#cyber-and-careers

1 messages Β· Page 87 of 1

hallow flame
#

Like they aren't valid anymore?

boreal zephyr
#

I just have Sec+ and Linux+. I'll need to get CISSP next year to meet a working requirement. Once your start building OJT the certs don't matter as much unless its absolutely required for the position

hallow flame
#

Ahh nice, I'll have to search what OJT is lol

boreal zephyr
#

on the job training, lol.

peak steeple
hallow flame
hallow flame
#

How long do they generally last?

boreal zephyr
#

Depends on the cert, but iirc Sec+ is 3 years. Then you have to take courses to build "CE credits" and take a refresher test to recertify

#

oh, and pay a maintenance fee.

#

its just a way for them to keep extracting money from you, really.

#

If you take online courses, like from LinkedIn Learning or Coursera for example, you might see it say "1 hour CE credit" or something similar, it means you can submit it to your certifying body for credit towards your recertification.

hallow flame
#

Ohh okay, that's pretty cool

#

Not the extracting money part, but the online courses xD

peak steeple
hallow flame
#

Every 3 years seems excessive

peak steeple
#

When you certify - Feel free to write to then and protest πŸ™‚

hallow flame
#

I like protesting against things so I might have to do that πŸ˜‚

boreal zephyr
#

Its really not that bad, you can't fail the recert exam. If you don't pass you just take it again until you do.

#

theres no proctor or anything, its just an hour or two affair done in your browser

hallow flame
#

Oh that's not too bad then, I thought you had to go through the whole process a second time

#

1 hour spent every 3 years is doable

boreal zephyr
#

Like I said, its more of a way to get money out of you than anything else. A lot of people let theirs lapse once they get further along in their careers.

peak steeple
#

@hallow flame You can still protest for me cause am too lazy to update certs I no longer use but my newer ones I will definitely keep current.

hallow flame
forest knoll
#

-arole 89220092960706560 sec+

serene umbraBOT
#

βž• Gave the role Sec+ to Tact#1357

forest knoll
#

-arole 89220092960706560 linux+

serene umbraBOT
#

βž• Gave the role Linux+ to Tact#1357

snow kraken
#

some of my certs expire in 2 years

thorny cloak
#

Should I keep working on THM to finish the learning paths or focus on a first cert? Have the voucher for sec+ waiting

spark junco
#

THM can definitely be helpful for some of the foundational stuff but I'd start digging into Sec+. It's not a bunch of memorization anymore, you have to actually understand the concepts they're teaching and how to apply them.

boreal zephyr
#

^ This exactly. There are practical components to Sec+ that require a full understanding of the concepts being taught. It isn't just multiple choice to memorize

spark junco
#

For instance, I dont believe THM goes over the roles of managerial, operational and technical security categories and the security types that fall under them. (Someone correct me if I'm wrong)

#

And they'll throw scenarios at you where if you don't understand what they are and how they work, you'll miss the question.

thorny cloak
#

Thank you, I will focus on sec+ and use THM to go over the concepts if they have specific rooms for that

spark junco
#

The networking stuff is a good place to start too, if you haven't gone through Net+

thorny cloak
#

Will take a look at the one last room im missing, didnt come across it in the beginner path yet. Between presec and beginner path networking, ive learned a lot the sec+ book went over

warm hinge
#

I got the Sec+ yesterday, what should I do now?

thorny cloak
#

Congrats! what did you do on top of reading material? Anything hands on?

warm hinge
#

Thanks!

#

I mainly stuck to Professor Messer, Jason Dions Practice Exams, Mike Myers Udemy course and a nice study guide I can send you I found on Reddit

thorny cloak
#

Yeah, please dm me

warm hinge
#

I read a little of that GCGA book but tbh I’m more of a video learner lol

thorny cloak
#

I currently have a book that i read, and listen to professor messer on my way to work

warm hinge
#

Of course, one sec

#

Just sent to your dms πŸ™‚

peak steeple
plain needle
#

Yo

sturdy patio
#

Im getting comptia CySa certificate soon, az900, along with SharePoint

quaint flare
lavish pawn
#

Hi everybody,
I'm currently studying Cybersecurity; I want to become one of the top experts in the field.

I recently made a LinkedIn account and I'm looking to make new friends and connect with other cybersecurity enthousiasts. So I invite everybody to connect with me so we can all expand our network! Here's my page link: https://www.linkedin.com/in/maximebeauchamp-cybersec/?locale=en_US

Thanks and happy hacking!

peak steeple
#

@lavish pawn Out of curiousity, how recently did you start? Since your THM rating is Wizard. That must be some hard grinding.

rose sky
#

hey folks! It feels like I've bitten off more than I can chew after diving in to some of these courses. I've been doing tech support for ten years now, and I want to move on past customer service. Defensive seems like a natural fit for me, but going through the Complete Beginners course, while I am able to progress with help from the wonderful folks over at #room-hints , I just feel a bit overwhelmed.

peak steeple
#

@rose sky It's very easy to feel overwhelmed when trying tomething new. What I do is try is learn at my own pace and tactle it a unit at a time. Never be afraid to aks for help or hints as in the real world - you will be working as part of a Team and have someone normally to bounce ideas off. This is my reasoning. Don't try and rush it - go sloowly, take notes as you go and remember to try google before asking. We are all here to help πŸ™‚

rose sky
#

❀️ thank you

#

I'm not so much of a note taker though, that may be part of my problem lol

#

I guess I just suppose in a field where Googling is everything

#

I just assume my resources are a bookmark and a ctrl+f away

stable delta
# rose sky I just assume my resources are a bookmark and a ctrl+f away

Hi @rose sky I'm in the same boat in terms of getting overwhelmed with all the new things I need to learn and I'm from a completely non IT background (Legal) and it is taking me much longer than anticipated. I don't know if you'll find this useful but what I found is when doing the rooms on THM or other online labs get too much, I signed up to online talks and listen to them whilst working or reading articles that will help me build my knowledge. Also I find note taking can take a while so I take screen shots of the things I've done and add bullet points. Not sure if it helps but hope it does!

spiral smelt
#

someone can tell me about purple team pleas

#

im already google but i dont understand what purple team will do

peak steeple
spiral smelt
#

tks sir

rose sky
#

TIL about purple team

undone shore
#

Google is wonderful, but your own notebook, organised in a way that makes sense in your head, will always be faster and easier to use

#

Once you've learnt something once you should not have to learn it again

polar rock
undone shore
rose sky
#

it's been like then years since I've taken notes

peak steeple
#

jopin and obisidan are also good! I will check out Turl too as I need to migrate away from note books to save the rain forest.

distant pier
rose sky
#

oh yeah also even for defensive I'd need to document plenty, huh

#

I mean as a tech support guy I take real-time notes all the time

#

stomps feet

peak steeple
#

Writing things down also helps you commit to memury atleast it does for me.

distant pier
#

Here's a fancy slogan I'll throw around πŸ˜„ Operationalizing what-you-know πŸ˜„

broken notch
#

For any of the pentesting certs, was the scanning aspect of them pretty straight forward? Were they just like a normal THM room?

peak steeple
#

@broken notch To my limited knowledge each cert has an associated course and level of difficulty. If it is a junior level -course it willl simple as just testing what you learned like eCPPT and if aimed at a highish level - like OSCP/OSEP. LPT - it is not testing knowledge but you skill at applying the knowledge andthere may be more stickier. Follow what the syllabus recommends. practice, practice, practice and finally when you Try Harder - all certs will gradually becom strat forward. Hope that helps a bit.

slate ridge
peak steeple
#

@slate ridge Yes, In asense that once you understand the teaching format you can aim for their higher certs like people of Offsec - go from OSCP to OSEP or CCNA to CCNA (Cisco). eCPPT will set you up for OSCP if you also wish but a different teaching sytle I hear.

slate ridge
#

My studies includes a prep for CEH (without actually paying for CEH), and I for one would rather invest into eJPT -> eCPPT -> OSCP

slate ridge
peak steeple
#

@slate ridge THM covers most of what eJPT does except for progamming basics (not needed for exam). I would focus on THM, just pay for eJPT exam as goodreviews and deep dive into eCPPT is my recommendation.

slate ridge
#

So I could do THM learning paths then take on eJPT?

#

I already have programming basics done and done, will have a master's degree by next year

#

Only "scary" thing is how dated my country is, still not acknowledging the need for infosec

#

Can't even get out for an internship in the EU, since they made it law that they only accept EU citizens

#

That's why I'm aiming for Certs, they could perhaps get me somewhere

peak steeple
#

@slate ridge Great! Forget about eJPT then and focus on eCPPT unless you want eJPT for taster .

glossy jetty
#

With a masters degree you will probably get a work visa in the EU if that's what you want

peak steeple
#

Yes, nosfergz is correct! Masters are international πŸ™‚

slate ridge
peak steeple
#

Adding a cert will give you hands on experience.

glossy jetty
#

They say that because they need someone that would have permission to work in the EU. If you have that, you'll be fine. I would look how to apply for a work visa in an EU country you like

slate ridge
#

I've heard from too many people that it's a must have by now so definitely working on these as soon, if not before, getting my degree

slate ridge
#

aka something akin to thesis

glossy jetty
#

I would assume you can do that in your country, then any EU country will be more than happy to give you a work visa

slate ridge
#

Again, I could defo get a visa (or try to) but not knowing my destination is not so cash money rubiusKEKW

glossy jetty
#

And some student visa would allow you to work temporarily in the country, so not sure if you could do an internship with that

slate ridge
#

I'll continue applying for em either way, thanks for the info @glossy jetty @peak steeple

serene umbraBOT
#

Gave +1 Rep to @glossy jetty

thorny cloak
#

How hard has it become for EU citizens to get jobs in the UK? I see tons of entry level cyber jobs in the UK but I am not sure of the current state

hallow flame
elder panther
#

Anyone know about ghacking competitions with give away prizes

#

???

unreal arrow
#

Google CTF this saturday

elder panther
#

@unreal arrow Thanks man

serene umbraBOT
#

Gave +1 Rep to @unreal arrow

spiral lark
agile tinsel
#

How would study for security +

stoic cave
pseudo creek
#

the google CTF is fun

agile tinsel
#

I have a voucher so I'm wondering if I should take 501 or 601

stoic cave
#

601

stoic cave
agile tinsel
#

Ah thanks so I'll study professor messers vidoes for 601

stoic cave
#

You're going to want to use more than just the videos. I should also mention that my degree is a BS in Computer Security and Information Assurance. Studying for me was basically a review of my degree

agile tinsel
#

What wake would I want

#

I guess practices tests

#

I'm getting a masters in cyber security and domain one is my hobby

solemn marsh
#

How do you think I could improve my resume for an entry level job?

distant pier
solemn marsh
#

Like hands on experience with nmap, metasploit, burpsuite, etc?

quick forum
#

At first glance, it's not clear how that experience ties into a security position.

distant pier
#

Like a Continuing Learning section that includes cyber learning platforms, taking courses, preparing for certification exams.

solemn marsh
quick forum
#

Because they're not IT or infosec jobs, I certainly think you could tie them in

solemn marsh
#

I'd rather put what I have

quick forum
#

Yeah, but link it to what they're looking for

solemn marsh
#

hmm, yeah true

quick forum
#

Transferable skills especially

solemn marsh
#

I think the fact I self-taught music production and learning my way thru the DAW is transferable, right/

#

I mean- I didn't go to school for any of that stuff.

#

Just watched online videos and performed trial and error

#

Or, my own initiative to commission those projects; I think that could show some sort of management experience in some form, right?

solemn marsh
distant pier
solemn marsh
serene umbraBOT
#

Gave +1 Rep to @distant pier

solemn marsh
#

well, and both of you, your help overall ofc

#

always appreciated ;0

quick forum
#

The thing with CV/resumes is that they should be tailored to the individual job you're applying for. It's hard work, I know.

#

Have a master CV, the original copy, and modify it as required.

solemn marsh
#

BUT, you see

#

as someone with no IT experience, I feel like listing the music exp at least helps me a LITTLE

quick forum
#

You have experience of sorts, and you're young so probably not that much exp expected

solemn marsh
#

Yeah- I'm 20.

quick forum
#

But you can include the transferable skills and show how it's relevant

solemn marsh
#

I mean, for managing my own business I think that's transferable to some degree, yeah?

quick forum
#

I'm also twenty, but I have the benefit of all IT experience part time for a while

solemn marsh
#

So, under the music section:

#

Could I mention something like, managed my own business, -> tie it in with how it'd be useful with pentesting

#

in a sense?

#

Dang dude I need to get an LLC

#

they're defo gonna ask

solemn marsh
quick forum
#

Focus on the transferable and soft skills, preferably with some context

solemn marsh
#

glad to see someone in the same range

#

mhm- that makes sense

quick forum
#

There's a lot of people here between sort of 16 and 25

solemn marsh
#

so, keep the music section, but tie it in more, perse

quick forum
#

I'd massively develop the education section too. You're young, it's important. Especially if anything you're learning is related.

solemn marsh
#

Well, I've heard varying opinions on this

#

Like, judging my resume off of age, it's apparently illegal to do that

quick forum
#

What

solemn marsh
#

So someone recommended me to keep the education section clean

quick forum
#

It's not that it's not clean. It's that it's empty. Sparse

solemn marsh
#

Like, they can't discriminate against age

quick forum
#

Yeah, of course.

solemn marsh
#

So, I could add my highschool diploma

quick forum
#

I don't know how US resumes work there

solemn marsh
#

But I mean, I feel like it could hurt me more than help?

#

I have two award I received from the principle in highschool

#

so if I mentioned highschool, I could mention those, I suppose.

#

One was because senior high I decided to do an act of kindness and hold a specific door in the building open, every day after lunchj

#

for the whole entire year

quick forum
#

Idk what you're doing at community college, but again I'm sure you're getting transferable skills

solemn marsh
#

and then, another was awarded because I act with purpose, and the administrators saw that, specifically when I was under pressure every morning with the morning announcements; I was a leader in regards to my video and media class, making sure OBS was set up to record every morning, etc.,

#

In my first semester of comm. college, I took a public speaking class- I thought that would be helpful to mention

#

I'm just figuring out how I would best word that

quick forum
#

Yeah, so you haven't listed classes etc

solemn marsh
#

I mean, should I? wouldn't hurt

quick forum
#

I have my study topics listed with very brief descriptions of what they cover

solemn marsh
#

yeah that sounds very wise

#

I mean, at least the formatting/hard part is out of the way

quick forum
#

My degree is a cybersec degree

solemn marsh
#

Yeah that helps a lot

#

I guess the tough part for me is going to making it "transferable"

#

so I should "delete" my points that I have for music and re-brand them to be more directed at soft skills?

#

Is what you're saying?

quick forum
#

No, I still think it's important to list what you did in that role.

#

Just, as a part of that, try to develop and relate it back to the role you're applying for.

solemn marsh
#

For my public speaking class, would it be strong to mention that I got a 90 or higher on all my speeches?

#

in some way?

quick forum
#

No idea

solemn marsh
#

"β€’ Public Speaking, with four various speeches up to seven minutes in length. Outlined the speeches for articulate delivery." maybe?

#

Maybe I'll add those awards from high school in the additional information section

boreal zephyr
#

The about you paragraph on your resume should be in a cover letter, not your resume. If you came to me with music producer as experience, I wouldn't take you seriously as a candidate. If you don't have direct job experience, you should speak to your technical experience in others ways, maybe through a blog, proofs of concepts you developed, or cyber related activites like THM, or HackTheBox, etc. If you plan on taking cyber related coursework in college, list the sorts of projects you've done and course related achievements. You don't need direct job experience to stand out, but you do need plenty of activities to show that your engaged in the field and understand the core concepts

#

And if you can, get a certification.

solemn marsh
#

I'm working on my sec+ ; mentioned that at the bottom. I understand you might not take me seriously, but I'm sure some of it is mentionable, right? Like, I'd hate to start from the very bottom. Surely some of the management with my own business can be transferable.

#

I'm in college for an associates in general studies at the moment- looking to pair that with certifications and activities, like you mentioned. This is an entry level resume. I'm looking to get opportunities for IT to be put on my resume.

#

Some resumes have a brief paragraph intro, some don't - it's a toss up.

#

I'm not totally sure what to do because some will be hardly for it, and others will be hard recommending it. It seems very subjective.

quick forum
#

Also bear in mind that a resume, if read by a person, will be scan read top to bottom. Most important stuff first.

#

So security stuff near the start

solemn marsh
#

Additional information would include my certs - how would I put those at the top instead?

boreal zephyr
#

Transferrable sure, but the idea is to not have to explain how your business experience makes you a good IT candidate. If you have a strong portfolio of directly related projects, like in a Github or Portfolium account where you can show off you skills and knowledge, you won't even need the business part in your resume.
I'm giving advice based on my experience trying to get my first cyber job, the only thing I've left in my resume that isn't directly related to IT in some way is my military experience

solemn marsh
#

That's totally fair, and I REALLY appreciate you being so constructive. It's very helpful - I'm just a little disappointed that my music production experience/business management experience can't go as far as it sounds like I'd want it to.

quick forum
#

I had like a couple of long sessions with the careers people, rewrote my CV, then got a cybersec job

solemn marsh
#

Yeah, I mean- I'm sure there's stuff that I've done that I could put on my resume; it's just either so long ago, or I don't really feel like I immersed myself enough in the cirriculum to safely put it down

quick forum
#

I know it's a little different over in the states, but a lot of the info is general

solemn marsh
#

Like, there are some silly projects I made doing my web development course I got from Udemy, where I made simple landing pages

#

I mean, I could mention my endeavor to learn front-end web-development on my own, couldn't I?

boreal zephyr
#

Those types of projects aren't silly, you just have to flesh them out into something you would want to show off

solemn marsh
#

Idk, I've always seen those things as not so amazing or incredible

#

Saw coding more as a little hobby of mine than anything; lots of those projects are hard to find now also

#

I mean, they exist, but they're very unorganized in a folder somewhere

#

I suppose I could upload most of them to github?

#

Idk if they're worth showing off though.

#

So, you're saying, get rid of my music self-employment in it's entirety

#

and the graphic design

#

and just fill experience with other things?

boreal zephyr
#

The idea is to show drive and initiative. An employer knows they are looking at an entry level candidate, they won't be expecting the pro, but they will be looking for that motivation and learning mindset that make fresh employees skilled employees very quickly

solemn marsh
#

I mean- I would argue I have that drive and initiative; it's shown through my music and thousands of unreleased projects. My 6 years of experience self-taught. My investing experience through self-teaching myself how to read-charts through YouTube videos. I'm pretty confident at least some of that could translate in some capacity. My difficulty is 1) where to put it, and 2) how to word it in an attractive manner.

boreal zephyr
#

I don't disagree!

solemn marsh
#

Dealing with clients, showing customer service experience with those people- I can communicate well with my clients, and I receive great feedback.

#

I just don't know exactly where or how to mention it on this golden ticket, that is, my resume.

boreal zephyr
#

You don't, you write it in your cover letter.

ancient prairie
#

you can always throw testimonials on your resume if its relevant

solemn marsh
#

I mean, it's not really in this case- it's thru my graphic design / music production; this is an IT resume.

#

Immediately it seems, only IT things apply here

ancient prairie
#

if they speak to your character it wouldn't hurt to throw in

solemn marsh
#

I'm sort of at a cross-road and I'm quite confused what would be safe to mention

ancient prairie
#

"Day is a hard worker and always great in projects blah blah" something like that is worth putting in

solemn marsh
#

I just feel like my resume is different than most because of my unique experiences. I'm not like the typical high school student that will have mcdonalds/retail on their resume

boreal zephyr
#

I'm at a different point in my career so showing you my resume won't really help, but I got my first job in IA with a Sec+,Linux+, and the Cyber Security Essentials course from Cisco networking. The only job I placed on my resume was my 4 year military career, which was in a completely unrelated field

solemn marsh
#

It's going to have to be articulately worded, precise, and clean- I'm going to have to think about the best way to word things.

solemn marsh
distant pier
boreal zephyr
#

^ bingo

solemn marsh
serene umbraBOT
#

Gave +1 Rep to @distant pier

ancient prairie
#

as long as you show you are capable of doing the job you are applying for - your background doesn't matter, over a year ago I was working construction and studied my ass off for A+/eJPT, passed, remade my resume and applied to about 200 companies, got rejected by 199

solemn marsh
#

I apologize if I sound frustrated. I think I'm just overwhelmed. I want to get this right!

#

You guys are so helpful and I'm very appreciative of this community, so thank you. It means so much.

boreal zephyr
#

Happy to help. Are you familiar with writing a cover letter? Thats where you can make your personal appeal to the hiring rep.

solemn marsh
#

I mean- I've written one or two applying for a music job; obviously didn't get the job because of my resume being like 10x worse than it is currently, I'd guess, but yeah

quick forum
#

Cover letters suck

ancient prairie
#

i've heard and had very mixed results with cover letters so I won't speak on those

solemn marsh
#

I've written a cover letter before.

quick forum
#

They're slowly going away

solemn marsh
#

It seems all people want are resumes

ancient prairie
#

I think a tailor-made resume is much better, if they require a cover letter to get past HR I really don't care to work there anyway

solemn marsh
#

like, your resume is your golden ticket

#

that's it

boreal zephyr
#

Cover letters suck, but if it comes down to someone who did write one, and one who didn't, guess who I would want to be

#

After your in your first IT job, dont worry about writing one. But for entry, do.

solemn marsh
#

I don't think I mind writing a cover letter.

#

What if they're not requesting one though?

ancient prairie
#

good advice, I 1000% will never be writing another one lol

boreal zephyr
#

Send one anyway. Most application portals will accept supporting documents

solemn marsh
#

What if they request via email?

#

I sent my resume (im starting to cringe now cuz I sent what I sent in chat) via email as per request, for an internship

boreal zephyr
#

Then once your foot is in the door and you develop a good reputation, ask for letters of reccomendation from your supervisors and replace a CV with signed letters of reccomendation

solemn marsh
#

sounds like a security issue but cba

#

CV being your cover letter?

boreal zephyr
#

correct

solemn marsh
#

Gotcha

#

Would a teacher recommendation look good or no?

boreal zephyr
#

absolutely

solemn marsh
#

highschool?

boreal zephyr
#

definitely

quick forum
#

What? CV is not a cover letter!

solemn marsh
#

Yeah, I thought CV was a resume

quick forum
#

CV is the UK/EU resume

#

Curriculum vitae

boreal zephyr
#

weird, ive always heard cover letters being referred to as cv's here

#

either way the point is the same

solemn marsh
#

Dang- well, either way; it's understood what you're talking about

#

Well, I guess I didn't realize a letter of recommendation would be that useful

#

I can get one from my senior high cyber teacher?

#

Would that look good?

boreal zephyr
#

As long as they are willing to say nice things about you lol

solemn marsh
#

Yeah lol of course

#

I'm a college sophmore now though so idk how much they'd be able to remember about me

#

Also, are you allowed to see your letter?

#

Like, could I have the letter on standby?

boreal zephyr
#

of course, your going to be the one sending it in

solemn marsh
#

Ah- for my college recommendations I didn't have the ability to read them

#

sorta sucked

#

is there a limit on how many I should get?

#

Like, I could probably get 3 guranteed

#

all tech related

#

video media teacher, cybersec teacher, and web applications teacher

boreal zephyr
#

I always do supervisor and upper manager concurrence. Since yours will be school, one or two I think would be plenty

#

cyber and wepapp teacher is who I would pick

solemn marsh
#

yeah, agreed

boreal zephyr
#

just ask them to speak to your character and your coursework and sign it

solemn marsh
#

So I guess, I'll awkwardly write an email to them lmao

#

it's been a year or two lmao

boreal zephyr
#

Trust me, I did it, lots of other people do it, its how you get ahead.

solemn marsh
#

I also needed to email my cyber teacher anyway, so

boreal zephyr
#

Having other people willing to vouch for you and put their name on something means a lot,

#

especially in the professional world

solemn marsh
#

Do you think this is alright?

#

``Greetings <teacher>

I hope you've been doing well; it's been quite a while - I'm reaching out to you because I'm working on updating my resume and getting things nice and professional for the information security field, and I was wondering if you would be open to writing a signed letter of recommendation about me, speaking in regards to my character and my coursework. I'd really appreciate it, and I really hope you've been doing well. Thank you so much for everything you've done. Wishing you the best.

Kind regards,

David <last name>``

#

I might want to mention there's not really a said deadline;

#

I know some teachers don't want a letter request last-minute.

boreal zephyr
#

Looks good! One big tip that I've learned, and its a bit of a knitpick, not to thank someone for something in an email before they agreed to do it. Maybe flesh out the "thank you" a little to specify thanks in relation to the class and not for the letter

solemn marsh
#

Ohhh I gotcha

boreal zephyr
#

you just dont want to seem presumptuous

solemn marsh
#

I hope you've been doing well; it's been quite a while - I'm reaching out to you because I'm working on updating my resume and getting things nice and professional for the information security field, and I was wondering if you would be open to writing a signed letter of recommendation about me, speaking in regards to my character and my coursework. I'd really appreciate it, and I really hope you've been doing well. Thank you so much for everything you've taught me in the class. The certifications in the Microsoft Office Suite were very foundational and applicable. Wishing you the best.

#

Like that maybe?

flat sedge
# quick forum CV is the UK/EU resume

It's also a lot more common in academia, not just in the EMEA region. Many professors maintain a CV, not a resume, that covers their entire research history. One of the EE lab directors I know has a CV that was 30+ pages and included references to all the students he graduated with a PhD or M.Sc, as well as every published paper he contributed to.

boreal zephyr
#

maybe, "I really enjoyed my time in your class, thank you for your insight and expertise, it was a pleasure to learn from you"

quick forum
boreal zephyr
solemn marsh
boreal zephyr
#

Nope, let them tell you if they cant or wont

solemn marsh
#

Oh ok

#

and shouldn't mention a deadline, right?

#

I'll let it be in their court

boreal zephyr
#

if you had a deadline, you would put it in the request

solemn marsh
#

they'll ask about it

boreal zephyr
#

but since you dont, let them sk

#

exactly!

solemn marsh
#

Sent πŸ™‚

boreal zephyr
#

Thats great! I hope it goes well for you πŸ™‚

solemn marsh
#

subject line is letter of recommendation

#

is that fine?

boreal zephyr
#

request for

solemn marsh
#

ah crap

#

sent the other one already

#

but for this one I changd

#

its ok

boreal zephyr
#

dont worry about it

solemn marsh
#

kk for this next one

#

I need to tie two requests into one email

#

Subject line and email

boreal zephyr
#

those should be two different emails, just off hand

solemn marsh
#

you think this looks fine? I'm trying to be as non-awkward as I can to a teacher I haven't seen in two years

quick forum
#

Your surname was in there

solemn marsh
#

oh nice

quick forum
#

You've redacted it so far, so I deleted it

solemn marsh
#

tyvm

#

much appreciated

#

I mean, I should write from scratch then?

#

Not try to morph it with the other one lol

boreal zephyr
#

I didnt get much more than the subject line

#

but yeah, definitely two emails

solemn marsh
#

1s

boreal zephyr
#

one is a personal request, the other is school related

solemn marsh
#

Request for Letter of Recommendation + Question about accessing my locked <school> account

Greetings Mr.<teacher>!

I hope you've been doing well; it's been quite a while - I'm reaching out to you because I'm working on updating my resume and getting things nice and professional for the information security field, and I was wondering if you would be open to writing a signed letter of recommendation about me, speaking in regards to my character and my coursework. I'd really appreciate it, and I really hope you've been doing well. I also had a question regarding my locked <school> account. Would it be possible to be temporarily unlocked so that I can access my data and perform a Google Takeout? I did this near the end of the school year but my account got locked before I could download the zip file. I really enjoyed my time in your class, thank you for the insight and expertise, it was a pleasure to learn from you. Wishing you the best.

Kind regards,

David <name>

#

ahhh

#

so not merge them then?

boreal zephyr
#

right, always separate personal email from non-personal.

solemn marsh
#

gotcha

#

So, just send the typical letter of recommendation

#

and then make another one for the question

#

I could use what I already typed though?

#

Shoudl i wait between or send both?

boreal zephyr
#

also, you don't really need to say its been a while, they know

solemn marsh
#

πŸ˜‚ true

boreal zephyr
#

the reason I say to separate them is because they might have to CC or forward the school request to someone

solemn marsh
#

oh yeah

boreal zephyr
#

and you don't want the letter request going to someone unintended.

#

there are lots of unwritten email etiquette rules youll learn over time

solemn marsh
#

I said I hope you've been doing well twice o.O

boreal zephyr
#

xD your just nervous

solemn marsh
#

i'm removing that lol

#

kk i sent it

#

gosh its been forever

#

only a year or two but like dang

#

so should I send the other one right away?

boreal zephyr
#

Sure, no harm in it

solemn marsh
#

oh no

#

my cyber teacher's email is disabled

#

wtf

#

he talked about leaving

#

😭

boreal zephyr
#

If you know their name and where they might have been going, you can look them up in faculty directory

solemn marsh
#

Crapp

#

the email isnt valid anymore

#

I have a friend that has his number though

#

he's really privacy aware

#

gonna be hard to find his stuff

boreal zephyr
#

If you'd like an example of my resume or a cover letter, or even my letter of reccomendation I dont mind sharing them with you. Just need to redact some PII

solemn marsh
#

yea thats fine o.O

boreal zephyr
#

I actually just went through the hiring process, so its pretty recent. Give me a few

solemn marsh
#

crap dude

#

This teacher would have been cool

#

idk where he went 😭

#

might of got fired lmao

#

he did some crazy stuff

#

Very nice o.O

#

Dang that's nice stuff o.O

#

Is it normal for a resume and stuff to stress someone like me out a little? Lol

#

Idk- I'm still transitioning from that school -> business aspect of things.

#

is this another recommendation or part of cover letter?

boreal zephyr
#

my actual resume

solemn marsh
#

ohhh

#

this isn't one page is it?

boreal zephyr
#

its like 3, which is on the longer side

solemn marsh
#

after some point you can't do 1 page anymore, right?

boreal zephyr
#

I don't personally, but some people swear by short resumes

#

and yes, resumes are stressful. that never goes away

solemn marsh
#

bruh idk what to do

#

i think I need to take a break lol

#

been thinking about resumes since 3pm today

boreal zephyr
#

right on

#

Id say you earned it lol

solemn marsh
#

lol

#

I'm still sad I cant reach that one teacher

#

I guess I'll try the video & media teacher instead

#

as a backup

#

Oo

boreal zephyr
#

The class is less important than what is said in the reccomendation

#

they are more speaking to your character and quality of work, than what exactly that work was

solemn marsh
#

The video & media class was where I really shined; that teacher is forever "wow"'d by me lol

#

He's the one teacher who I'd say would hands down be happy to do the recommendation

boreal zephyr
#

then thats who I would have went with first lol

solemn marsh
#

I asked him during when I was applying for colleges but he forget about it

boreal zephyr
#

should have led with that

solemn marsh
#

lmao

#

well, both the web teacher and this teacher

#

they both speak highly of me

#

πŸ˜‚

#

the web teacher recommended me when my guidance counselor had to solve a problem with a school and they wanted me to create an excel sheet to carry that data

#

lmao this was a while ago- why didn't I think of it?

boreal zephyr
#

sounds likes your in good hands then πŸ™‚ if I were you, I would create a github account or a blog site and start doing writeups on all the THM rooms you complete

solemn marsh
#

she got me chikfila as a token of her appreciation lmao

boreal zephyr
#

oh nice!

solemn marsh
#

Yeah I created a github

#

I have a site but I need to touch everything up

#

I'm trying to make my personal domain dedicated to a "resume" thing

#

so at the bottom of my resume I can say, check out this site for projects, blah blah

#

you know?

#

and it has linkedin, github, etc.,

#

writeups on even the beginner rooms?

boreal zephyr
#

yes! many application portals will even give you the chance to paste your links

#

If you complete it, write it up. Your successes, failures, and lessons learned

solemn marsh
#

My email is my own domain too- I thought that would look more professional than a gmail

#

Is there a given format for a write-up?

#

Even if it's a SIMPLE room? Like, linux/windows fundamentals?

boreal zephyr
#

Doesn't matter, write it up

solemn marsh
#

Dang ok

boreal zephyr
#

if its simple, take it a step further

solemn marsh
#

do you have any example writeups?

#

I want to get an idea for the format

boreal zephyr
#

You aren't bound by the confines of the room, those are just the bare minimum

solemn marsh
#

Is it just explaining what the room is about, what you learned

#

like, chmod is this, does this, etc.,

#

cat does this

#

and then windows, cmd, cd = change directory

#

things like that

#

?

boreal zephyr
#

Do some googling, there are lots of writeups out there, part of it is finding your own style and adding you own intuition/thoughts

solemn marsh
#

Github formatting is different than word right?

#

That's fine though I guess

#

I would do a blog site of write-ups but I have to get a thing that will be permanent; my site I'm unhappy with atm

#

I can't find a nice portal thing- wordpress is clunky for my personal "portal"

#

with wordpress

#

Cmnatic's my reference πŸ˜‚

#

any ideas?

#

Might have to code it from scratch ;/

#

Seems simple other than the responsive part

boreal zephyr
#

Dont lost the trees for the forest

#

If you arent trying to get a webdev job, dont worry about the frontend

solemn marsh
#

yeah but I mean

boreal zephyr
#

even if its templated, just make it look presentable and easy to navigate

solemn marsh
#

I'm trying to make a nice portal page

#

I cant find a nice template for wordpress that's as similar to it as a portal

#

it's clunky

#

I need a better CMS

boreal zephyr
#

looks like the page you linked leveraged jekyl

solemn marsh
#

ayy im gonna take a braek but its been a pleasure talking and I really appreciate all the insight you provided. it means the world dude- sent you a discord friend req; would love to keep in touch.

solemn marsh
boreal zephyr
#

Happy to help, good luck out there!

#

ask CMN? they are on this discord right?

solemn marsh
#

yeah I reached out to cmn- he offered to host it for me 😎

#

but I mean,

#

I'd love to use my own webhost if possible. I'd hate to have him do that. I'm sure it wouldn't be in his way though

#

very kind offer nonetheless

boreal zephyr
#

maybe just ask for help on how to do it and then do it your own way?

solemn marsh
#

i would self-host if I knew I could have reliable up-time

boreal zephyr
#

there are always smarter people in the room, I try to learn as much as I can from them

solemn marsh
#

i'd be hosting on a pi and I dont know if I can ensure my pi stays up at all times

#

plus it'd be pointing out of my own house

#

sort of risky cuz self-host with IP

boreal zephyr
#

in any case, do some research, find the best solution for you, and worry about the details down the road

#

step A > B, then work B > C

solemn marsh
#

heck yeah- sounds great; I'll do some more research

#

yeah exactly

boreal zephyr
#

πŸ™‚ You got this

solemn marsh
#

πŸ˜‰ appreciated as always man

#

ttyl

boreal zephyr
#

take care

willow sedge
#

I have a doubt that I am pursuing ceh currently and I wish to do a job at the same time any idea what role any company will provide me by knowing my certification isn't completed yet

north hill
#

Guys I again need some help

#

WAF+L7LB+Firewall
Or
WAF+Firewall+Network Load Balancer+Ingress

pseudo creek
#

it all depends on the purpose and honestly, this is the wrong channel for those type questions

north hill
#

Okie Dokie :D

signal zealot
#

Hello guys

ember spruce
#

hello hackers

rugged stump
#

Hello guys! Has anyone ever gotten a job in the cybersecurity area just by leveraging skills learned through THM?

fair cypress
# rugged stump Hello guys! Has anyone ever gotten a job in the cybersecurity area just by lever...

This is a great question. I have not seen it directly but I recently saw an article that stated hiring managers are looking more at "non-traditional" paths for job applicants. There is such a shortage of cyber qualified candidates right now hiring managers need to consider all options. With that said, I would recommend adding your skills learned here to your resume/LinkedIn to show that you are practicing self development and learning skills.

rugged stump
serene umbraBOT
#

Gave +1 Rep to @fair cypress

hot fog
#

I sat w this guy the other day, he says application development is way better than cybersecurity in terms of income. What do you guys think of his statement?

flat sedge
#

Depends on the organization and what the business goals are. App development immediately provides business value in the form of a product that generates income; security does not normally bring money in and gets a lower priority for increased budget

hot fog
# flat sedge Depends on the organization and what the business goals are. App development imm...

How about this example, you've got 2 firms.

Firm A is cybersecurity focused and provides services in that regard. Whether its penetration testing, or defensive operations to a business/company etc.

Firm B is mainly focused on application development and offering to create apps for different companies depending upon what their vision is.

I know this answer would be based on a number of factors, and a simple answer wouldn't suffice. But, which one would be a safer bet for the future?

Again, I realise and understand the description I've provided is abstract.

flat sedge
# hot fog How about this example, you've got 2 firms. Firm A is cybersecurity focused and...

Again, depends on the org. Firm A would probably be something like CoalFire or FireEye. They won't have a lot of developers, because they aren't providing a product or product support, they are providing services. Firm B may or may not employ dedicated security teams, and if they do, security requirements are going to vary based on who B is providing the product too. Government, especially 3 letter, agencies or financial institutions have wildly different security requirements that they must adhere to; developers and cybersec ought to make roughly the same in that situation. In a firm that doesn't prioritize security over everything else, developers will likely make more, based on what value that developer provides. IE, a fullstack dev will probably be paid more than a backend dev.

serene umbraBOT
#

Gave +1 Rep to @flat sedge

paper grove
#

Just want to add to the conversation here. In all my research, both job sectors have clear potential to get into salaries within and above $120k a year (USD estimates), but as mentioned, it depends on the organization you work at. And if you're progressing from either no career yet, or a career that previously only made $30k peak a year (like me), then any kind of increase is nice. In my opinion, getting into the fine details of which job could make $120k vs $130k is splitting hairs. Try to pursue the one that you feel can provide you with a comfortable living and that you enjoy more.

celest needle
#

How can you get something posted on the jobs boards… I’m a security architect for a large UK company and we’ve got openings for SIRT, SOC analyst (L2/3) and security testers in house

rugged sable
#

Ask muir!

celest needle
#

Thanks!

pseudo creek
# hot fog I sat w this guy the other day, he says application development is way better th...

I didn't scroll up to see the question was about pay. It probably depends. In my experience, the average cyber security person will make the same or more than an application developer. Now there are certainly one offs, like plenty of stories of top tier developers in Sillicon Valley who make $1 mil (that is including stock options) but they also live in a place where the average home price is over $2 mil. In cyber security, to make that kind of money, you either have to be a CISO of a major corporation OR have your own independent business (think of someone like TheCyberMentor).

hot fog
#

Ofc

#

I'm just asking about it bc me and my friend were debating about it

#

Me and him both agree that it's easier to make an independent business when it comes to app development

pseudo creek
#

sure, but then you are also competing against people who live in low CoL countries who will work for pennies

misty vigil
#

Hi guys! Would you prefer to work for MNC or Government?

worn spire
#

The big thing about being in business I have learned is a lot of it is convincing your customer about the value you bring. While there is certainly competition, do not let competition scare you from competing in the market.

worn spire
# misty vigil Hi guys! Would you prefer to work for MNC or Government?

Working in Government seems to have it's own Pro's and Con's especially in the US, if you have student loans there are ways to get them forgiven and there are some nice perks. However you will likely make less then working in the private sector, and when I say less I mean "A LOT LESS"

quick forum
#

In the UK, gov jobs have really great pensions (or at least used to?) But have a different hiring process and I'm not sure about the pay.

celest needle
#

UK gov pay is rubbish for cyber unfortunately that’s why most the talent is private sector

worn spire
#

In the US a lot of pensions have gone away completely, there are still some but the closest thing you tend to find are 401k's.

celest needle
#

We have our state pension which I believe our national insurance goes to which every one is guaranteed then companies put in as mandatory per regulation into an employee pension for that company

#

Then you can have a private one as well but all this does is make a massive pension pot mess with 20k here there and everywhere if you move companies frequently

worn spire
quaint flare
quaint flare
worn spire
#

Depends on the job, but I have seen senior security people pulling 175-200k+ in the private sector, I have not seen that in the public sector.
The only source I could find specifically for the NSA salaries was on glassdoor
https://www.glassdoor.com/Salary/National-Security-Agency-Salaries-E41534.htm
That being said a lot of government jobs are based off the GS which tops out at 143k
There are exceptions though.
https://www.opm.gov/policy-data-oversight/pay-leave/salaries-wages/salary-tables/pdf/2021/GS.pdf

quaint flare
#

hmm

worn spire
quaint flare
#

im doing some research as well. this is interesting! thank you

worn spire
#

Lots of pro's and con's both ways, either way you can't really go wrong.

#

But if your interested in working for the DoD I think you can still get college paid for through cybercorps
https://www.sfs.opm.gov/

quaint flare
#

what would you say are some basic pros and cons for each?

#

i did actually apply for the SFS

quaint flare
worn spire
#

Well, for one, I work in the private industry and also have my own business. I work multiple jobs, a lot of that can go out the window when working for the government because of conflicts of interest and anti-moonlighting policies. The pay tends to be a little lower for the position, and the private sector is very chaotic. You can be thrown into a lot of frustrating situations that make absolutely no sense and have to deal with plenty of corporate pursuits that very well may stretch your ethics depending on the company you work for and what field you work in. On government jobs, I can only tell you what I have heard. I have done work for the government as a contractor but not a full-time employee. The government moves slow and is slow to react but is predictable and meticulous in its decision-making. This sometimes means a more predictable pace and fewer turns. The government generally gives better benefits, is normally more stable, less chaotic, and with notable and debatable exceptions. I would argue ethically you might feel better than working for a company since, depending on your position, you are helping protect US citizens and government assets, so there is a patriotic sense to it. Of course, you could always be a contractor and more or less still work for the government full time as well.

quaint flare
serene umbraBOT
#

Gave +1 Rep to @worn spire

worn spire
#

Also if you can get equity, go for it

pseudo creek
#

Gov pay is also capped. Like I know I make over the gov cap.

warm hinge
#

I also was thinking of maybe going for a gov job in the EU or a hospital job. Partly because of ethics. Though I am not sure if it is the best place to start a career

worn spire
worn spire
pseudo creek
#

yeah, healthcare IT is something I think that does well.

dapper lichen
#

Any one know the entry level position ,

warm hinge
#

or like on an entry level

worn spire
# warm hinge Did they start in healthcare?

That person specifically did not, however it doesn't mean you couldn't start in healthcare. The thing about cybersecurity to remember is that it is a sub-discipline of IT that has gotten big enough to be it's own category. A lot of things you do in cybersecurity you still have to have that IT background. I see far more people transitioning from IT to cybersecurity then entry level cybersecurity jobs. That is something to keep in mind, a good strategy might be getting an entry level it jobs that can transition quickly into a cybersecurity job, such as a systems administrator.

thorny cloak
#

Is SOC usually windows or is it 50/50 windows/linux?

worn spire
#

@thorny cloak Great question! Depends on the org but normally you will have a mix. In some organizations you even have a combination of Mac's, Windows, Chromebooks, Ipads, Android tablets, and IoT machines(like raspberry pi's that monitor production of wine or beer production).

thorny cloak
#

Roger that. I do see SOC as entry level on the blue side, but Ive been focusing on Linux.. as its usually the choice for offensive. Its also most of the beginner path in THM. I have to commit some more time to Windows. Thank you @worn spire

serene umbraBOT
#

Gave +1 Rep to @worn spire

worn spire
thorny cloak
#

something about THM... the more attacking I do... and I love it. I love even getting that user.txt.... but the more blue grows on me

worn spire
#

@thorny cloak At the end of the day we are all a bit purple. Without blue team there would be no purpose for red, without red blue could never improve. Most orgs are hiring for people that have a good understanding of both.

thorny cloak
#

Thats exactly what ive found looking at job reqs/preferred. I think im going to do the defense path for a bit... before i finish with the beginner path

thorny cloak
worn spire
#

@thorny cloak It depends, when I was a Lead security engineer we would write scripts, but they were very specific scripts. For example, we would use elastic stack for our SIEM. We would write custom powershell/python scripts that would send log files over https in json format to our SIEM. In that way we could automate various tools and have them ingest the logs in the SIEM. For example we took the output from Norton Power Eraser and then wrapped it using PowerShell to send logs. We used automation over PSEXEC to automatically kick off Power Eraser scans on any computers that seemed suspect(like after downloading a strange file, or visiting a strange url).

#

It all depends on the technical level of your team, some teams will do that, I have met some "security professionals" that can't program "hello world!". It all really depends, it's certainly an advantage if you know how and can show in an interview how you can automate security processes and bring efficiency. The big part of the interview is when you get a chance to sell yourself and your skillset. One of the biggest issues i see in new applicants is not being able to show how their current skillset will benefit the org. If you can show your value, it's a much easier hire.

thorny cloak
#

Ive been purely focused on red.. So I gotta google a few things from your first paragraph. I do have an engineering background so the coding is not an issue but explaining how you use it... I had no idea that was even a thing. Im gonna get going with the cyber defense path... close to done with the beginner path but its almost purely red. Im the same % at beginner path and pentest+ path without entering that path once

#

Do you mind if i PM at some point when i dont have basic google questions?

#

Do you practice blue here in THM?

worn spire
thorny cloak
#

fascinating. I came here to learn from scratch and see that a lead sec engy still practices.. I havent discovered 5% of this place then

worn spire
thorny cloak
#

hats off to you, congrats on the climb

worn spire
solemn marsh
#

@oblique forum Do you think these are all closer to IT related?

#

`` Produced an excel spreadsheet for my high school guidance counselor to propogate data with relevant charts in order to propose a change in a school related meeting.

Innovated highschool daily morning broadcasts to run more smoothly by switching out the broadcasting software and delegating students to manage different positions.

Created a python script to efficiently search for available domains by concatenating two word lists and appropriate TLDs, exporting a desired amount, and copying to clipboard and a randomly named textfile for personal use.

Acquired hands-on experience with configuring Cisco 2960 Switches and 2901 Routers, such as: vlan configuration, enabling ssh encryption, enabling dhcp, disabling telnet, enabling trunking, displaying arp tables, etc.,

Coded landing pages with HTML, CSS, Javascript, and the Bootstrap 3 framework through an online course and self-ambition.``

elder panther
#

Any one want to join my team in Google CTF, here is the join code

hazy sky
#

Hi all

worn spire
#

What's the google ctf?

#

HI @hazy sky

golden ore
hazy sky
misty vigil
stoic cave
#

I would also like to add you can work in government but not be employed by the government. DOD Civ is a lot different than DOD Contract and you can work on cool government projects but get paid like private sector

solemn marsh
#

Do you think this resume will help me land an IT Help Desk job?

stoic cave
#

Personally, I'm not a fan of "modern" resumes. I wouldn't put a summary, that's what a cover letter is for. The work history I would replace with experience and tie those jobs into the job you're going for. Lastly, skills you need to make sure you're solid on everything you list. I got burnt in my IT internship because of it even though I thought I had a good understanding of what I was listing

solemn marsh
#

that's all really fair advice- so for "work history" heading, changed to experience, but keep the same content?

stoic cave
#

So top down would be:

Title with contact information
Education
Skills
Experience
Extracurriculars
Projects (personal or otherwise)

solemn marsh
#

And yeah- I liked the traditional format but the template couldn't fit everything

stoic cave
#

Website portfolio and profiles would be the contact information

solemn marsh
#

I think contact at the top would be the best location

stoic cave
#

Yes that's what I am saying

solemn marsh
#

ohh

#

move sites to top?

stoic cave
#

You have a lot of blank space at the top

solemn marsh
#

ah yeah- make the heading less big

#

and then I have a little more room

stoic cave
#

Yes if it's a personal website, social profile, etc it goes at the top

#

Also by moving to a singular column you'll have more space

solemn marsh
#

well, I have another template I really liked but let me show you how it looked, 1s

#

I need to redact some stuff

stoic cave
#

AwesomeCV is a good template

#

It uses latex and is dead simple

solemn marsh
#

oh nice I'll play around with it o.O

#

free?

#

This is the right template?

#

I agree w your summary idea btw I just know it's sort of subjective- some people like it, some don't

stoic cave
#

Yes that's the template

#

I removed the color though

solemn marsh
#

yea understandable

stoic cave
#

Fixed

solemn marsh
#

so don't include work experience at all?

#

or put that in experience

stoic cave
#

That's what experience is

solemn marsh
#

keep everything in my resume I showed you, just with a differnt header?

stoic cave
#

Lemme see if I have a redacted copy of mine

solemn marsh
#

yee nw at all

stoic cave
#

Here is one that's about a year old

#

I cut the top for obvious reasons

solemn marsh
#

oh yeah totally fine

stoic cave
#

Just put the AwesomeCV header there and it's a full page

solemn marsh
#

and it doesn't go into 2 pages at all?

#

That's clean

stoic cave
#

Nope

solemn marsh
#

this awesomecv thing looks great but it might take a while to change everything yeah?

stoic cave
#

If you try and print a paper copy you might have some issues with borders but it fits and can be read easily by robots

solemn marsh
stoic cave
solemn marsh
#

oh yeah I bet

#

so cv.tx is where all the contents are?

#

tex

stoic cave
#

I think i renamed mine

#

I don't remember

#

One is a cover letter and the other is the resume

solemn marsh
#

ahh

#

I shouldnt need the cover letter for nwo

stoic cave
#

Once you look at the code structure it's actually pretty simple

#

I always include a cover letter

#

And write a new resume for each application

solemn marsh
#

For position, if I'm seeking an entry level job , should I put my title as that?

#

even though I've not held that position before?

stoic cave
#

What? Don't lie

solemn marsh
#

oh nono - wasn't intending to lie at all; I guess I'm just confused. Do I put ANYTHING there? Like,

#

I could put Music Producer, but this is an IT position- I'd rather leave that blank.

stoic cave
#

I got my job, as a Cyber Security Engineer, with lifeguard, cook, and a 3 month internship in my resume

solemn marsh
#

Oh wow

stoic cave
#

That's why I said tie your old jobs to the one you want

solemn marsh
#

I guess to better reword my question, I'm just wondering what title would work best

lofty ibex
stoic cave
#

IT is problem solving

solemn marsh
stoic cave
#

Talk about problem solving skills in your little job descriptions under each job

#

Like look at my lifeguard entry under work experience

solemn marsh
#

Well I mean, I thought I listed some transferrable skills under my past experiences in the first thing I sent - are they not transferrable enough?

stoic cave
#

I talk about management and planning skills

lofty ibex
solemn marsh
stoic cave
#

And then during my interview I was able to talk about those planning skills that I developed at that job and how it applies to the cyber domain and so on

solemn marsh
#

I may need to completely re-evaluate

stoic cave
#

The Defense Contractor internship was an Enterprise IT internship

#

So pretty much yeah

solemn marsh
#

because I'm studying for my sec+; my goal is to get my foot into the door with IT one way or another

stoic cave
#

I got torched during the internship and learned some valuable lessons

solemn marsh
#

A soc would be a major goal of mine to be in

stoic cave
#

Sec+ is a good start

solemn marsh
#

end goal is pentesting, but I mean, one leap at a time

solemn marsh
stoic cave
#

Do you have any military installations near you?

solemn marsh
#

sooner or later, depending on how I feel

stoic cave
#

They are always looking for Help Desk

solemn marsh
#

Like, if I can just jump straight into infosec, that's rad

lofty ibex
#

being adaptable is usually the easiest way to start in IT, helpdesk may be the job you land first, or you may apply for junior pentesting and get it prior

#

Until you start actively looking you'll never really know what your path will look like

stoic cave
#

I got my shot because literally the only requirement was have a Computer degree and I guess I interviewed well

solemn marsh
stoic cave
#

Now, that door has closed, at my company anyways

solemn marsh
#

Yeah, dang- I just wish resumes were less subjective, but like you said @lofty ibex - every hiring manager is different. I've spent so much time this week trying to organize a nice resume, trial and failure, get knocked down, but I'll find the right way to do it. I really appreciate your guys' feedback as always.

lofty ibex
#

After a while you get a real good grasp on what type of resume will get you an interview

solemn marsh
#

Yeah, I mean- the other thing that sort of plays against me is that my music + graphic design experience is all self-employed, under myself, so I mean, not every person may consider it a business

#

I have yet to get an LLC license- started taking it seriously this year

#

And ideally, I wouldn't want to get a fast-food/retail job, honestly; I really would love to jump straight into the workforce.

lofty ibex
#

But you can spin that, because it's self employed you've had to develop a strong sense of self-discipline and time management to meet client expectations while still developing excellent interpersonal skills to provide the best experience to the client

solemn marsh
#

Like, idk- I need to stop floating in the wind and anchor myself to one idea and stick with it

#

I keep asking people for suggestions and then try that idea and then someone tells me something else and I'm spinning in circles.

lofty ibex
#

Sadly until you land a role, you kinda have to be a jack of all trades unless you really tunnel into one area and go ham for it

solemn marsh
#

Yeahh.

lofty ibex
#

like my experience and advise coming from a pentesting background will 100% be different to someone working in a soc

solemn marsh
#

Well that's just the thing

#

I want to be where YOU are right now

#

Like, I'd love to get a job as a pentester out of the gate, but that just seems unlikely

#

with no prior experience other than my self-employment?

lofty ibex
#

It's not the easiest thing and usually comes down to connections + location

solemn marsh
#

That just sounds like a crazy feat.

lofty ibex
#

I went straight into pentesting with no degree/relevant experience

solemn marsh
#

Dang

lofty ibex
#

It's for sure possible but it's about putting yourself out there, if you're able to go to cons and network that's amazing value

solemn marsh
#

yeah I'd love to go to defcon - need to convince my parents or move out before I can probably do that, but like, yeah dude

#

or get my actual license lmao

#

I only got a learners right now- been reluctant to get on the road and practice more often

lofty ibex
#

a full license is an amazing self investment that'll stick for the majority of your life, unless you lose it somehow

worn spire
solemn marsh
#

yeah dude- I mean, it sounds great; I just often think of that one hand-slip where I go into the other lane, and it keeps me on-alert 1000% of the time I'm behind the wheel

lofty ibex
#

I think everyone starts with similar fears but once you start going out fairly frequently it rapidly disappears πŸ˜„

solemn marsh
#

It may be an irrational fear, but man, there's some things I just NEED to get over.

#

Hopefully time will get rid of that daunting thought πŸ˜‚

#

I'm 20, for reference-

#

I also don't feel like there's an immediate need for my license b/c everything's at home/accessible for me right now, but I mean, thinking ahead, it might not always be that way.

#

But yeah dude, you and Moose raise completely valid points- I really appreciate you taking the time to chat; it means the world. I get frustrated at resumes and business related things that seem so subjective sometimes, but man, it's nothing personal. Thanks for sticking through haha.

lofty ibex
#

Aye we've all been there! It's part of the reason we help out πŸ˜„

solemn marsh
#

πŸ˜‰ dude it seriously goes such a long way. I was never taught how to develop a resume in high school until I got to junior year, and even then, it was a very VERY basic resume. School doesn't teach you the important stuff it seems. ;/

#

So here I am now, sophomore in college, looking to get my foot in the door, going for an associates, should finish sometime next year, and I'm having to adapt so quickly to this new world of adulthood where everything is fastpaced, professional atmosphere, etc., I mean, thank God I have some business experience with clients and my own endeavors, otherwise, I'd be completely lost.

warm hinge
#

What is the next certificate to go for after the Sec+ if you're interested in the Pentesting side of CyberSec?

#

Pentest+, CEH, or OSCP?

undone shore
#

Well you can knock CEH right off that list unless you're in India or want to work for the American DoD

#

It's useless, and the company who offer it are deplorable

#

OSCP arguably has the best value of the three

warm hinge
#

Alrighty, cool

boreal zephyr
undone shore
#

They certainly did until very recently

#

Although they added one of the CompTIA ones as an equivalent a few months ago -- either Sec+ or PT+, can't remember.

#

So, yes, while it will still help with the DoD, you're better off with one of the others πŸ€·β€β™‚οΈ

boreal zephyr
#

Sec+ and CySa are both IAT approved for DOD, not sure about PT+, I am almost positive CEH is not. OSCP is def the way to go, but it is magnitutes more difficult than Pentest+

pseudo creek
#

my company does a lot of gov contracts, any position that does anything with the Gov lists CEH as a 'highly desired' cert. I don't know about gov jobs directly but I do see that in our job listings

#

there are also a few people in Certification station who do work for/with the gov and have said they were told they had to get CEH so...

boreal zephyr
#

CEH covers CSSP only under the 8570, so there is a small subset of people in that arena that need it but for the large majority of the CSWF it isn't desired or there is another more desirable cert like CySA or Pentest+. Basically, if you want to work for the govt as a contractor or civilian, the 8570 is your reference point for what cert(s) you will need

pseudo creek
#

of course but that doesn't also mean that they won't ask for or expect CEH

boreal zephyr
pseudo creek
#

and I'm saying that CEH can be a HR filter and potentially even a hiring manager filter

#

8570 is why 90% of our Cyber folks have CISSP

#

regardless if they work gov contracts or not

boreal zephyr
#

Again, not disagreeing with you. Its also why im working CISSP right now. Some orgs will want CEH, most won't; its as much of an HR filter as any other cert. The 8570 is just a baseline, orgs can pick and choose which certs they want to look for.

pseudo creek
#

you can still say most won't want it and I'll disagree with you on that because I see it so much in our job listings and have heard from others who work in other companies

#

but overall, the best way to figure out what you need for the job you want is find those job listings, see what they ask for and target that

boreal zephyr
#

In your small corner of the DOD that may be true, in my small corner it isn't. The DOD is massive, and it really depends on the job. In all of the CSWF, CSSP is a very small subset of the work force.

pseudo creek
#

I'll say we aren't a small corner but... thats neither here nor there. The fundamental reason that it doesn't matter if its a garbage cert is the fact that people don't like studying for certs / taking certs as a general rule. And the value of a cert comes with if hiring managers are placing value on it and they often solicit input from their teams. And as long as people who have the CEH are part of the process, they are going to say the cert has value. Because honestly, who is going to tell their management 'yeah that cert you sent me to a class for & is one of the few certs I have, it is garbage'. Because people generally aren't going to devalue certs they have. It is why when my company has multiple bootcamps per year to get dozens of people CEH certified, I just close my mouth. I also have similar feelings about CISSP (when I took it, it was very very gov centric, had nothing to do with my job at the time or the many years since I took it but... its value won't lessen anytime soon)

#

although ISC2 isn't a trash company like EC-council so there is a slight difference

boreal zephyr
#

I completely agree. It is one of the major problems with standarization of the workforce, you tend to get the lowest common denominator which end up being certs like CEH and CISSP. While I think CISSP is a worthwhile cert, there is no doubt that it is a mile wide but only an inch deep.

pseudo creek
#

I think studying for CISSP provides you with a baseline as the topics are so great but who knows, the test may be different now, it’s been 15 years since I took it

paper grove
#

@pseudo creek and @boreal zephyr thank you for sharing. I'm in a similar boat as Jun and your experience sharing has been helpful.

serene umbraBOT
#

Gave +1 Rep to @pseudo creek

thorn owl
#

Starting from scratch in Cyber Security- going through some formal training for Security Plus and CEH. Expanded role in my job, and this type of content is new to me. Fascinating and Mortifying all at the same time. Trying not to be overwhelmed by sheer amount of content. Learning all I can as fast as I can due to ever increasing threats. Will follow this thread to learn what I can learn.

forest knoll
golden ore
#

Pentest+ is a good replacement for the CEH if it not required where you are as a base level cert

thorn owl
#

πŸ‘

golden ore
#

also if you do the Pentest+ path you can get a discount on the test

fair cypress
fair cypress
pseudo creek
#

Although not helpful for entry level, Security+ seems solid for that

fair cypress
#

I usually see people get Sec+ first then go for CISSP. Sec+ will get you in the door, CISSP will get you promoted.

peak steeple
#

Should I go CISSP or CCSP if I want to my Cloud my domain? Some day I need CISSP before CCSP and others say I can do it alone.

fair cypress
peak steeple
#

I might need both and start of with Associate of ISC and pray the expericne requirments overlap. CISSP for my pentest side and CCSP for my Cloud.

flat sedge
#

CISSP is not a pentest cert. It's a security management cert; it's helpful to understand the business perspective on tech and security, but honestly, it doesn't translate much value into a pentest aside from risk awareness

peak steeple
#

@flat sedge I assumed that while it covers the management side - the domains crossed paths with network/Infrastructure security as I have seen any pentest jobs requiring testers to have them .

warm hinge
#

It would validate that you have knowledge of those domains but I am not sure if it is the best cert to learn about those domains @peak steeple

peak steeple
serene umbraBOT
#

Gave +1 Rep to @midnight wasp

near locust
#

Hi
Question about career
I am a non-US citizen who is currently in the US working on a H-1B visa. I have 3 years of experience mainly in software development around the web backend(some frontend as well). Have negligible experience with cybersecurity(outside TryHackMe and CTFs). I am interested in security(pentesting), but there are some points people tell me that are stopping me from going full on into the field:

  1. Pentesting is not a 9-to-5 job, and it is much more stressful than software development in general. (I prefer 9-to-5 with exceptions only sometimes)
  2. My experience is not in pentesting, so even if I get a cert, it will land me in a role that will likely be junior, and its basically like resetting my career and losing my experience.
  3. Since role is likely to be junior, I am going to definitely suffer a significant pay cut.
    Can someone please give some advice on this?
languid hearth
# near locust Hi Question about career I am a non-US citizen who is currently in the US workin...
  1. It purely depends on the company. A lot of pentesters are salary over hourly. I've worked both and much prefer salary. You tend to have a fair amount of downtime and keeping track of your hours can be a bitch.
  2. Not true. You will still have experience that's valuable. Since you were a developer, I'd look at AppSec pentesting specifically. Apply for anything that pertains to white box code reviews. You might shine there. Remember, getting a certification won't necessarily get you the job, it'll just increase the interview amount. What you know will get you the job.
  3. Pentesting isn't an entry level field so you shouldn't expect an entry level salary. 70,000 USD is generally a safe starting number to assume no matter the location/position.
near locust
serene umbraBOT
#

Gave +1 Rep to @languid hearth

molten minnow
#

Is it worth contacting a recruiter in the UK to get him to find you a job?

#

I am SOC analyst in Greece and looking to move to the UK and target similar roles but I'm not dure how to go about it

#

With the whole brexit sitation

peak steeple
#

@molten minnow You have everthing to gain by contacting recruiters or going to Cyber security expos where you can mingle and talk directly to lots of companies. Brexit is a pain and making my dream of working in Spain harder by the second. Where there is a will - there is away. Also make contacts of Linkedin and they might throw in some pointers in the right direction. Dont let Brexit put you off πŸ™‚

solemn marsh
#

LIke, continuing to re-certify?

boreal zephyr
#

Yep, just means you recertify when it expires

#

You have to obtain a certain number of CE credits in order to be able to recertify. You can obtain them through courses that offer CE credit which apply to the cert

solemn marsh
#

Ohh I gotcha

#

ohhh

#

That makes sense

#

lmao CEH is such a joke

boreal zephyr
#

There are certainly better certs out there.

solemn marsh
#

OSCP seems tough but after getting Sec+ and an entry level IT job, it will probably be the route I'd love to head for

boreal zephyr
#

It is extremely challenging. I took PWK just to get a sense of things and I felt very overwhelmed. This was back in 2017 and I've learned a lot since then, but still. It isn't something you just jump into. I'd explore and complete everything THM and HTB have to offer before challenging the OSCP.

solemn marsh
#

yeahhh

#

I was thinking that actually- complete offensive path in THM, get comfortable with everything, and then move over to HTB perhaps,

#

but I mean, OSCP is like, a HUGE goal of mine, so it's definitely not something for the light hearted, so I've heard. 24 hour exam in a live box; sounds tough.

boreal zephyr
#

Several boxes. Lots of boxes. The documentation alone is daunting. Its one thing to be able to penetrate, but also having to be extremely diligent in recording your actions and methodology adds an extra layer of complexity. Once you get your foot in the door somewhere, I would definitely save up for the PWK or ask your company to pay for it. They give you tons of resources and videos to learn from and cover a wide variety of topics. Its expensive, but worth every penny if your serious.

solemn marsh
#

Oh yeah- I TOTALLY agree with everything you said

fair cypress
pseudo creek
solemn marsh
#

Technically speaking, is helpdesk a good "first-stop" for getting my foot in the door with IT? End goal would be a pentester, but I'd love to get as close as I can as a first job. I think helpdesk would be starting very low, but the benefit would be that I'm in IT - I really just want to get to that end goal and want to make sure help desk would begin that path.

near locust
boreal zephyr
solemn marsh
#

perhaps a SOC?

boreal zephyr
#

Yep, try and get that entry-level SOC analyst position.

solemn marsh
#

even without no prior experience?

#

I guess my issue would be, my goal is to get a sec+ cert by November

#

and well, until I get that, I wanted to get an internship somewhere for next semester

#

i mean, you think balancing school and an internship would be complicated? I could just skip that idea and gun it hard for a sec+ and get into a sec position; that would be closer to what I want to do

boreal zephyr
#

From my experience, a Sec+ cert, with some of the other things we discussed the other day (portfolio,blog,etc) will get you an interview. From there, its all on your ability to wow the interviewer

solemn marsh
#

Yeah- I think I could do that pretty well as long as I get into the interview. I think from now until november, if I start a blog, make it consistent - find some projects to work on, build a home lab with active directory, get hands-on experience with some of the tools in the business world, it will show my amibition and dedication to learn, and I think that's what employers are really looking for, at least, with my currently knowledge, that is

boreal zephyr
#

You got it, thats a good plan.

solemn marsh
#

Yeah - I feel like help desk would be good experience, but I don't really want to start at the very bottom, you feel me?

#

I mean, it's still going to be useful knowledge, but I mean

#

I'm trying to shoot as close as I can for the end goal which is OSCP + pentesting, and if SOC will get me closer than help desk and it's still possible, that's what I'd like to do honestly

#

SOC sounds a lot more exciting than helpdesk password resets, troubleshooting, etc.,

boreal zephyr
#

Lots of people start at help desk, there is nothing wrong it, you may even want to apply for both and take what you can get.

solemn marsh
#

Yeah that's also a good idea-

#

My mom has been in help desk for a while, so maybe she could help reference me; I've got an update from my digital applications teacher and he said he can work on a reference letter btw, and he was excited to see my email

#

so that's really a plus

#

haven't heard from the other teacher yet - the cyber teacher seems to mved like I mentioend earlier, so I'm not sure if I'll be able to reach him

#

but these teachers are very eager

boreal zephyr
#

Right on, I'm glad to hear thats working out for you. I would keep your references professional/academic, using your mom as a reference would look....bad.

solemn marsh
boreal zephyr
#

but she might know where there is an opening and help you get an interview, thats typically okay as long as you wouldn't work directly for her (nepotism)

solemn marsh
#

oh yeah- I'm pretty sure she's said something like that also

#

in her department would be so weird

#

@boreal zephyr So do you think this is an improvement? Should I put some soft-skills back on the list? I replaced them to make room for hard skills

#

I guess this is more catered to a help desk job, so I'd want to change some of the skills for a SOC

#

or perhaps a resume for each one

#

so this could be a help desk resume, and then I could have a different one for an entry level soc

boreal zephyr
#

Its definitely better, I usually lump education and training into one category, it reads a little easier that way, but otherwise its a marked improvement

#

Are you shooting for a one-page resume?

solemn marsh
#

Yes- really want it to be 1 page

boreal zephyr
#

I think it could use some formatting, I'd put experience at the top, followed by skills, then education & training, and add the certifications under that section instead of having an "additional information"

#

Lastly, I wouldn't mention Sec+ on your resume until you actually have it. You could mention that your studying for it in a cover letter

#

I never put soft skills on a resume, people can usually tell if you have them or not when they speak to you. Thats what the first interview is for. There is not hard and fast rule against it, its just how I've always viewed it.

solemn marsh
#

Ahhh I see

#

Man, you raise some extremely useful and valid points

boreal zephyr
#

I've been around the block πŸ˜›

solemn marsh
#

I'm definitely going to consider restructuring it to combine training and education.

#

And yeah dude- I'm so glad people like you who've ACTUALLY BEEN IN THE FIELD can help

#

it means the world

boreal zephyr
#

Happy to help, I wish I had someone to guide me when I was just starting out. Its my little opportunity to give back.

solemn marsh
#

so something like this right?

solemn marsh
boreal zephyr
#

That is a good looking resume!

solemn marsh
#

You think that's it?!

#

LETS GOO

boreal zephyr
#

Move your name to the left margin and your good to go

#

or the center, but the right side is strange

solemn marsh
#

and contact?

#

I think center would look good

boreal zephyr
#

yeah and contact

solemn marsh
#

mg that is sexy

#

in the middle

boreal zephyr
#

There you go. Thats rock solid

solemn marsh
#

Hell yeah

#

You're the best bro

#

I owe you

boreal zephyr
#

nah just pay if forward when the time comes πŸ™‚

#

Plus, you did all the work, I just made suggestions.

solemn marsh
#

πŸ˜‰ I will definitely man. It's always so cool to meet people in the field you're interested in

#

XDD yeah dude, your suggestions are rock-solid

boreal zephyr
#

Good luck on the job search! Let me know if get an interview; Do you know about Dice?

golden prawn
#

Hi All
i've had almos 5 years as an IT Techinician and i know about hardware and software.
i want to be an ethical hacker bum i'm drowning wether i should start with learning coding or learn the operating system or learn networking everybody is saying something and i'm just truly lost
keep in mind i live in the middle east and i dont have a lot of budget.
Thanks i appreciate it.

languid hearth
golden prawn
serene umbraBOT
#

Gave +1 Rep to @languid hearth

languid hearth
#

learn the fundamentals of networking

  • Routing
  • Switching
  • Subnetting
  • VLANs
golden prawn
#

thank u very much u have been great help.

flat sedge
blissful raft
#

Hey everyone, hopefully this is the right channel for this. I'm sure someone has already asked about how to get into security roles, but here's my thing:
I've been a cloud engineer and am now in devops, and I've got some security certs (sec+, aws sec specialtly, ccna cyberops), but I've sifted through sites like Indeed and literally everything I saw that's cyber security related wants the candidates to have cyber sec experience. How can I get experience? Is there some small part time or temp role out there that I can use to get my foot in the door? Is that what it takes?

boreal zephyr
#

@blissful raft You have sec+ and ccna?

blissful raft
#

yes

boreal zephyr
#

And OJT cloud engineer experience?

#

OJT being on-the-job experience

#

and are currently in devops?

blissful raft
#

yes to both

boreal zephyr
#

Okay, you don't need anything further. Your experience screams devsecops

#

What country are you in?

blissful raft
#

oh ok well that's refreshing lol

#

i'm in canada but i'm dual american/canadian

boreal zephyr
#

Do you want govt or private?

blissful raft
#

hmm maybe private? i'm not too familiar with govt jobs actually

boreal zephyr
#

Dice for private, if you can obtain a Secret clearance (no felonies, not a drug user) clearancejobs is a great place to find work

#

either or, you have a great background

#

I would suggest creating a profile on both sites, with the caveat that you can get a secret clearance

#

assuming you don't have the felony/drug issues.

blissful raft
#

awesome, thanks for the advice!
nope, no felonies or drug issues. I'll look into getting a secret clearance.

boreal zephyr
#

You can't just get one, but a company willing to hire you will be able to put you through the process. Edit: usual terms are ability to obtain a clearance within 6 months of hire

#

Are you willing to relocate in the US? I might know of a full-time opening in gov. DM me if your interested with a bit on your background, resume if your willing.

blissful raft
#

Ah I see. I suppose I could possibly relocate, depending on the right job. I'll DM you.

solemn marsh
serene umbraBOT
#

Gave +1 Rep to @boreal zephyr

solemn marsh
#

Does a clearance cost money?

languid hearth
languid hearth
#

I wonder if there's a geolocation block on google sites

solemn marsh
hazy sky
stoic cave
# solemn marsh Does a clearance cost money?

As Spooky mentioned, yes it costs money and no you cannot sponsor yourself. Even if you have the funds to sponsor yourself you're still not allowed to. If you wanted to get cleared many jobs will hire for the cleared position and will have you work an uncleared assignment until you have been cleared

pseudo creek
#

and in my company, they'll sponsor clearances for people who work uncleared jobs... 'just because'

stoic cave
#

You must me a citizen to get a clearance

#

They have a thing for non citizens though but I forget what it's called

distant pier
stoic cave
#

Yup that's it

paper grove
#

All good stuff. Does anyone have any suggestions on networking? I just sent a few LinkedIn connection requests to some "talent acquisition" roles at different companies. Is there another method that's better? I currently work as a Technical Support Engineer and have completed a cybersecurity bootcamp, plus Sec+ cert. I'm really interested in Blue Team roles.

polar rock
#

Twitter, discords, conferences, local meetups

fair cypress
# solemn marsh https://images.imdavidday.com/i/B2UiZRL9MuKPK3wK

I think it looks good overall. I would recommend getting rid of "I believe" replace with something like "I am confident" or just "my skill-set includes". For me "I believe" is not very confident, it is like saying "I think I have the skills you are looking for". I also recommend you put a estimated completion for the Sec+ course. Best of luck to you!

thorny cloak
stoic cave
#

Alumni are a great source of information. Don't just message and say "hey gib job" either though. Message and say who you are, when you graduated from the institution, and then ask a question and also if they have a few minutes to chat over the phone

#

90% of the time they will be glad to help and then the other 10% will direct you to someone who you can talk to

flat sedge
paper grove
#

Thanks all. I'll try a bit of all of that.

quaint flare
boreal zephyr
#

It is essentially a background check that is done to determine if a person is suitable for access to classified information.

#

once adjudicated, you are given a "clearance" at whatever level it was initiated at, Public Sensitive, Secret, Top Secret, Top Secret/SCI, etc

stoic cave
quaint flare
#

what is it good for? govt jobs?

stoic cave
stoic cave
quaint flare
#

do you make more money?

stoic cave
#

Some private sector jobs require government clearances and a lot of gov jobs do

languid hearth
#

theoretically

stoic cave
languid hearth
#

you might be a secretary, but you also might handle sensitive documents all day

#

the guys who handle FOIA request likely have top secret

polar rock
#

its basically just yeah the government trusts you to not go and leak shit or do something stupid

stoic cave
#

Cyber Security + Clearance = $$$$$$

polar rock
#

fax

quaint flare
#

interesting

languid hearth
#

just remember, your salary will top out

quaint flare
#

i assume it's hard to get

stoic cave
#

And then having further developed skillets equals more money

languid hearth
#

there is a ceiling that won't allow you to go higher in the public sector

boreal zephyr
languid hearth
#

yep, and it might take you your whole career to get there

quaint flare
#

interesting, that is really cool

stoic cave
#

Yeah but then you get a fat Pension lol

boreal zephyr
#

Pension and TSP

stoic cave
#

Job security and a pension is really nice

#

Being a government employee does have its cons though

boreal zephyr
#

and some of the best healthcare available

stoic cave
#

Yep

quaint flare
fair cypress
#

+1 all of the above

stoic cave
#

Pay scale is set in stone

languid hearth
#

i will say having an annual bonus is incredibly nice

stoic cave
#

And it may be hard to transition around to interesting work

#

And with having a clearance even if your state nullifies something it's still applicable to you as a government employee

boreal zephyr
#

in other words no legal weed

stoic cave
#

For instance, I would like to try CBD as an alternative to ibuprofen but I can't because Marijuana and it's derivatives are a Schedule I drug

#

Which means loss of clearance and sometimes prison

quaint flare
#

you get tested i assume

languid hearth
#

yep

#

and asked about it

quaint flare
#

but you could always transition into private sector right?

stoic cave
#

Some people get tested some people dont

languid hearth
#

always assume you will

boreal zephyr
#

wouldnt matter, if you have a clearance, its a no go.

languid hearth
#

its never worth risking it

stoic cave
#

Fed still cares

quaint flare
#

like if i dont want to work for the govt anymore, i could just quit and go to private i mean

stoic cave
#

Right but you're still cleared

#

And a loss of clearance doesn't look good on a resume kekw

quaint flare
#

if you go to private sector you lose your clearance?

languid hearth
#

or you just transition to a company like Lockheed Martin

#

ezpz

#

you lose it the minute you're employed by someone who wont be utilizing it

stoic cave
#

You can have a clearance and still be private sector

#

You can make a boat load of money that way

#

Like a enterprise storage specialist that's cleared can easily pull $250k a year

quaint flare
stoic cave
#

A clearance is something that's given federally

#

If you leave the government, the clearance is still attached to you

quaint flare
#

are you saying in reference to the drugs

#

like you still have to get tested

stoic cave
#

You can also have a clearance and not work for the government