Cyber security jobs

Oddly enough I was just chatting to a friend about this.

He's said he's interviewed several people this week (with OSCP certs) who couldn't penetrate a wet paper bag... :ROFL: I would have thought with hands on lab exams that the quality of candidate would have been much higher (unless dumps are prevalent or the course is aimed at script kiddie run X or Y tool without comprehension?).

You can't take anything away from experience but if you have your heart set on cyber security this is the cert to get.

You get good and bad candidates in all industries I'm pretty sure the one guy I worked with paid for someone to do his exam because he barley knew the cmd lines in Linux but was employed with the right BEE status. He sat playing on his phone and getting paid for it for 8 months before he was so bored he left.

I had another guy who irritated the **** out of me while being trained up but what he achieved in 3 months takes most people a year to understand. I now phone him for help on what I don't understand.

Once you finish that course you have a great understanding of how but you aren't taught everything for the rest you have to stay on top of it.

There is no script kiddie stuff, for the practical questions you get clues and you spend hours figuring them out but that won't pass you an exam. For the labs it's a box with a vulnerability where you have to find 2 flags and get root access. These get harder as you go but there is many secrets hidden in and around the labs which well are secret.
 
Last edited:
You can't take anything away from experience but if you have your heart set on cyber security this is the cert to get.

You get good and bad candidates in all industries I'm pretty sure the one guy I worked with paid for someone to do his exam because he barley knew the cmd lines in Linux but was employed with the right BEE status. He sat playing on his phone and getting paid for it for 8 months before he was so bored he left.

I had another guy who irritated the **** out of me while being trained up but what he achieved in 3 months takes most people a year to understand. I now phone him for help on what I don't understand.

Once you finish that course you have a great understanding of how but you aren't taught everything for the rest you have to stay on top of it.

There is no script kiddie stuff, for the practical questions you get clues and you spend hours figuring them out but that won't pass you an exam. For the labs it's a box with a vulnerability where you have to find 2 flags and get root access. These get harder as you go but there is many secrets hidden in and around the labs which well are secret.

GNS3 + Kali linux ;)
 
so I was thinking about the ethical hacking route for a while. Been in IT for 20 years, have pretty much done it all. But I do think a focused course like PEN-200 will help as I've always had a very much defensive mindset in systems & network architecture, application development etc.

It's like going from a relational DB design to NoSQL.. single table design, data duplication is OK, normalization is old etc etc - you have to radically change your mindset.

Maybe for me its best to do some ethical hacking short courses through somewhere like Pluralsight, and if my interest remains - maybe then spend the money on PEN-200

Would be interesting to get some input from those in this specific industry
 
Last edited:
so I was thinking about the ethical hacking route for a while. Been in IT for 20 years, have pretty much done it all. But I do think a focused course like PEN-200 will help as I've always had a very much defensive mindset in systems & network architecture, application development etc.

It's like going from a relational DB design to NoSQL.. single table design, data duplication is OK, normalization is old etc etc - you have to radically change your mindset.

Maybe for me its best to do some ethical hacking short courses through somewhere like Pluralsight, and if my interest remains - maybe then spend the money on PEN-200

Would be interesting to get some input from those in this specific industry

You would be lapped up with 20 years experience and would cruise through a lot of the course. A lot of the top guys have lots of experience but have only been in security for a few years. If you want to focus on being aggressive the pen300 course is "red team" where pen200 is "blue team". I haven't done the pen300 I'm focused on getting my degree at the moment but I have heard good things.

To see if you enjoy it you can try https://www.hackthebox.com/ or https://tryhackme.com/ and think there are a few others. Why spend money if it doesn't appeal to you and these give a good idea of what to do. These will also lead you to things to learn which is basically the idea behind pen200, try - research - repeat small steps until you gain access.

You just have to change your mind set, developers are human they make mistakes, leave in debugging tools or just have a lazy moment. These are exploitable
 
You would be lapped up with 20 years experience and would cruise through a lot of the course. A lot of the top guys have lots of experience but have only been in security for a few years. If you want to focus on being aggressive the pen300 course is "red team" where pen200 is "blue team". I haven't done the pen300 I'm focused on getting my degree at the moment but I have heard good things.

To see if you enjoy it you can try https://www.hackthebox.com/ or https://tryhackme.com/ and think there are a few others. Why spend money if it doesn't appeal to you and these give a good idea of what to do. These will also lead you to things to learn which is basically the idea behind pen200, try - research - repeat small steps until you gain access.

You just have to change your mind set, developers are human they make mistakes, leave in debugging tools or just have a lazy moment. These are exploitable
Awesome thanks - makes sense. Will definitely have a look at the resources you suggested.
 

David Bombal is excellent ....
 
There really is more to cybersecurity than pen testing
Figure out what part of cybersecurity you are interested in
Network security, application security, endpoint, pen testing, risk and compliance, data security, cloud security, identity management...the list is long

It also is not as glamorous as you might think. Ethical hacking is death by documentation and long nights. It can be exceptionally rewarding, but you need to love it.
 
Oddly enough I was just chatting to a friend about this.

He's said he's interviewed several people this week (with OSCP certs) who couldn't penetrate a wet paper bag... :ROFL: I would have thought with hands on lab exams that the quality of candidate would have been much higher (unless dumps are prevalent or the course is aimed at script kiddie run X or Y tool without comprehension?).
PEN-200 or OSCP is still very beginner and more like a CTF rather penetration testing real networks so I hope your friend had this at the back of his head while interviewing them. I have also interviewed people with OSCP and I always put them on a juniors even though they hold the certificate as they do not know real work networks and how to compromise networks without exploits. There are dumps available but the exam changes so often some of those dumps are useless but people will always cheat either way.

wahahaha , i knew it ...... Its why i keep banging on about the fundamentals , but people just want to take shortcuts.Says alot about the industry when you have these fancy certs but companies are being hacked left right and center.
People will always take shortcuts hence why when I interview people I am assessing how they think about a problem or how they would tackle a scenario I have given them rather than ask them to hack some CTF box I have created. I can always give them on the job training and other missing skills but I wont compromise on problem solving and creative thinking.
 
There really is more to cybersecurity than pen testing
Figure out what part of cybersecurity you are interested in
Network security, application security, endpoint, pen testing, risk and compliance, data security, cloud security, identity management...the list is long

It also is not as glamorous as you might think. Ethical hacking is death by documentation and long nights. It can be exceptionally rewarding, but you need to love it.
Fully agree it is literally:
1. Death by reporting (to be honest this should be automated)
2. Long days and nights of hacking
3. Angry clients as you compromised their baby aka their network and showed their "IT rockstar" he doesn't know security as well as he thought he/she did.
4. Politics

"Network security, application security, endpoint, pen testing, risk and compliance, data security, cloud security, identity management...the list is long" yes yes yes we need more people doing other forms of security even defensive security is needed.
 
PEN-200 or OSCP is still very beginner and more like a CTF rather penetration testing real networks so I hope your friend had this at the back of his head while interviewing them. I have also interviewed people with OSCP and I always put them on a juniors even though they hold the certificate as they do not know real work networks and how to compromise networks without exploits. There are dumps available but the exam changes so often some of those dumps are useless but people will always cheat either way.


People will always take shortcuts hence why when I interview people I am assessing how they think about a problem or how they would tackle a scenario I have given them rather than ask them to hack some CTF box I have created. I can always give them on the job training and other missing skills but I wont compromise on problem solving and creative thinking.
Thanks - that makes a lot of sense.

I do like the hands on approach (it's why I favour things like Red Hat exams).

I assume progression wise these get a lot harder (e.g. PEN-300) and then are more valid / sought after amongst the community?
 
Fully agree it is literally:
1. Death by reporting (to be honest this should be automated)
2. Long days and nights of hacking
3. Angry clients as you compromised their baby aka their network and showed their "IT rockstar" he doesn't know security as well as he thought he/she did.
4. Politics

"Network security, application security, endpoint, pen testing, risk and compliance, data security, cloud security, identity management...the list is long" yes yes yes we need more people doing other forms of security even defensive security is needed.
I've contemplated infosec a few times, as a viable path (from a Linux architect / devops background) - but the sheer level of compliance or policy based certifications (things like CCISP) have put me off.

Most people I've met who are in infosec seem to be all policy or paperwork driven and have almost zero experience when it comes to how systems work, comp sci fundamentals, pen testing etc. It's really frustrating working with them as a result - as you understand systems better, but are constrained by what vendor A or vendor B says, as they have their ear.
 
Thanks - that makes a lot of sense.

I do like the hands on approach (it's why I favour things like Red Hat exams).

I assume progression wise these get a lot harder (e.g. PEN-300) and then are more valid / sought after amongst the community?
Yeah correct PEN-300 is more real world and then OSEE is like finding 0-days and weaponizing n-day vulnerabilities. I just completed AWAE or Web-300 and that exam was insanely hard as I had to review source code and create a custom exploit that will bypass authentication and perform RCE to gain access to the OS. To answer your question "is sought after by the community?" yes but some aren't at that skill level yet.
 
Most people I've met who are in infosec seem to be all policy or paperwork driven and have almost zero experience when it comes to how systems work, comp sci fundamentals, pen testing etc

so basically a glorified accountant / auditor :X3:
 
so basically a glorified accountant / auditor :X3:
Yep - some even employed to click the "patch" button without knowing what a CVE is or how to read it... but will then try and tell you that they're in infosec and "know better" :ROFL:.

God sometimes I just hate what suits / marketing have done to IT.
 
Yep - some even employed to click the "patch" button without knowing what a CVE is or how to read it... but will then try and tell you that they're in infosec and "know better" :ROFL:.

God sometimes I just hate what suits / marketing have done to IT.

thats when you tell them to get a real job , and sod off ......
 
and dont you love some of these partner sponsored adverts on mybb , where they have "Cyber Security experts" making out they are the bees knees , and punting there products.
 
Top
Sign up to the MyBroadband newsletter
X