security focused role than an IT site support role

slate crag
#

Ye that would be great, wish I had a sys eng job before now

pseudo creek
#

I have CISSP too and really SSCP isn't something we look for, I don't know why but its not, we look for Security+ over that

slate crag
#

would make it much easier I bet

river cloud
#

Hello everyone !!
I need some path guidance..
My goal is to go for bug hunting..
So, I have completed the Jr. penetration Tester and fundamentals
Now, Should I go into bug hunting ? or complete any other tasks/rooms on tryhackmeanimewave ??

next quiver
#

Hello all! I am an army vet and currently in a DEVOPS pathway going for SEC+, CEH, and SPLUNK certs. I am looking to find a good entry level IT job that will apply the stuff I am learning in everyday use on the beginner level as I have no IT experience other than what I am learning now. Are there certain job titles that I should be looking for while seeking this? Thanks for any and all responses!

pseudo creek
#

assuming you are in the US, it varies widely but things like security analyst, security engineer are common titles. You could also look at things like SOC analyst, GRC analyst, incident response analyst

#

also part of the problems is job titles may be similar whether they are junior or senior so those job titles don't guarantee they are junior, just options that could have junior titles

desert sonnet
#

Question for my UK peeps: how do you tax bug bounties? I've not done any yet, but I've been looking at potentially trying some, for experience, but I can't really find any conclusive evidence on how you tax them if you get rewards. While I doubt that my novice self will get any payouts for any bounties I may find, in the event I do I'd like to know what I'm supposed to do with them.

static tide
#

simply do not tell anyone

hollow plume
# desert sonnet Question for my UK peeps: how do you tax bug bounties? I've not done any yet, bu...

Hello fellow British woman. It depends how much you earn in a tax year. If you earn £1000 or less from soley the service you provide as a bug hunter then you don't need to do anything.

But if you earn more then £1000 in a tax year you'll need to fill out https://www.gov.uk/self-assessment-tax-returns

desert sonnet
#

I am a woman, but thank you for the information. I wasn't sure it was so simple, because usually bug bounties are in $ and as I understand it foreign currency is taxed differently, but I'll give that a read to see if it answers my questions

#

I suppose if it became an issue I could talk to my bank, they should be able to advise (you would hope at least lol)

hollow plume
#

I made no error 😅👀

desert sonnet
#

You're fine

hollow plume
#

Mb but if in doubt you can just contact HMRC directly and they can provide advice

desert sonnet
#

That's true, I hadn't considered talking to them directly, just because dealing with govt offices is a pain

hollow plume
#

True nothing can be worse then student finance though.

desert sonnet
#

Please don't speak of student finance to me, I do not wish to be reminded of their existence \j

#

I have spent hours on the phone with them, they're ridiculous

hollow plume
#

Then they give you the wrong advice after all and its actually this form and not this one its just gr

undone shore
#

If you happen to hold SC... good luck

desert sonnet
#

I don't hold SC currently, so at least that won't contribute to the paperwork nightmare

little gust
#

What are the recommended entry level certs? I mean I get that most times it's about what you are capable of and what you have done.

pseudo creek
little gust
stoic beacon
pseudo creek
#

and you didn't say what country as certain countries put certain weight in various certs, although for pentesting, OSCP seems to be accepted worldwide

little gust
pseudo creek
#

obtaining work in a country that you do not have the right to work in is insanely difficult and not worth it to most companies unless you have a very specialized skillset

little gust
little gust
stoic beacon
#

begin with THM's beginner path then

#

to build on your current knowledge

#

reiterate what you already know, etc

pseudo creek
# little gust Doesn't it depend on your skill?

not really, I mean if you have a unique skill like you are only 1 of 100 people in the world that can do xyz and a company needs someone that does xyz, that could change the tables but it is very difficult for companies to hire outside their country

little gust
# stoic beacon to build on your current knowledge

Agreed, I have been building up. I'm currently level 7 and I'm learning new and old stuff I already knew just to get a different angle. Once my skills matrix is well rounded I will begin CTF challenges with other hackers

little gust
#

Well for people from my country

pseudo creek
#

but like I said if you want a cert that is applicable worldwide, OSCP is a solid cert

pseudo creek
#

?

serene umbraBOT
#

Gave +1 Rep to @pseudo creek

pseudo creek
#

if you have the right to work there, then you are golden... it just isn't that easy to find remote work outside of your country (or outside of region where you have the right to work)

#

like even in the US, a lot of remote work is still tied to a specific region / timezone and most companies won't allow remote work from foreign countries (even for US citizens)

little gust
#

I'm too much of an optimist I guess 😂😅 it's probably because I managed to get a few graphic design jobs in the US and UK once in a while

#

I believe in being the best in the room and if I'm not I shoot the guy who is, jk 😂

stoic beacon
#

@little gust please don't send me unsolicited friend requests

little gust
stoic beacon
#

it's in the rules

#

#1

little gust
#

Just networking and knowing like mind folks, no big deal. I canceled the friend request

stoic beacon
#

i understand the intention but just sending random friend requests isn't necessarily the way to go about it

carmine jolt
#

I'd recommend to read through the #rules anyway 😄

#

if you havent yet

little gust
little gust
serene umbraBOT
#

Gave +1 Rep to @carmine jolt

carmine jolt
#

haha, it's just good to be aware 🙂 that counts for everybody here!

little gust
#

Well it's actually ADD but ADHD is more well known

carmine jolt
#

your risk 😉

little gust
#

I have a condition, takes a while hope yall bare with me

little gust
carmine jolt
#

I'll pass it on to the admin ✅

#

do you have any suggestions on what you'd want to see? I dont decide on this matter but it would be good for Hydra to have some suggestions. If you want, drop a msg in #general as this is not the right channel for these kinds of things

little gust
#

A short to the point list would work for me, video or audio too.

carmine jolt
#

phoenix please leave it 🙏 not everyone experiences things in the same way

serene umbraBOT
#

Gave +1 Rep to @carmine jolt

placid torrent
flat mist
#

Hell just put it in with the certs they let you link to anything in there. Pornhub doesn't work we tried, but yea according to hacker1 it's a best practices issue.

placid torrent
#

pornhub 😭 ???

placid torrent
#

i need it to look good

flat mist
#

or should I use denylist instead of allowlist

#

unless something has changed in the past year take a picture it will last longer

placid torrent
#

ty

flat mist
#

linkedin is all about who you know as well. Network with people. Join study groups. Branch out.

misty musk
#

The absolute hell would I write in these boxes as an unemployed person, with only customer call centre experience?

static tide
#

dealing with clients

little gust
warm hinge
#

hi

#

what's difference betwenn cyber defense and cyber operations?

flat sedge
clever rain
#

@misty musk Call Centre experience is quite good since being able to talk to people is arguably more important than tech skills in some cases. Perhaps use examples of your experience that might help on the job. As for how to relate your current role...perhaps this is an opportunity to take a chance and show some humor and/or personality? Or, ChatGPT is all the rage so you could try playing with that for inspiration. I put in the question of:

As a stay-at-home dad, in two sentences please tell me how your current role relates to a job in cybersecurity?

and the answer I got wasn't terrible IMO:

As a large language model, I do not have a current role or personal experiences. However, as a stay-at-home dad, you can still play a role in protecting your family's online security by setting strong passwords, educating your children about online safety, using parental controls, keeping your devices and software up to date, and using a secure connection when accessing sensitive information online.

Edit: Formatting and tagging OP

ancient quail
#

Hi guys
Do you need to work as a pentester first to become a malware analyst?

wicked hound
ancient quail
#

But you need some sort of offensive skills right ?

wicked hound
wicked hound
# ancient quail But you need some sort of offensive skills right ?

As far as I am concern, you sit on the computer, open new malware samples in VM, run them through a few tests, also check something manually (F8, F8, F8, F7, F8, F8, like woodpecker), then make some signatures from malware behaviour and that's pretty much it. After this you open other sample and repeat it all again

#

What you really need is knowledge of ASM, patience and love for forensics. Otherwise, it will be boring as hell for you, because it's quite tedious - to check through so much obfuscation, antisandbox techniques etc. Some malware you will probably know "in face", some can be a bit sofisticated, APT-related, some you might even miss.

wicked hound
ancient quail
#

Thanks

patent kayak
#

Good day All, when someone finishes a path for instance the security analyst where one would do the three course (pre security, SOC1 and Jr pentester) , what else should some one do before trying to get a starting job in cyber security? Looking forward to a response from who can answer

hexed magnet
#

The default answer is get certified

pseudo creek
warm hinge
#

Hello pen testers, I would like to ask a few questions. What is your day to day like as a pen tester? What educational path did you take and how did it work out? What is college like for a computer science degree? And how much is entry level pay as a pen tester?
And another question, what is the day to day life in cyber Forensics?
I start college next fall and I would like to know what I will be expecting.

pseudo creek
warm hinge
#

I am in the USA

wicked hound
serene umbraBOT
#

Gave +1 Rep to @pseudo creek

pseudo creek
#

ahh so I can start with computer science degree (to an extent), there will be a lot of programming, but it basically builds a foundation for other careers which you may embark upon.

Entry pay in cyber security varies throughout the country but someone with a college degree is usually in the $60k-$80k range

I'll leave day to day life for pentesting to someone else although I work with pentesters and red teamers. I deal with them on the reporting and presentation side as well as prioritization of issues.

For forensics, it can depend on what type of forensics. I've done some intrusion forensics in the past and it is really tracking down what was done, when to what by whom. It can mean sifting through logs, it can mean evaluating system images and using various tools for that. It should be a team effort.

pseudo creek
patent kayak
serene umbraBOT
#

Gave +1 Rep to @hexed magnet

clever rain
hexed magnet
warm hinge
# clever rain Humble question <@456226577798135808> ...why are you thinking about being a pen ...

I have always wanted to be a ethical hacker since I was 10 years old. And I want to explore the opportunities in cybersecurity. I want to become a network engineer to learn more about networks, then a malware analyst to learn about malware and how it operates then digital forensics to investigate cyber crimes and learn what hackers are up to, then I will be a pen tester for the rest of my career. I will have a complete foundation.

clever rain
# warm hinge I have always wanted to be a ethical hacker since I was 10 years old. And I want...

@warm hinge I see - sounds like you really love it! Okay, for your original question(s), you're going to get a lot of varying answers but here's mine, as a dude that manages 6+ pen testers. Typical day is going to be similar but very different depending on the organization. Educational path might be different too; many organizations require degree + certs, some don't. I got folks on my team with no certs and some with advanced degrees + certs but since you are just starting out, try to get a few foundational certs and keep networking and reaching out like you are now. But more than anything, make sure you have a solid understanding of business and can communicate well. Communication is super important when explaining what's on those forensic or pen testing reports. Doing what you love is one thing but doing what you love to make a living is another; Ideally you want to make a living doing what you love but you might have to take some jobs that aren't what you want but you need the financial support. If you end up in that situation, don't be discourage and still learn what you can. And it's okay if you get knee deep in forensics and/or pentesting only to decide that it isn't what you want to do for a living. If you aren't already, I highly recommend following what Heath is doing at TCM Security and keep hacking away here at THM. Good luck my friend!

warm hinge
serene umbraBOT
#

Gave +1 Rep to @clever rain

royal grail
#

Consider what kind of freedoms each job has and whether there is room to grow or move around within each company.
During my first job as a sys admin (with 0 security functions in my job description) I went out of my way to suggest and implement various security controls every chance I could. That beefed up my hands-on experience (and resume) enough to land a full-time InfoSec job. If Cybersecurity is what you want to focus on, you'll find a way to make it happen.

bleak pine
royal grail
# bleak pine How did u get started as a sys admin? Did u get a degree or?

I got the job about 4 months before I got my degree. So technically it went Job>Degree>Certs. I did a lot of self-learning between courses, mostly from content creators like Professor Messer, ITPro TV, and TryHackMe. Between all of this, I was able to confidently hold technical conversations during interviews.

bleak pine
royal grail
bleak pine
#

thank you!

mellow ledge
#

Looking for some help. Master in Computer Science with Security+ cert and top 1% on HTB. looking for a SOC analyst role. Currently bartending. Thinking about taking the CEH even though I hear the cert isn't great for anything except getting past HR. I have a small SIEM for my home network and my web server, but other than that I have not SOC experience. My IT experience was a job as a Systems Analyst that started as an internship and moved to part time when I was completing my Masters. I finished in 2018. There's a gap because I had a family member who was terminally ill so i took care of them. Moved cities and couldn't get hired so I've been bartending since about 2019. Any advice or is this a thing that's "damn, that sucks" kinda thing?

clever rain
# bleak pine How did u get started then?

@bleak pine I had certs and a degree, had been using computers all my life (e.g. building, fixing, etc.) but nobody would hire me because my professional experience was only in music and at the time, paper MCSE's (Microsoft Certified Systems Engineer) had flooded the market. This was during the dot com bubble. I had to take a job in accounting and others but kept applying, applying, and networking. I finally got a job as a sys admin for a school. Then moved up to help desk as a military contractor, then sys admin again and then networking, virtualization, and other jobs before I even started full time in cybersecurity. Everyone is different and of course things are different in 2022 (e.g. housing issues, crappy market, layoffs, student loans) but my path was not easy. It took me 10 years to pay off a student loan for a degree that wasn't even in IT. lol However, IMHO, the two things that haven't changed and likely won't anytime soon is communicating well and people networking. Those two skills help with any career and it's tough for techies like me that tend to be introverted. All the "crap" jobs I got (IMO anyway) were from applying online; all the fantastic jobs have been through people networking. (This is just my experience, note that I'm not saying that jobs applied for online are always crap)

bleak pine
serene umbraBOT
#

Gave +1 Rep to @clever rain

remote gale
#

@warm hinge

grand phoenix
#

My coworker is actually moving to a cyber job without a cert. It's not about the cert.. It's about your knowledge.

undone shore
#

If you don't have any of those then you could be the most proficient cyber professional on the planet and still be rejected.

grand phoenix
#

Cert got my foot in the door into IT. That's it.

undone shore
#

Aye.
It's worth getting a couple of the entry-level certs if you're trying to move into cyber / get your first job in cyber. Provides a baseline proof that you probably know what you're doing

#

That ^^

grand phoenix
#

Can't complain there 🙂

#

Even if it's the most horrible company you've ever worked for in your life... I stuck it out for 2 years...

#

then cut

undone shore
#

Heh. That's where lots of certs come in handy kekw
I got to pick and choose my grad job a bit.

grand phoenix
#

Rephrase on my "coworker without a cert" thing.. oh no.. he has several certs.. just not in cybersecurity..

undone shore
#

On which note, I should really get back to WUMED 😆

grand phoenix
#

Let me be very clear.. He has Azure, MS, AWS lots of things. lol.. just not related to cyber field.

undone shore
#

Tbf, proprietary cloud certs are pretty much all that's available for cloud cyber, so they're still very good / relevant if you're getting a cloud pentesting job

#

Heck, I'm working on the AWS stuff rn

grand phoenix
#

I mean.. I can probably hit him up on Teams to ask exactly what certs he has on Tuesday when we go back to office/remote/mostly remote/i have to go into the office that day.

grand phoenix
undone shore
#

Nah, there are very few cloud pentesting specific courses / training

#

You need to get just the regular in-house stuff from the providers

#

AWS has a security architecture course iirc, for example

#

You'd be best doing the earlier ones there first though

#

@pseudo creek is also the person you wanna talk to about cloud security stuff. It's... far from my speciality

grand phoenix
#

Also interested in Azure

grand phoenix
#

Oh.. Take notes on stuff. 🙂 good career advice.

#

nite all

clever rain
#

@bleak pine it depends. College first? Depends on the college and program as well as the cost of the school. Certs? OSCP might get you some interviews but depends on who is hiring and if you have limited experience (I know, I know...catch 22) you'll get filtered out at the interview. Applying to anything you can find online will be a numbers game however, will be good practice for interviewing and you'll eventually be able to talk yourself into a job. If it were me starting over today, I'd focus on getting any job in IT and I would be working on all college/degrees/experience at the same time...Get a few certs while you're in college (some schools like WGU I believe have certs as part of the curriculum) and apply for internships and/or jobs along the way. If you happen to find a job while you are still in school; take the job and finish your degree part or quarter time. Whatever you do, please do not go into debt for a degree for a career in cybersecurity. At the end of the day, you'll learn a lot from school and studying for certs but companies are hiring for these pentesting roles (and other cybersecurity roles) to manage risk and become/remain/increase profits/value which is why they tend to favor folks with experience. Remember @bleak pine I'm just some dude on the Internet and I don't know you so please take my comments with a huge grain of Himalayan salt but I do think that answers to questions like yours are usually going to be some form of "it depends" because there are just so many variables to consider and luck, for better or worse, is one of those variables in getting good, meaningful employment.

clever rain
# grand phoenix I'm still looking for good cloud pen relevant info. I cannot find educational ma...

I've held a few of the professional level AWS certs, the associates ones, as well as the security one. A friend had me consider interviewing for an AWS job and guess what? AWS didn't even care about the AWS certs. They were still going to have my take a basic IT skills online test and whatnot so I didn't even bother continuing. Note that this is in Asia; perhaps it's different stateside but from my own anecdotal experience, AWS didn't seem to care about it's own AWS certs so unless you are going into consulting or a role that requires these certs for AWS enterprise agreements ( need to have x number of professional level certified staff), I wouldn't lose sleep about not being certified. As a matter of fact, I'm letting all my AWS certs expire. (if you are just starting out however, they might have some value of course; my situation is different so huge caveat) If you haven't already and if you want to focus on AWS, check out the AWS Security Digest; there is usually a lot of information about AWS cloud pen testing: https://app.mailbrew.com/zoph/aws-security-digest-HrkhwqNrwBBk/97

Mailbrew

AWS Security Digest Weekly Newsletter. Curated by Victor GRENU.

pseudo creek
# grand phoenix I'm still looking for good cloud pen relevant info. I cannot find educational ma...

Black Hills InfoSec / AntiSypohon has some good (inexpensive) stuff on pentesting cloud. Basically, if you know security, you should be able to apply that to whatever technology. I have never pursued security focused cloud certs but just cloud certs. Cloud certs do go a long way in the Cloud Security realm if you can show you know security on some level as well.

I'd peruse the AntiSyphon site on various cloud specific security training
https://www.antisyphontraining.com/

Antisyphon

Home of  “Pay What You Can” Training. Antisyphon provides high-quality and cutting-edge education to everyone, regardless of their financial position.

clever rain
serene umbraBOT
#

Gave +1 Rep to @pseudo creek

fierce belfry
#

so is it a good idea to go around small businesses asking if u can do a small assessment of their website to see for any vulnerabilities ( kind of like mini pentest) just to get some experience and so i can put that on my resume

#

and its also helping them as well

rugged delta
# fierce belfry so is it a good idea to go around small businesses asking if u can do a small as...

No, absolutely not. If you're conducting a security assessment, you're essentially performing acts that would otherwise be illegal and you might not be qualified to properly detail and agree the extent of a penetration test and the consequences of your actions. You would be advised to join an organisation who can arrange the penetration testing activities, as you would likely need the assistance of a lawyer/solicitor to define to what extent you are liable when you might make a mistake and bring down or otherwise negatively affect their service, gain access to information they were not aware was exposed, and you might also need help discussing/defining the scope, etc...

You might gain some experience by learning how to properly undertake bug bounties (don't expect to make a lot of money at this, at least initially, and join reputable orgs like bugcrowd/hackerone/synack, for instance)

fierce belfry
serene umbraBOT
#

Gave +1 Rep to @rugged delta

rugged delta
# fierce belfry thank you for keeping me out of prison ( not being sarcastic, honestly thanking ...

If you're learning to conduct a security assessment, you'd be expected to be part of a team who would have the knowledge/skills to conduct all of the task around it. A normal third party pentesting company would have expertise in the various aspects of performing a pentration test. I know you mean well by encouraging small companies to improve their security posture but it does take a large amount of effort. It's why a lot of companies recruiting cybersecurity talent are looking for you to hold professional certs like Security+, CISSP or OSCP etc., and why you gain knowledge and experience in a regular IT field performing security duties like secure coding, network security architecture (installing firewalls, IDS/IPS, proxies, systems security etc and the policies and procedures around these things.

There's a lot to consider and that's why, when you're doing cybersecurity work, it's good to have plenty of experienced people around you and a good legal team 🙂 When you're learning, you need places like THM, HTB, etc. to take care of all that for you and as your skills grow, you'll find other resources like PicoCTF or other platforms specialising in learning other aspects of cybersecurity... Plus there's all the books, courses, certifications to help you learn and demonstrate to employers that you are learning valuable skills. You're at 0x8 H4CK3R level on THM. You're doing well. Keep pushing and you'll get to where you want to be

fierce belfry
serene umbraBOT
#

Gave +1 Rep to @rugged delta

clever rain
# fierce belfry so is it a good idea to go around small businesses asking if u can do a small as...

I'm hesitate to suggest this but setting up a legitimate business (e.g. LLC), cold calling, and offering your services BEFORE doing any assessment is a great way to learn sales, communication, and business, so I'd say yes for that. Don't sell yourself short and offer "free" because free is typically associated to "no valuable". Set a reasonable price, be upfront with your potential customers of your intentions and emphasize the win-win, and work from there but be prepared for a lot of "nos" and/or "f* off", assuming you get a reply at all. You will need to learn about contracts and in your contract, you'll need to be very clear that your service is just a mini-assessment and is not meant to be used for the customer's 3rd party vendor contracts, assurance, etc. If what I just wrote doesn't make any sense at all, then I would avoid this route so that you don't end up feeling defeated or worse, sued. Doing an assessment without permission (even passive scanning) would be a big no no and will almost certainly put one in legal trouble so definitely not cool as already mentioned by @rugged delta Again, I'm hesitant to offer this advice but entrepreneurship and following through on your ideas is really, really valuable. If you try this route, please focus on really, really small companies and limit the scope of your service to something like DKIM, SPF, and DMARC because that's almost always a problem. lol @rugged delta just posted more good advice above, especially the legal team comment, so keep that in mind.

fierce belfry
clever rain
rugged delta
#

Basically, everything we do outside of our learning environments (our own personal labs, THM, etc.) requires some legal expertise, whether it's vulnerability assessments, pentesting, storing information for a client, hosting a server, etc) These days compliance is a huge aspect of everything we do. In my prior job, we couldn't even discuss some activities in relation to the workplace without first having our boss get a representative from legal to review and approve the topic, for our own, and the org's protection

undone shore
#

Oh Dear God do not offer to do technical assessments without legally binding authorisation documents.

#

No matter how small a scale. You will end up sued.

#

Or otherwise prosecuted. Doesn't have to be the business complaining about it -- computer misuse laws still apply.

#

Also, cold calling is just shitty smfh

#

Pretty decent way to make sure you end up on do-not-hire lists if you make a name for yourself by pissing folk off kekw

fierce belfry
#

was going to my old bosses( really chill ppl btw) and ask but following @rugged delta advice and not going to jail seems pretty nice 😂

undone shore
#

Yeah, maybe avoid going to jail. That's another thing that can often put a dent in your employability...

fierce belfry
#

idk, free boarding, free meals, networking, seems kinda nice

#

sorry going off topic but yea @rugged delta and @clever rain are right not work the legal trouble and not really there yet but i will get there 😄

clever rain
#

@undone shore nobody has offered advice to do assessments without authorization, and I don't think that was the OPs intention. "You will end up sued" is not an absolute but yes, point taken that it's risky which is why I wrote "hesitant to advise" and other caveats, specifically contracts. Yes, cold calling sucks but there is a right and wrong way to do it. You do understand that businesses have to find customers and sometimes that means reaching out. As a CISO, I have to deal with cold calls every single day and the ones that are honest in their intentions, usually get my time, even if it doesn't lead to business. As for this case, yes, probably not a good idea, hence all the caveats. As for do-not-hire lists, sure, if one is a complete a**hat in their approach (e.g. annoying, persistent, dishonest) but as I mentioned, the OP is probably going to get rejected anyway however, if his approach is good, he might have some contacts for later down the road when he is ready. Anyway, I think the conclusion is clear that for the OP and agreed by the OP, this is definitely a no-go so the world will be fine!

undone shore
#

Learn about contracts
Does not a lawyer make kekw
Hence the "legally binding" caveat.

That said, you have more patience than I do for cold callers. Personally, if you're calling me to sell me something which I do not want and haven't requested then you're taking up my time, and interrupting whatever I had my mind on before. i.e., you're a nuisance, regardless of how respectfully you're doing it (though respectfulness would certainly play a part in no-hiring, fair). Although I do agree there are better ways and worse ways to do things... email, for example.

fierce belfry
#

it wasnt really going to be cold calls, it was going to be ppl that i know and are willing to help out, im not randomly choosing ppl out of google maps or anything, it was going to be ppl i trust and have known for a good while. sorry for not clarifying

undone shore
#

Aha, all good -- I think we're on the theoretical at this point 😆

clever rain
#

@undone shore man the times have changed. When I write "cold call", I was actually referring to emails. Nobody calls these days. lol Regardless, good discussion points and I think these points will help others! Thanks again for the points!

serene umbraBOT
#

Gave +1 Rep to @undone shore

undone shore
#

Bahaha, well, that's fair. I think we're in agreement then kekw

#

And same to you 🙂

clever rain
#

@undone shore now if we are talking about actual phone calls...then let's not talk about recruiters. lol

fierce belfry
#

if were going theoretical then im definitely cold calling bill gates kekw

undone shore
#

Christ, yeah...
Between recruiters and PPI firms...

fierce belfry
#

PPI firms??

undone shore
#

In theory the claim backs have finished, but I still get the odd call about it. The calls are just scams at this point though

#

Oh, and injury compensation calls...

rugged delta
fierce belfry
#

@undone shore but ur car warranty is about to expire kekw

clever rain
#

In Japan it's a bit more tricky as the "law" in regards to cybersecurity is well....tricky. On one hand, things are really relaxed but on the other hand, you can get smacked unreasonably hard. My meetings with chief legal counsel are often hazy on what is okay vs not okay. And then there is the language component of interpretation, intent, etc. I love this country but man, lots of mental gymnastics sometimes. lol

rugged delta
# clever rain In Japan it's a bit more tricky as the "law" in regards to cybersecurity is well...

In many pentesting exercises you would tend to plan out the extent of your actions, down to the commands and switches you're going to use, in a lot of cases. They'll all end up in the report afterwards if you do the report correctly but it's generally part of the legal agreement of any pentesting activity that the scope of the test is part of the legal agreement and the procedure should always include having a 24/7 contact with your client and gaining specific, signed approval for the activities you're undertaking. This could also include stop-and-confirm steps in the process, whereby, after you have gained signed approval, you would still pause the testing and contact the client, getting further written verification (such as an email from an approved individual) to proceed with an activity.

Your intentions are generally to not interfere with the normal functioning of an operation but some of the techniques used could potentially cause a Denial of Service (intentional or unintentional) by interfering with network operations or bringing a server down or other production interference. This is something you try to avoid. A lot of pentesting work can be conducted on pre-production systems and red teaming is usually attempting to be discreet as well but you would only conduct that level of assessment in an organisation that already is expected to have a mature and refined security infrastructure in place.

This is why THM is such a great platform, you have the ability to conduct your activities to any extent on your assigned targets and can learn the effects of your actions in a controlled environment where the worst that can happen is you'll need to terminate and launch a new copy of a target you've broken

clever rain
# rugged delta In many pentesting exercises you would tend to plan out the extent of your actio...

Very true however, this is not necessarily done across the board in my experience. I'm currently responsible for a number of pen testers (e.g. in house and outsourced) and I've of course used external pen test services from the likes of Black Hills etc. Correct me if I'm wrong but your points are related to outsourced, external pen test organizations providing services to a customer, correct? In that case, the methodology is applicable to Japan as you highlighted but mainly because I know it's the right thing to do (hence one of the reasons why my org pays me a paycheck every month). However, believe it or not, for my internal pen test team, a lot of what you wrote is not necessary or required to explicitly be written in legalise; I don't require full blown reports but I do require tickets and walkthroughs with the affected teams. Of course many of the fundamentals still apply–don't disrupt business for example–but in regards to an internal pentest team, they have the luxury/privilege of actually understanding the intricate details of our service as well as how our teams work so the reporting requirement has been loosened and other requirements to stop-and-confirm are universal for all teams. I'm actually lucky to even have an internal pent test team so there's that. lol THM is absolutely fantastic however, and again using my own anecdotal experience, none of the THM exercises that I've seen so far are applicable to my business and tech stack so while great for training and indemnification for legal action, much is out of context. Huge caveat, I'm only here for Advent of Cyber and to make sure I don't lose touch on much of the technical stuff. If I find things relevant I will work with my team but I think the biggest value here is the mindset of solving problems.

rugged delta
# clever rain Very true however, this is not necessarily done across the board in my experienc...

Oh of course if it's an internal pentest, you won't need to go into all the ins and outs of the legalese in every encounter. There'll be rules and processes and definitions already in place and in-house legal will already have an understanding of the extent of your activities and its impacts on the business, there'll be a chain of reporting up through risk management and legal and up to the CISO and other executive officers, since cybersecurity should be an executive concern. I'm sure the involvement of the pentesting team is part of the development/production process and yes I hope they would be familiar with the infrastructure to a great extent, and possibly a greater extent than the administrators in many cases. How you manage internal assessments has a great deal to do with the internal culture of the organisation, and the security environment and it seems your work is we-embedded in that.

I'm sure as you go along you'll find more things relevant to your specific environment, there are about 600 objectives on THM and yes, the mindset is a very important aspect of learning this skillset. The AoC is great, especially from a beginner perspective and much of the content on THM is aimed to get people interested in cybersecurity from a basic level up to a moderately competent level where they can understand and pursue certifications/careers and potentially up to an advanced level. It's a great community to learn various skills and competencies and many go on to other specialist environments too based on what they learn here

flat sedge
grand phoenix
#

Thanks for the info @pseudo creek and @clever rain . Bookmarked both sites and will check them out.

serene umbraBOT
#

Gave +1 Rep to @pseudo creek

clever rain
peak crater
#

Hi

short pike
#

Heyo! Which path is the hardest/most directly relevant to a career in security? I'm graduating soon and wanted to brush up and maybe learn some new helpful topics to prepare for some new grad roles in security

#

I started the red teaming path yesterday and so far it's been pretty helpful but I wanted to check in and make sure that's a good path to pick

grizzled onyx
glossy tree
dusk fulcrum
#

Hello everyone Namaste
I'm beginner in cyber security and I'm having lots of problem while starting and don't know how to start and what to learn . So is there anyone who can guide me to learn the cyber security ?? I really wanna study it but having lots of problem

short pike
serene umbraBOT
#

Gave +1 Rep to @glossy tree

warm hinge
#

Hello Computer geniuses, I would like to ask a few questions and this is for the experienced. What is one class you regret not taking in college and why? What classes should I pay attention to that are important that most people don’t? For example an analogy “before I can run I need to learn to walk”. What advice would you give to someone going to college for computer science? What was your biggest mistake in college and how did it affect you? What would I expect in computer science major? And what is the hardest class that most people hate that has the best outcome and how could i prepare now? I am in high school I start college next fall so I want to be prepared.

pseudo creek
gritty flicker
sinful cipher
#

I'm also studying for the CYSA+ -- any recommendations of TryHackMe rooms for practical experience ... already tracking NMAP...thanks much!

rugged delta
kind glade
#

Any toughts on Red Team Certified Operator by Zero Point?

rugged delta
vital epoch
#

just a quick question : What is the better qualification , CPENT Master or OSCP ?

vital epoch
#

thanks

rugged delta
# vital epoch thanks

Unless you're in India, you should probably avoid EC Council altogether. There are problems with that company and there are much better organisations out there

vital epoch
#

I am in zurich

rugged delta
# vital epoch I am in zurich

Then best bet is probably OSCP. Search on LinkedIn and other job sites and see what companies are asking for. Sec+, CISSP and OSCP are generally the 3 most requested certs where I am

warm hinge
#

Anyone with network+ can give me a basic idea of what the test asks you and how it’s like?

#

And some important things that are recommended to know?

rugged delta
kind glade
odd sparrow
#

Could healthcare informatics or EHR analyst roles be considered IT experience? Also if I keep my full time non-IT job, could a per diem/weekend helpdesk job still expose me to IT concepts and experience that could get my foot in the door to go full time for cyber or a senior IT role?

#

Don’t think I can take a pay cut going from my current pharmacy job to full time help desk due to mortgage and family. So was thinking of keeping pharmacy full time and help desk per diem, or vice versa if the total income is good enough. Then would pursue full time IT/cyber once that salary is decent.

flat sedge
#

In my opinion, your best bet to get into a cyber role is to leverage your understanding of HIPAA/HiTRUST and medical compliances into a GRC role.

#

Understanding how to maintain compliance is huge and a very valuable skillset to have

rugged delta
#

Some of the ISACA certs like CRISC, CISA or CISM can really help, the remuneration for these certificate holders tends to be about 150k and the exams are reasonably priced

odd sparrow
#

The idea of GRC sounds great. What should I aim to get out of a grc role if I want to eventually work in a soc/MSSP/blue team environment?

flat sedge
#

That would be a transition into technical work - that requires a much deeper understanding of the tech stack than you would need for GRC. GRC is just as well paid (often moreso) and honestly, going into the SOC from a GRC is more than likely at least 2 steps backwards

odd sparrow
#

Interesting. What roles should I expect to work up towards if I happen to break into GRC?

flat sedge
#

Compliance Analyst is a good one, and can cover a huge variety of controls.

#

A large part of that job is checklist management, ensuring that the organization has appropriate controls for framework requirements and that evidence is gathered and stored for ongoing and future audits

warm hinge
#

Anyone here that has taken the network+ can give me a idea of what’s it like?

#

Or what they ask you?

warm hinge
serene umbraBOT
#

Gave +1 Rep to @rugged delta

warm hinge
#

I will check him out

odd sparrow
thin whale
#

Hi,

Anyone with resources on OSINT or any Career roadmap on Cybersecurity (Grey team)?

pseudo creek
thin whale
pseudo creek
pseudo creek
thin whale
pseudo creek
#

so there is the idea of a black hat hacker, someone who hacks for various reasons but does so illegally, then there is white hat hacker, someone who hacks legally and professionally such as a pentester... then there is grey hat hacking, someone who skirts the edge of legality

grim lichen
#

Hi guys. I'm looking for a team in workspace on the tryhackme. I want to improve my knowledge in the team, and maybe even create my own project. Who does not mind write to me in private messages!!

pseudo creek
rotund cliff
#

I mean the stuff I did there on some teams was pretty cooked lol

#

Was referring to the part about Grey hat hackers.

pseudo creek
#

so am I

rotund cliff
#

None of them are black hat.

pseudo creek
#

so things you do on behalf of a government should still be in line with the legality of that country, that isn't grey hat hacking

rotund cliff
#

It is because it's from the other perspective

pseudo creek
#

and various government entities would be allowed to do some things that citizens of that country would not be able to do

#

when we talk about grey hat hackers, we are talking about individuals

rotund cliff
#

Yes and they still are

pseudo creek
#

if you are doing something on behalf of a country, that isn't being grey hat

#

if you are off doing something on your own without authorization, outside of scope, etc, that would be regardless of employer

rotund cliff
#

Sure it's legal to do it in in the country but it isn't persay legal to execute in the target country

pseudo creek
#

yeah but still thats not being grey hat

warm hinge
undone shore
#

It's no less illegal than black hat activities. The "hat" a state-actor wears depends on your perspective. In their home country where it's legal they are undoubtedly considered to be white hat. Their targets undoubtedly consider them to be black hat.

#

When it comes down to it these are very loose terms to quantify human behaviour -- they don't matter. The actions are what matter.

faint ice
#

maybe shadow has a job as a candy taste tester in their future

#

which would fullfill the human behaviour of wanting to eat sweet tasting things

cobalt escarp
flat sedge
#

I can't wait to see the grade you get including an informal discord screenshot as a citation reference

cobalt escarp
#

I'm just going to insert the message link in the middle of the sentence

faint ice
#

well that is going to be fun

cobalt escarp
undone shore
cobalt escarp
#

Yeah but if I'm going to be unprofessional, might as well go the full length

undone shore
#

BRB, will put that in a blog post for ya

odd sparrow
#

Does this job sound like it could be used as IT experience? Pharmacist: Supply Chain and IT

#

[redacted] is recruiting for a Pharmacist to assist the Supply Chain and Pharmacy IT needs with data base management, information technology and automation. In this position, you will also help to optimize medication purchasing, inventory, supply, distribution, and control processes.

Principal Duties and Responsibilities:

Support the creation, management, maintenance, and troubleshooting of all formularies and databases
Support data extracts including requests regarding medication usage, location of inventory, monthly cost transfers and systems activity
Primary pharmacist involved with checking medication output distributed from, the Pharmacy Consolidated Service Center (PSCS) including PillPick®, Boxpicker® and other automated devices as well as technician prepared kits and/or packaged medications

#

Serve as the resource for requests related to pharmacy system changes to find opportunities for optimization, including participation in drug shortages, formulary maintenance task force and pharmacy event review team
Coordinate the assembly and configuration of the new automated dispensing cabinets (ADC) upon arrival as needed
Assist in configuring and optimizing new ADC hardware including which drugs should be stocked, how the drawers should be arranged, setting up max and pars and assigning medications as needed
Assist with the testing automation changes to hospital applications that affect pharmacy
Perform drug stability evaluations or reviews as needed
Assist in creating satellite and office practice inventory ordering procedures and templates

#

Assist in monitoring, adjusting and follow up of refrigeration equipment and events
Ensure all hazardous medications are being handled correctly in accordance with policies and procedures as it pertains to the PCSC and Pharmacy Supply Chain
Collect and document system problems identified by staff and refers to Supply Chain Leadership for direction and resolution
Communicate, plan, and implement utilization strategies to prevent excessive stock and reduce expiring medications and coordinate with formulary maintenance task force as appropriate
Participate in tasks relating to drug shortage mitigation
Help to determine appropriate outsource supply options to ensure the availability of needed medications, to reduce cost and/or to improve medication safety
Serve as a resource for supply inquiries involving drug utilization, availability, or alternatives
Coordinate pharmacy waste program in collaboration with Public Safety, Nursing, and Occupational Safety
Serve as a backup pharmacist for controlled substances ordering

#

(Sorry for the huge wall of text)

quick forum
#

@odd sparrow you've missed a redaction of the company name btw

odd sparrow
#

Oh

#

Not sure what you’re talking about 👀

grizzled onyx
grizzled onyx
# odd sparrow [redacted] is recruiting for a Pharmacist to assist the Supply Chain and Pharmac...

It says it wants a pharmacist, which I think means it would require cert/degree.

I think you can use almost anything as IT experience. People post some wild stretches, like IT support if they do any job but have ever fixed an issue themselves that other teammates would make an IT ticket for.

I think you would have to stretch if you wanted to call that an IT job, but that it wouldn't be hard. I see data entry, possible database, but a lot of logistics. Kinda looks like a misc bucket of tasks and likely a place that wants a lot more than they are willing to pay for, but I could be wrong. Can you share the pay range and the requirements/softwares mentioned?

undone shore
odd sparrow
#

The job uses swiss log and the supervisor told me the job would be in charge of more buying and inventory of medications and supply in the hospital’s logistics center. Realistically not as technical as help desk, but on paper could it be perceived otherwise?

#

My wife actually works at the hospital and she said I might be miserable at the job, so I may pass anyways.

pseudo creek
grizzled onyx
warm hinge
#

For those who’ve taken the PNPT, how long did you study/practice before taking it?

jovial anchor
#

What's the best certi to do for Active Directory after you pass OSCP?

warm hinge
dense sundial
kind glade
undone shore
undone shore
kind glade
undone shore
#

Aye go for it

kind glade
serene umbraBOT
#

Gave +1 Rep to @undone shore

undone shore
#

My DMs are on for this server -- that will be at your end 🙂

warm hinge
#

Would it be a good move to niche out in this field and focus exclusively on Cloud Security?

rugged delta
pseudo creek
#

in saying that, I think its a great move to learn it

warm hinge
pseudo creek
warm hinge
#

Also, how are you liking it so far?

serene umbraBOT
#

Gave +1 Rep to @pseudo creek

pseudo creek
#

we have all sorts of need for cloud security people from those that are building automation, to those that are designing cloud solutions, to those that are doing pentesting on cloud, etc, etc

#

I love doing cloud stuff, it is so easy to prototype and try things out and better than working with outdated systems

warm hinge
#

Thanks for all of your input @pseudo creek

#

And you as well @rugged delta

rugged delta
# warm hinge Thanks for all of your input <@740248496283713617>

There's a lot of good resources these days for learning cloud skills. The major clouds have some good resources available. There's other platforms that are reasonably priced. I used A Cloud Guru but there are others. All the major cloud platforms give you access to a free tier of their service so you can learn and play around with their tools as well. There's lots of books but the cloud cert tracks tend to move a little faster than the books. There's also tonnes of documentation online for a lot of the theory you'll need.

Helps to have knowledge of networking and operating systems when going in but you can learn these as you go as well.

warm hinge
#

I’ll get started checking those resources out, thanks!

rugged delta
jovial anchor
#

Also btw. I love the rooms you make/co-create @undone shore. Thanks for all your work

serene umbraBOT
#

Gave +1 Rep to @undone shore

undone shore
jovial anchor
#

Ah. Thank you anyway. Have you tried your hand at OSED btw?

pseudo creek
#

Muiri is doing it now cuz he crazy

stable oasis
#

Hey guys, just have a small doubt is professional certification mandatory for a entry level cybersecurity job

#

??

stoic cave
stable oasis
#

Can you recommend some professional certification for a 3rd year btech student.... Like i have no experience I'm still learning so

#

Can you please tell me how to prepare for the certification too @stoic cave

keen compass
#

@stable oasis If you are looking for an entry-level cybersecurity certificate, I would recommend CompTIA Security+ as a good starting point. It may not be the most highly sought-after cert, but its comparatively cheap, covers a lot of material and the process of getting it is a valuable learning experience.

There are lots of ways to study for it, I’d recommend buying a Udemy course that goes through it, take practice tests, and book an exam date early so you have something to work towards.

serene umbraBOT
#

Gave +1 Rep to @keen compass

pseudo creek
# stable oasis Thanks a lot

Although based on your terminology, I'd guess you are in India? I'd double check with professionals in your area and/or job listings to see if Security+ is an accepted cert. in India, CEH seems to still be very popular as a cert for cyber jobs

keen compass
#

It still recommend Security+ as a good thing to do even if it isn’t recognised where you live. Its cheap enough that the knowledge you can gain from it is worth the cost IMO, even if it doesn’t land you a job.

#

If you are a student, you can also get a discount on CompTIA certs. I imagine you can with other providers too but I wouldn’t know first hand.

stable oasis
#

So ceh is hard right ... So where can I get some good training for that

pseudo creek
red hornet
#

What is the best way to get your first IT job.

#

Everything on Indeed in my area wants years experience.

sharp leaf
#

hiii teammm

rapid ice
bleak pine
#

I mean like jobs can gou use to gain experience or pivot to cyber security without a degree?

odd sparrow
#

Anyone have any experience working or hearing about Allied Universal soc analyst roles? Feel free to DM me if you can’t discuss publicly

rugged delta
red hornet
serene umbraBOT
#

Gave +1 Rep to @rapid ice

rapid ice
red hornet
solar patrol
#

blobfingerguns What if I did a complete FullStackDev training (Zero2Mastery) and then applied to Cyber jobs... is that a thing? And land a job? I see a lot of CS grads landing jobs in Cyber because of the coding experience they have through the degree ... why not just go through a code camp and apply to cyber jobs? HackingMagic

pseudo creek
#

no one is going to see a coding bootcamp equivalent to a comp sci degree though

solar patrol
merry hatch
#

Maybe off topic but I'm making a personal website. Is it better, as a cyber security professional to use a specific platform? I.e. Squarespace, wordpress etc.

Would a hiring manager or recruiter deduct marks if you were using a wysiwyg platform like squarespace?

plain vault
#

Hello

stable oasis
#

Hello guys can you tell me which certification in comptia is good and has value for students who are yet to get jobs

plucky fog
#

Could you please pass me the link 🙂

cunning shadowBOT
#

:hammer: CryptoH4ck3r#8692 has been banned.

quick forum
warm hinge
stable oasis
warm hinge
serene umbraBOT
#

Gave +1 Rep to @last monolith

pseudo creek
stable minnow
#

Hi, anyone know what CREST is?

#

Im looking at jobs and I need a CREST Certificate?!

stoic cave
quick forum
#

Googling "crest certification" is all you need here - it spells them out exactly

rugged delta
# stable minnow Im looking at jobs and I need a CREST Certificate?!

CREST is an organisation that performs security certification in various areas; pentesting, threat intelligance and incident response. They're recognised globally by various organisations. You should check out their website and yt channel and the various other yt channels that discuss them. There are a lot of training and certification options available in the industry but it is usually a good idea to pursue qualifications that are highly recognised in your region

hollow magnet
#

Hello everyone, Im currently taking classes for my bachelors in digital/computer forensics. Does anyone have any recommendations on what courses to take? Or what else i can add to resume for internships would look my way?

hexed magnet
#

Anyone here taken ISC2's CC and Sec+? How do the exams compare to each other?

ashen cairn
# hollow magnet Hello everyone, Im currently taking classes for my bachelors in digital/computer...

Any specific of area of Cyber you're looking to get into? Putting in your work on THM/HTB would be a good way of showcasing your dedication to self-learning outside of traditional education. HR will typically screen resumes for specific certifications/experience and that would depend on what area of Cyber. Security+ is a very broad security certification that's often required (Even the US government require it to work on some projects I believe).

wheat bison
#

Is network+ worth getting? just got my security+ and wondering if I should aim for something higher security related (sscp?) or do my network+ first.

pseudo creek
rugged delta
hollow magnet
ashen cairn
# hollow magnet Well my bachelors degree that I will get this year is Computer Forensics & Digit...

TryHackMe/HackTheBox - Essentially you'll want stuff on your resume in addition to your education that show's your willingness for self learning. I would imagine that's especially important if it's an Internship. Maybe focus on some general Cyber certifications like Sec+, then look into some specific Blue Team oriented certs since most Computer Forensics teams will operate under SOC/CSIRT. Along with your degree you should be able to walk into a job with all of that.

#

Do some research of Internship/positions that you'd like to hold in the future. The majority of the time they will tell you what certifications, skills and experience is most desirable to them. Some of it may be difficult to get without the job itself, but the beauty of the cyber security industry (and the majority of IT in general) is that almost everything is available to learn on the internet, and a lot of it for free.

calm harness
#

hi everyone I wanna make the switch to cyber security and the field I liek the most is pentesting and malware what are some of the best advice tips you can give

hollow magnet
serene umbraBOT
#

Gave +1 Rep to @ashen cairn

stoic cave
# hollow magnet Thank you for all that information. It really does help! Just been lose, I've ap...

If an internship is requiring industry experience, I would say they are doing it wrong. Also, none of the things mentioned would be considered professional experience. Professional experience is gained through working in a professional environment/or jobs requiring a W2 or 1099 (or foreign equivalent). As an intern, I wouldn't expect you to have any certs either. I saw earlier that you mentioned you were receiving your degree this year. That would put you in your senior year, which is too late for the majority of internships as they are meant for current students(there are always exceptions and doesn't necessarily apply if you're going to postgraduate).

#

With that being said, and if my assumption of you being in your senior year is true, I would look for full-time employment. Open up your search to IT/Helpdesk positions or really any computer industry position in order to get a job. That will allow you to start building your professional resume and gain that professional experience. Once you have some experience, look at jumping into the field you want to be in.

hollow magnet
# stoic cave If an internship is requiring industry experience, I would say they are doing it...

Yup I should be graduating half way through this year. That's the crazy part, I have been looking for internships since the beginning of last year and they say I'm not a great fit. I applied to internships because I have no real world experience but I get turned down because I have no real work experience. I will take a look at IT/Helpdesk positions, would you still recommend taking courses in TryHackMe/HackTheBox to build up more experience?

stoic cave
#

THM and HTB are extracurriculars to show you're self learning. They are not experience.

hollow magnet
minor echo
#

Guys, got an Associate of Science Degree in IT, and now pursuing a bachelor’s degree in IT, and also plan to go for a master’s degree in CyberSecurity, are there any ways to get straight into Cybersecurity jobs?

pseudo creek
minor echo
#

US

#

By building up an online portfolio in cybersecurity, what do you mean by that?

#

And what could you say about getting started with internships at university?

hexed magnet
wheat bison
#

Is network+ and security+ and 1-2 years support engineer (helpdesk) experience enough to get a junior / entry SOC analyst position?

pseudo creek
vernal comet
#

Like I wanted to study abroad for masters in cybersecurity as in my country I'm not seeing that much opportunities/good packages for this field

rugged delta
# minor echo And what could you say about getting started with internships at university?

Some universities have internships as part of their cybersecurity programmes and other courses. You're generally expected to be doing one of these when you apply to a company's internship programme. The US has by far the largest cybersecurity industry. There are a lot of opportunities for certification and learning. Looking on job sites like Indeed and LinkedIn will show you the certs in demand in your area. Lots of people here will give advice on what certs they have or are popular or usually considered a good thing to have for an application. Maybe check out the Tribe of Hackers books, they give good advice on how to starta career in various areas of cybersecurity.

stoic cave
minor echo
#

@rugged delta Thank you for replying, bud. Also, I also struggle with the question, what If I get my certification(Sec+, Network+, etc.) now, and get a job later, will those certs still work for me and my employer? For example, they might say that I passed the exam 1 year or so.

serene umbraBOT
#

Gave +1 Rep to @rugged delta

minor echo
#

Or they are just curious about the knowledge that you took from those certifications?

rugged delta
# minor echo <@608332968796225549> Thank you for replying, bud. Also, I also struggle with th...

Gaining the certification is what matters but they will ask you to demonstrate that you didn't just cram for an exam and actually know what you're talking about. CompTIA certs are aimed at people starting the IT profession and it's generally expected that you still have some way to go to be considered an expert in your field. HR will recognise your cert but as part of any interview process there's going to be a technical test, especially at entry level or if you don't have the professional experience to perform those tasks yet

flat sedge
rugged delta
strong steeple
#

hey guys so im already a month of learning with tryhackme, i did : intro to networking, intro to cyber security , pre security, bash scripting , and im half way on Jr pentesting . a friend that working on the industry for long time told me i should split my study method to half learning with tryhackme and the other half to already start doing CTF's , so i wanted to ask what you guys think about it and also if anyone have a good resource for beginner CTF's ?
ty in advance 🙂

dense dagger
#

picoCTF is a good beginner CTF resource

midnight birch
#

hey just a small question... how can i get an unpaid internship either remote or in my location?

#

related to cyber sec ofcourse

pseudo creek
midnight birch
pseudo creek
midnight birch
#

prolly imma look

pseudo creek
#

I'd take that with a huge grain of salt. Generally if you have the funds, certs are going to get you much farther than doing things like but bounties which aren't looked at as experience on a resume. Some people spend time doing bug bounties when their time could be better spent. Now this does vary by country because poorer countries, sometimes bug bounty hunting does make sense.

#

(Also I had to verify who the interviewee was, and confirmed it is someone who was not a hacker for the nsa but may have been involved in some work there for a very brief period and overstates their qualifications)

vernal comet
stoic cave
#

Still not enough to consider a masters

vernal comet
#

So like is it okay to join as a software developer for 2-3 years and then go for cybersec? Cause that's only field I can get from on campus placements

stoic cave
#

Masters typically make sense around 6ish years into your career and only if you're receiving an education stipend

loud marsh
#

I have crowdstrike interview tmr. I wonder if anybody here have experience with them?

#

Couldnt find interview information anywhere after hour of searching

stoic cave
#

I interviewed with them for an internship. It was a pretty standard interview format, but make sure you know whatever you applied to back to front

stoic cave
#

Internship might be different, but it was a phone screen and then a technical interview

loud marsh
#

when you say technical interview

#

Is it practical or verbal ?

#

Are they give you a problem to solve on your PC or it is just technical knowledge?

rugged delta
# loud marsh Is it practical or verbal ?

Usually both a verbal and practical part. you have to be able to comfortably talk about numerous topics you have experience in and also answer technical questions verbally, in writing and perhaps in a practical demonstration

short iron
#

Hello everyone, I am a high school student working on a project and I am looking to interview someone in the cybersecurity field, such as a security engineer or penetration tester. If you or someone you know would be willing to participate in an interview, I would greatly appreciate it. Thank you.

cobalt escarp
short iron
cobalt escarp
#

as well?

short iron
serene umbraBOT
#

Gave +1 Rep to @cobalt escarp

short iron
next quiver
#

Random question, I am studying for my CEH cert. Someone near me has a Matt Walker practice test book and study guide. Would they still be relevant to the new test?

swift mist
next quiver
serene umbraBOT
#

Gave +1 Rep to @swift mist

bleak pine
#

Hey I have a question, how hard is Security+ and is it worth and how far can you get with it

fallen cipher
#

Hi there blobfingerguns

pallid barn
hexed magnet
warm galleon
#

Ine is better

undone shore
#

Don't do INE certifications

#

SANS is better

violet mountain
#

Don't hear about unkown people

#

do what you want

dreamy kelp
#

Anyone wanna help me in CTF?
Have found the target but having trouble in getting the foothold

carmine jolt
#

Youre in the wrong channel, but we dont help with CTFs generally. If you need help for a thm room, please move over to #room-help

rough loom
#

Can i delivery a Message for the tryhackme owner its urgent

broken idol
#

(Not the owner, but probably the best person to ask for your to converse with)

cobalt escarp
#

Thanks Scrubz

rough loom
serene umbraBOT
#

Gave +1 Rep to @broken idol

pallid barn
warm galleon
warm galleon
undone shore
undone shore
stoic cave
#

Yeah, Comptia has its issues, however, I don't think ive seen corpo or fed asking for INE in my area

pseudo creek
#

INE as a company has gone down the drain along with their reputation, I'd avoid at all costs

#

Comptia is well respected in the US and various other countries

rugged delta
#

Yeah currently I suppose the best cert vendors currently include:
CompTIA (particularly for new entrants to topics),
SANS (for people who have employers or other revenue to pay small fortunes),
OffSec (cos their whole Try Harder mentality is a big selling point and the knowledge gained is on point),
ISC2 (cos according to hr, all beginners need a CISSP and a million years experience to have a job, or else get Sec+)
And CEH if you're in India... There are alternatives in other countries

#

Then there's a bunch of other cert providers popping up and gaining some level of relevance in niche spaces with good reputations:
TCM's PNPT, Zero-Point's CRTO certs, Security Blue's BTL certs and others... There's several options these days

distant pier
#

Cisco for networking (CCNA, etc.), AWS for Cloud, ISACA for management (CISM). SANS related certifications would be from GIAC. 🙂

pseudo creek
paper stratus
#

Hello all, any recommendations for ICS Pentesting besides SANS?

rugged delta
sterile kelp
#

Anyone taken SecOps certs?

#

@pseudo creek you know anything about this?

pseudo creek
sterile kelp
#

I meant to ask it here

#

Never seen these certs mentioned before

pseudo creek
#

well there are a few things, random companies do make up their own certifications and it is also in the UK, but yeah that is one I've never heard from our UK folks either

half bough
#

I’ve not heard of that in the UK, common ones over hear are GIAC, EC Council, OSCP

quick forum
#

CSTM, CREST

minor echo
#

What could you say about the Security Blue Team cert? BTL-1, BTL-2

#

And I think they plan to start BTL-3

rugged delta
alpine marsh
haughty swift
#

Hi everyone i wanted to ask a question for you people.If somebody like me who wants to be a penetration tester (in future possibly red teamer) what would be the first job that i should get in order to achieve my goals.

warm hinge
#

Hey guys! I started my first job in October as a Detection and Response Solution Engineer (ik HR went a bit crazy with that title) out of Uni (BSc CompSci & MSc CyberSec). My manager wants me to become an expert in EDR and told me to take one of the SANS certifications, with regards to EDR, but also what I want to do later on in my career. My current work is doing field work for the ppl that write the detection rules: looking at what data is available, providing some use cases and PoC. It's not an operational role and I feel like I'm missing out on "getting your hands dirty". That's why I would want to do a course that involves this aspect.
I'm currently looking at:

  • FOR500 (Windows Forensics)
  • SEC560 (Enterprise Penetration Testing)
    Any other recommendations for EDR or thoughts?
    Thanks!
distant island
#

Begin giant response:

#

I'm a software engineer, but have studied how to become a red teamer.

As far as your first job that you should get, it depends on your experience.

#

If you have no IT experience, then helpdesk is the traditional rite of passage. It totally sucks, and you'll be helping customers with basic computer issues, but it will introduce you into the first level of knowledge and pain associated with IT, haha.

If you need to get your foot in the door, CompTIA A+ certification will help. Once you've gotten a helpdesk job, I highly recommend studying for CompTIA Network+. It will cover baseline knowledge you will require throughout your career as IT and then pentester / red teamer. The cert isn't very marketable if you're already in helpdesk from what I understand, but get it if you want.

One thing to point out - it doesn't look good if you've been at helpdesk for more than 2 years. Most people try to get 1-2 years experience with helpdesk maximum while they build their skills and then move into a sysadmin position.

#

After helpdesk, the next best role is sysadmin. This will get you familiar with maintaining servers and also possibly networks. I highly recommend learning as much as you can about Active Directory, as this is critical for most corporate networks. Linux is also important for web and other types of servers, so spin up a virtual machine at home if work doesn't provide access to Linux servers. While you're working as a sysadmin, I highly recommend studying for and obtaining your CompTIA Security+ certification. This will give you baseline security knowledge and also allow you to work government jobs that require DoD Approved 8570 baseline certifications.

#

After you've had your fill of sysadmin, I recommend getting a job as a SOC analyst. This will expose you to probably more than what you would have seen as a sysadmin, in terms of security alerts. From what I understand, you will basically triage, process, and escalate security alerts all day that come in from a variety of sources, and learn about all sorts of real-world attacks. While you're doing this, I recommend studying for and obtain your CompTIA CySA+.

Note: You might be able to go directly from helpdesk to SOC analyst, or even no experience to SOC analyst if you know what you're doing and can market yourself.

#

You can then work your way up the SOC chain (tier 1, 2, 3) while learning and practicing pentesting. CompTIA Pentest+ is basically the same material as CySA+, from what I understand, so I figure it's worth tacking onto your resume once obtained. Once you have a good reputation as a SOC analyst and have proven yourself in the blue team, I think it makes you way more marketable as a penetration tester. You can then start applying for jobs. Seeing that you have SOC experience with side projects at home on TryHackeMe or HTB, alongside a variety of relevant vendor-neutral security-related certifications will demonstrate that you're capable of being a penetration tester.

#

At this point, you've gotten a penetration testing gig, and are learning how things actually work at that level. You'll probably gain a ton of experience and hopefully pick up your OSCP cert along the way. After years of penetration testing, and you've become an expert with senior-level knowledge, I think that is when you can become a red teamer. When you're not just smashing tools against a server, creating tons of noise, but actually crafting specific, quiet, custom payloads with misleading meta data, on the bleeding edge to carry out a campaign over months against high-value clients.

#

Hope this helps! 🙂 (I wanted to become a red teamer, but now am more interested in appsec and reverse engineering malware. But, I have the blueprint for you!)

quick forum
#

Note: That advice is US specific, it will vary country-to-country

old furnace
dreamy whale
# distant island I have.... a very long response for you. Lol. It's Sunday, I've had my coffee, a...

I just wanted to let you know that I think you gave a very solid response. I was also wondering if you or someone else could provide some more information about career paths in the field of cybersecurity in India. I am currently a junior software engineer and am interested in transitioning to a role as a security engineer. Do you have any recommendations or advice for how to pursue these types of careers in India?

haughty swift
serene umbraBOT
#

Gave +1 Rep to @distant island

marble pagoda
#

I’m a senior at university, I’m getting my B.S. in CS, I hear that the pay isn’t very good in cyber security. Is that a myth? I’m in the US.

rugged delta
pseudo creek
elder crater
#

Henlo people! Does degree in psychology bring any value in this field?

dreamy whale
distant island
distant island
serene umbraBOT
#

Gave +1 Rep to @old furnace

distant island
warm hinge
#

Hey. Shot in the dark but is anyone available for a few quick questions and has been working in industry for 3 or more years? Its for a scholarship & no I don't need any information about you.

asked azure!

silk crag
#

hi

pseudo creek
cerulean zodiac
#

good so far

simple crater
#

Hello everyone, any information would be much appreciated. I am planning to interview for a entry-level incident response position, the position is a federal position. My questions is, what was your experience with an entry level incident response interview? Were you stumped by any particular technical questions? I feel like it should be pretty basic general cyber-related principles, incidence response cycle for an incident, etc.. was just curious if there was anything that anyone in here thinks I should look at or work on before the interview. Thanks in advance.

pseudo creek
pseudo creek
simple crater
# pseudo creek I would focus on what is on the job listing. They will most likely ask you basi...

Awesome, thank you. This will be the second interview so I assume this one will be a little more geared towards the technical questions, but who knows. I'm assuming they will ask about some SIEM tool experience and the general ones that you pointed out. I really would be more worried if they were to ask forensics questions as I don't have a lot of experience in that realm. This site seems to have some good info though so this should help. Thank you again for your response.

serene umbraBOT
#

Gave +1 Rep to @pseudo creek

warm hinge
#

Hello, I am conflicted on whether going cyber through the military or going the college route. Looking for opinions

pseudo creek
#

are you in the US?

warm hinge
#

@pseudo creek hi! are you still available for those questions?

clever knoll
#

I figured id get this question out pre-age but is there any reccomendations on wether to focus on blue teaming or red teaming for careers in the future

flat sedge
#

That's up to you. What do you enjoy, where do you think you can bring value.

#

Both parts are essential, in my view, to a supportable and informed security posture.

pseudo creek
#

I wouldn't worry about it too much, do some studying, figure out what you like then focus a bit on that

#

nothing you do will be set in stone

clever knoll
flat sedge
warm hinge
clever knoll
serene umbraBOT
#

Gave +1 Rep to @flat sedge

clever knoll
#

I appreciate it both of you :)

warm hinge
#

azure is big cool

pseudo creek
# warm hinge yes in the us of a

so first thing that you know is all recruiters lie... they can tell you that you'll totally get a cyber track within the military and then you don't. So you are locked into a few years of the military not doing what you want or possibly what even helps you afterwards.

warm hinge
#

no I would actually get it

#

Im already in the service

pseudo creek
#

oh! ok

#

so can you switch to cyber?

#

or is it part of the reserves?

warm hinge
#

yeah, I can do that

#

I would go active cyber

pseudo creek
#

well also you will be paid vastly less in the military than you can be paid on the outside, you might want to join VetSec, usually the question you asked is asked by people who are thinking of joining

warm hinge
#

I do want to work for the government doing hacking, but if I went NSa they would pay far less then military

serene umbraBOT
#

Gave +1 Rep to @pseudo creek

pseudo creek
#

you might know that NSA has gov contractors, direct hires as well as military assignments

#

I know someone who was in the Air Force (and actually in the Air Force...) and worked at the NSA on assignment

#

but the NSA cap is less than private industry and I think even contractors working at the NSA have to keep to that cap

clever knoll
#

I kinda wanna do cyber usa

#

I swear they dont have to move round like cybersecurity military here

pseudo creek
#

I dunno, the person I know who was at the NSA was rotated out after a while

#

but I know someone in the reserves working in cyber and their job seems to be site located

clever knoll
pseudo creek
clever knoll
#

chill out at your local base

pseudo creek
#

(reason to choose Marines/Navy/Coast guard as you will be at a coastal location... ) (don't shoot me other branch people)

pseudo creek
clever knoll
#

I might still try it but i need to do the fitness along with it🥹

pseudo creek
#

once you get there, won't be too hard I don't think

clever knoll
#

Uk navy is deadly my brother send me videos of him doing it💀

pseudo creek
#

getting fit / passing a fitness test seems daunting but lots of people have done it

clever knoll
#

fair enough

#

I just need to get myself prepped and i might give it a shot

#

its been alot of help speaking to someone in that position tho

#

ty :)

warm hinge
#

i think im going to go the civilian/contractor side

#

I really want to go to CMU

dreamy whale
#

Hey everyone! I was wondering if anyone here has recently taken and completed the Certified Appsec Practitioner (CAP) exam from SecOps? If so, I would love to hear about your experience and whether you think it was worth it! Thank you in advance for your insight.

wet spire
#

is there a good certification to get to make it easier to get a entry job or intership? i looking to try to find one soon

stoic cave
wet spire
#

i graduated on CC last year, have been working as a developer for sometime and now want to go to infosec, i am trying to enter on a pos gradeation degree on it but i not enrolled yet

#

probably will be later this year

stoic cave
#

So, it's not typically recommended to go for a post grad while also trying to get a an entry level job. Doing so will price you out of entry level salaries.

#

Should also be known, that typically in order to get an internship, you need to be enrolled in an undergraduate or postgraduate program.

#

Am I right in assuming that when you say you've been working as a developer, you're doing it for a company?

wet spire
#

if i enter in it, i would apply for intership

stoic cave
#

I don't know that it will be advantageous to enter a post grad just for an internship

wet spire
#

so what would you recommend?

stoic cave
#

Postgrad is typically designed for those who have some level of industry experience and need it to advance past mid level positions

#

In previous posts, others have recommended looking for security roles that incorporate what you've been doing as a developer. I cannot speak to this personally though, as I went into security straight out of undergrad.

#

As far as certifications, Security+ is the fundamental cybersecurity cert in much of the world. India does its own thing, afaik

wet spire
#

well this already helps, thanks brother

edgy torrent
#

hi guys. I checked a few messages here in order to figure out where I can move from SDET position. And since I have some IT background - the best option, as i understood will be SOC. Is that true? Another question - I have tried to find wages for this position and I am not sure if those numbers are realistic. Can you please share from your experience - which salary I can expect as Jr for SOC position (I have 6 years as SDET)?

pseudo creek
edgy torrent
pseudo creek
edgy torrent
rapid zenith
#

Wages in europe are highly dependant not only on the country of where the position is offered, but also on the city. A place with higher cost of living in general will have a higher pay

#

So if you are wondering if X EUR is realistic, it depends

#

The US is probably similar. Zojj should know

pseudo creek
#

well the US is tricky as a lot of cyber positions are US citizens only and a company that would take you on with a green card may pay you less, sadly. Pay varies greatly but for a US citizen for a junior pentester, I'd say 70k to 110k...

loud marsh
edgy torrent
serene umbraBOT
#

Gave +1 Rep to @pseudo creek

edgy torrent
rapid zenith
#

You'd be entering a new field in an entry position after investing multiple years in other career path

#

Highly likely it would be a pay cut

pseudo creek
#

and generally, software development is a highly paid field

rapid zenith
#

Good luck with the move, though!

drifting swift
#

Hello how can i become a pro hacker

warm hinge
#

Anyone have a good quiz to see where you best fit into Cyber/determine a Cyber path?

austere fractal
drifting swift
mighty solar
#

Hello, I'm going to have my first interview for a cybersec intern at a bank. What are the best ways to prepare for cyber interviews?

rugged delta
# mighty solar Hello, I'm going to have my first interview for a cybersec intern at a bank. Wha...

Congrats on getting that far. As it's an internship, the bank will most likely be interested in knowing how far you've progressed along your path to a career in cybersecurity and where you see it taking you. You'll need to understand at least some of the concepts that the bank is hiring for in the job description they had that you applied for, but the purpose of an internship is also to give you an opportunity to learn about a role or the organisation themselves.

If you're in a college/university course, be able to talk about the subjects you're learning, the ones you feel the most important to your path and where you might like to go with those skills. If you have projects completed, be able to talk about them and your experiences. You might be asked about specific technologies being used or roles the bank offers but in most instances you probably won't have to know much about the technologies in use in a SOC or what a specific product does as part of an Identity and Access framework or what skills you need as a cloud security engineer.

The main thing is to just be able to talk about technologies in general (mainly operating systems, networks, applications, security systems, programming/scripting), security skills and technologies (If you've read the Sec+ it would be a great help), skills and challenges you've encountered in THM, college projects, any other certifications, books on the subject... Show enthusiasm and professionalism and a willingness to learn

mighty solar