#cyber-and-careers

1 messages · Page 32 of 1

fiery oar
#

If I do isc2 cc exam , is it really mandatory to pay the membership fee. There won't be any trouble if I get the cert and stop paying for membership ryt?

pseudo creek
humble panther
#

Hello everyone I'm currently working as a DevSecOps and I would like to switch in a different career ideally in Digital Forensic and apply in cybercriminality field at the end of my Master degree in CS. I have some knowledge but still a beginner in this topic does anyone got some advice in term or course/activities book, feedback or any others stuff related to that ? Thanks in advance blobheart

jade shuttle
#

Just got my sec+ certification as I'm trying to ditch being a line cook to become a cloud pentester. I'm studying for Net+ but it's hard on a line cook schedule. Anyone got advice for landing an entry level support job?

ember wind
fringe spade
peak canopy
#

This seems like the best place to ask this question. Does tryhackme count for (ISC)^2 CPEs? If so how do people normally submit them?

stoic cave
thorny light
#

Cert question: After Sec+ I'm seeing a bunch of different recommendations on what I should pursue next. Some of the common responses are: CompTIA CySA+, CEH, CISSP, and more.

#

anyone have thoughts on the "Cert path" I should look into?

flat sedge
#

Whatever will enhance your job role and you can get work to pay for

#

Spending your own money on certs is not a great idea unless you have cash to burn

thorny light
#

I got the Sec+ myself so I could try and transition to cyber from development

#

I'm writing about future plans to show interest and growth

flat sedge
#

Ask to shadow your current security team

#

See if you can start to build that experience within your org first, before trying to spend your own money on business things

thorny light
#

my next cert will certainly be paid for by whatever sec job I get

#

I'm just trying to have some idea of what I want to pursue without sounding like an idiot

#

Sec+ was really easy for me, I think I could do a CISSP but I'm not sure how that comes across to people who may not know me.

flat sedge
#

unless you are in india, EC Council is not a good look

thorny light
#

That's CEH?

flat sedge
#

CISSP is a great one to have, but I think exam is almost $800.

#

Yeah, CEH is an EC Council cert

thorny light
#

I was just reading about how CEH has lost a lot of credibility

#

I wonder how HackTheBox certs are seen

flat sedge
#

and CISSP requries 5 years experience in at least 1 primary domain to qualify

thorny light
#

I believe if you pass and you don't have the exp you get an "associates"

#

IE: passed the test, hasn't checked a box yet.

hot pelican
#

Hi I'm new here...... And new to i.t..
Can anyone recommend learning material for the network plus?

The material I've been given is far too detailed.. And I'm never going to remember 48 hours of videos in a few months.. 5 or 10 hours more memorable for a beginner like me.

Thanks

thorny light
#

Cybersecurity as an industry is very research heavy, you should get used to studying and taking notes.

thorny light
#

Yeah don't try and do too much in a given day. That's heavily romanticized but it's something you have to build up to.

#

So start small. Consistency is key.

hot pelican
thorny light
#

Take notes on what the videos talked about like you would in a lecture

#

If you have the time consider making projects based on what you've learned

hot pelican
serene umbraBOT
#

Gave +1 Rep to @thorny light (current: #2190 - 1)

thorny light
#

Oh hey I got my first rep. Nice

cerulean sun
#

Yo

#

😭😭 lvl isnt synced yet

warm hinge
#

and boom

#

it syncs

valid fractal
#

Hello everybody,

I get my first security job a few months ago and today we noticed somebody is using a bot for Brute Force Attacks using some of my coworkers' accounts.

After a few failed attempts, the accounts are blocked, preventing the people from working.

Does anybody has experience blocking these kind of bots?

How can I stop them?

Thanks.

warm hinge
#

|| @broken idol can't help with work, right?||

broken idol
valid fractal
serene umbraBOT
#

Gave +1 Rep to @broken idol (current: #1 - 2655)

still apex
#

PFIC 2024

drifting bolt
#

hi , im new here and also my english its not good , sorry for my future mistakes. Somebody from Europe who ist appsec admin, sast-dast-sbom. thanks a lot and have a nice day

broken idol
#

Can you please see the respone I wrote.

#

As much as we'd love to help.

We don't know if;

a) They have the permission to make such changes.
b) Have to research and workout this by themself as part of their jobs/responsibilities..

agile ingot
broken idol
#

@hardy socket Please reach out to our admin team, if you wish to post a job.

hardy socket
#

Oh sure

broken idol
hardy socket
loud narwhal
#

Iam a job seeker from india, obviously iam a fresher, is there any job opening, please let me know, moreover Iam bad at texting so please apologize for any mustake if any.

shy otter
#

is distance/purely online pen testing a thing, freelance/independent work? or is it primarily in house hiring. curious if anyone has any experience on that, and wouldnt mind clarifying. thanks!

soft pike
#

I failed the CBBH and I had managed to do a little more than 50% of the exam, I was not up to par and I thought maybe I should move on gradually and I saw the TCM PJWT, would it be interesting for a web pentest / bug bounty certification before the CBBH? Or do you think I can directly do the PWPT?

#

Else if you have labs from THM / HTB / Other plateforms to be sure to have CBBH without too much difficulty, I take it as well :), to train.

pseudo creek
#

I think generally port swigger and the CBBH training, plus some practice could be/should be, enough?

daring hinge
#

Any ideas of what to train for a first internship in the US? Turning 16 in a while.
Want something in IT/Cyber.
Have done Security+, Google Cybersecurity/Data Analytics, PCEP (Python), A few TryHackMe pathways already.

thorny light
wary frigate
#

Looking for simple online challenges to test what I can do in a realistic scenario.
I've got plenty of isolated knowledge, but I need to start tying it together with experience.
Any ideas?

wary frigate
serene umbraBOT
#

Gave +1 Rep to @dense dagger (current: #22 - 392)

pure depot
#

How we can implement our programming languages like c++ python into hacking

soft pike
pearl mango
# dense dagger TryHackMe has CTFs

Are the result shown in like a public profile or something
Like you know some leet code programs, where even non-signed in users can visit your public profile and see your achievements

dense dagger
#

Usually, you'd only see the rooms done by people and that includes non CTF rooms

pearl mango
#

In short I'm looking for things I can showcase on my resume

#

I have mentioned my certs there
So I was wondering if there's anything besides certs to showcase too, like labs n ctfs
Coz they're usually things like these are private, I can only see mine with my acc

soft pike
#

In any case, it's the key to everything, but personally, I didn't find the environment I had at all to be at the same level of the courses.

dense dagger
worldly whale
cobalt nymph
#

Hello, can someone who has a career as a Pentester help me? I have a lot of doubts about how to start a career and take the first steps to learn more about the subject as I am very confused.

Thank you!

flat sedge
serene umbraBOT
#

Gave +1 Rep to @flat sedge (current: #10 - 773)

cobalt nymph
#

My question to Pentesters is, how do I start from scratch to achieve a career as a Pentester?

flat sedge
#

Pentesting requires a decent understanding of systems to be tested as well a good understanding of risk - the role of a pentester is to test security controls in production without causing unacceptable damage. Acceptable damage is always determined by the system owner.

I would say that pentest is not entry level to security, and security (in general) is not entry level to IT

stoic cave
cobalt nymph
# stoic cave Without a degree or prior professional experience? Start in an entry role, ie He...

This is certainly a great way to go! And yes, I don't have any experience or a diploma or even knowledge of the content, I'm looking to learn more about this area because it's the area I'm determined to work in and also the one I'm most interested in, and at the beginning of the year I intend to look for a diploma that is directed towards this area, could you direct me on all this as well?

dawn wraith
tight mason
#

Hi, what is the first entry point for beginners in tryhackme.com site? i mean first initial steps for learning...

soft pike
dawn wraith
cobalt nymph
dawn wraith
# cobalt nymph Interesting! What I'd like to know is if tryhackme really has the basics I need ...

well. i'm an educator and switching careers. so, my suggestion is to get a book on self-learning (like the science of self-learning by Peter Hollins). from there you can get all the resources you need to teach yourself anything. entering an education facility would then be something you know if you need to do or not. (for example, you want to become an orthodontist, you need to go to dentistry school). to answer you more directly. you need to use several resources to learn what you desire. tryhack.me is one, and a great one. pulling resources as you explore from other areas will be more obvious to you, once you begin going through all your chosen resources. but to think you will become indiana jones and solve the mystery of the pyramids from reading one book is a lofty assumption to achive your goals. if you catch my drift.

tight mason
dawn wraith
#

actually ask in the pre-security-pathway room, not here. i think we aren't suppose to really be talking about this in this channel.

cobalt nymph
serene umbraBOT
#

Gave +1 Rep to @dawn wraith (current: #2193 - 1)

bitter blade
#

I have 73 badges out of 74

hallow sierra
#

Hello. I work at a business who employs in house Red and Blue teams. I am not in the infosec side of things at all though. It is something I have always wanted to get into but have been busy with life. I have a history in computers as a hobby, mostly on the physical side of things but have also dabbled in programing video games. My main experience is in Windows but I do have a little experience with linux. Where is a good place to start my journey? I plan on going through all the TryHackMe courses. I am wondering if there is a suggested guide to getting certs; which ones are worth it and what order to do them in. Also, is there something I should be doing before TryHackMe? I have seen online suggestions of getting a "help desk" job or something like that first. Any help would be greatly appreciated, and sorry for the novel.

dense dagger
# hallow sierra Hello. I work at a business who employs in house Red and Blue teams. I am not in...

Since you already are in a company that has an in house blue and red team, I would suggest try to do an internal pivot to them. You should definitely solidify your foundational skills (Networking, Linux/Windows, application, etc.) and TryHackMe definitely helps there. Keep in mind that TryHackMe is a way to dip your toes into these concepts and technologies but you should definitely also challenge yourself with doing projects and other things like CTFs to build your skillset and problem solving.

#

For certifications, there is really no order to do them. I would suggest looking in your local area or peers among your company which are good certifications to take however.

hallow sierra
#

Yea, the plan is to pivot internally. But I fear they wont give me the time of day until I have more knowledge under my belt. I will work on TryHackMe and then do some CTF's though. Thank you.

dense dagger
hallow sierra
#

Thanks. I will do that. I appreciate all the advice.

high flower
#

Who is TryHackMe's HTTPS certificate issued by?

pseudo creek
broken idol
glacial ibex
#

hey guys, I want to prepare for the security +, I have a degree in computer science and cybersecurity. Whats are the best resource to start to study for the security + ?

glacial ibex
serene umbraBOT
#

Gave +1 Rep to @crystal acorn (current: #2194 - 1)

crystal acorn
#

People also recommended Inside Cloud and Security on YouTube

glacial ibex
earnest lark
glacial ibex
#

what is your current level on cybersecurity ?

stoic cave
stiff oriole
#

Do you consider a salary range of 65k-155k as a red flag in a job description?

glacial ibex
#

in us ?

stiff oriole
#

yes

crystal acorn
stoic cave
#

More experience = higher salary

stiff oriole
#

I could see that. I always figured it was just them trying to catch the largest pool of people without actually paying that much but you're probably right. It's a remote job so they probably thought for low cost of living it's 65k and New york or SAn fran it can be 155 or something

#

thanks

quick escarp
#

tryhackme.com is really cool website so far. Looking forward to taking networking security based lessons from this. Never really thought I would of been any good at network security cause I tried a network class a couple years back and failed it cause I was subnetting wrong. I only collected like 3 or 4 badges so far but question. Does anybody feel more comfortable learning on here then going to a college and dealing with all the pressure to learn the fundamental's of cyber security. Cause the schools want you to learn about general education courses that require lots of reading a writing and math. Which if you tell I already have issues with. Maybe I could just become a pen tester and dabble in different software's. I am nervous I might not have a good enough background in computers to go this route.

stoic cave
# quick escarp tryhackme.com is really cool website so far. Looking forward to taking networki...

If you have the opportunity to attend a four year degree, I would do it. You'll receive information at a steady pace and it's goal is to make you a well rounded contributor to society. It also helps salary wise. As far as reading and writing, that's what you do in cybersecurity (this includes pentesting) . A lot of the work is report writing and requires you to be able to put together well written/formatted documentation.

quick escarp
# stoic cave If you have the opportunity to attend a four year degree, I would do it. You'll ...

I need to practice more on my reading and writing and report writing? Wow! That sounds exhausting and repititious. But your right I would contribute to society better with a 4 year degree I only have an associates degree and work in construction with some health issues. But im trying to go in some direction at least. Networking is somewhere I figured I could start off at or there's A+ computer repair. Something where I'm sticking to the fundamental's of something towards. I am just neverous about having timelines again and not having everything finished to continue with school. All of my comprehension and placements scores would be terrible right now. Maybe there's some school or some class I can still take that get my mind better inclined for a cognitive thinking.

dapper heath
#

Hi friends,

I’m 23M in the UK. I completed my Bachelors in Computer Security this year, Security+ and now working on my CCNA. I have 11 months of IT Helpdesk experience, and I just landed an IT Support Engineer position with a focus on networking (will be groomed into a network engineer).

I have been doing CTFs for years now, mainly for fun, with 300+ labs/rooms completed across TryHackMe & HackTheBox alone. I’ve purchased the PJPT & PNPT exams from TCM but haven’t taken them yet because my focus is all over the place, and that’s why I need your help. I’m desperately seeking your advice on what a path could look like to achieve my goals and how I should move forward in my career.

My dream is to one day become a very specialised penetration tester, mainly focused on something super niche like IoT, embedded systems, 4G/5G, wireless etc.

I’m by no means in a rush to get there, and although I feel behind some of my peers that landed a cybersecurity position after graduating, I think the network engineering experience will only help me down the line. What’s important to me is to get there eventually, and be the best that I can be when I do.

What would you suggest I do to best equip myself to not only land a job as a penetration tester, but be a great one when I do? I’m willing to do whatever it takes.

Here are a few paths I have thought about:

  1. IT Support Engineer -> CCNA -> Network Engineer -> CREST CPSA -> SOC 1 -> PJPT -> PNPT -> CREST CRT -> Jr. Pentester Job?

  2. IT Support Engineer -> CCNA -> Network Engineer -> BTL1 -> SOC 1 -> PJPT -> PNPT -> OSCP -> CREST CRT Equivalence -> Jr. Pentester Job?

TLDR:

  1. On the path to become a network engineer, how can I prepare to break into cybersecurity from there and then into pentesting?
  2. Should I focus on SOC skills/certs after CCNA?
  3. What pentesting certs would you recommend in the UK?
  4. Am I on the right path?
  5. How can I stop comparing myself to others who are ‘ahead’?
#

Sorry if this makes no sense, but I’m really lost with no one to go to and in a bit of a panic before starting this new job. Thanks in advance, anything you can add will be greatly appreciated.

rugged delta
# dapper heath Hi friends, I’m 23M in the UK. I completed my Bachelors in Computer Security t...

It seems you've been working very hard and have developed some unique interests, always a positive when pushing into cybersecurity. Knowledge of IT and networking can carry you a long way, as they are an essential part of cybersecurity knowledge and skills going forward.

Your certification path is certainly interesting and well thought out, and your training so far appears to be in line with a successful career path if you maintain your learning rate. Completing the CCNA as a network engineer is pretty par for the course and could lead you on to the CCNP as well, if that's where you're spending a few years.

BTL1 is gaining recognition as a good cert for junior SOC analysts and a number of regulars on this Discord have had a good experience with it. CREST CPSA is a worthwhile pursuit in demonstrating your abilities and professionalism and there are a number of recognised training orgs in that sphere with a high level of quality learning platforms. An alternative to, or progression from CREST would be the Cyberscheme, in association with the NCSC and UK Cybersecurity Council.

PJPT/PNPT are a good path into pentesting, and offer a reasonable representation of junior-level pentesting, but you would probably be expected to acquire the OffSec OSCP, as that is still the most widely recognised junior pentesting certification. Still, if you hold the CREST/Cyberscheme/TCM certs, you should feel capable of applying to such a role.

As you have set your sites on recognised certifications, and have been building your skills on multiple platforms, you should be in a good position. You could consider doing CTFs (PicoCTF is a good start here), bug bounties (mostly for fun, don't depend on it for reliable income) consider writing a blog, and/or writeups, maintaining a Github account...

As for comparing yourself with others, realise you are on your own journey, as is everyone else. Throw yourself into it, doing the work will inspire your confidence and you'll see results

brittle galleon
#

Hello guys, for someone looking for roles in cloud security, what will be the ideal pathway? Will you also recommend taking Comptia Sec+? Then what will be your view on CCSK cert as well.
Thank you and I will need some guidance. I am currently pursuing my masters in Applied Cybersecurity and Digital Forensics at Illinois Institute of Technology.
I am also in search for Internship opportunities and will appreciate some leads.

Thanks 😊 🫂

rugged delta
#

To operate successfully in the cloud, in general you should have a good understanding of general Linux/Windows/Network administration & engineering. You should be able to setup and configure Linux and Windows machines and services (on a computer or in a vm) and understand basic networking (Network+ level knowledge). The Security+ is a good entry level cert into all areas of cybersecurity.

As for cloud certs, each of the big three (Google, Azure and AWS), they each have their own certification paths and you should at least follow their beginning engineering certs for the platform(s) you want to work on. While their security certs are reasonably good, you should already have a decent level of knowledge of how their platforms operate and how to use them. Security would be considered an advanced topic, so shouldn't be your first foray into the cloud, but it's definitely something that's not beyond your ability to pursue. There are a lot of free and paid training facilities online and in books, etc.

The CCSK has been gaining some recognition as a good intro to cloud security, and something you might find helpful on your journey. They have a free prep kit you can use to gain good general knowledge in your preparation. It might not be necessary to pursue the full cert if you're pursuing a specific cloud provider's certifications. The main thing you should be doing is gaining hands-on experience with cloud platforms and the big three each have their own free tier offers to help you

fiery oar
#

My frnd got an internship offer as a Security Analyst at a mid-sized company. It’s unpaid but they’ll cover food, transportation, and medical insurance. The internship lasts a 1 year, and they’ve mentioned there’s a good chance of a full-time job if he performs well and there’s an vacant opening. He's concerned about it coz work hour is full time and has multiple shifts with strict holiday policy even for interns which disturbs the uni placement stuffs. I'm from India

Considering how tough it is to break into cybersecurity as a fresher, do you think this is a good opportunity to take?

tall stone
#

Hello. My name is Aaron and I'm trying to get into cybersecurity. My background is in music. I was in Warehouse Operations Management for seven years. I have been taking the lessons in TryHackMe. I have been listening to as many podcasts as I can about cybersecurity. I was going to take the Google Certification exam. Does anyone have any advice for someone like me that is entering this field as a newbie? Any advice would be appreciated. This is something that interests me and I'd like to make a career out of this. Thanks in advance!

rugged delta
# tall stone Hello. My name is Aaron and I'm trying to get into cybersecurity. My background ...

Welcome to the world of cybersecurity. I would advise developing an understanding of computers, how to install and run Windows/Linux, install/manage general applications like web servers/databases, learn some basic bash/python/powershell, understand the basics of networking. You can learn a lot of these by following THM and supplementing with other resources like books/courses/websites/certifications as you progress, but if you're just starting out, there are a lot of helpful walkthroughs and fun challenges here on THM.

I personally wouldn't worry too much about the Google Cybersecurity Certificate, it's just a certificate of completion and doesn't stand for much in the field. You're better off learning here and pursuing something like the CompTIA Network+ and Security+. Even following Professor Messer's free courses would go a long way to developing your knowledge, even if you don't pursue those certs at present

tall stone
serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #19 - 413)

bronze spire
#

Do remote jobs that require top secret clearance exist? Or is that not a thing?

stoic cave
#

It's going to depend, so I won't say it's not a thing, but it's pretty much not a thing. TS is a different animal. Hybrid is more likely.

warped ocean
#

hello people, im currently a student completing my Computer Science degree in college and Im very interested in Cybersecurity field. Wanted to ask, should I first focus completing my degree and then do Cybersecurity courses or do them side by side? Also what all courses or material do yall recommend?

dense dagger
#

If you feel like you can do it at the same time, that’s great. You’ll be able to understand concepts and then see how it is from a security perspective

woven mirage
#

you might want to redact private information before posting a resume on a public discord server

broken idol
woven mirage
#

he posted a resume with his full name and location

woven mirage
broken idol
#

Or if he doesn't mind his name and location being public.

#

That all depends on your opsec.

knotty juniper
#

Hi there, another question from me 😄 do you have any particular course to recommend which prepares to CEH?

dense dagger
serene umbraBOT
#

Gave +1 Rep to @dense dagger (current: #22 - 396)

flat sedge
warm hinge
#

@dense dagger what do u recommend me? Dominican Republic

#

i have no idea what cert go for

rugged delta
# warm hinge i have no idea what cert go for

I see from your previous posts you are interested in pentesting. So you should be comfortable with a reasonable level of Linux/Windows/Active Directory/Powershell/bash/Python/networking knowledge; such as being able to install and manage web servers/databases, configure Active Directory settings, understand/modify a script, know what routers, switches, firewalls, IDS/IPS are. You'll learn a lot more about them on your journey.

For pentesting certs, consider the OSCP, it's generally recognised as the standard, as it's intended to get you from beginner to junior/intermediate level, and teams/hr/clients frequently request/require it. Other people will go for certs like TCM PNPT, HTB CPTS, as they are cheaper and might be better at conveying knowledge/skills for certain subjects/topics.

While certs might be good for your cv/resume, you really need to be able to demonstrate your skills/knowledge above and beyond, so consider entering CTFs (PicoCTF is a good precursor), doing bug bounties (not a dependable way to earn but good for experience), maintaining a blog, doing writeups, having a github account

serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #19 - 415)

warm hinge
#

thats the only thing i dont know on the list

rugged delta
# warm hinge sorry, i have another question, how can i learn python scripting?

Python is a very common language in cybersecurity, programming and IT. There are lots of free and paid resources online. There are rooms in Try Hack Me that teach some Python skills. There's a book called 'Automate The Boring Stuff with Python', free to read on the book's website, or available to buy from the publisher, No Starch or other book retailers. You can go to python.org, learnpython.org and lots of other websites for free or low-cost lessons, tutorials and other learning materials

https://tryhackme.com/r/hacktivities/search?page=1&kind=all&searchText=python
https://automatetheboringstuff.com/
https://nostarch.com/catalog/python
https://www.python.org/
https://www.learnpython.org/

warm hinge
#

thanks so much again, i love this community <3

rugged delta
#

Good to have you here, keep up the work

warm hinge
#

You can have ChatGPT write you code, also. : )

rugged delta
# warm hinge You can have ChatGPT write you code, also. : )

Yeah but you're not learning anything, and it can frequently be poor quality, very basic, or wrong; so you'lll still need to understand the code to be able to correct and modify it. Even the best coding LLMs have an effective rate of about 13-14%, and can actually increase the workload of professional programmers

warm hinge
#

Of course

#

But let's face it: AI is very helpful

heavy elm
#

hi! i have been learning cyber for a year and i have good foundations but Active Directory and Windows Exploitation are too complicated for me currently. Can i ask how have you learned those topics?

warm hinge
#

Who, me, or mister Subtlets?

heavy elm
#

anybody 🙂

warm hinge
#

Everything I have learned has been by myself, I started when I was 15, creating stupid banking programs with C# lol. I study a lot, and practice makes perfect. In this field, you need the motivation and practice. You can learn a LOT in a month.

heavy elm
#

on what have you practiced?

warm hinge
#

A lot.

rugged delta
twilit prairie
#

hi, would anyone be willing to look over my resume? this is my first time writing up a resume and need help

rugged delta
twilit prairie
#

i will do that now, ty

#

its not allowing me to attach photos

crude sphinxBOT
rugged delta
twilit prairie
#

if anyone would like to review my resume here it is 🙂

stoic cave
#

I'll take a look a bit later, but generally the battle with prior service resumes is the translation to things that civilians care about

twilit prairie
#

yea it was hard trying to translate military to civilian on the resume

#

i did military for 9 years, worked as a cashier/housekeeper before that as a teenager and haven't had other civilian experience

#

so writing the resume was a little hard for me

stoic cave
#

Yeah, it's not an issue. Just have to use the right words

twilit prairie
#

i used this resume to apply for jobs and never hear back. so at this point whatever makes it sound or look better

stoic cave
#

Just visually, imo, the center justified is kinda bleh. If you've got some time, I'd look at putting this into a LaTeX template. AwesomeCV is a popular choice. Its machine readable as well, which is good.

twilit prairie
#

LaTex temp is a website right?

stoic cave
#

I use Overleaf for LaTeX editing

plain temple
#

thinking of going into AI

twilit prairie
#

is that downloadable?

#

ive never heard of that before

zinc girder
#

any blue teamers ever miss a TP then realise a few days later and feel like a complete idiot and have to go back to it because it's been eating at you because you knew somethign was off and then discover a really novel exploit that you hadn't encountered before

stoic cave
twilit prairie
#

ah gotcha, and it helped you?

main mango
#

Hi

#

i actually have a simple question, what after ejpt? my goal is to be a red teamer maybe a bug bounty hunter in the future i dont want a certificate i just want experience and knowledge. thanks

dense dagger
#

To be a red teamer it is preferred to have experience in working in a pentesting environment either in a consulting or internal team. It is seldom that these teams hire recent graduates or new to the workforce with little to no IT experience so you’ll also need to gain some IT experience before pivoting to these types of roles.

#

Knowledge can come in different aspects, whether it be specializing in network/infrastructure, web, mobile, etc. so as long as you’re learning you will be able to piece together different IT domains together.

zinc girder
stoic cave
main mango
main mango
stoic cave
#

Attend a four year degree if you can.

stoic cave
main mango
#

yes i got paid , yes i paid taxes

main mango
#

So i dont and take other courses untilli graduate ?

#

until *

stoic cave
#

You should focus on school because that's what's important. Do things like TryHackMe on the side, but don't let it take away from a life requirement.

main mango
#

yeah definitely my main goal is to graduate now but i will take courses after school like CPTS

stoic cave
twilit prairie
# stoic cave Its just a LaTeX editor, so not really sure what you mean. If you're asking if u...

I finish college on September 30 2024. In BA Business Information Systems. Then I start school for Cybersecurity and Information Assurance. I have a lot of experience while I served and my jobs were IT and I was a Cybersecurity Liaison for senior leadership. However I never recieved any Certifications whil I served, which now I'm regretting but trying to get my certs now through school

main mango
last wolf
#

Hello everyone
I want to abandon Kali-LInux and set up my own environment with tools on Ubuntu.
Where to start and how to do it correctly.
Maybe there is already a ready-made article on this or a video.
I will be glad for any information.
Sorry if I wrote in the wrong section)

agile ingot
#

Maybe start with plain Arch or Gentoo if you are crazy😆

pseudo creek
last wolf
#

Thank you, yes, I tried Google, a lot of garbage, that's why I turned to a specialized chat) I'll try to look for it. Thank you.

main mango
late reef
#

Hi! I have Net+, Sec+, CySA+, and working on PenTest+. I currently work in cyber. Does anyone have any recomendations on what Cert I should do after PenTest+?

#

Honestly, I'm not really sure yet. I'm low level blue team now and think I will stay that way for a while, but eventually I would like to get into pentesting

#

Same, US East

#

I sorta work for the goverment now so I was looking at the CEH. Maybe CEH - CPTS - OSCP would be a good track? I understand CEH isn't the best

#

I can get my work to pay for some of the cost at least

#

Also thank you for the advice 🙂

#

Sounds great. I'll do that. Thank you again!

serene umbraBOT
#

Gave +1 Rep to @hallow sparrow (current: #143 - 50)

wintry elm
#

Can anyone suggest some research area in cybersecurity

twilit prairie
stoic cave
twilit prairie
#

this one made me laugh

twilit prairie
stoic cave
#

Yes, I modified it though to remove the color, image, and other things.

twilit prairie
#

gotcha, thank you 🙂

#

should i include my profile/summary

stoic cave
#

Just put a resume together using the template and we'll review it here.

twilit prairie
#

sounds good

torn saffron
# warped ocean hello people, im currently a student completing my Computer Science degree in co...

One thing you could consider is a bootcamp like https://www.carolinacybercenter.com/. One classmate is working on his Computer Science degree from another country (not US), at the same time. Throughout the program you're learning and preparing for the certifications such as ITF+, NET+ and SEC+, in addition to a section on scripting and Network Defense Essentials. Plus it's at night, so that may help you depending on where you're located. The cert exam vouchers are included, plus there is access to labs where you can practice skills. Could be something to consider. Everyone is treated as an adult with responsibilities and a life, so there is understanding when time conflicts and other issues arise. Just wanted to share in case you haven't considered a bootcamp.

torn saffron
pseudo creek
#

$14k... for network+, security+ and aws cloud practitioner? uhh yeah that is a bit excessive

#

considering those 3 certs together are what? $800? and aws cloud practitioner doesn't have much value

torn saffron
pseudo creek
#

Professor Messer (free on youtube) has various cohorts from what I've seen where you can study with others at the same time

#

Comptia itself has self paced training classes as well, I'm just going to say thats a lot of money for something that doesn't cost a lot to do

torn saffron
pseudo creek
#

even Comptia has instructor led classes, pricey but still cheaper $2400 for Security+, $2200 for Network+

#

how much was this scholarship?

#

I guess, how much are you paying out of pocket?

torn saffron
torn saffron
# torn saffron Less than 2k.

But it also varied because there were multiple things you could get scholarships for...so mine might not be the same as another's - such as location.

pseudo creek
#

well that tells you a lot considering their advertised price vs what they willing to knock it down to. Also it may be because certain states, including NC, offer money to technical training vendors

#

so you may be paying $2k but they are getting $10k from the state

torn saffron
#

You likely have more experience with this than I. Just trying to share because I do enjoy it.

#

Oh that's interesting!

pseudo creek
#

yeah there are state and federal grants for technical training vendors

#

the entire idea was to offer free or near free training to people to help get them into technical careers

torn saffron
#

Gotcha! Thanks for sharing. Learned something new.

ripe musk
#

Is it worth going for ITIL before security+ if going for a Helpdesk role?

shell mist
#

Heyyy...I want a lil bit of help I'm a college student and I was thinking of pursuing my career in cyber security soo could anyone help with it like how to start with and stuff and what I need to do (and yeah i have one course of cyber security on udemy but i dont think it will help that much)

twilit prairie
#

i cut down a few bullets to make it a little shorter but not sure how much i should cut out

warm hinge
# twilit prairie how does this look?

Make the Skills section two columns, put education and skills under work experience so work experience is emphasized to the reader. If not applying for government jobs you can merge most of the Air Force stuff into one job (you can use your most recent title) or at least one job per location

stoic cave
# twilit prairie how does this look?

You have work experience, so put the degree below the experience. Your skills should go side to side, don't use a double column. Your skills are also very vague and not all are technical. Your clearance also isn't a skill, but you can rectify that by going side to side. Cut the experience down the three bullets each, then we'll go from there.

#

You can break the skills into categories: clearance, certifications, software, technical, programming, etc

main mango
#

this may be stupid but im aiming to be a bug hunter so do i take the pentester path or the bug hunter path? and which one is better ?

stoic cave
#

Have you done any of the paths?

main mango
#

nope

stoic cave
#

There's a pin in #general too with a recommended path order

warm hinge
#

At least, that would make sense

fickle grove
#

It usually appeals to beginners or those aspirants wanting to shift into cyber security.

warm hinge
#

Yeah

pseudo creek
# warm hinge *Largely cyber bootcamps are a scam.* Why that? Is their level of educating too ...

also another reason is they often focus on certs that aren't that good like CEH. That particular one they linked had CND from EC-Council, which not only is EC-Council horrible but that cert isn't a good cert.

Another thing I've noticed is bootcamp vendors (there are around 2-3 that are prevalent in the US) are buying university names to go with them. So basically they approach universities and say 'let us give you some kickbacks if you lend us your name'. So then they charge $20k for someone to get a handful of not great certs, backed by a university name.

#

but as some have discovered, it is easier to scam the government than individuals. So they are using government grants to fund themselves

#

I mean for $20k, you could basically get 3 SANS certs and get a solid name behind them as well as a huge networking org

hard coyote
#

Hello, my name is Sékou Coly and I am here to learn new things in the field of security.

warm hinge
#

Thanks for explaining @pseudo creek

serene umbraBOT
#

Gave +1 Rep to @pseudo creek (current: #15 - 516)

torn saffron
pseudo creek
#

they have plagarized content, their content is often wrong

#

Pentest+ is a better alternative to CEH but not by much, OSCP would be a better option and HTB has en emerging cert that is being looked upon favorably called CPTS

#

but EC-council had a bad reputation before that

#

(and their CEH documentation did tell women to wear heels and skirts)

torn saffron
#

Oh lawd.

pseudo creek
#

but for US gov/contractors, they don't look at CEH favorably anymore, Pentest+ is considered better for a multiple choice exam but employers aren't really going to be look at multiple choice exams for pentesters

serene umbraBOT
#

Gave +1 Rep to @pseudo creek (current: #15 - 517)

torn saffron
#

Thanks! I appreciate the feedback.

serene umbraBOT
#

Gave +1 Rep to @hallow sparrow (current: #143 - 51)

flat sedge
#

PT+ fills the same role as CEH on the new DoD cert schedule, and it's several hundred dollars cheaper. I could not, in good consciousness, recommend any EC-Council cert to anyone outside of India.

flat sedge
serene umbraBOT
#

Gave +1 Rep to @flat sedge (current: #10 - 775)

flat sedge
#

no need to be so formal about it. just giving a heads up

distant island
#

Not sure if this is the right place to post this, but I figured I'd give it a shot. Was laid off today due to budget cuts. Have skills in penetration testing, cybersecurity analysis/engineering, and also software development. This post contains my public resume in case anyone is interested in interviewing me. https://www.linkedin.com/feed/update/urn:li:activity:7234753485060067328/

fickle grove
serene umbraBOT
#

Gave +1 Rep to @fickle grove (current: #11 - 668)

loud narwhal
fickle grove
sick spindle
#

hello, could i share my CV here to check with u guys if its any good for cyber positions? i used my template previously for 3D related jobs but thats no longer the case, so i wondered if i'll have to redo the whole cv lol

fickle grove
sick spindle
#

alright, should be fine i hope 🙂

#

i did notice the education is moved to previous page, though its just a temporary issue as it sometimes gets weird

shell mist
#

Could someone suggest me any courses for Cybersecurity from udemy??

broken idol
#

Alot of the courses I've seen is just re-hashed outdate content.

sick spindle
broken idol
shell mist
# broken idol IMO, none

I mean I wanted to have some certificates for like internship purpose soo that's why i was asking and also where I can learn easily from

warm hinge
#

yo guys, how can i learn to develop honeypots?

dark hemlock
serene umbraBOT
#

Gave +1 Rep to @pseudo creek (current: #15 - 518)

dense dagger
warm hinge
#

thanks

severe ermine
#

Hi everyone, I completed my B.Tech CSE in July 2024.
Is PJPT a good to go certification to just get your 1st internship/ 1st Job in pentesting?
This is the cheapest certification I have found for $250.
PJPT is provided by TCM Security and I have not found any job post which is mentioning it.
Though I found 1 job post which mentioned PNPT instead, but again PNPT is expensive i.e for around $500.

I know there are other well known certifications like CEH Practical, ejpt, OSCP etc, but currently they are expensive for me.

https://certifications.tcm-sec.com/pjpt/
https://academy.tcm-sec.com/p/practical-ethical-hacking-the-complete-course
Kindly go through the content of the PNPT from above link, and guide me if I can get my 1st internship or job after doing this certification after passing its exam.

Currently to gain knowledge, I have subscribed to Tryhackme membership for around $12 I guess for a month, and I have done
(1) Intro to cyber security from Tryhackme
(2) Pre security from Tryhackme

And I am about to complete Junior Penetration tester from Tryhackme

rugged delta
# severe ermine Hi everyone, I completed my B.Tech CSE in July 2024. Is PJPT a good to go certif...

PJPT is a junior pentesting certification. It is trying to teach you the basics of penetration testing, and the course is fairly high quality. Penetration testing is not considered an entry-level position, and you would generally be expected to have a reasonable amount of IT/Programming work experience in pursuit of such a role.

The course for the PJPT is included in the course for PNPT, so you'll be covering that same content, along with other things you'll be expected to know as a pentester. While the PNPT has been available for a couple of years now, and it does have some recognition, it's not widely recognised, and might not fully prepare you for a role as a pentester.

As pentesting is considered a highly complex role, no certification is really going to be sufficient to cover all the duties of such a thing, but the OffSec OSCP is the most widely recognised and requested cert for junior pentesters, though it's likely not going to be sufficient on its own. You can also benefit by doing things like partaking in CTFs, bug bounties, having a blog/vlog, doing writeups, going to conferences and networking with others. I would recommend reading the Tribe of Hackers books, a set of interviews with experts in various roles in the field, and checking out PicoCTF and the free training provided there, as well as the content on THM

severe ermine
serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #19 - 417)

stoic cave
paper nacelle
#

What type of attack uses Unicode characters in the domain name to imitate the a known domain?

stoic cave
#

In regards to certifications, you should be looking at what the jobs are requiring. Security+ is the baseline certification for the cybersecurity industry. As subtlety mentioned, pentesting is not an entry level area within the cybersecurity industry.

worthy shoal
brittle pier
severe moss
#

Hello, I am looking for a hacker to take revenge on a group of people who took all my data with a python link please, I have to take revenge, it is mandatory

cobalt escarp
woven star
severe moss
#

where can i find people to help me

woven star
severe moss
hidden flare
woven star
severe moss
hidden flare
#

You should use this as a learning opportunity instead of making more mistakes

woven star
# severe moss no

if they stole ur data it means they are more aware than you... don't try anything

severe moss
woven star
#
  • it will not change anything, they have ur data anyways so yeah
severe moss
woven star
#

i mean yeah we could do something, but it's illegal

#

if u really want to do something, do it yourself...

severe moss
woven star
severe moss
undone shore
undone shore
#

Calm down. Don't be an idiot. Report them to the police and move on with your life.

severe moss
undone shore
#

Hate to break it to you sweetie, but most of them aren't kekw
The internet is a largely lawless place. It covers every jurisdiction on the planet, and law enforcement haven't caught up to that yet.

#

There's precious little more a vigilante can do either.
Even if you do track them down, what then?

#

There are shitty humans. Many of them. It's a defining characteristic of the species.
The internet functions as a medium for that.
Unfortunately, there's sod all anyone can do about that 🤷‍♂️
Report them to the police. It's your best (and only) bet. At the very least there's a record of it then.

Report them, and move on with your life.

stoic cave
#

You ruin any chance of a case being brought against them by poisoning the well and get yourself arrested for illegal activity in the process

severe moss
undone shore
#

Oh, wow, so you just want to scam them? Dump a virus on their machines? Steal their data?
Very scary

#

How's that gonna stop them?

#

This is assuming that they're dumb enough to fall for the same crap you did.

severe moss
undone shore
#

And that they keep anything important on the machines that they use for "work"

undone shore
#

Think this through to the endgame. What exactly do you hope to achieve?

severe moss
undone shore
#

"stop them from hacking". How will hacking them do that?

severe moss
undone shore
#

You think you're going to scare away criminals by stealing their data?

undone shore
#

Calm down. Think logically.

wraith bay
severe moss
undone shore
#

How

wraith bay
#

Bad time to ask for advice?

undone shore
wraith bay
#

Ok ok, I'm going then

#

I'm new to this cibersec world

#

Currently I'm only doing some lessons in tryhackme

#

but I'm having the feeling that I won't progress much using only tryhackme

#

But I don't have a solid base in cibersec lol

undone shore
#

What's your background?

wraith bay
#

Currently I'm in the third semester of computer engineering

severe moss
# undone shore How

with a good person who has experience in the hacking field as they say in France revenge is a dish best served cold

wraith bay
#

and never had any contact with cibersec

undone shore
undone shore
#

Which parts of that interest you most?

#

And do you know where in cybersec you're most interested?

severe moss
wraith bay
wraith bay
#

But I don't see myself doing it

#

So I would think maybe a SOC (?)

undone shore
# severe moss it's humor forget it if you can't help me find what I'm looking for

Hate to break it to you, but what you're looking for doesn't exist.
You want a magic bullet. A hacker who can snap their fingers and break into their computers.
Then somehow translate that into a real world consequence.

That's not how it works.
If you want to stop someone from hacking, you arrest them. That's it. That's the only way.
What you're asking for just isn't a thing.

undone shore
#

From memory the Splunk training courses are still free as well -- or at least the first few. Those are well worth doing too.
I hear good things about Blue Team Labs as well

wraith bay
#

So, these homelabs would be used to practice(?)

undone shore
wraith bay
#

Wow, do they even give the certifications in the free courses? johnwow

brittle pier
#

Also if you spin up two VMs and download splunk on one and use the other for launching attacks at the splunk one you can see the attack being flagged. It’s pretty cool

#

I did that with snort

undone shore
#

I'd suggest grabbing a cheap, ex-enterprise SFF PC off eBay or something. You can often get them for well under £100.
Doesn't need to be fancy, just something to mess around with networking on an actual system.
I'd personally put a type 1 hypervisor on (Proxmox being a prime example).
Either way, setup a SIEM and a couple of endpoints so you can get some practice with how that all works

#

Exactly what AceS is suggesting, yeah ^^^

#

You can then try running something like a C2 agent (or some other malicious software) on one of your monitored endpoints. Try to catch that.

#

It's all about learning how to track down indicators of compromise and write rules to automate that

#

I don't know where you're based, but in most places your degree will help. Throw in some of the BTL and Splunk training, as well as work on a homelab, and you'll be in pretty good shape

wraith bay
#

Okay, that was a lot to digest lmao

#

But I'm going to start for sure

#

Thank you so much for your advice

undone shore
#

It all starts with a single step 😄

#

... Followed promptly by tripping headfirst down the research rabbit hole

brittle pier
undone shore
strong anchor
# undone shore Anytime! 🙂

Hi, i have a question , what do u suggest to someone who is studying cybersec outside the education system and want to get a first job in that field knowing that he wants to be a pentester :) ?

#

what github project related to pentesting? can u elaborate?

#

okay thank u !

serene umbraBOT
#

Gave +1 Rep to @hallow sparrow (current: #129 - 55)

stoic cave
quiet sand
#

we got any PSIRT folk here? got a question.

glacial oak
#

Looking for some career advice. I am curious about reentering the tech job market and I am unsure how to get started. I'd likely need to be remote. I am wondering if I should self-study with THM to try to prepare for a cybersecurity position, if it makes more sense with my experience to be in software/programming, or something else entirely? Any advice? Thank you for your time.

I worked for a company from 2018 - 2019 as a cybersecurity intern(security analyst/engineer type of work) for 6 months, and as an IT intern for 9 months. I graduated at the end of the internship with a AAS in business information systems, C# developer certificate, C++ developer certificate, but I did not secure a position with the company. I had some trouble finding a job after that, this was when covid was taking off, and I have not been back in the IT field since.

stoic cave
dense dagger
glacial oak
quiet sand
stoic cave
rugged delta
vocal heron
# glacial oak Looking for some career advice. I am curious about reentering the tech job mark...

I'm currently an senior analyst. I would say get some certifications. I would also top it off with courses with THM or Hack the Box, and find out what type of security your into (blue team, red team, or others). Keep learning everything you can about your interests, and clear up what your flaws are, or stuff that you aren't too familiar with. Finally, have a good salary that you are aiming for to start (mine was 70,000 per year, for example, to start). Keep applying for three jobs every day, and keep an Excel sheet of the various jobs that you applied for, the date that you applied for them, what qualifications they called for, how much they are offering, whether you were rejected from them, whether they were scams, etc. Be prepared for some harsh rejections, but try to learn why you were rejected from them, and improve for next time. You also have to really try for each application, don't just send in your one off resume: you have to fine tune your CV for the job at hand. I didn't get an job for about four hundred jobs, and only got a job with two interviews for two companies.

glacial oak
inner wigeon
#

Hello, I need a copy of the "Web Hacking Arsenal" book plz?

stoic cave
cunning shadowBOT
#

Done!

stiff oriole
#

Does anyone else look for hidden easter eggs/intentional mistakes in job postings if they say "attention to detail" in the posting?

fickle grove
stoic cave
#

It has fallen by the wayside for the DOD and I wouldn't get it unless it's specifically written into the contract or is otherwise required for the position.

#

I believe Pentest+ meets requirements, you're going to have to look at the contract and or position requirements, going forward

#

With the OSCP news, we might see them added to the fray as well

errant ledge
#

Currently building a Wordpress style website that includes my resume, contact info, about me page, and labs I documented in Google docs through the Google course to showcase basics for Linux, SQL, and Python. I plan on doing projects and am wondering is it better to make a GitHub site for projects I do moving forward and including that link in my website or should I just do everything (resume, labs, etc.) on GitHub and use that as my “Resume/Portfolio website”?

stoic cave
#

Look at what the job postings are asking for.

#

Getting certs just to get certs is honestly a waste of money, if you're paying.

#

The only certification that I would recommend anyone pay on their own in Security+

#

Why did you delete your message?

glacial oak
# stoic cave Why did you delete your message?

Honestly, thought your username was a bot at first and that I had asked a dumb question I should have googled. Thanks for the advice, tho. The original message was "what certs are valuable in NA?"

serene umbraBOT
#

Gave +1 Rep to @stoic cave (current: #17 - 450)

stoic cave
#

You're welcome

#

The caveat to certifications is that they don't really stand on their own like a 4 year degree or prior professional experience.

#

If you don't have either of the latter, you should find a way to rectify that.

glacial oak
# stoic cave If you don't have either of the latter, you should find a way to rectify that.

Right. I'm not in the situation to be able to do a 4 year degree. I'm not sure what kind of professional experience I can get at this point, considering that I graduated Dec. 2019. Otherwise, my most recent experience is 4 years at a startup family farm. I did some IT work(website, asset management, etc), I wore many hats. Unfortunately, it did not work out and now i am honestly not sure what to do with that or if it is even worth mentioning if I try to go for a new job. That was why I was interested in the certifications to add to my resume so I could have something more recent to go off of.

flint river
#

Anyone else here a data analyst or at least working in data science right now?

#

has anyone tried making a project apply ML to cybersecurity?

#

it's pretty fun, especially when you start off with the basics like clustering applied to finding unwanted ip addresses on a server

coarse heath
#

I did some data science work for some years (more on medical computer vision side), but we had an anomaly detection demo on our cyber security course. I'm planning on trying something of that sort in the future.

flint river
#

That sounds really cool

#

especially since it's so relevant to both fields

stoic cave
inner wigeon
stoic cave
inner wigeon
serene umbraBOT
#

Gave +1 Rep to @stoic cave (current: #17 - 451)

warm hinge
# glacial oak Right. I'm not in the situation to be able to do a 4 year degree. I'm not sure w...

You don’t need to be paid to list it as professional experience.

John Smith & Co Farm - IT Technician (or whatever name you want to give yourself) June 2016-June 2020

  • Led IT modernization efforts to upgrade company websites by transitioning to HTTPS, building secure, compliant web platforms, and enhancing overall cybersecurity posture.
  • Upgraded physical hardware components and installed advanced firewalls to strengthen network security and protect against external threats.
  • Implemented asset management security best practices, ensuring current and accurate tracking of all IT assets and minimizing security risks.
stoic cave
warm hinge
#

Unless you’re applying for a government job, nobody is checking with the IRS to audit your work experience. It can be on your resume under professional experience until you have enough to replace it. If you want a separate grouping for projects/extracurriculars sure you can do that, but if you’re trying to compress your resume you can also just put those under work experience.

stoic cave
shrewd raft
#

experiences count or the proof of it? i am lying is the question? or it just the fact they are requiring years of experience that make me non valuable for that position?

#

i guess we should tryhackme

stoic cave
shrewd raft
#

who's moral and who's ethics . Taurus. Experience is Experience, what counts is what you are able to do, Ur Skills, Competences. Besides that, if you have certain requirements and feel like applying for a Position, u should't not wait too much years, sometime is okay but not like 5 years for seniority

#

What is your standard of comparison between personal (non-real) experience and work (real) experience? How much money do you make, or how important is it considered?

zinc girder
#

personal learning and practice experience is not the same as having to deal with a business environment

#

all the skills and knowledge you acquire on your own are not the same as having experience of those same skills and knowledge in the context of a business that has its own needs and flaws and goals and objectives and challenges and senior management making weird decisions and users doing insane stuff you can't account for

#

security isn't a job where you walk in and just bolt everything to the floor. You have to navigate the company's risk appetite, however hungry it may be.

shrewd raft
#

I Think it is difference between roles

sick briar
#

Hello everyone, I am still learning and I was asking about bug bounties. what are your thoughts?

rugged delta
# sick briar Hello everyone, I am still learning and I was asking about bug bounties. what ar...

They're a great way to learn and practice your web pentesting and reporting skills according to a defined Scope of Work on real targets. It's something you can use to demonstrate your experience, using platforms like HackerOne and Bugcrowd, or other bug bounty programs run by other orgs.

It can be a way to earn money, but it's certainly not a reliable method. Many of the successful bug bounty hunters submit multiple bugs a day. You can check out #bug-bounty and consider buying a copy of Bug Bounty Bootcamp by Vickie Li to learn more
https://nostarch.com/bug-bounty-bootcamp

serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #19 - 418)

vocal heron
# glacial oak Much appreciated for taking the time to respond, this is great 👏I will keep all...

That sounds about right. You can also start broad and then narrow your interests as you go, and you can change.

I forgot to mention to network too. Go to hackathons, and anything in your area. Make sure people know your name in a good way. Most jobs come from people you know, and not from strangers or jobs postings. In addition, usually companies will pay you friends or acquaintances for recommendations for a job.

vocal heron
sick briar
serene umbraBOT
#

Gave +1 Rep to @vocal heron (current: #2204 - 1)

worthy fiber
#

how do you guys use acronyms in resumes and portfolios? I feel like at least in my portfolio using all the acronyms that I am. I could see how it might be annoying.

#

especially if its not refered to more than once.

stoic cave
#

Then following that instance you can use the acronym.

worthy fiber
#

Alrighty, thank your friend.

worthy fiber
#

so SSH would be Secure Shell (SSH)

#

It just feels weird to spell out Random Access Memory instead of calling it RAM.

stoic cave
#

In what context are you trying to use it? That seems fairly granular for a resume.

worthy fiber
#

It's more for project documentation on a portfolio.

#

speaking wise there are some acronyms i'd spell out and some where i would just say the acronym which is why it feels weird to me. But I feel like if im pick and choosey on it, then it will also sound read weird.

stoic cave
#

If it's a project writeup, then yes, do what I showed you.

#

If it's a resume you're sending to people, it's more than likely too granular

worthy fiber
#

Right, thanks you for your help.

worthy fiber
#

Would anyone be willing to look at my project writeup for making my ubuntu server? Id like to know what could be improved upon so that way i can fix the formatting and documentation now before i'm using it on other projects.

stoic cave
#

You can post an image here if you want, just redact any PII

worthy fiber
#

So im wondering if there is a better method to format this. Also want to make sure each section is a thorough as it needs to be.

#

I plan on explaining most of the acronyms in the project summary

stoic cave
#

For a writeup, this isn't detailed enough imo. You've also passed off whole sections to other people's work.

worthy fiber
#

how am I supposed to set up a server for the first time without using online resources?

#

unless youre only talking about the setup and configuration parts because it doesnt contain a lot of other bullet points like the others. these didnt really have a whole lot of steps. like the setup menu most of the options were just left to default.

#

also in the bullets there will be hyperlinks linking to pictures.

zinc girder
#

I'm curious to hear different opinions on the question I've just been asked:

"Why do cybersecurity jobs pay so much more in the US than elsewhere in the world?"

#

I don't have a good answer for it. Only some vague gestures toward "US corporate culture is more tech-pilled than the rest of the world and values it higher"

hollow locust
#

Every job pays better in US and especially Tech

#

It's the biggest economy

#

So the simplest answer is that there are just way more money available than everywhere else

zinc girder
#

yeah, GDP just doesn't really feel like a super satisfying answer though

#

because you can compare individual companies that have similar gross + net and headcounts between countries and see CEOs on similar packets but with staff at massive disproportions

#

or even within a single company with international branches + separate employee sets

#

Rapid7 for a good example on that; UK senior eng ~50k, USA senior eng ~170k

#

I should not be an economist

hollow locust
#

Probably has to do with the salary that somebody expects to get in different countries as well. UK salaries have always been around that and the prices in general somewhat reflect this kind of income

#

That's why you see outsourcing as well. Companies are eager to profit from this difference of cost of living and income expectations

#

It's not a question that someone can give and answer to in a simple way tbh as economy is not wholly based on rational factors

shut zinc
#

has anyone taken the google cybersecurity cert before their sec+?

#

i did the google cybersec cert a few months ago and forgot where to find the sec+ discount voucher that comes with the course

rugged delta
shut zinc
#

that's what i've been doing

#

im ready to schedule the test i just need to find the code

#

cant find it in my email

rugged delta
#

Then try the coursera site

shut zinc
#

at this point i have to wait on their support to respond

#

fingers crossed they do it soon

stoic cave
stoic cave
brave plover
#

peeps, is it worth to be on linkedin? I'm just transferring into the field, was active duty before so I have no idea how or whether linkedin is valuable

stoic cave
#

If you're in the US, I would consider it worth it. Its probably a necessity, tbh. If you're concerned about privacy/opsec, adjust the settings.

brave plover
#

yep, that was my concern. I'm not in the US though. Thanks for the input. I did some freelance web-pentests but I would like to focus on bug bounty, therefore I'm like; I don't know, whether to do linkedin or not.

flat sedge
#

For a "real" comparison of salaries across regions in the US, let alone across countries and continents, you are better off doing the analysis based on purchasing power of the offered salary in that location.

zinc girder
#

if you do it based off of purchasing power by region, the wage gap between UK and USA looks even worse. On the whole taxation and cost of living are much lower in the US, while the salary is much higher

#

but in particular the focus is also on cybersecurity as an industry. There are other industries where salaries between the US and UK/EU are comparable, but cybersecurity (and tech more broadly, but especially cybersecurity) seems to have a very sizeable difference

flat sedge
#

You aren't fully taking into account employer taxes as well. UK has much higher benefits that the employer is required to pay, as well as much higher employee protections as well.

A large part of the "salary math" includes risk; an employee in the US is much more likely to be 'at will', and can be terminated at any time. There's a lot of 'hidden' taxes that employees never see because of regulation.

It could also be that certain areas of the US see that work as being more valuable, and are willing to pay more for it.

zinc girder
#

yeah these things are true, esp. around worker's rights and statuatory benefits

flat sedge
#

It's my perception that the EU is more willing to hire junior and entry level security personnel; most US companies do not want to train and will pay more for senior engineers and analysts.

zinc girder
#

but since many other industries have comparable salaries, it seems to ultimately keep boiling down to a cultural thing - the roles are more highly valued in the US

#

which i guess is the issue I've been having with the question in the first place. This answer feels nebulous

#

and is hard to tie down to objectivity

flat sedge
#

It's also extremely difficult to get an entry level security job with 2-5 years of experience in IT.

#

In the UK, I hear it is much more common to get hired without a lot of background experience or education.

sturdy scarab
#

Struggling to find what job roles are called related to appsec, pentesting etc.
Any suggestions?

zinc girder
#

that's also true, but the example salary i gave off-hand was for senior engineers

sturdy scarab
#

At a big company

zinc girder
#

perhaps it really does just boil down to GDP and company wealth, though. greater expendable capital means they can afford to invest more into security. Lower capital means expenses are more tightly divided between critical functions.

#

But there is also the fact that tech companies are generally valued higher on the NASDAQ than the FTSE indecies

flat sedge
#

Don't get the idea that everything is good in the US security market, though. Many companies (especially startups) don't understand the value of security until they have to go through an audit without competent infosec and grc.

zinc girder
#

oh for sure I'm totally excluding general quality of work life from the equation. I'm only looking at the raw salaries 100%

flat sedge
#

Security is often seen as "putting up roadblocks" when the reality is, those roadblocks are designed to give investors and other 3rd parties confidence that the company is behaving responsibly and ethically.

zinc girder
#

but I'd say companies not understanding the value of security is pretty universal lol

flat sedge
#

Looking at raw salaries is not a helpful comparison

zinc girder
#

except in Russia where they seem to take a radically different approach of proactively not caring in a lot of cases

flat sedge
#

The same job role for same department within the same company could vary by as much as $50k annually just based on the place of residence for the employee

#

if the employer offers full time remote, an employee in cleveland OH could expect a substantially lower salary for the same job role than an employee in NYC or SF

frigid lion
#

I am wondering guys do you actually work 40 hours a week? On paper it's that but do people really put 8 hours of work a day 5 times a week?

woven mirage
#

they dont in most jobs

#

even outside of IT

#

i do powder coating and we only do full 9h with no slacking if the company is getting stacked with orders

frigid lion
woven mirage
#

i invent work lol

#

theres 3 of us, if theres not much work 2 sit and one works and warns the others if someone comes

#

and we rotate

woven mirage
#

i had a friend who did embedded software and he would watch anime all day

frigid lion
woven mirage
#

i used to work 12h in a factory

#

you get used to it

#

time passes faster if youre working nonstop

frigid lion
#

I mean alright let's say work times goes but how will I have time to do other stuff like I got a personal project I am working on

woven mirage
#

40h work week is standard in most of the world

frigid lion
#

I am just worried cuz I am gonna start my first job tomorrow inshallah

#

new experience you know

woven mirage
#

parents were right all along when they were warning us not to waste time

woven mirage
frigid lion
#

I have to make use of that time yes

#

it's a no come back point sadly

#

work forever till death

woven mirage
#

some countries are experimenting with a 4day work week

#

you could strive to work those eventually

#

or finding a remote job

#

if your career allows it

woven mirage
frigid lion
#

I am thinking of just making my own business at some point

woven mirage
#

good luck

frigid lion
#

Thank you

rancid mural
#

Can someone shoot me examples of their resumes and cover letters? Applying to some cyber internships !

river shuttle
#

I was thinking of gettin my first cert, and was wondering which would be better. The CCNA or network+ ? Any advice on each of them would also be helpful

zinc girder
#

CCNA is vendor-specific (Cisco) whereas N+ isn't, but at that level of cert I'm not sure it's a huge gap between them really.

sleek sedge
#

^ CCNA focuses more on cisco specific products iirc

warm hinge
#

@broken idol our master of ethics 😉

broken idol
pseudo creek
#

also s/there/their/

lofty elbow
#

Does anyone here know if cybersecurity sector is in high demand? Also what would be a good certificate to obtain if I'm going down the pen testing route and want to land a remote job?

stoic cave
#

I'm going to assume you meant certifications, as certificates are not the same, but the question I have for you is do you have a degree or prior professional experience in any field?

errant ledge
#

Does having a self-portrait on my website/resume make a difference compared to not having one?

#

Example (stock photo)

agile ingot
#

It should

worthy shoal
# errant ledge Example (stock photo)

Depends on the country I suppose. I would avoid it unless you are in a location where it is all but required (for the resume mainly, but in general as well)

errant ledge
#

U.S.

worthy shoal
#

Then don't include it

errant ledge
#

Solid, thanks.

#

While I'm here as I'm completing final touches LinkdIn actually make a difference on applications?

#

Seems overkill to have website(github extension included) and a resume and a linkdin?

worthy shoal
#

LinkedIn can be very good for networking - on the flip side it can also be completely useless if you don't use it well. I would say its worth having though

fringe spade
errant ledge
#

Got it I'll get that touched up then once I complete uploading labs to the site, thank you for the help on getting things together 🙂

flint river
#

are there any jobs that primarily focus on recon and defense ops?

random sparrow
#

Currently in the Help Desk, mainting the AZ-900 & Network +. I want to jump more into System Admin work before fast tracking my way into Security. A lot of the guys in my Company that are SOC Analyst informed me they were systems/network Admins. I just want to understand the best way to not fast track, but to stay on pace to devloping the necasarry skills to move over to security work. That being said, any advice is great and something I will always keep in mind.

#

Original question: Quick question. I feel like I have a decent understanding from a Network+ standpoint. I recently passed and got the N10-009. I'm trying to structure my learning and trying to figure out which cert I should go for next.

A) Just continue to build my Home Lab & go for CCNA

B) Continue to build homelab and go for SEC+

Reason why I ask, I just want to understand how strong of a understanding of Networking did you all have before perusing Security fully. Any tips I'm grateful for

lofty elbow
thorny light
#

What certs would be best short term / long term to look into for junior to mid level cyber professionals? I already have a Sec+, was considering CySA or CISSP.

thorny light
#

I'm thinking about purusing a CASP+ next, it's the technical version of CISSP from what I see

stoic cave
thorny light
#

I figured another cert might help

#

I have Dev / Systems Engineering exp and a degree in CS

#

Would CySA be next then?

stoic cave
#

If you have a degree, experience, and Security+, just apply to roles

thorny light
#

It's rough 😦

stoic cave
#

You need to take a look at your resume then, imo. You're qualified

random sparrow
#

I want to start going knee deep into Security but I feel like I should have exp configuring switches, routers, firewalls etc

#

Like I only know about them from a CompTIA/Theory perspective. What would you recommend? I'm going to get a home lab enviroment going. I just don't want to sink to deep into Networking unless I have to before transitioning over to Security perspective of things? That would be great!

#

Not to mention, I don't know anything from configuring AzureAd/AD group policy etc

#

I just know all of these topics from an in theory perspective

stoic cave
random sparrow
#

Becasue jumping into Security, you have to have a strong understanding of how systems work. So before I route over to trying to break systems, I'm trying to understand them. Does that make sense?

#

Like I have CompTIA certs, I just feel like they're good at telling you what to from an in theory perspective? How good where you at configuring things in AD/Networking/ETC

#

I hope you can understand what I'm saying, lol

stoic cave
#

That still doesn't answer what I asked at the linked message. Are you currently employed in tech? If not, do you have a degree or any prior professional experience?

zinc girder
#

I love imposter syndrome. It feels so good, and best of all it never goes away!

quick sierra
#

I’m close to finishing the Microsoft cybersecurity analyst course, I plan on taking the SC-900 after that. Any recommendations on what my next steps should be to land a job?

dense dagger
#

SC-900 is a shallow cert, it doesn't bring value. If you rly want to take it that's okay but imo, SC-300 or AZ-104 are better equipped to give you the required knowledge

woeful moth
#

Hello everyone, just started off my Career in Cybersecurity since 2023, I’m certified by ISC2, and CISCO introduction to Cybersecurity. I have also interacted with tools like Nmap, BurpSuite, Wireshark. Basics of Python and bash. Now I have been actively looking out for Internship roles to further gain Hands-on Experience and it’s been discouraging to not get an offer yet.
What am I not doing right. Pls I need an answer. Thank you

rugged delta
# woeful moth Hello everyone, just started off my Career in Cybersecurity since 2023, I’m cert...

Internship roles are generally reserved for college/university graduates, and most other cybersecurity roles will expect you to have a number of years experience in another computing role, such as helpdesk/support/qa/system administration/network administration to demonstrate that you have worked with the systems you're supporting. You'll generally need at least some knowledge/experience of Windows/Linux/Active Directory/networks, an understanding of basic programming/coding, web servers/apps, databases and applications, and at least some professional experience within an area of computing.

While this isn't the case in every role you apply to, you will need to be able to demonstrate practical experience in some way. Which ISC2 certification do you hold? Is it the CC or CCSP/SSCP/CISSP? While the CC and Cisco Introduction are a good sign of your pursuit of security certification and signifies your interest in the field, it wouldn't usually be sufficient to demonstrate your abilities.

I would suggest that you read one or more of the Tribe of Hackers books (approximately $15-20 usually) for suggestions about how to prepare to operate in a cybersecurity role. Gaining experience using tools like the blue teaming tools discussed and demonstrated in the various Learnign Paths in THM are a good first step in positioning yourself in a very competitive market. I would also suggest have a home lab, consider having a blog where you discuss tools/technologies, do writeups about rooms, participate in CTFs (PicoCTF is an excellent and free training platform for this), consider doing bug bounties, and include this experience in your cv/resume

pearl hemlock
#

Hi guys...I'm a cyber warrior and working in cyber security since 2010. I have worked on Microsoft SCCM, Symantec AV Manager, Forti UTM, Splunk, Deployed Honeypots in DC infra, Core Impact VAPT Tool, Windows/Linux administration in DC for AD/ AD CS, DHCP, DNS , PKI and all others services provided by Data center. I m also equipped with knowledge of Forensics and Malware Reversing. Now I want to shift from LAN infra to corporate. Can you please suggest some certification and role to which I would be suitable. I have hands on experience on all above mentioned infra but didn't apply for certification.

woeful moth
serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #19 - 419)

stoic cave
pearl hemlock
rugged delta
# woeful moth Thank you so much, will definitely put all the suggestions in play. But in the a...

Don't worry about a job claiming to want 2-3 years of experience. A lot of people don't have that, and it's not important if you can demonstrate your abilities. A lot of people will start in helpdesk/sys admin/network engineer/programming/qa roles and build their experience from there. Cybersecurity isn't generally considered an entry-level field in most cases, so you would need to show your knowledge/experience of computing through the ways I suggested above.

Having a home lab with just a few virtual machines of Windows/Linux servers and playing around with the applications they can run can really help you understand the tools better. As you've done Cisco training, I'm assuming you've used PackTracer at least somewhat to build practice networks. You can explore more complex concepts as you go. It is something that takes time, and effort on your part. It's not a sprint. And in today's market, where there are a lot of people new to the field, companies can be very selective. Most people will have their first encounter in a cyber role in a SOC or taking on some security duties as part of an IT or programming role. Having curiosity, and taking your time to build knowledge and skills is essential.

As for certifications, keep going trying to pursue higher levels. Most people at your level would next move to pursue the CompTIA Security+ and perhaps Network+, aiming to take practical certs like the OSCP or BTL1 within a year or so of that. That means you will likely need to invest in training and pay for certifications. This can include getting study guides and following free/paid videos or courses to supplement your learning. I'd suggest watching the following video for a good justification of this pursuit
https://www.youtube.com/watch?v=ZsEWUguYXgM

Will FREE training give you the skills and knowledge required?

There are many people out there, especially in the cybersecurity content creation space, who are pushing free content to the masses. These efforts come with promises of landing your dream job in Cybersecurity and IT, but is this realistic?

Join me in this video as we discuss the re...

▶ Play video
rugged delta
stoic cave
pearl hemlock
#

Ok

stoic cave
#

If you're struggling to get hired, you can post a redacted image of your resume here for review. You will need to verify to post images.

crude sphinxBOT
warm hinge
#

I'm studying for my A+ certs, and trying to decide if i should go for a degree in cybersecurity or something else

#

any advice would be appreciated!

#

basically, I'm trying to explore what the different branches and jobs are in the IT/tech industry. Right now it's more of a thing that I don't know what I don't know 😂
So I'm also kinda looking for ways to dabble in different things to figure out what i would like

#

OK! I'll check those out! And appreciate the advice on the degree, it seems like a very specialized degree, and with cybersecurity being pushed as much as it is right now, I would honestly be concerned about landing a job in the sector by the time I wold be through with any degree program

#

Cool! network engineering is also a degree at the school I'm looking at, so might be looking into that program when I'm ready?

warm hinge
#

anybody a discord moderator trying to get a job so I can transfer colleges and continue my path in nc \

woeful moth
serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #19 - 420)

glossy dock
#

Anyone have experience or testimonials on Josh Madakor’s courses?

serene umbraBOT
#

Gave +1 Rep to @dense dagger (current: #22 - 397)

spring agate
#

success isn’t just about giving up, it’s about you appreciating every step you take, every hurdle you clear, every challenges you overcome and every sale you make. Be proud of each win, no matter how small, and let them remind you of just how far you've come. Keep goingyou’re on your way to something incredible. New sales made🎉🎉 . All thanks to GOD🙏🙏

candid matrix
#

For the more experienced folk that have done both OSCP and SEC660, which did you consider more difficult? I'm seeing reviews saying that OSCP is basically an intro for SEC660.

dense dagger
#

Is it an intro to SEC660? Not really I would say. There are similarities but OSCP doesn’t teach the pre requisites for GXPN imo

#

I would say its more similar to OSEP & OSED combined

warm hinge
#

Is OSCP still worth it?

#

I know it's a broad question but I've been thinking lately and OSCP doesn't seem to cover that much

dense dagger
#

If its in the job postings in your local area, its still relevant to you

warm hinge
#

Sure

#

But idk, I have some fear

dense dagger
warm hinge
#

I don't want my cybersec job to consist in phising employees and people related to the company

dense dagger
#

It specifically hones your methodology

warm hinge
#

Or using the same techniques

warm hinge
#

It's a good introduction, from there you can develop more things

dense dagger
#

Yeah. Its a pain to explain it to a lot of people that the OSCP doesn’t necessarily train you with all the latest and greatest techniques (granted that the syllabus should be updated for the latest known and utilized techniques)

warm hinge
#

Yeah, they're monotonous techniques that won't do nothing against a company with a decent cybersecurity

#

It's disingenuous to think that you can bruteforce lots and lots of directories without getting detected (maybe this applies more to read team)

#

In pentesting you don't have to really worry about it

pseudo creek
#

There are lots of jobs in cybersecurity and most of them don't even consider OSCP to be anywhere near a requirement

#

if you want to do pentesting, you will find jobs that will have a high desire for it but that doesn't mean its a requirement

dense dagger
#

Even then, you can try to circumvent it but thats another topic

warm hinge
pseudo creek
#

I know quite a few people who got their first pentesting job without OSCP, they basically worked their network, talked to people, went to conferences, had a public presence

warm hinge
#

Idk, to me sounds like incidence response is more interesting, you get to analyze malware and to see more sophisticated techniques

pseudo creek
#

it can be

#

I prefer cloud security, you get to build things, try out new technologies

warm hinge
#

Fr

#

Cloud security is goated

dense dagger
#

Biggest goat now is IAM

pseudo creek
warm hinge
pseudo creek
#

also GRC is huge

#

Identity and Access Management

alpine marsh
#

Ew GRC, I personally hate it

warm hinge
#

oh

alpine marsh
#

Too much paperwork

warm hinge
#

When working in cloud security do you have to deal with AIs?

#

May sound stupid but i'm curious

pseudo creek
#

we had an intern project whether they were like "we want to use this cool AI feature within AWS", we were like "sure"... a few thousand dollars later, we were like 'let's not"

warm hinge
#

Oh

#

Hhahahahahha

pseudo creek
pseudo creek
alpine marsh
warm hinge
#

I just don't want to interact with AI

pseudo creek
#

AI services in the cloud are also super $$$

#

so going that route is a total decision

warm hinge
warm hinge
#

There's maybe some good uses to it but it's making everyting tasteless, from art to text

pseudo creek
#

AI is more than generative AI

warm hinge
#

Ik

pseudo creek
#

generative AI isn't going to go away

warm hinge
#

Damn (soon everything will end)

zinc girder
#

people spending hours upon hours doing prompt engineering to write their code for them when they could've just written the code themselves in less time is SO COOL

broken idol
#

...You don't use ChatGPT to write code for you for your work? 👀

zinc girder
#

is that a sincere question

broken idol
#

Yes.

zinc girder
#

the only time i've found any real value in it is getting it to summarise documentation for APIs

broken idol
#

Ah, you'd be surprised how many people I've spoken to who have, or inputted sensitive information. 😅

zinc girder
#

i WISH i was surprised :)

cobalt ivy
#

Hello everyone. I want to connect with the remote (also freelance) workers . Your counseling and advice is needed. Thank you in advance

vapid kiln
#

Hey everyone,

I'm currently a Computer Science student actively applying for internships. So far, I've applied to about 60 positions but haven't received any responses. I've tailored my cover letter to each position, ensuring that my resume includes relevant keywords. Despite my efforts, I'm not sure what I might be doing wrong or what I could improve on.

My current company is sponsoring me to take the Security+ certification this month, and I'm planning to pursue more certifications this year to strengthen my profile.

I'd really appreciate it if someone could review my resume and give me some feedback or advice on how to increase my chances of landing an internship.

Thank you!

#

P.S. my past experience was from knowing someone who got me in

stoic cave
stoic cave
#

I'll take a look at your resume a bit later when I have time

wild pecan
#

Hi guys, I'm a beginner wanting to learn cybersecurity in the area of ​​offensive security, I started with the first room and I can't get through the first task it says: which of the following best represents the process in which you simulate the actions of a hacker to find vulnerabilities in a system?
as an option we have:
offensive security and defensive security, but when I select offensive security the wrong answer comes up, what do I do??

frigid lion
#

Hello, someone asked me to suggest him some certs (offensive), I sent him the following, what do you think?

OSCP: content quality: average, recognition: very high, difficulty: inter/hard

PNPT: content quality: above average, recognition: low/medium, difficulty easy/medium

CPTS: content quality: very high, recognition: low, difficulty: very hard

Security+: content quality: low, recognition: high, difficulty: braindump

stoic cave
stoic cave
frigid lion
frigid lion
stoic cave
vapid kiln
stoic cave
vapid kiln
#

these are all security related internships

stoic cave
#

OK, are you shotgunning or tailoring your resume to each role?

vapid kiln
#

i havn't had any luck with responses or even a rejection

#

tailoring to each role

stoic cave
#

Also, when are the internships slated for? Summer 2025?

vapid kiln
#

Spring CO-OP or Summer 2025

stoic cave
#

Are you including a cover letter?

vapid kiln
#

yes

stoic cave
#

I'd bump skills above experience

#

And include relevant classes under education

vapid kiln
stoic cave
#

Also GPA if it's above 3.5

vapid kiln
#

i have gpa listed

#

3.7

stoic cave
#

I missed it then

vapid kiln
#

oh wait actually its not on that version

#

i have gpa on the one thats not censored

#

its been really rough i have 1 year and 4 months of IT experience before i even graduate

#

what are people doing to get these roles 😭

vapid kiln
#

i always wondered if it was worth changing it like information technology intern

stoic cave
#

Put what your title was

brittle pier
#

Speaking of internships. Can you still get an internship if it’s a college but doesn’t specifically specialize in cybersecurity?

flat sedge
#

If you want a career in security, don't limit yourself to just cybersecurity internships

#

anything you learn in any IT domain will be useful down the road

vapid kiln
#

i just wanted something new

glossy dock
#

Do you guys think getting CCNA after Network + is redundant, or a waste of money, in other words? A lot of network engineer jobs want CCNA.

pseudo creek
glossy dock
serene umbraBOT
#

Gave +1 Rep to @pseudo creek (current: #15 - 521)

pseudo creek
#

network+ is more like 'you know some networking'

glossy dock
#

Ok makes sense, thank you!

worldly herald
#

I'm going to be honest i hate coding am i cooked?

worthy shoal
#

Depends on what you want to do? Not all cybersec positions require coding, though most benefit from it

vapid kiln
empty quiver
#

yup

serene umbraBOT
#

is he cooked
:8ball: As I see it, yes

worthy shoal
#

Ah man, the 8ball has spoken, sorry dude

cosmic skiff
#

Looking for advice on my Resume, And/or possible job opportunities!

dense dagger
#

It takes up so much pain and honestly not everyone is going to read that

#

Be concise in what you want to say and provide actionable results preferrable with data to back it up.

#

Like you said you fixed hardware and software issues, do you have data that you did minimize downtime and improved overall system reliability?

#

You have a certifications section but you say you’re working towards them. So technically you don’t have these certifications? Maybe you can rewrite this or remove it altogether and maybe add it into an About You section. There are those that like those and then there’s those that don’t

#

The key skills is maybe all over the place, there are things there that I don’t think are necessary like Cybersecurity protocols, what do you mean by this? Maybe its better to expound or put in specific skillsets that you do have. Words per minute is not really a skill and I don’t think you should include it.

#

Under Education, I would recommend a format such as 2021-2024 for your education so they know how long already you’ve been there.

worldly herald
#

i just feel like with our future of ai coding is useless

foggy vine
#

Hey guys, has anyone completed the eJPT certification?

I've finally decided to get out of 'tutorial hell' and start doing real things to land a job. I’m thinking of starting with the eJPT certification first.

Any tips?

rocky flax
#

Hi All,

I'm reaching out for some advice as I'm currently at a career crossroads.

I've spent the last few years in consulting, managing digital transformation projects like DWH migrations, IT systems implementations, defining data strategies, etc. But I've always been drawn to cybersecurity and feel like it's a field I could find myself in.
Now that I'm between jobs, I'm seriously considering making the switch to cybersecurity. I’m really not interested in returning to the corporate world where I find myself babysitting C-level executives again.
I've already done a few courses on TryHackMe, and I'm thinking of taking the leap with a bootcamp. If anyone has gone through this transition or has experience with bootcamps, I’d really appreciate your advice. I'd also love to chat privately with anyone willing to share insights or offer guidance.

Thanks in advance!

vocal kettle
#

It also depends on how much time you can give yourself to gain knowledge and/or certificates.

rocky flax
vocal kettle
#

well nothing beats expierience but I would say it also depends on the area where you live and how much you want to earn.

#

Since you already have some expierience in the IT business you might be ahead to some people whou want to switch from a different field.

dense dagger
#

If the local jobs around you require eJPT, you can consider it

#

OSCP is a cert that is usually being looked for by HRs but it has a high barrier of entry at $1649. You can also opt for the HTB CPTS which is a lot cheaper and is more in depth. I believe that the CPTS is a better cert if you just want to get better at pentesting but if you wanna jump the HR barrier, OSCP is good.

#

If you live in India, you can consider the CEH but EC-Council has a known bad track record and most of their certs hold little value outside of India or governments that require it.

pseudo creek
# rocky flax Hi All, I'm reaching out for some advice as I'm currently at a career crossroad...

cybersecurity bootcamps are largely a scam. I will say that the market is tough right now in IT in general including cybersecurity. There are a lot of people who are trying to get any job they can including cybersecurity. If you want to get into cybersecurity because you think you'll enjoy it, you can certainly do that and there are a few options.

Although it may not happen at junior levels, I will say that cybersecurity can be heavily influenced by c-level executives. So there may be at times that you'll need to explain to c-suites executives why things are the way they are or even at the behest of execs, bend cybersecurity rules in a way to meet their demands. It really depends on the company.

river musk
#

hey @dense dagger

#

Since you have done multiple certification which include OSCP. I have heard that OSCP is over hyped and that it is not really as worthy as it is being said in the community.

#

As a newbie here in cyber security field I really am not being able to wrap my mind around it. Whether should i go for OSCP or not.

#

I heared that CPTS is a good one also and that CPTS are far superior than OSCP. So which one to choose and how to prepare for this?

#

Also what are the opportunities you got based on the OSCP certification. Since you are highly skilled personal I can see that.

Considering someone having not such exponential skill but having knowledge of whatever required to pass the OSCP, or CPTS, also having these certificate.

How many oportunies is out there?

#

Also how much does the country am living in matters?

dense dagger
# river musk Also what are the opportunities you got based on the OSCP certification. Since y...

I think what matters when getting a cert imo is it return of investment to you. I don’t value certs which doesn’t fulfill either 1.) give me a head start on jobs OR 2.) give me good knowledge.

I picked OSCP bec. looking at my local area, OSCP is a big factor in getting a pentesting job, nothing more nothing less.

OSCP is overhyped, I’m not largely sure. I do see other people’s sentiments that the OSCP is overpriced when you compare them to other certs but I think people are more concerned about the techniques it teaches you (I understand, pentesting courses should be updated to reflect the current landscape) but rather it teaches you on building a methodology. There are numerous modules within OSCP actually that drill down on this. I think that’s one of the biggest things people forget.

OSCP versus CPTS, I would have to agree that CPTS has more depth in their course and exam tbh but its only non-redeeming factor (so far) is that they’re not rly being considered by HRs. Once CPTS gets tracking on HR, we will see then.

dense dagger
#

Its very competitive bec. consulting companies do not necessarily hire people with little to no related experience to pentesting and most companies are not really equipped to have an internal pentesting team.

#

This is my own POV, but a lot of big companies are now moving towards lower income countries, building satellite offices there, so they can get cheap labor. This way, they can actually maintain internal pentesting teams while cutting down the costs.

fringe belfry
#

How is the cybersec job market for beginners?

river musk
#

Anyways, Which cert you recommend going for first?

#

OSCP or CPTS?

#

Also, how do I know if I am ready for the exam because really big amount gonna be on stake for both of them

dense dagger
# river musk OSCP or CPTS?

If you’re planning to leave, I would look at overseas employment and see what certifications they want to consider you.

dense dagger
#

I set my exam date and told myself I wouldn’t re schedule it.

dense dagger
# fringe belfry How is the cybersec job market for beginners?

I don’t know where you live but where I am, its awful. A lot of new graduates wanting to get in the field and not enough positions to be filled. Not every company is welcome to new graduates bec. it takes time to train them and they haven’t actually experienced actual enterprise IT let alone securing it.

#

I’ve noticed that only big companies are more willing to hire new graduates and I am assuming its bec. they have the training and financial resources for these new hires, they can put them under a bond, they have available seniors, etc.

river musk
#

So that means certs alone doesn't help land job as a fresher?

river musk
#

Gettting job at big firm is just short of luck imo

dense dagger
vapid kiln
#

its cooked

dense dagger
#

Cooked I’d say. Good luck though in finding a job

vapid kiln
#

i have 2 years of IT internship experience, Cert, and projects w/ decent skills

dense dagger
vapid kiln
#

and i've been rejected to every internship ive applied

river musk
dense dagger
#

Better to network with people and get your name out there instead.

vapid kiln
#

it will help you get sec+ later

dense dagger
river musk
vapid kiln
dense dagger
#

Plus the ISC2 CC is just a cash grab imo. Not that depth in content and it requires you to pay $50 to get the cert.

#

The $50 being an annual fee for being an ISC2 member.

vapid kiln
dense dagger
dense dagger
#

I forgot the exact words that juun used, but I guess that’s the gist of it.

river musk
#

Also what do you suggest? Should I buy HTB subscription. I am getting student discount there

vapid kiln
#

have you guys done any job sims?

dense dagger
dense dagger
vapid kiln
#

theres like 4 job sims you can put on a resume and they give you a cert with creds

river musk
vapid kiln
#

might help get you past hr

river musk
#

I have more than 6 months of subscription left here

vapid kiln
#

and there free

river musk
#

So just wanna know I do have spare money to get the subscription

#

So what would you recommend complete ctfs here on THM or get HTB?

#

@dense dagger

dense dagger
#

You can always dip your toes in both platforms, no harm in that.

river musk
#

So doing some ctf after the red teaming would be much better Idea. Than diving again in tutorials on HTB.

dense dagger
river musk
#

Or get some internship

#

One last question @dense dagger .

Should I invest some money on getting the desktop. I have laptop with decent specs. which does the job. But I feel the screen size is not enough for me. Which is 15" inch

dense dagger
river musk
hollow sand
#

Hiya everyone,

I'm reaching out to see if anyone could offer advice for those who want to go straight into degree apprenticeships or just the work environment in general. I'm approaching to my final year of A levels and have some decent experience in IT through projects and certs. I'm wondering if anyone's gone through this route and can offer some guidance on how to approach it. I'd love to go into cyber security but I think it's more reasonabe to settle for anything in IT. Asking from the UK ☺️

rugged delta
# hollow sand Hiya everyone, I'm reaching out to see if anyone could offer advice for those ...

When considering a role in IT, you should be considering spending a while studying about the technologies you want to work with. Learning about Windows/Linux/Active Directory/Networks/coding are highly advantageous pursuits, but you can pick up entry-level knowledge quite quickly. You should be aiming to pursue a degree and/or certification while also partaking in activities like CTFs/hackathons, consider having a blog to discuss the tech you're learning, along with doing writeups of challenges you undertake (depending on the rules about sharing such things).

If you're only learning the basics, starting in THM can help guide you along the right path with a huge amount of free and paid content, and people here in the Discord are available to suggest other pursuits as you progress. A degree can be a distinct advantage, so can be very beneficial to pursue. You may even be able to do so while working in some organisations

hollow sand
# rugged delta When considering a role in IT, you should be considering spending a while studyi...

I'll have a look at participating at some Hackathons. I don't want to chase any more certs for the time being because of schoolwork and I already have 3 on me, which probably don't carry much weight but it's CompTIA A+, Google Cyber security Certificate and SOC L1 cert from TryHackMe. I've set up my own home lab and am currently working on a project related to data recovery. I would love to do a degree but it's so expensive, if it was a degree apprenticeship then it would be a perfect world which is why I'm trying to look for as much advice as I can get around that. If not then a gap year it is and I'll definitely work towards everything you've said in your reply, especially CTFs and the Hackathon. I really appreciate your advice

#

If I don't land one then it would have to be a similar certificate equivalent to a degree. If that were the case do you have any suggestions.

rugged delta
# hollow sand I'll have a look at participating at some Hackathons. I don't want to chase any ...

Ok, well it's great that you're making headway towards your goals. The CompTIA A+ is a good certification to show you understand basic computing, but you will need to learn other topics as you progress. The Google certificate is a good indicator of your interest, but it is only a certificate and not a certification. It doesn't hold any weight when looking for a role, unless it's part of you pursuing another certification like Security+, which will require more effort. SOC L1 from THM contains a lot of good info for entry level understanding of SOC duties, but again, you would need to demonstrate your abilities through certification such as the CompTIA CySA+ or BTL1, but you are just getting started and you have a lot of potential.

I know you're eager to work in this field, but it is highly competitive so you'll need to build a demonstrable level of skill in various areas as you progress, and it can take a lot of time and effort

hollow sand
serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #18 - 424)

rocky flax
serene umbraBOT
#

Gave +1 Rep to @pseudo creek (current: #15 - 522)

pseudo creek
#

Basically Network+ and Security+ are really the only certs that have much value, I think CySA+ may be gaining traction. But also again would check if the case is the same in Germany

#

I am US based so can only speak to that

#

also other certs that could be useful is a cloud cert like AWS Solution architect associate or Azure AZ-104

rocky flax
pseudo creek
#

but pentesting positions are difficult to get as a first cyber position

flat sedge
frigid lion
warm hinge
#

What are the best blue team certs you can get? Also are there any specific ones on digital forensics? Please, Ty

rugged delta
warm hinge
#

Okay thank you

stoic cave
#

For digital forensics, you have SANS, Cellebrite, and I think Encase does certifications

rugged delta
#

The SOC Level 1 and SOC Level 2 paths in THM will teach you a lot of essential SOC skills

warm hinge
#

How to get into cyber jerb?

warm hinge
#

Thank you 🙏

storm valve
#

hello guys, can someone review my resume so i can improve it before sending it to job offers ?
i have no university education and i fear that'll hinder me.

#

thanks in advance 🫡
my git is still a WIP

dense dagger
serene umbraBOT
#

Gave +1 Rep to @dense dagger (current: #22 - 398)

storm valve
#

i don't know if i should post the hackthebox path as experience or let it in projects

#

and detail it more

vapid kiln
brittle pier
#

I personally would block everything personal out and then share

warm hinge
#

Yours is so nice compared to mine

#

I love the use of icons, makes it pretty

storm valve
storm valve
serene umbraBOT
#

Gave +1 Rep to @pseudo kiln (current: #2211 - 1)

warm hinge
#

You’re welcome

brittle pier
brittle pier
storm valve
#

i mean someone can probably Osint me easily anyway due to the nature of this server NotLikeThis

stoic cave
#

It's not professional experience, nor is it your own project

south monolith
remote swift
#

How hard is it to get into entry level CS/IT jobs

#

Assuming you have a CS degree

dense dagger
vocal kettle
potent laurel
#

Hello guys , I wiil try ths CS+ exam next month , do you want to study with me ?

sudden zodiac
#

hey yall is the ISC2 cert good for a someone who is just starting to shift there career into cyber sec?

arctic dome
#

hey ;] What first certificate is good for begining in cybersecurity ?

potent laurel
#

is the basic one, you learn everything to be able to understand the structure of cyber sécurity

arctic dome
serene umbraBOT
#

Gave +1 Rep to @potent laurel (current: #2212 - 1)

potent laurel
arctic dome
storm valve
serene umbraBOT
#

Gave +1 Rep to @south monolith (current: #562 - 8)

storm valve
lean flame
#

Where do i find summer 2025 internships for cyber?

stoic cave
worthy shoal
# storm valve

Well imma have to disagree with the other people here and say that all of the colors, columns, and icons are not a good idea. Keeping your resume simple is really the best way to go, black and white text everything in one column.

I also think there's need to be way less focus on courses completed and more focus on stuff like projects - you list some nice projects that are apparently on your github but don't talk about them at all? Expand on the projects, rename certificates to something like "Extracurriculars" or "Personal Development" and make it way shorter, then separate out Security+ and put it in a Certifications section (which is very different from certificates of completion). Additionally TryHackMe is not a project, its an extracurricular activity.

Remove the job title "Security Analyst" from your header and unless your country strictly requires it, remove the picture of yourself. Perhaps expand on that weird one sentence quote at the top and make it into a full on summary section of like 2-4 sentences?

errant ledge
#

Switching industries from finance and services to security and currently studying for network+. Looking to add more depth to experience and not much the educational area at this time while I work for the N+ cert. My question is should I focus on a udemy course for python to get more practice that also provides projects to complete that I can utilize for applications or is there something else I should focus on like expanding on Linux and SQL or SIEM systems?

#

Here is what my resume looks like if its any help to what I should be focusing on considering experience up to date

worthy shoal
river shuttle
#

thinking of studying for the network+ exam, apart from professor messer's videos are there any other resources that will help me pass the exam ?

vagrant summit
#

I’m gonna just throw this in here and hope someone will read it. Ok so I wanna be a read team operator/penntester, what will I need just to land my foot through the door with an entry level job. What are some of these entry level jobs that will push your experience levels up to secure the better jobs yk. And what are some certs that could possibly make it a somewhat smoother ride in the beginning .

vagrant summit
#

I’m from the United States and I just wanna land that first job in cyber space

vagrant summit
#

Yes I have my own personal experience and knowledge tho mostly from networking with others and hands on learning with htb, tryhackme and a little bit of vulnhub. I’ve noticed networking is a huuuuge factor as well.

#

I don’t have any IT on the job experience that’s what I’m lacking rn

#

So I would just like to know what are some of these entry level jobs even if it’s apprenticeships or internships I would like to just step into that and get the fire started

shut zinc
#

taking my sec+ in 3 hours wish me luck

#

im doing professor messer's practice tests rn

#

i feel like i'm just barely ready and by the time i take the test i should be good to go

worthy shoal
worthy shoal
zinc girder