#cyber-and-careers

1 messages · Page 95 of 1

low osprey
#

What's up? I took it last month.

#

2 months ago

hard haven
#

I've been at it for 6 months, so I didn't expect that at all.

low osprey
# hard haven I've been at it for 6 months, so I didn't expect that at all.

Different from person to person. PT+ is the only cert exam I've ever failed, but I only prepped for 2 weeks and didn't have any labs. I was also doing 90% on the CertMaster Practice questions, so that apparently wasn't a good judge of my preparedness. Spent another 2 weeks studying before testing again and passed with a 795.

sly gyro
#

Passed it last weekend, some of the questions were tough

#

Don't put your faith into passing with just practice questions... It's gonna hit you in the face based off the questions they had

stoic cave
#

Dion usually has really good practice quizzes

#

Tougher than the actual exam in my opinion, this was for Sec+

low osprey
#

Yeah I used Dion between my failure and my pass. Probably helped me pass.

grim lion
#

Is it possible to become a security consultant from being a ethical hacker / pen tester with the CREST certifications think

light iron
#

Define Security consultant ? I would say Yes, though CREST is more Pentesting soo you might benefit from a breoader scope of cert like CISA/CISSP but juet depends on the exact role. You could of cours move up the lap from Pen testing to Consultant.

grim lion
#

and the pay seems nicer

#

and eventually when im older i could do it very part time if i just dont want to work alot

light iron
#

If you DONT want to work in Pentesting - you can easily bypass Pentest roles with Cyber sec certs: https://www.giac.org/certifications/ I am not saying take a GIAC cert but their roadmap should shed light on how to progress. Dont follow the herd and do Pentest certs if you dont plan to use them - life is too short.

#

Why not hit the job boards just to get an idea of the variety of certs Consultants need and go for the open thet best suits you. Just my thought.

grim lion
quick forum
#

CISSP fits in well there

grim lion
quick forum
#

CREST is only really good for CHECK

#

And remember there's CyberScheme and TigerScheme as alternatives

grim lion
#

im ngl im really confused what that line means

quick forum
#

Companies can put you through CHECK btw

grim lion
#

yeah its a one time thing tho isnt it, once you SC you SC for life or something

#

so i gotta find a company whilst im a pen tester who will put me thru

light iron
#

Not in the UK its not unless thing have changed - my friend has get his done ever 6 years

grim lion
#

oh damn

quick forum
grim lion
#

i just presumed like you would be good for life

light iron
#

But once in a company you're solid and getting SC is e much easier

static tide
#

you only have to do sc paperwork (which is a bitch) once

#

but you just resubmit every x years

grim lion
quick forum
#

Where abouts in the country are you, and how are your pentesting skills?

grim lion
quick forum
#

A few people here work for places that are hiring pentesters, that's all

grim lion
#

not given up quite yet monkazoom

light iron
#

Exactly! There's also CompTIA and Masters seems gaining steam ...

grim lion
#

i hope in 6 months i can sort my qualis out and stuff. like atleast get CPSA at a minimum

light iron
#

You re in right mind! Master all the THM skills and the rest will a walk in the park except maybe ISC2 certs

grim lion
#

yeah i plan on working hard on loads of THM and other related stuff for now, and when my life gets more predictable with free time. Signup for some course which i can then get my Crest certs from

quick forum
#

I know my company is hiring and will put you through an exam for CHECK Team Member

grim lion
#

omg we can be work buds FK and james.

quick forum
grim lion
quick forum
#

19 isn't going to be as much of a problem as 17, seeing as you can sign contracts from 18 properly

grim lion
#

ive only got a few months left of the title

#

which is really scary ngl

quick forum
#

FWIW I'm 20 and working in a pentest role

grim lion
#

but i really appreciate all of your help jake ninja and kitty aPES_Kiss

quick forum
static tide
#

we’re also hiring if you wanna dm freshie

warm hinge
light iron
#

If you re still a teenager - also remember things change fast in the Cyber world - so try to stay abreast of changes in technology....

quick forum
warm hinge
#

awwww

quick forum
warm hinge
#

Will keep on looking then

#

thx

grim lion
#

this might sound like a silly question, but were u not scared moving onto 20

quick forum
#

No, same old same old

grim lion
#

fair play man

light iron
#

Does THM tale vounteers so you dont have to pay us - we just want the experience?

quick forum
#

Not hiring for THM

quick forum
grim lion
#

i shall DM you both jake and ninja but i presume i dont fit the bill but i would really gain alot from the information ❤️ if thats alright

warm hinge
quick forum
#

Dark has a tutorial somewhere

sour pike
#

to create a room is still on my bucket list

#

i saw some remote jobs on crowdstrike, but i dont got any idea what company that is and no experience with remote jobs

warm hinge
edgy tiger
#

Just be "out" there and connect and talk to a lot of different people

#

Also making sure you "give back" to the community will open tons of doors

sour pike
#

totally agree

#

thanks @edgy tiger

serene umbraBOT
#

Gave +1 Rep to @edgy tiger

warm hinge
#

Question: on LinkedIn, you can input a certification ID. THM certs have one but I can't seem to find a use for it on the THM website - like a tool to verify that a cert has actually been delivered to x. Is there such a thing?

sour pike
#

idk maybe with acclaim?

warm hinge
#

😬

#

That's kinda not great for privacy

#

Until THM exposes some sort of API (or codes to validate like AWS does)....I see it kinda hard to prove you actually did something in a way different than what I suggest :/

stoic cave
#

Certificates are given upon completion of a task but don't actually certify knowledge of the material

#

Certification leads to professional accreditation

faint ice
#

probably because of this certifications has to be renewed???

stoic cave
#

Also if your using LinkedIn your real name is going to be out there. Not sure why your name being on the certificate would be cause for concern

light iron
#

Cant I put 'Certified by TryHackMe in . XYZ' on Linkedin?

stoic cave
#

No, I wouldn't

#

It's a certificate of completion

#

Not an accreditation by THM

#

Idk if im using the words right

#

THM is an extracurricular

light iron
#

Even for the Paid labs - throwback and Wreath ?

stoic cave
#

I haven't done those but I'd still say no

#

It's an extra activity, like HTB

light iron
#

Thanks for saving my bacon @stoic cave I was just about to ....

serene umbraBOT
#

Gave +1 Rep to @stoic cave

warm hinge
light iron
#

Back to studying .....

stoic cave
#

Sec+ is a certification and professionally recognized, which is why it belongs on the resume/LinkedIn in a main section

stoic cave
#

Something like "Great material and very informative" and attach an image of the certificate

#

Shows your learning on your own but not trying to pass it off as professional experience

warm hinge
#

That's the best option imo. Forgot completely about posting it. You leave some sort of proof you did it.

flat sedge
#

In the best case, THM certificates of completion may be accepted as CE credits to maintain your existing certifications.

#

An existing certification is usually only worthwhile to list on a resume or CV if you had to sit a proctored exam.

wet meadow
#

If anyone has worked for Mandiant, or currently works there, how do you like working there? What is the culture like working there? Specifically for the Advanced Analysis Team or Security Analyst positions, is the job and Mandiant culture rewarding and positive job satisfaction? I am waiting to hear back on whether I will get an interview or not. Mandiant has been my dream company and job roles for a long time, and I'd like to get some feedback on them and if it is as cool as I think it is!

warm hinge
#

@wet meadow connect with Zander Work on linkden https://www.linkedin.com/in/zanderwork. Hes super friendly and works cybercrime unit in the threat intel department. Just connect with him, send him a friendly message first, get his discord tag, have a convo with him and then u can ask him what the culture is like.

wet meadow
#

@warm hinge Awesome, thank you so much!

serene umbraBOT
#

Gave +1 Rep to @fleet surge

stoic cave
#

Wouldn't necessarily recommend cold messaging someone but that's just me

#

Especially if you have zero connection with that person such as same Alma Mater, former Employer, etc

#

Mandant is a well known company. I'm sure there are plenty of interviews in both video and written format available for your consumption

warm hinge
#

Well thats why I said connect with him with a friendly message attached before even engaging in a full on convo or asking a question off the bat. Plus you use linkden to network and connect with others anyways, so its not a total cold message. What else is he supposed to do

stoic cave
#

That's the definition of a cold message. Sending a message to someone who you have zero in roads with.

#

I provided alternatives in the message above

#

I believe Darknet Diaries has also interviewed people who have worked or are currently working at Mandiant as well

warm hinge
#

So if ur someone i want to connect with, and i want to connect and send u a message attached, i can never do that because i dont have any roads with u but im trying to start one road with u

stoic cave
#

I'm sure others will weigh in, but in all honesty I would probably deny the request. I don't know you, don't have any mutual connections, etc

warm hinge
#

Okay, fair, its ur choice in the end. But the mutual connections can literally be that one person is an influencer in the community lets say and accepted both. But im guessing ur saying it has to be a close mutual to then consider it

stoic cave
#

Looking at all of their profiles, none of it screams influencer to me. The person working at insert popular company doesn't automatically make them an influencer

warm hinge
#

Okay content creator

#

I just wanted to know what mutual connection meant in your head. Thats all

stoic cave
#

Yup that's fine. All I'm trying to get across is that it'd not necessarily cool to just message people and request a connection. Their response may be friendly but in reality they may not like it. LinkedIn is a professional platform and people talk. If they are rude word may get around especially if they are working at a well known company

warm hinge
#

As I see it: In case its a +3rd connection and the person I'm trying to add to linkedin has no public exposure (Ie: Presented at a conference, wrote a book, taught a course, has a blog or something like that) I won't add them. Otherwise I send them a cold message telling them how I came across their profile. That's how I see it at least. I mean...I've presented at a small conf and I've been sent requests from +3rd connections. I then look at their profile and decide whether to add or not.

strange junco
#

hi guys, i work for a small start-up company as the only IT person and my big mouth suggested a pentest cos we have had breaches on our websites and servers (we had to change our domain hosting provider as a result) and everyone just kinda glossed over it after the change and igot the site running again. then i started thm on the jr pentest path now i'm full on paranoid of what might have been leaked when i haven't even finished the jr pentest path 😫 . now i'm getting gittery, and not sure of myself

#

any tips will be appreciated cri

warm hinge
# strange junco hi guys, i work for a small start-up company as the only IT person and my big mo...

First of all, have everything in mail mmmmkay? IF they don't want to run the external pentest, have them reject it via mail. If you warn them about the consequences, do so via mail. Leave a trail of everything. That's rule #1. Something happens tomorrow they might try to blame it on you and have an excuse to fire you or sue you for any loss when in reality you were doing an excellent job. Words have no weight remember that.

Second, that place is now a time bomb. I don't really know your situation and if you can afford the extra stress it brings, but I would start searching a new job asap. Somewhere else where they at least pay attention to security and best practices.

Third, it's not your responsibility to carry out the aforementioned pentest or vuln analysis on your site. You don't have a reason to doubt yourself and your skills. If you really worry about the security and want do something in the meantime, check out the hardening basics rooms (part 1 & 2).

quick forum
#

Someone should be the named person in charge of security

strange junco
serene umbraBOT
#

Gave +1 Rep to @twilit arrow

strange junco
warm hinge
#

yeah really if they're at that stage, being small and not caring at all about security....not a nice sign

quick forum
#

Someone needs to write policy documents and handle security

warm hinge
#

(in the same way GDPR states you gotta have a data protection officer)

quick forum
#

I'm ignoring any legal stuff because I don't know it and I don't know where they are

warm hinge
strange junco
strange junco
#

we're based in the czech republic, might have to research the laws

strange junco
serene umbraBOT
#

Gave +1 Rep to @quick forum

stuck rover
quick forum
stuck rover
quick forum
#

We have a board, we have someone who writes and signs policy

stuck rover
#

Suddenly that makes him qualified to handle everything

ebon mica
#

How reliable do you think the salary figures in glassdoor etc are?

stoic cave
#

Honestly no idea

#

I try to look around at multiple sites and then average them

pseudo creek
#

I don't think they are all that reliable because they work on averages

ebon mica
#

I'm not looking for exact figures, just trying to gauge a bit.

pseudo creek
#

when I was a junior, I thought the listed numbers were high now as a more senior person, the amounts look low

ebon mica
#

Even considering roles and levels within a specific company and location?

pseudo creek
#

well often they don't have levels

ebon mica
#

That data would be mostly useless, I agree. It might help in comparing companies, but not much else.

#

Then again, if a company has listed e.g. SWE, Senior SWE and Staff SWE, that's likely more reliable. But do people post real data there? 🙂

pseudo creek
#

depends, people may inflate

jaunty heart
#

Guys I'm looking for remote internship Or a job in Cybersecurity.
I'm Certified
1-CEH Master
2-CASP+
3-Pentest+
4-CCNP Enterprise
5-Certified Burpsuite Practitioner

Please help.

pseudo creek
#

you also didn't say where you are located

jaunty heart
#

I'm from Afghanistan, I migrated to Tajikistan country with my family 4 months ago due to war in Afghanistan.

#

@pseudo creek I also have a bachelors degree in information technology. And I have one year of official work experience and 3 yrs of teaching (Networking and Cybersecurity).

#

No one looks at my resume or replies when I mentioned I'm from Afghanistan 😥

pseudo creek
#

that is a lot of PII, I'd suggest scrub it if you want feedback, if you aren't on LinkedIn, get on it

jaunty heart
#

I'm on linked for more than 2 years.
Honestly I'm so frustrated. I applied for 100s of job postings but heard nothing. That's why I shared my resume without scrubing it to prove its not fake.

#

Thanks for the feedback, I wanted to blur PII, but 😓

#

Here is my resume.
Looking for intern or entry level job in Cybersecurity/IT

#

I'm sorry if this isn't the right place to comment my resume.
Apologies.

stoic cave
#

Couple of things off the bat, in Education, if you have a degree you don't need to put high school. Second, you don't need the images of the certs, it makes it cluttered. Third, the resume is rather long with too much white space. I also wouldn't necessarily put twitter links in the community involvement section. If it was a talk I would put a link directly to where the talk is hosted

#

Faces on resumes can also go either way and you also dont need that paragraph next to it. That's what a cover letter is for

flat sedge
#

I agree with Moose, @jaunty heart . Put in the cert ID# and a link to verify instead

stoic cave
#

Special Projects and CTFs can also be a single section under Extracurricular

lusty peak
#

Not sure if I’m wrong but most companies would rather have 1 page vs 2 page resumes

stoic cave
#

Also there may be a typo on iTex, not sure how you can work into the future

#

if you're still working there, I definitely wouldnt do that

stoic cave
#

the second is that HR sits and reads resumes all day. If you give them one thats nicely formatted and concise its going to go a long way

jaunty heart
#

@stoic cave
Thank you for your feedbacks.
I really appreciate it. I will definitely consider those points.
Regarding certs images. I watched John Hammond video, he suggested certs images will make your resume to be notified .https://youtu.be/ZAt8MM8WG0o

serene umbraBOT
#

Gave +1 Rep to @stoic cave

stoic cave
#

Going to have to disagree

#

I would be fine with it if it was a resume on a webpage

jaunty heart
stoic cave
#

but on paper id try to keep it neat and concise

stoic cave
#

its free and easy to use

jaunty heart
#

@flat sedge
Noted i will definitely add cert ID.

flat sedge
#

LaTeX is non trivial for most people

#

There are some pretty reasonable markdown templates out there

#

The nice thing about storing your resume or CV as a flat file is it becomes very easy to comment out sections that aren't relevant for a specific role

jaunty heart
#

this is how the company writes its name "iTex"

stoic cave
#

its how I have mine setup, this is just a redacted and old copy

stoic cave
ancient prairie
# jaunty heart Here is my resume. Looking for intern or entry level job in Cybersecurity/IT

piggybacking on moose's comments about overall structure:

  • I think the blurb next to your photo is fine, I have a similar one and have received feedback from hiring professionals specifically about that who says thats fine in lieu of a cover letter, I am however anti-photo for resumes
  • tear out the "competencies bit", roll it into "Special Projects", "CTF Involvement", and "Community involvement" , call the new section something like "Professional Development" or "Continuing Education" and stick it towards the end
  • remove the cert images
  • elaborate on classes taken at uni
stoic cave
#

I think all of that is good except the last one. I think listing the classes is fine but describing them could get cluttered

flat sedge
#

Making your coursework relevant and including something like a home lab can be huge for an employer

#

because it shows you aren't starting from zero for their needs, you have some background already

#

Moose is outvoted, keep the coursework 🙂

stoic cave
#

I might be talking about a different thing

ancient prairie
#

dont have to list everything

stoic cave
#

mine has both a course list and then one course that I went in depth about

ancient prairie
#

above 3.5 GPA is notable enough too if applicable

stoic cave
#

I thought we were talking about taking a course list and expanding on everything

#

if its just choose one, i agree with that

#

Also, you can list In-Major if its considerably higher than the total

#

I had to do that because of Biology

jaunty heart
#

Thank you guys for your amazing feedbacks. I really love it. I will definitely consider all these.

heady axle
#

Hello guys and girls. I have a bachelors degree in digital forensics and cybersecurity but I’m struggling to find a job as I do not have any relevant experience. I am currently working as a data center engineer and I want to switch to something a bit more close to my degree. I was thinking to try and get the CompTia pen test+ certificate as a booster but I wanted to hear some comments or advice about my plans.

stoic cave
#

Do you have Security+

#

if not, I would do that one first

sour pike
#

depend on what job you wanna get

heady axle
#

Unfortunately I do not have any certifications. Is cecurity+ be more beneficial than pentest+ in general? @sour pike
@stoic cave

stoic cave
#

Pentest+ is more designed for those who want to get into Pentesting and that line of work

sour pike
#

all certificates will benefit , but only get a certificate if your future job needs one

flat sedge
#

pentest+ is more specific to pentest activities, security+ is more of an overview of security as a whole. Take a survey of jobs you want and target your cert learning to that.

stoic cave
#

Security+ is an entry cert for the Cyber Security field

heady axle
sour pike
#

than start training yourself with the pre-security path of THM first

heady axle
sour pike
#

sounds like a good start

heady axle
heady axle
quick forum
#

Are you UK?

#

What country?

sour pike
#

you definitly need more training

heady axle
quick forum
#

Country dictates certs

sour pike
#

dont agree Ninja

quick forum
#

That degree combination seems familiar to me lol, I graduate in July

heady axle
sour pike
#

your new job dictates certs

quick forum
# sour pike dont agree Ninja

Then you're allowed to be wrong.
UK pentest roles often want CHECK certified people. That's Security Clearance and a CREST, TigerScheme, or CyberScheme team member cert.

quick forum
sour pike
#

depends on what job you want to get

#

can be different , different companies ask for different jobs

#

eh certs

#

so check out first your new potential job , look at what certs they ask

heady axle
#

Most of the ads I see do not specify any certificate requirements but they all want some experience…

quick forum
#

@heady axle How are your pentest skills? Which end of the country are you?
My company is hiring pentesters down south. No experience although your DC work would probably benefit you, only skills required

#

Pentesting doesn't tend to be an entry level field. A lot of people go through SOC analyst roles for a year first

heady axle
quick forum
#

Keep me in mind then, we're south coast

#

You can DM me for more info, just mention it's about the job role

#

There's at least one other person here scouting for pentesters in the UK too

heady axle
quick forum
#

This is very good stuff to cover in a CV/interview too

heady axle
quick forum
#

If you're confident with medium rated THM boxes, I bet you'd do fine

heady axle
# quick forum If you're confident with medium rated THM boxes, I bet you'd do fine

The thing is most recruiters don’t really care about CTF experience because there are walkthroughs so anyone can pass them and earn the badge. But I started using THM as a learning platform to work on my penetration testing skills. So hopefully by the summer I’d have some certifications and the required skills to start looking for a penetration testing role

quick forum
#

I'm talking specifically about the apprentice type roles we're hiring for here

boreal ermine
#

as a complete beginner in the IT and InfoSec fields, what subjects / learning pathways should i go down to start and what certifications should i aim for

stable delta
# boreal ermine as a complete beginner in the IT and InfoSec fields, what subjects / learning pa...

Hello! So I am practically in the same position as yourself, very little knowledge of IT and wanting to get in to infosec. I was suggested to go for sec+ to get in to infosec, however, if you're anything like me and want to learn about computers first, then A+ is a good place to start and then take it from there. Also if you want to also learn ethical hacking then pre-security pathway on THM is pretty awesome and then follow with the complete beginners path. Good luck in your journey and welcome to cyber security 😄

warm hinge
#

@boreal ermine thats up to u. None of us can tell you what area in cyber to begin in. U just have to mess around with a little bit of red team stuff and a little bit of blue team stuff and that will give you a more clearer path as to what area u like the most. The most common example is web exploitation. If u do the rooms on thm or learn on portswigger and get ur hands on practice in to apply what ur learning and it excites u, motivates u to want to learn more and go the extra mile to become better, then focus on web app exploitation and everything that accompanies it

hazy tree
warm hinge
#

I definitely can't afford to work a help desk job

drifting radish
#

So you highly recommand paying and using comptia certification ?
An old 30 years old french in retraining here

pseudo creek
#

yes, net+, sec+ are good ones

pseudo creek
# warm hinge I definitely can't afford to work a help desk job

I don't know where you are at, but in the US, help desk jobs vary widely and some with very good pay ($70k). On the flip side, if you work it, network well, you may be able to get job like jr sys admin, network admin or soc analyst, but again those pays would be similar.

hoary wind
hoary wind
#

i need to go out from italy

warm hinge
#

Currently I make 120k but I hate my job

pseudo creek
#

is your current job in IT?

hoary wind
pseudo creek
#

notice top 3 certs are most boring certs ever...

#

also certs that more senior cyber people would have

hoary wind
#

Idk why OSCP is bad like that

#

😮

#

Impressed

pseudo creek
#

because pentester / red team jobs are fewer than other cyber jobs

warm hinge
native elm
#

Hard to compare anything to USA

hoary wind
#

yeah my friend soc analyst take about 18k

pseudo creek
# warm hinge No

then I'd say you are going to have to take a drop in salary to move to a cyber / IT job, there is one guy on TCM's server who busted his butt and was able to get $100k as an entry level pentester, he sent out hundreds of applications, networked, built up skills, etc

grave turtle
#

sure, but living in romania is way cheaper than living in more developed countries like the USA

pseudo creek
#

yeah and we basically have 0 social safety net

warm hinge
grave turtle
#

I'm also romanian, but i'm only 16 so i don't have to worry about taxes yet ))

#

unfortunately

warm hinge
#

Ouch

strange junco
#

hello everyone, I don't have any certs yet and I want to start taking certifications as a pentester and i'm torn between the INE eJPT and Comptia Pentest+ . Also I got a discount for A+ but i'm not sure if it will be relevant to a career in cyber and infoSec so I didn't take it yet. for entry level purposes which should i start with?

languid hearth
#

do some research on LinkedIn, Indeed, or other places and see what the most requested certifications are for the job you want

serene umbraBOT
#

Gave +1 Rep to @languid hearth

drifting radish
serene umbraBOT
#

Gave +1 Rep to @pseudo creek

tranquil rampart
#

Hello everyone! I am pretty new to cyber sec. Just passed my MTA in security fundamentals. What cert should i be looking to learn/complete next?

#

Its not really comparable. I worked with a Chef in the UK from Romania. On poor UK wages he was able to buy land and build a house in Romania. Same wages here you would struggle to even rent in the UK

tranquil rampart
#

Bucharest. My point is more that afaik that wage is good for the country. Its the same reason as why people in the UK are payed more if they work in London as its down to the cost of living, house prices ect

#

ost of living in Romania is, on average, 48.51% lower than in United Kingdom.
Rent in Romania is, on average, 67.43% lower than in United Kingdom.

#

But you do have sick internet tbf

#

Would like to visit sometime. My friend spoke alot about how nice the Black sea area is

#

Yeah which also brings wages up, well hopefully that is

#

I wouldn't want to live and pay rent in london. might as well be a slave

#

Pretty much what the guy i worked with said. He only went back because of the house he built and his kids

#

Yeah that's fair enough and i would never begrudge anyone trying to better themselves or their families. Issue you will be just left with how do you guys put it. With people that do gypsy work lol

#

Hopefully it balances out in the end

#

I was told a Romanian term for "bad work" is gypsy work. l

#

as in doing a poor job

#

tbf he may of just not liked gypsies thinking about it lol

#

Nah i know they are different. I don't associate a Romanian as being a gypsy. Afaik they come from India a long time ago

#

Exactly what my friend said tbh

neon sequoia
strange junco
#

Hey anyone got insight into OTW on twitter? saw his profile and website. Just don’t know much about major players in cyber security

hazy tree
#

In a dilemma.. hiring manager is negotiating salary, no formal offer yet.. but I feel like he wants me to accept, say yes… I already asked for time to consider other options I have, that was 2 days ago.. they offered and I countered, so don’t even know if they met my request. And at this point I’m feeling pressured because I’m still interviewing at other places .

flat sedge
#

if there is no money on the table, you are under no obligation to accept

#

"I would like to accept, but you haven't sent me the employment contract yet"

#

that should both buy time and inform you the details for compensation and benefits

remote bluff
#

And upgrade your system, as needed

hoary wind
languid sequoia
#

hello everyone

austere ginkgo
#

Hey guys! Would a customer sales executive job be considered as an entry level job/helpdesk job in IT?

hoary wind
#

someone here have done burp suite practitioner exam?

strange junco
strange junco
hoary wind
warm hinge
languid hearth
#

okok kids

#

GRID or GREM

swift briar
#

hey guys just wanted to ask about cyber sec career and potential kind of things
just attended a workshop on ui/ux today the seniors were talking about how good prospects ui/ux has
and getting a good entry level job in cyber sec is harder
i researched a lot on these things in the past but after todays workshop couldnt help but ask

warm hinge
# swift briar hey guys just wanted to ask about cyber sec career and potential kind of things ...

look, not gonna lie...I have the same impression and even though it's purely anecdotical evidence, everytime I look up someone in Linkedin who's working in a UX/UI role...they have some degree that has nothing or veeery little to do with IT (Sociology/Law/Biz admin/Marketing) and they had a bootcamp under their belts which clearly got them the opportunity to get their current UX/UI job. Can't say I've seen the same with cybersecurity.

swift briar
polar rock
strange junco
swift briar
warm hinge
# swift briar <:psyDuck:861274247438532639>

I mean, I could have gone down the path of developing and earned fat stacks of cash (easily putting me in the %1 of my country. By far) but...I don't really like it. I enjoy programming but it's not what I want do for the rest of my days. On the other hand, I know that I'll get job offers and a decent salary for my skills if I keep on working in cybersecurity and it's something I enjoy 100%

#

so you have to take that into account. Perhaps you do an UX/UI bootcamp, get a well paid job and then find out it's not what you really wanted and it's not something you enjoy at all.

waxen plaza
#

Hello everyone. I recently connected on LinkedIn with a sales recruiter at my top choice for a cybersecurity company. The main commonality is attending the same college, and of course the interest in the industry. I have a pretty good idea of how to open the conversation more and network, but I'm wondering if there's a certain way I should approach it or something specific I should mention.

frozen flicker
#

@waxen plaza be upfront with your intentions and something that I love to lead with when looking to move into an organization is to say "Hey, what can i look into and learn right now to make a me working there integrate faster?" If the org uses specific tools or platforms while you might not have previous experience with it you can start looking into it. This communicates that not only do you want the job but you want to be apart of that team.

remote sedge
#

I want to ask,which cert is best for pen tester to get more practical hands on approach?

stuck rover
stuck rover
sour pike
#

whats PNPT?

undone shore
#

TCM's exam/cert

sour pike
#

TCM?

undone shore
#

TheCyberMentor

sour pike
#

ah ok, that one i heard before

remote sedge
undone shore
#

Nothing wrong with that 🤷‍♂️

#

OSCP was my first cert

sour pike
#

1st cert, is easy to get with certs from THM, ok not a macro cert, but at least a micro-cert

stuck rover
#

A lot of people do. It's just nowadays there are other options that people do first as a "warm up"

remote sedge
#

I want it to apply for jobs and also get proper,structured knowledge

quick forum
undone shore
#

Out of those two

quick forum
#

A certification has industry recognition, a certificate from THM really doesn't

undone shore
#

Ideally search for job descriptions in your local area and see what they want though

sour pike
remote sedge
#

Currently I am in india I also prefer oscp because of its practical element

quick forum
sour pike
quick forum
#

You're welcome to disagree, but they're not the same and you CANNOT lump them together. It's been covered here a million times

sour pike
#

every thing counts if you apply for a job, if you cannot appreciate the small you also cannot appreciate the big (its never good enough)

quick forum
warm hinge
#

@sour pike its not about the appreciation of the paper, the point is, certificate and certification are not the same

sour pike
#

i am not telling you that they are the same, i only tell you that everything counts to make a good impression to apply for a job (certifications, certificates, experience, even experience in playing CTF's or other extracurricular activities)

quick forum
#

For some crazy reason, employers seem to like CEH which is not a good cert

remote sedge
#

Last I remember they have diff exam 1 practical and 1 theory but not in one package ,if the structure is diff now correct me.

idle river
wet oasis
#

][;

hazy tree
#

Did an interview with a school district today 🤞🏼

inner elm
hoary wind
#

lol

#

but practical is useless i prefer to go for offensive sec

warm hinge
#

I am currently not working in cyber security but my job has a cyber security department. Would it be a good idea to get in touch with them about my interests or should I wait until I have security+

pseudo creek
#

sure wouldn't hurt

stable delta
warm hinge
#

Oh really? That's awesome

#

Maybe I should try it

remote sedge
#

I am also seeking out people in my country who are currently working in cyber sec

warm hinge
remote sedge
#

If you guys have a dept of cyber sec surely get in touch with them

stable delta
#

I'd also suggest networking wherever you can, here, other related servers, twitter, career's fair and linkedin. It is exhausting if you're not social butterfly but well worth it in the end as you have your go to people to help you out when you need it 🙂

remote sedge
#

@stable delta what you are doing currently with the cyber sec dept of your org?

stable delta
#

And also one of my friends works in that dept so he keeps in the loop of anything coming up

remote sedge
#

You got it mate slowly slowly you will get there even small improvements daily will pay off in long term keep it up! I also try the same approach if I have lots of thing to do but keep hacking as a habit.

stable delta
remote sedge
#

Currently I am in last year of my comp
Eng and learning to hack and want to get a cert to get my foot in the door in industry path similar to yours

stable delta
remote sedge
harsh imp
#

Hi everyone, we're (Fanatics) looking for an intern for the summer of 2022. Is this something anyone would be interested in? If so once we get the req approved I can post it on here.
The title would be Security Operations Analyst Intern and you'll be working in a SOC located in Jacksonville, FL.

stuck rover
sharp phoenix
#

Got one in indiana?

languid hearth
#

@urban sapphire might know some people in that area

urban sapphire
languid hearth
#

can't believe our resident Floridian doesn't know anyone in Jacksonville smh

pseudo creek
#

Florida is a long state, long way from south Florida to Jacksonville

#

I know someone in Orlando looking for Summer '22 internship but that still isn't going to help

cedar tree
tough spruce
#

So advice,

I got passed applying and got asked for a phone interview,
Okay sweet,
So the recruiter asked me to give my availability for the week okay sweet I did. Never heard from them. New week. I follow up. They ask if I’m available that day to talk I say yes. Okay they cancel ask if I’m available next day, I say yes. Never hear from them. Okay I follow up, they ask if I’m available and say confirmed they will call me at so and so time I say okay, never heard from them. ….

flat sedge
#

I'd email the recruiter and say that you aren't comfortable working with them due to their inconsistency and move on.

#

Was this dealing with a recruiter or corpo talent acquisition?

tough spruce
#

Recruiter

flat sedge
#

I'd ask if the company is cancelling, or if it's the recruiter playing schedule games.

#

If it's the recruiter, I'd ask for another contact at that agency. If it's the company, I'd tell the recruiter I'm not interested in working for a company so dysfunctional they can't host a meeting they asked for.

#

Not being able to confirm a time they asked for is a huge red flag for me

tough spruce
#

Bet. Ur right

#

Thanks

pseudo creek
#

yup

austere ginkgo
#

Hey everyone! How do you write a resume for an entry level job in IT especially if you don't have an IT/CS bachelor's degree or experience (but you do have a few projects to show)

pseudo creek
austere ginkgo
serene umbraBOT
#

Gave +1 Rep to @pseudo creek

stoic cave
#

I wouldn't put degree changes just the degrees you have earned

pseudo creek
stoic cave
#

Also, Latex and Awesome-CV are excellent resume choices

austere ginkgo
#

I've completed one diploma in metallurgy, and then a degree in biomedical engineering

#

So I'm just wondering if it reflects badly on a resume

pseudo creek
#

stuff like that is really country dependent on what you would put, but it wouldn't reflect badly on your resume

austere ginkgo
stoic cave
#

Yeah, I don't see either of those being a detriment

austere ginkgo
#

It's not an abrupt change after BME because a lot of it is connected to embedded systems

#

But that jump is kinda hard to explain

stoic cave
#

When I was exiting college it seemed, from professors and Alum that came back, that Cyber Security was going to be the next rush in Biomedical Engineering

austere ginkgo
#

Wow

#

Tell me more pls haha this is pretty exciting

stoic cave
#

Sorry I really can't. They were talking about medicine in general but mentioned BME and then more specifically the security of devices that have direct control over people like pacemakers, insulin pumps, etc

austere ginkgo
#

Oh yeah, recently there's a surge in IoT based cybersecurity

#

Thanks though! Needed this guidance

harsh imp
tough spruce
inner elm
#

Do y'all get yearly evaluations? What's the format like?

quick forum
serene umbraBOT
#

Gave +1 Rep to @quick forum

pseudo creek
# inner elm Do y'all get yearly evaluations? What's the format like?

I think it varies from company to company and even within the company I'm in, it has changed over time. Generally for us, we write goals for the year, then write how well we did on those goals. Then we have peer reviews which way into on how well we did our goals. Then we talk to our manager about our goals and how well we did, things we need to improve on, things we want to focus on for the next year.

inner elm
#

Thank you for the feedback Zojja

vast totem
#

What type of things should you expect during a Help Desk Interview (Specifically an Internship if anyone has any insight)

wet oasis
#

f0.vgbhjnmk,l.;/

#

+4

hazy tree
#

I had an interview the day before HR calls me the next day that they found a candidate but there’s going to be an opening for another position and they want me to apply what kind of.. man!

split ermine
#

I'm looking for remote jobs! Really hard to find

warm hinge
#

hi guys! same here

#

dont even know what to do, I'm really enjoying cybersecurity but I don't feel confident on landing a job here. So far I haven't got any certs but I 've been active on HTB and THM for a while, and even started my own blog a couple weeks ago to try to demonstrate that I'm really interested on the topic but man I'm desperate

#

I'm considering switching my focus to python or web development because I think it's easier to find a job although I dont think I will enjoy those as mush as I enjoy pentesting

split ermine
warm hinge
#

still a bit of time ahead before I get to OSCP level, plus the fact that it's expensive, thats why I was thinking about maybe switching to a bootcamp which might be a safer option

flat sedge
#

Pentest is not a task that usually gets assigned to entry level roles.

split ermine
#

Easy come easy go. Trust me. Keep your hard work. It is not about "I must get a job", it is long career.

flat sedge
#

Penetration testing also has a much level of risk associated with it, and requires more knowledge across the board to not unintentionally break the items in scope for the test. I'm not trying to discourage you, just be realistic with what your next steps to get to that point should be.

#

Also understand that the value of a pentest is in the report that gets handed off to the client - cannot stress enough that the final report makes or breaks the value of the test.

warm hinge
warm hinge
flat sedge
#

Dev can also be difficult to break into also - look for qualifications for the jobs you find interesting on linkedin or indeed or hired, and start looking at what it takes to get there. OSCP is industry standard for pentesting in the US, but preferred certs and quals are going to be different based on region

warm hinge
#

but I wouldnt mind working remote for an US enterprise

split ermine
warm hinge
serene umbraBOT
#

Gave +1 Rep to @split ermine

split ermine
#

I've just started so I have less experience in cybersec. I'm looking the answers for the same question haha

#

But I have couple of papers in AI topics and exp as dev and research help me a lots

#

Why don't you get a degree?

warm hinge
#

Its not worth really

#

my main career is aviation and hopefully I can get a job there way before 4 years ahahah

flat sedge
split ermine
warm hinge
flat sedge
inner elm
pseudo creek
#

I am taking Pen-200 right now and the primary concern was for people who were expecting to take the test early next hear but after Jan 10th as well as those that have run out of lab time. Overall, the changes are better for the cert in itself as it tests something you are more likely to see. I wouldn't worry too much about those that have not started studying yet, we will just need to hear from people after the new test takes effect to see what they say about it.

languid hearth
#

new changes are good because it ensures you have the required skills to be a penetration tester

#

the real world runs on AD.

quick forum
#

Changes are good, execution was not.

languid hearth
#

execution was fine. They could have switched it and not said anything like literally any other cert vendor.

#

you're not suppose to know anything about the OSCP exam environment prior to the changes, so instead of hate you should be thanking them for making it more clearcut ;x

#

something a lot of people miss is everything about the previous exam environment has been leaked. Not officially published by OffSec

#

if you had gone through the full course with expectation that anything could be on the exam, you would have been perfectly fine with these changes.

#

at the end of the day it was <insert person's name here's> choice not to do the AD section and it really shows who it's biting

pseudo creek
#

Certainly there are people who did the AD portion that were still nervous about that aspect of the exam. It is natural to nail down the concepts you know that are on the exam even if you weren't supposed to know they are on the exam. So people who have done AD but also studied buffer overflows over and over would still be upset

vast totem
#

What type of things should you expect during a Help Desk Interview (Specifically an Internship if anyone has any insight)

sour pike
edgy tiger
vast totem
#

Yeah fair enough

edgy tiger
#

Also the AD part will help being preped a "bit" more for OSEP I think..

vast totem
#

I'm not too worried it's just going to be my first proper internship and thought Help Desk would be a good place to start in Cybersecurity bc I highly doubt I would get accepted for a Networking Position rn

edgy tiger
#

So you made the right step 😄

#

Get your feet wet and try to stick with the sec guys

vast totem
#

Yeah I'm currently in University planning on getting Certs starting Junior / Senior yr

merry osprey
#

Like TJNull's list probably doesn't exist in a universe where PEN-200 isn't a slab of a PDF and a "Good luck! Try harder!"

jaunty patrol
#

I'm a CCNA and preparing for CCNP SECURITY, I discovered tryhackme few days ago and it looked very interesting to me so how can I pan out my career ? Can I do it in both the fields ?

vernal moth
dapper depot
#

Hello All,
Curious if you guys can give me a bit of direction. Specifically the people who are currently employed haha.
I work as a school teacher now and I'm in my early 30s. I do not have a bachelor's degree and my aim is to pursue a career in cyber. It's something I'm deeply passionate about and have been casually doing ctf's for a couple years and enhancing my knowledge.
I am considering going back to school to pursue an undergraduate degree. My question is, are cyber degrees worth the time or am I better off going cs to learn programming while attempting to gain certs while in school? That way I'll have more options when I graduate. I'm not passionate about programming but I do have some interest.
I could also finish my AA and do the last couple years in cyber.
I'd appreciate any info or direction. I'm located in the US btw.

#

Another concern I have is am I too old? Will it matter if I have a degree and certs if I'm up against 30 somethings with degrees, certs and years of experience?

flat sedge
#

Picking a career path is always a personal route - certs get you the interview, not the job. I'd also survey the jobs you like, and see the certs required

dapper depot
jaunty patrol
vernal moth
#

The advice I've gotten is that it's better to be a generalist because things change.

#

Good to understand many areas.

vernal moth
flat sedge
dapper depot
jaunty patrol
vernal moth
#

Do what you like and you'll find a place

jaunty patrol
#

I just bought the subscription for tryhackme and will go with flow

vernal moth
#

Have broad knowledge, be good at something. You don't have to know everything, but it's good to know something about a lot.

flat sedge
flat sedge
#

Security is such a huge domain, I think it makes sense to specialize first, and cross apply that domain specific knowledge to the other silos

dapper depot
#

or specializing in specific tools and understanding how those tools apply to the larger scope

vernal moth
jaunty patrol
vernal moth
#

The imposter syndrome thing is real and it's a big deal. I feel like that a lot of the time. There is just so much to know and there will always be someone that knows more than you. Something that people in the forensics side like to say is that most security people don't think they're experts, but they are experts compared to most other people.

#

Another area where we have to be strong is communication. I know many cyber people that do Toastmasters to build up those skills

jaunty patrol
#

true

hoary wind
#

I'm preparing for OSCP , but really guys.. What you learn with OSCP?

#

Hack some unrealistic boxes?

#

I need to do this exam just for job.. But it teach me nothing

#

i hope in 2022 they do something good.. And good courses too

#

I think it is too overrated certification

hoary wind
serene umbraBOT
#

Gave +1 Rep to @vernal moth

pseudo creek
# hoary wind I'm preparing for OSCP , but really guys.. What you learn with OSCP?

OSCP is mostly learning about methodology. If you've already learned methodology on your own and understand the concepts already presented then you are a step ahead of many people. I find the PWK/Pen-200 course to be full of useful information, lots of practice and a good way to practice methodology. I mean, sure its not a lab of hundreds of windows xp/server 2000 machines so you may find it unrealistic but a lot of it has to do with being able to research what you do find, figure out how to solve it, figure out how to document it and present a report, which is very realistic in job terms.

languid hearth
#

if you've spent basically any time in hacking prior to your OSCP, you're going to get significantly less out of it.

#

but aside from the new exam, there isn't a ton more that you can get out of it

#

and what Zojja said, report go brrrrr

hoary wind
#

Yup, anaway i'm with this guy

#

PNPT vs OSCP this guy had each

pseudo creek
#

The TCM training stuff is really good. Also a report with an oral part? amazing... but it will take a while for PNPT to really catch hold as something which HR is looking for in critical mass

#

Also, I don't know why anyone would listen to the videos, I think fluff mentioned for things like buffer overflows, but I've been through the entire PWK PDF and it is excellent, lots of good stuff, and I never listened to the videos

rugged delta
pseudo creek
#

and I might be unusual but not according to the OffSec discord but I don't need OSCP, no desire to be a penetration tester and no jobs I'd apply to would ask for OSCP, I do TCM courses but have no desire to do the PNPT.. I think one of the biggest benefits there are the oral presentation part, which I do every week if not a few times per week

rugged delta
rugged delta
pseudo creek
#

presentations are great, painful at first, but you get used to it. Also to its credit, OSCP will be recognized as an industry cert outside of penetration roles

rugged delta
pseudo creek
#

a huge part of my job is building threat models and attack trees, which are a paper exercise but understanding offensive aspects are good for that

rugged delta
#

Yeah a lot of the defensive measures we put in place for projects require recognition of potential vulnerabilities and either guidance on how to overcome the issue or performing pentesting to demonstrate security flaws at various stages of the production process or both

full sandal
#

Why do employers put a pay range in the job listing, confirm that in the first interview, then turn around and say they can only do like $7 less an hour

#

And then they get like offended when I tell them I won't accept that offer

flat sedge
#

Because they are playing budget games.

#

They may not think you are worth that extra $7/hr, depending on how well they think your current skillset fits into the role

rugged delta
#

Many organisations find that their lower salaries can only retain quality engineers for a certain period until they up sticks and move on, unless there are other benefits to stayting, such as location, technologies, advancement etc

flat sedge
#

That's also true. Also check the title; if the pay at that company is significantly less than industry standard in that area, it's likely they are paying people with titles not money

rugged delta
#

A lot of large orgs will also focus on moving you around to different departments at your level for various reasons, as they don't want you to be the golden goose of your technology area and they also want to ensure you don't burn out if your work is beneficial

#

Even larger organisations get stuffed in the upper levels so they have to keep you interested, engaged, give you new opportunities and try to give you a competitive offer and they balance out their needs and yours in a lot of different ways...

#

Would suggest going for a place that has opportunities to try several different roles over a number of years and provides support for training

misty narwhal
#

Hi guys! I have the option to enroll into a university next year but I was wondering, are your university degrees related to your current career in cybersecurity?

#

Do I need a degree? Can I get a pentesting job with only certifications like CEH / CompTIA etc?

pseudo creek
#

a lot of that depends what country you are in and where you are at skill wise. I would consider college generally to be building your foundation for your future career. Some countries, College seems to be a must (India/Europe?), others it seems very optional (possibly UK) and US often has alternate paths but lots of traditional companies want college degrees.

#

like in the US, a frequent alternate path is the military. Sometimes people are able to work up through the ranks starting with help desk. Help desk is a common suggestion throughout various countries though

misty narwhal
#

I see. I'm currently in Singapore. To be honest, I have no idea where I am skill-wise. I've completed a lot of THM rooms, I've done a lot of CTFs, but I don't really know how this fares in terms of "real world skill"?

But skill aside - Assuming I can get certifications like the ones I mentioned, would there be any issues in terms of employability? I'm just thinking if I should attend for 4 years OR simply just keep learning things online and achieving the same amount of knowledge anyway..

pseudo creek
#

yeah you'd need to talk to someone in Singapore to determine how critical going to college is or what certificates are best

#

I think in the past, people have mentioned that Singapore is more college heavy than other areas but I could be wrong

misty narwhal
#

Oo. Do you know any active members from Singapore?

#

Yes, generally, employers in Singapore look for a degree as their first criteria. But I'm not sure if this is applicable to infosec-related careers as well.

pseudo creek
#

possibly, I know one of the mods from InfoSec Prep is in Singapore (a different discord)

misty narwhal
#

Oh! That's really great to hear. Thanks, I'll check it out. It's currently 4:30AM here though so I doubt they'll reply but I'll update you tomorrow :)

native elm
#

@misty narwhal My company has an office in SG.

inner elm
#

"Why did your peers choose you as a nominee for this award?" Don't say, "I dunno, I'm just happy for the opportunity."

languid hearth
#

I believe foleosy from the OffSec discord is from Singapore. That may be who Zojja's referring to

neon sequoia
#

I thinks it's always wise to enrol in a university if that's possible. It not only enhances your knowledge in cybersecurity, but also in the field of doing research, working together and change of mindsets (personal experience). A degree also enlarges your opportunities abroad. There is always time to learn and get relevant certifications!

Good luck!

red coral
#

Curious of everyone's opinion on this, but would it be a good idea to jump right into Pentest+ as a cert concerning a path for employment and continue up the chain, or would it be necessary to almost mandatory that one gets the more foundational stuff like Security+ and even Network+?

vernal moth
harsh imp
#

Here is the intern position I was referring to before. We're trying to create a pipeline for future candidates. Come join us this summer if you're trying to break into Cyber and hopefully you would consider us for full-time employment. 🙂
https://jobs.lever.co/fanatics/7d2909f8-a2ec-4f13-b218-d7a7d65ad399?lever-via=4NS0llbs1I

stuck rover
red coral
# vernal moth Depends on your timeline and existing skills. But Network+ contains invaluable ...

Interesting. What I'm ultimately aiming for is the offensive side of cyber security and whatever it entails. I've come to really like the idea of being a red/purple teamer and want to jump into that as a focus so I've been curious what I should try to get to essentially "prove" myself to employers and a lot of what I see is in reference to stuff like the OSCP, CEH, eCPPT and the like so that's where I was curious whether or not having the more foundational certs mattered as much or at all in comparison to these more focused and demonstrative certs.

inner elm
#

certs are also important for jobs that require 8570 certification, it's a DoD thing

#

so, contractors care about that

#

so, in short: go look at the job you want and go read their requirements. figure out if it's a wishlist or if it's a legitimate need. eitherway you'll probably get a sense of what they are looking for

red coral
#

Hmm. So it's more of a tailoring kind of posture to take rather than looking for a one-size-fits-all approach.

inner elm
#

I'd say so. I mean if you take a look at the Nice Framework there's like 52 job roles they list and there's overlap in places. you could compare what you're interesting in doing and look for patterns. if you're working for yourself on bug-bounties no one is going to ask for your bonafides, but if you're trying to work for an employer (especially one who takes on government contracts) you're beholden to the structure they set up

#

computers will filter you out based on what pieces of paper you have, once you get passed those you'll have interviews with actual people who will see what you've got

red coral
#

Hmm. Well bug-bounties and stuff free-time based I'd probably look as side-hustles and aim for actual employment and possibly government contraction, so I guess I'll need to look up stuff in association to that. I live in Canada, but I imagine Canadian requirements and government standards aren't that far off from American ones.

mortal crater
#

Does anyone here work for the DoD in cyber?

inner elm
stoic cave
#

Ask your questions and I'll see if I'm able to answer them

mortal crater
#

So, currently active army. Looking at transferring out in spring 2023. Currently looking at the certs required on the DoD webpage and such. I guess I just need some explanations on what's required and what's just extra experience? I have 0 experience right now, working on some CompTIA certs like security+, networking+ and A+. I don't have a degree, but will have almost 9 years of service with multiple leadership/management jobs I have fulfilled. Also currently don't understand the levels. I.e. IAT 1, 2, 3. ... IAM 1,2,3... CSSP etc... And what those jobs mean and such lol.

Sorry I'm not smart on this field yet 🤣

stoic cave
#

All good

#

If you want to get into specifics my DMs are open

mortal crater
#

Absolutely ❤️

warm hinge
#

Anyone have experience with IoT/Embedded or Automotive systems?

#

Please DM for details about a job opportunity!

flat sedge
stoic cave
#

We had a good long chat

random lotus
#

I don’t know who can help me but I’m trying to decide if I want to go for GIAC certs, GCFE or GCIA… I don’t know which to pick

#

I also don’t really know what I’m interested in but maybe if anyone knows what they have to offer? What kind of jobs it more leans to? Or what is most beneficial? I’m so lost

hollow drift
#

Hi guys, If you were in highschool going into college, what would your end goal be?

#

Would it be to work at a big company like offsec or Google or to create your own business

#

Or anything else that you could do as an end goal

stoic cave
#

My end goal would be to graduate college

random lotus
#

Graduating is good

stoic cave
#

I know it seems silly but focus on what's in front of you before worrying about what's ahead

random lotus
#

Things change so much so fast long term can be hazy

stoic cave
#

If you look too far you're going to get slapped in the face by something that's right in front of you

#

The question should be what do you want. What do you want out of life and how can you position yourself the best you can to meet those wants

random lotus
#

I have no idea therefore I have no idea which cert to take

stoic cave
#

Doesn't mean those wants are going to become a reality though, because frankly, that's life

#

Sec+ should realistically be the only cert you're paying for out of pocket in my opinion

random lotus
#

I have GSEC

stoic cave
#

Maybe CCNA or net+ too

#

But anything higher than that I think is way out of budget for people

random lotus
#

So I have to kinda pick

#

Didn’t really want to talk about money though but.. just wanted help ❤️

stoic cave
#

Oh sorry, I didn't see you had asked a question

random lotus
#

Ahh it’s ok. I don’t know many people who can answer.. career counselor told me to pick what makes me happy lol I’m still stuck

stoic cave
#

The post from Lonervamp seems relevant

random lotus
#

Ahh it’s GCFE (so windows) but similar yah

stoic cave
#

Dammit

#

Sorry

random lotus
#

No no this works well!

#

Cause the GCFE really is the start of the forensics line of courses for them

#

It worried me that the sans website reviewed GCIA as one of the hardest courses they offer

#

But it makes sense that forensics with memory analysis seems more on-site and less remote. And I really want to work remote

#

It’s also good to know there are some other pentester certs out there, I really didn’t want a pentester course; I feel like working through THM or other places can help me learn without a cert

stoic cave
#

Personally, I like digital forensics so I would probably go with GCFE myself. I'm sure others are better equipped to discuss these certs than I but, based off the names, I would assume GCFE is more the "this is how you analyze the data from the responders" and GCIA is more of a networking incident response type thing?

random lotus
#

I think if I ever got stupid amounts of extra money I’d like to go forensics route for sure. I love analysis and forensics both.

stoic cave
#

GCIA seems like something Network Engineers would do

random lotus
#

What worries me is that GCIA is so close to GCIH that I don’t know if necessary?

#

I have GSEC and GCIH

stoic cave
#

Yeah, I've never really looked into GIAC stuff

random lotus
#

I blame KringleCon for getting me into this mess 🙂 but I’m grateful. I rather be in infosec than accounting lol

stoic cave
#

Wait im a dummy. GIAC is SANS

random lotus
#

Yah

stoic cave
#

So yeah I've been eyeing the FOR498 course

random lotus
#

Ohhh

stoic cave
#

I got a one hour lunch and learn with them and it was probably the most I've learned in a single hour ever

random lotus
#

Oh man! I’d love to sit down with any of them! I’m really enjoying the classes I had so far and they’re not even talking to me; it’s all videos

#

Forensics was initially what I wanted to get into when I started but hearing it might not be super remote friendly got me second guessing.

stoic cave
#

Yeah, I wouldn't think it would be remote at all given the cost of some of the tools and systems as well as the sensitivity of the data

hollow drift
serene umbraBOT
#

Gave +1 Rep to @stoic cave

hollow drift
#

I guess it's like the argument of being in the present or the future

#

And how school makes us keep thinking about the future instead of in the moment

wide mango
#

do you think If do as many rooms as I can on tryhackme, it is a definite way to get good at this field?

quick forum
serene umbraBOT
#

Gave +1 Rep to @quick forum

wide mango
#

What do you recommend for other resources

#

Any good books?

warm hinge
ruby ocean
#

Hey everyone! Im not sure if this is the right channel to ask, but I was thinking about changing my masters degree program and going into Cybersecurity. My bachelor is in Information Science (IT) but I dont have any prior knowledge really in cybersec, just basics. So in order to get into the Cybersecurity program I was thinking about getting a comptia sec+ certificate to have some knowledge in cybersec and not just go there completely new and lost. Do you guys think its a good idea to do that, or what else should I look into in order to gain some knowledge and be fine in a cybersec program?

inner elm
inner elm
inner elm
hollow drift
#

Hmm, I've done some calculations on roi and uni seems to be the best option but I don't know how to actually research for jobs that would accept me

#

It's kind of hard to look for jobs 4 to 6 years in the future

tough spruce
#

wowowowowoowowowowowow. i had to do a challenge, passed it, got scheduled an interview, they cancelled for after christmas and now i got a message that the position is filled and i didnt even get an interview

ebon mica
#

I take it wasn't a large organisation?

tough spruce
#

f-secure

ebon mica
#

May I ask where this would be? If you're not comfortable sharing it here, but would be in private, you may DM me for it.

flat sedge
tough spruce
#

whats that mean

flat sedge
#

Finding a link/paper now

#

Basically, you randomly sample 10-25% of the applicants to form a baseline

#

Then you take the remaining candidates, and interview until you find the very first one that meets the requirements you figured out from the baseline

#

then you stop interviewin

#

so if you get 1000 applicants, you interview 100 to get a baseline

#

from the remaining 900, you interview until you find the first candidate that is satisfactory enough for the job

queen cargo
#

Currently waiting for a job offer or a kind no thank you after 4 rounds of recruitment

tough spruce
#

so if they schedule for say last week. cancel cause its busy before the holidays and tell me to wait until after the holidays, but then tell me its filled, its their algorithm?
i would understand if,
im an applicant in that algorithm, and they planned their schedule for interviews properly, not cancel reschedule and then hire

queen cargo
serene umbraBOT
#

Gave +1 Rep to @tough spruce

flat sedge
#

Business changes

#

It may be that the candidate hadn't accepted, or they hadn't made an offer when they rescheduled

#

so the interview was still valid

tough spruce
#

i guess that makes sense unfortunately

flat sedge
#

Most people aren't deliberately malicious - poor planning and change are much more likely causes for stuff like that to happen. All you can really do is recognize that there are other pressures working on the situation, and accept that there are things that won't be explained and that won't be in your control

queen cargo
#

Most annoying thing is when recruiters wont inform applicants if they're not getting an interview...like total radio silence

flat sedge
#

When that has happened to me, I stop responding to emails from those recruiters, even if I was actively looking

#

There are enough recruiters out there that you will find one that will act like a reasonable adult

tough spruce
#

@flat sedge you had good advice on that too though previously to me and said try reaching out to another recruiter in the company

#

in regards to you @queen cargo you can try another recruiter in the company if youre having trouble hearing back and the position isnt filled yet

queen cargo
ebon mica
reef anchor
#

OSWA vs OSCP?

languid hearth
#

if you're getting into pentesting, do oscp

stuck rover
#

Never thought I'd see this question

#

OSCP all the way

waxen plaza
#

What do y'all think about this InMail I want to send to a recruiter at a company I'm interested in?

Hi,

I hope all is well. I connected with you a few weeks ago, as I saw we both graduated from CSU and have some mutual connections.

I also see that you're currently with SentinelOne, which I've noticed is one of the leaders in XDR, and also happens to be my top choice for the next step in my career. I would love to learn more about your experience and how I can best prepare myself for any potential opportunities.

Thank you,

Gabriel

ancient prairie
#

well said imo, I wouldn't change a thing

stoic cave
#

I'll respond once I get home

#

Can't type that fast at a red light lol

stoic cave
#

After rereading it more thoroughly, I think it's fine

#

You don't necessarily need to send an inmail if you're already a connection

#

When I was reaching out to alumni I would send a short blurb such as the following:


Very Respectfully,
*redacted*```
#

Then they would usually send over their phone numbers and it would result in a hour or so conversation, if not longer

hoary wind
#

hello guys, CRTO from hackthebox is a valid certification for job?

stoic cave
#

Did you take the exam?

languid hearth
stoic cave
#

Only 3 jobs on LinkedIn are looking for the CRTO certification it looks like

hoary wind
languid hearth
#

it's from zero point security lol

stoic cave
#

Googling it produces results from Zero Point

languid hearth
#

whoever is putting it from HTB has no idea what they're doing

stoic cave
#

CRTO is the certification for the RTO course

languid hearth
#

i can tell you why they're putting it from htb, but it's not from htb.
Rasta made Rastalabs. HTB bought Rastalabs. Therefore people correlate Rasta (and his company) with HTB.

hoary wind
#

This is why people write CRTO

#

i can see now lol

boreal ermine
#

how should i go about deciding what position i should aim for in cyber security? at first i was dead set on pen tester but now that i've broadened my knowledge more i'm not sure where i want to go into in the long run, im still heavily a beginner with everything info / cyber sec but i'd like to hopefully have a goal. i did the aoc3 career quiz and got incident responder and i thought that was pretty interesting too, my main interests are most likely pen testing, all forms of ethical hacking, red teaming, incident response

flat sedge
#

So there is room in security for a lot of different roles, goals and careers. Pick a domain that interests you, and build out from there. Depth before breadth, but you'll eventually end up with breadth if you stay in security long enough

queen cargo
#

Awww shit I got the job

hoary wind
#

but sure you will learn so much things

vivid flume
#

It infuriates me when I look for cyber security roles and the "entry" level ones demand 6 years experience... wtf

quick forum
#

This is changing, but it's still mostly the case

vivid flume
quick forum
#

Also entry level pentest would be different to entry level analyst

#

But if you think a company has silly requirements, don't apply

vivid flume
#

Yeah no point in applying if I don't tick enough boxes for them

young kraken
#

Yo
I'm am a total beginner at cybersecurity. Is it worth to buy the thm premium? Should I have a better knowledge to understand further modules or I can get this knowledge through the course?

queen cargo
#

THM is beginner friendly

vivid flume
inner elm
serene umbraBOT
#

Gave +1 Rep to @inner elm

inner elm
distant pier
inner elm
#

my wife applied for something she didn't think she had a shot at and they wound up calling her before she could submit all the extra stuff that was requested. (in her case you submit the resume, then fill out a bunch of stuff like references, etc view the website)

serene umbraBOT
#

Gave +1 Rep to @vivid flume

rugged delta
# inner elm Apply anyway. https://www.linkedin.com/pulse/why-job-description-only-wish-list-...

Yesterday a recruiter got in touch for a single role looking for a security engineer to prepare the security policy, write the documentation; engineer cloud, onsite and data centre security; be familiar with and implement secure programming standards and oversee and perform software engineering security evaluations, perform forensic and malware analysis and implement a SOC while being a Linux engineer

quasi hatch
#

needed qualifications: Be a wizard

rugged delta
# inner elm Sounds awesome, did you bite?

I'm guessing it's likely a small company with a few Linux servers probably looking for someone with familiarity with the field or someone re-wrote a Facebook SRE job description cos it looked slightly familiar to one of those I saw shortly after but no, this week I'm finishing off some college projects and I don't want a pre-Christmas interview

ancient prairie
flat sedge
#

That is a lot of roles for 1 person. CISO down to SOC Analyst in one go?

rugged delta
flat sedge
rugged delta
stoic cave
#

Dumpster fires are fun, where do I apply?

whole notch
#

Hey all. Looking to get into cybersecurity. Would like to get involved in the offensive side but know its not really a starting position. Any advice on how to get into cybersecurity or maybe what certs might be good to get starting off. Any help much appreciated.

stoic cave
#

Keep in mind cyber security isn't necessarily entry and offensive cyber even more so

whole notch
#

BSc in computer networks and 6 years as IT support technician.

stoic cave
#

Oh, rad

#

Do you have any certifications already?

whole notch
#

I don't. Just my degree

stoic cave
#

Sec+, in my opinion, is the base and then you move up from there. Others can correct me if they feel I am wrong

whole notch
#

Was looking at the sec+ or the Pentest+

stoic cave
#

Sec+ and then OSCP would be my recommendation

#

Sec+ gives you that foundation and ability to move into another security field if you so choose

whole notch
#

Ok cool. Thanks for the info will look into Sec+.

simple vine
#

not active in here as much but the other day i was offered a cloud & security engineer role! gotta give it to Tryhackme for getting me familiar with most cyber concepts and practical experience!

devout wasp
#

Hi everyone, I'm new here. I need help and direction in starting a career in cyber security. I have little knowledge on cyber security but I am a fast learner. I appreciate your help

hot marten
#

I just came home from the last day at my old workplace, gave back all my equipment and said goodbye. I'll finally start a new job as a senior security engineer in January, yay! happyPanda

pseudo creek
#

congrats 🙂

hot marten
#

Thanks! I was at that company for 13 years... Much too long! Need to see something new...

pseudo creek
#

I've been at my company longer but they keep me interested and happy ... for now

hot marten
#

For some people it works but in my position it was just company politics lately and that was exhausting.

pseudo creek
#

oof

devout wasp
hot marten
#

Thanks! THM is really good for training and getting a feel for offensive security. Luckily in my country companies do not look for certs as much as the ones in the US but I will still be preparing to do the OSCP next year. My goal is to land some job in OffSec later 🙂

stuck rover
#

Noice!

mortal crater
#

i just want to say thank you to all of you hard working hackers out there that just post random insight and i just lurk here and gain knowledge as i try to get into this field ❤️

upper jolt
#

Hello everyone

#

I’m new here

willow gate
# upper jolt I’m new here

Welcome, have fun. If you are new i would recommend checking out #start-here . Moreover if you just want to have casual conversations you can use #general and for any queries you can use relevant channels.

upper jolt
#

Okay thanks

serene umbraBOT
#

Gave +1 Rep to @willow gate

willow gate
dire rivetBOT
maiden canyon
#

Ok great.

warm hinge
#

Hey @flat sedge hope all is well!

#

So I just landed an entry level IT job and finding myself not really thriving in cyber security. Is this the path I need to take in orde to get into cyber sec? I not doing anything related to cyber sec so just wondering where do I go from here

stoic cave
warm hinge
tall solstice
#

coding bootcamp or college degree

stoic cave
#

Security itself isn't exactly entry level and by going through IT first it allows you to understand how the systems work together before you start making security decisions

stoic cave
tall solstice
warm hinge
stoic cave
#

I don't think a coding bootcamp will help you accomplish your goal then

tall solstice
#

varible that im throwing in is that my college tutition can be paid for so student loans is not an issue or bootcamp

stoic cave
#

If your college is paid for, go to college

tall solstice
#

ok . what can i do while i attend

#

no almost done with proff meyer video series

#

30 more vids

stoic cave
tall solstice
warm hinge
#

Then I'm getting apple and Samsung certified

tall solstice
#

i live with my girl n babe

stoic cave
warm hinge
#

Theirs

stoic cave
warm hinge
#

Which is pretty cool cause I'll be A+ , Apple and Samsung certified

stoic cave
#

Others can correct me but I'm pretty sure CISSP is more of a management certification?

serene umbraBOT
#

Gave +1 Rep to @stoic cave

warm hinge
#

I've read online that in order to get a broad spectrum of cyber sec and all the avenues you can venture to take the CISSP

warm hinge
#

They said this

stoic cave
#

I don't know if i would necessarily get it before you do some of the lesser certs

ancient prairie
stoic cave
#

Ok

#

Gracias

#

I wasn't sure

ancient prairie
#

you also need 4-5 years experience in the field

stoic cave
#

Right

ancient prairie
#

otherwise you can still take a test and get CISSP associate i think?

warm hinge
#

Niiiiiice

stoic cave
#

Yeah it's associate until you hit the experience mark

warm hinge
#

So certs are okay ?

ancient prairie
#

either way def not in the cards for me for a while

warm hinge
#

Like Pentest+ CISSP etc..

ancient prairie
#

i have been promised SANS courses as soon as Im off this damn contract pepehands

flat sedge
warm hinge
flat sedge
warm hinge
#

And look at viruses 😍

#

Juun!!!

#

I have to clock in now soon in 10 minutes

#

I will revisit this conversation later i sincerely apologize

flat sedge
#

No worries. I will be around, on and off, for the rest of the day

warm hinge
flat sedge
#

... You aren't repairing a dead board without soldering. Part replacement != repair, even though they get conflated very often.

warm hinge
flat sedge
#

Ok. Physical security aside, you probably won't touch much in the security space outside of encrypted disks.

fierce light
#

hey guys i'm thinking about going into the pentest field and i was first sold on my decision that i might just get all the recommended certs but i was looking through job listings, just so i have a reference to future job listings, and i found that a lot of these entry pentest job fields do require a Bachelors degree. I was also looking at cyberseek and it did mention that the requested education for this field is a BA. i'm really torn because there obviously isn't an exact way into this field but i'm just really confused on all the information and I guess I'm just not trusting myself into finding a path and sticking to it. Does anyone have any recommendations as far as paths go? A second opinion would be really helpful or any information honestly! Some background information about me is that I am 21, I graduated High School (2019) with a proficiency in Engineer and Computer Science, have been working with computers since I was 7, just want a change in my life and I feel motivated to chase after this career! I was thinking about going for the eJPT into eCPPT-into OSCP cert route. Currently using tryhackme to get some networking and pentest knowledge in, started this about a week ago haha 😅

languid hearth
fierce light
serene umbraBOT
#

Gave +1 Rep to @languid hearth

shut violet
#

quick question
I'll be setting up a file server along with trilium on server and wireguard, I want to document/ blog about it as you do for proof that I can do things. But I'm not sure entirely sure which parts of the setup are important to document and include in the blog? if anyone could give a bit of guidance or point to a good example

flat sedge
#

struggles you had are a good thing to add in

#

additionally, if are running it in a container or deploying via an infra management tool, that's a really good thing to have

shut violet
#

I see. I still have to get my bearings on how to do everything but struggles is a good thing to add

#

I'm just using UNRAID on it

ancient prairie
shut violet
serene umbraBOT
#

Gave +1 Rep to @ancient prairie

ancient prairie
#

and as with any good technical blog post, journalists have a good structure they use where the first one or two paragraph can be read by an 8th grader and sums everything up, leave all the hands-on-keyboard stuff until towards the end

inner elm
ivory nest
stoic cave
#

Yeah, it kind of amazes me how there is a severe deficit of Cyber Security Professionals and companies are still looking for that "Rockstar"

#

I understand though at the same time because it's a business risk

earnest marsh
#

That mindset from companies worries the hell out of me. Like, just train me and help me fill in the gaps for things I don’t know. I’ll never be a “rockstar” in cyber security. Hopefully when I’m ready I’ll find a company that fits me well.

distant pier
#

The fear is that if they train you up in 3 months, you'll be gone in another 3 months when you get recruited by a competitor who gets you trained up for free.

earnest marsh
#

Fair point. But offer me something to keep me there long term. Treat me well and I’ll treat them well.

distant pier
#

A business sees a job as a value proposition. What can a new hire bring to the table: add value. Training someone without retainment is a net loss. It is cheaper for them to hire qualified candidates. Training someone is a double-cost (trainer + trainee). 🙂

earnest marsh
#

You’re making me nervous Tim lmao

distant pier
#

Everyone is going to be nervous at first. It wears off eventually. 😄

#

Now there are situations where the apprenticeship model is available. 🙂

earnest marsh
#

So, that worries me as well. Im 30 with a family. If it doesn’t pay well I can’t move forward with it. Im hoping I didn’t screw myself by switching careers too late in life

distant pier
#

Another trend is having two part-time jobs, to transition slowly. One full-time job + transitioning will be a challenge, but not impossible. 🙂

earnest marsh
#

Yeah, it’s hard with kids. But I see your point

distant pier
earnest marsh
#

I’ll take a look, thank you

#

Btw, since you are here. Just wanted to say I appreciate what you do. Out of all the staff you are here the most and helping people. Thanks for being awesome 🙂

distant pier
#

John Hammond said it best: Security is a team sport. 😄

timber fern
stuck rover
hot marten
#

I see that some people have their certificates in their profile page (roles) on this server. How do you do that? (not that I have a lot...)

hot marten
#

As I'm afraid of a mods wrath if I DM one, could you make give me a CEHv11 tag, please? 😄 @undone shore I just passed this morning! First OffSec cert ever. I know some don't like CEH, but it was paid for by my old boss 🤷‍♂️

undone shore
#

I've added the role though 🙂

#

Also, congrats!

hot marten
#

Thank you! I know, I know... I think I want to do OSCP next! Would be awesome to win in AoC >_<

undone shore
#

Hehe, good luck!
OSCP is fun

hot marten
#

And a lot of work! Respect to anyone who has it already, really.

undone shore
#

It's a good way to develop a methodology, I'll say that much for it

hot marten
#

Say if I was confidently solving hard THM challenges - how much harder or how would the OSCP exam be different? Is it comparable?

undone shore
warm hinge
flat sedge
warm hinge
# flat sedge That's up to you, and what your career goals are. Whatever that ends up looking ...

Man you are absolutely right, after being here for a month without missing a day it's been quite the experience and even gave me an insight of where I am and how much I don't know about hardware and entry level technical problems. Maybe i should stick here for at least a year or two than transition into becoming an Incident Response or in Management in Cyber Security.... somewhere around these realms

#

Do you know what certs or degrees i should take incase i want to work in Cyber Sec after my 1-2 years in IT experience?

flat sedge
#

That'll be up to what's valuable for the next role you want. Sec+ is a very common cert, but it may not be a value-add for employers in your area. Check the available job market with recruiters, linkedin, and other jobs listings when you start to think about your move

warm hinge
viscid yew
#

For university graduates I was wondering what certificates are good starting points?

#

especially for cloud, devops, and pretty much info sec

hazy tree
#

I have a big interview Monday for a Sr SysAdmin/InfoSecAnalyst! Wish me luck 🍀

primal elk
#

Hi fam, I'd like to ask if THM is still looking for graphic artists?

stuck rover
hollow quail
#

Hi, can anyone experienced give me advice what should i do after I gain decent knowledge in cyber security. I m mainly using THM for learning for now. Is there something else I must do like get certifications? I m doing B.tech in CS and will be graduating next year so I have good knowledge of programming too.

edgy tiger
#

If you want to become a pentester, ejpt > oscp?

hollow quail
quick forum
#

Also, you said B.Tech. Are you in India?

hollow quail
#

yes

quick forum
#

India still respects CEH for some reason, and it's often quite neccesary

quick forum
hollow quail
#

which one is it?

#

nvm

#

first one

hollow quail
serene umbraBOT
#

Gave +1 Rep to @quick forum

hollow quail
#

looks like I will have to wait few years before I can switch to security

unique sandal
#

Any news in cyber security?

weary quarry
#

Only log4j. All log4j.

unique sandal
#

I heard about too

#

What’s the community take on log4j ?

ebon mica
#

only log4j? You're missing a lot then.

faint ice
#

poor apache getting hit with multiple baseball bats

ebon mica
#

(this is likely not the best channel to discuss general infosec topics)

faint ice
haughty patio
#

@fierce lighthello! do you want to be oscp-buddy? 🙂

regal hare
#

Hey guys just wondering, could we talk about GRC career paths here?

pseudo creek
#

you could

warm hinge
#

I what to learn Hacking

hazy tree
#

Did my interview today. Overall I think I did pretty well. I did feel like they thought I was a bit junior and they were looking for someone who might be doing infosec a bit more, but overall I think I sold myself pretty well. We’ll find out

vivid flume
#

That should set you up nicely

strange junco
#

hi everyone, so I have a question regarding getting a masters in cybersecurity. I have a 1st degree in Computer Science and i'm finishing up a masters program in Environmental modelling. wanted to challenge myself hence the switch and it has been quite a ride. Then i bumped into thm on linkedin and I kept wondering why I didn't think about going into cyber after my first degree. basically finished 2 paths in less than 2 months thats how hooked I am now. Thinking about getting a masters in cybersecurity but i was wondering if thats relevant to me. what i want basically is deeper knowledge on all things cybersecurity related besides the job opportunities and i don't know if an academic setting will have what i want or i can just keep exploring other resources available.

pseudo creek
rugged delta
# strange junco hi everyone, so I have a question regarding getting a masters in cybersecurity. ...

A masters in cybersecurity can be beneficial and if you're not already familiar with cybersecurity, it can bring you up to a level of knowledge in several of the fields within the realm of cybersec. I'm currently completing a Postgraduate Diploma with an option to change it to a masters by doing a thesis year. The first year was heavily technical in areas like cybersec fundamentals (if you're not already familiar), hacking/pentesting (our projects involved using online resources like THM/HTB to simulate a real pentest), cryptography (very maths focused), secure programming and research (you generally get to pick any area of cybersec research that excites you). There is benefit for going into management but it's also a real eye opener to the broad application of cybersec theory to real job role scopes

flat sedge
#

A M.Sc can also price the candidate out of the entry level security positions, while also lacking the background experience necessary for more senior roles. That's not always true, but that seems to be the way many of the hiring managers I've spoken with view a grad degree without experience

strange junco
serene umbraBOT
#

Gave +1 Rep to @pseudo creek

pseudo creek
#

yeah generally if you already have a degree, certifications are the way to break into cyber security.

pseudo creek
#

also something to consider, you will most likely want to not include your current masters on any resumes for cyber positions

strange junco
strange junco
pseudo creek
#

I've worked with a group of people trying to break into cyber, unfortunately lots of them come to us after having a cyber masters, they have no luck getting an entry level position, we tell them to take their cyber masters off their resume and all of a sudden get offers

#

but I'd remove any masters

quasi hatch
#

Meanwhile there's me with sysadmin experience but no degree. (don't know how or why I ended up here) Is a degree necessary to switch into cybersec, or would getting certs to pair with my experience be enough?

strange junco
pseudo creek
quasi hatch
#

I'm in the US. I've got around 4-5 years of network admin/sysadmin work (currently doing), and also a few years of help desk stuff

pseudo creek
#

in the US, the general recommendation if you decide not to go to the college route initially is try to use tuition assistance programs to get a Bachelors because of the strong bias

#

but other people have successful careers without so...

flat sedge
#

Agree with Zojja on the degree front. If you have any experience with applying STIGs or other hardening guidelines, that's a big experience to list when making the jump to security

pseudo creek
#

yeah if you do network/system admin, emphasize any security experience. I started as a network admin so I focused on the various network security aspects/involvement in investigations

quasi hatch
#

Will do, I've got a bit that I can emphasize. The reason I'm in charge is because I found out the last guys were putting RDP ports on the open fucking internet

#

That was a fun month

#

It's a multi-state company too kekw

flat sedge
#

I would throw that into a category of 'resolved findings while working with internal groups to reduce public facing threat landscape'

hazy tree
serene umbraBOT
#

Gave +1 Rep to @vivid flume

pure nebula
#

Is Bachelors in cs with focus on infosec better or just cybersecurity

flat sedge
#

CompSci prepares you for a much broader career, overall

#

If you get a degree in CyberSec, it doesn't really translate well to roles that's not security

pure nebula
stuck rover
#

Here's me wondering how someone gets to become Head of Application Security without knowing how to use Kali Linux??? Logic???

blazing kelp
#

me who using arch

flat moss
#

I'm using Parrot OS - damn - denied :))

ebon mica
undone shore
#

Fun fact: until recently 0day hated using Linux and rarely ever used Kali. He went, what, almost 20 years (including getting and holding Number 1) mainly just using Windows 🤷‍♂️

#

Don't look down on people for their choice of operating system. They may well still be better than you chceyes

fleet cypress
#

Was he using virtual machines or wsl ?

#

Or installing tools on windows which I didn't know possible(tools like nmap supports but idk the rest)

clear ravine
fleet cypress
#

thanks for pointing out

clear ravine
#

maybe he used his custom tools and programming like using sql queries instead of automating with sqlmap

stuck rover
stuck rover
undone shore
undone shore
#

Genuinely, when I do infra/internal pentests, I nearly always use two VMs: one Windows, one Kali. Once moving past reconnaissance, I rarely use the Kali box

#

Kali is useful for poisoning / relaying / hosting attack infra / and using exploits that rely on Impacket.
Any kind of "normal" AD interaction (e.g. exploiting misconfigurations) tends to be easier from Windows.

hot marten
#

Nice insights, Muiri! So you do pentests for a living?