Like all things, different niches attract different people. There's a market for cyber security and if you're well-versed and highly qualified, you could certainly make as much, if not more, than a software developer. Of course, we could get into the cynicism of how corporations view cyber security professionals (i.e. as someone to blame when something goes wrong, despite not listening to their cyber security employees because it would hurt their quarterly earnings), but that's tangential.
Security is more interesting work than development for many.
Also, money and job security. At least from my experience, and intermediate Security Analyst will make about the same as a senior developer (Mid West market), and there does appear to be a much lower salary cap for developers than security engineers. In addition, Security seems to have far more available positions right now, as many corps are trying to 'catch up' and finally admit they need security.
> and there does appear to be a much lower salary cap for developers than security engineers.
Shit this is what’s kept me from leaving software. If that’s true, maybe I should try security, I’ve done some security adjacent stuff, but mostly implementing software for compliance purposes.
Don't go into security for the money. For the same effort you can make more money in some other part of the software industry. Only go into this industry if you're nuts about it because you will be competing with people who are nuts about it.
Not sure what parts specifically. There are FAANG software engineers making $200k entry level. Making the same salary in security requires far more work and skill than doing entry level software development for FAANG.
This is my observations for midwest area (not chicago)
I have no idea what out west is like. There is a HUGE lack of talent for application security, most security starts as network security, and then matures into application security. So if you are a competent developer and have security adj. experience in the appsec space, you likely will be able to do a better job and have an easier time than existing security professionals who specialized in network security.
You can do both in exploit development and there's some really good money [1] if you come up with something very dangerous. However it's a very hard field to break into unless you have tons of programming experience with system-level languages like C/C++, x86, ARM (extremely relevant today since virtually everyone trusts their privacy to their mobile devices).
Out of interest, are these larger, and more "corporate" focused shops? I have directly worked with a range of client companies, and none cared about certs (even government!)
I'm wondering if OSCP is an "easy resume filter" in a time of online job applications being easier than ever before, rather than something they have a business need for, as their clients demand it?
The clients dont care, the shops care. The shop that will hire the pen tester onto their staff are the ones that do the filtering of applicants based off certs.
The reality is that OSCP is very hands on focused in training and examination. For the most part, based in real world skills and tools. Certs like CEH, Sec+ do jack shit for real world application, and focus you into memorizing things. At least passing the OSCP means you are competent in at least the basic tool set usage and application in an lab environment, which is more than most can say. Sure, you can be a competent pen tester without it, many are. but when you are staring down 100 resumes, where people spend more time making their resumes look good than they spend on polishing their skills, OSCP actually does its job in creating a known baseline of skills better than most other certs. (What certs are supposed to do)
Rarely have I seen clients care about the pen tester having OSCP. It has always been the employer that has cared.
OSCP kinda sucks because the pentesting industry kinda sucks (I have OSCP). Things are different now since there's a ton of guides and videos specifically for it.
Long term, you're better off being a developer and getting into security that way. Plus you're going to learn to program as a pentester anyway. The job market and day-to-day and salary is also much better. It is hilarious how necessary/important security is but pentesters seem to get low salaries and have high barriers to entry.
I think this is true of netpen work, which is heavily commoditized, but much less true of vuln research and appsec, which are the fields you're shooting for by learning to code. I generally agree that developer -> security is the right way to go.
Just curious, why do you say that? I'm no expert in this field, but I thought the OSCP cert was viewed as being a valuable entry level cert in the field?
I remember doing a bootcamp for it many, many years ago when I was getting started in Infosec. I was already doing boot2root type challenges but this was a "real" cert and I was really nervous.
I remember the relief washing over me on the first morning of the bootcamp when there were questions such as "what's a shell" and "What's Linux?".
Can anyone with experience in cyber security attest to the value of the recommendations given in the article? Are certificates really that important? Is the roadmap a good roadmap to follow if one wants to get into cyber security? Any other recommendations for a beginner?
> "Cyber Security is one of the most expensive fields, You are required to do a number of exams and certification. Unlike Software Development, These certifications are very crucial, They are more or less like a "Get out of jail free" Card."
This is terrible advice. You don't need lots of BS certs to get into security.
The only cert here worth doing is OSCP, and even that has lost respect/value in recent years to rampant cheating and answer sharing.
Agreed, and I have a variety of these (certifications).
Most of the top tier people that I know in cyber security are not certified professionals, but rather people that have deep knowledge in their area of expertise with the ability to apply security knowledge to it.
The list of certifications is bad because:
- it only focuses on offensive security work, which is a small part of the actual field (there is the entire blue side as an example)
- it focuses heavily on the software side of the house which is once again not the entire field (more than a few places have been popped due to infrastructure misconfigurations and issues)
- it ignores many common enterprise environments that use things like Active Directory, Otka, EUA, SSO, etc. These are things that you will encounter and must know how to work with or secure if you are a generalist in the field (if you're specialized you may never touch these things at all).
In short, this is good if you want to be a consultant doing generic penetration testing but not much more than that. They may also serve as HR checkboxes for recruiters that do not understand the job requirements.
Certifications are far less important than this article makes out - this roadmap seems to really just be a roadmap of certifications for some reason, rather than a true roadmap for a beginner. If you focus on certificates, you won't gain the rounded knowledge you'll need.
You don't need certifications at all to do well in the sector - people are still judged on their merits (and previous gigs), as there's a broad recognition, by those who are any good at least, that certifications are very prescriptive and don't signal quality. I have none, nobody has ever asked about them.
The recent scandal around some large security companies sharing cheat-sheets and answers to certification exams [0] shows one reason people don't trust certifications.
Some "customers" will want certifications, generally those that have no clue about cyber security, and who therefore have no clue what they want. You might find it hard to break into those kinds of roles in the first instance without some kind of certification, however once you've got some experience and track record, you tend to find they go away.
I've been in security for the better part of a decade. I have none of these certs (I have no security certs at all). The OSCP is the only certification in this list that I've ever even heard of being part of hiring discussions, and even then I've really only ever seen it required/desired in penetration testing roles.
In fact, this article is very narrowly focused on penetration testing-type roles. There are a whole host of other security roles that require all kinds of different skillsets which aren't even mentioned here.
If you do want a penetration testing role, I don't see anything wrong with this roadmap other than the fact that it over-emphasizes the need for certs. Like all other types of roles, some hiring managers might be part of the "certification chaser" crowd and might require certs for candidates, but IME most don't care and someone not having a cert has never stopped me from hiring them, and quite frankly if someone does have certs it doesn't make me any more inclined to hire them.
I've spent much of the last 15 years hiring pentesters and not only have I never considered OSCP, I've never talked to a peer that did either. It may be a big thing with body shop netpen firms; don't work for those.
you’re probably in a tech company. most security jobs (most software jobs period) are in non tech companies. insurance, healthcare, auto parts, you name it. in most of those roles, certs are very helpful if not mandatory to even get your foot in the door.
Disclaimer: my account is a biased one. With that said, I hope the following comment helps.
Not working there but have a friend that does and looked around a bit myself.
My experience:
- 3 university courses from VUSec (e.g. how to do Rowhammer via JavaScript? How to analyze a binary? How to do a XSRF, XSS or SQLi? <-- is stuff I learned there)
- Hack The Box full-time for 2 months, most difficult machine I pwned was PlayerTwo (making a working heap exploit by poisoning the t-cache).
My friend also did OSCP after that and he rated it between easy to medium level compared to Hack The Box. However, you did need to be faster at finding the easy to medium exploits compared to Hack The Box (since OSCP is time-based and Hack The Box isn't). The levels of Hack The Box are: easy, medium, hard and insane. IMO, this is a false characterization, since the levels are more like:
Easy: metasploit vulnerability
Medium: some payload vulnerability
Hard: harder to find the vulnerabilities, but most vulnerabilties are of level "medium", mixed in with some binary stuff that's quite easy to do (if you know binary, because if you don't, you're gonna cry with how hard it is. I suspect most people don't know how to do it, but VUSec prepped me well for that)
Insane: medium web level vulnerabilities (same as hard), but the binary stuff becomes a lot harder, also mixed in with C vulnerabilities (e.g. heap exploit).
That's it for the education side, now for the work side.
-----
My insight is, there are two types of companies:
- Tech companies (they don't care about things like OSCP)
- Traditional companies (they care a lot about things like OSCP)
The job ads that I saw for tech companies, or tech-related companies (e.g. Airbus [1]) were quite deep. Most of them require deep C/C++ skills with binary stuff and less on the web side.
The job ads that I saw for traditional companies were more web-based, had no clue about binary/low level stuff and terms like OSCP were mentioned quite often but not always.
My friend now works at a traditional company. He noticed a few things that the article doesn't touch (I skimmed it, I might be wrong).
- The level that he needs is at most medium hack the box level (technically)
- The level of social skills that he needs is quite high, because you're always telling some IT team that they didn't secure their shit properly
- The level of political skills that he needs is quite high as well, because not only do you deal with the IT team, you also deal with all the managers relevant to it
So yea, that's what I know. So the resources that this article gave were quite good for getting a job at a traditional company as a pentester, because it's more or less what my friend did. However, if you want to work at Google or something, I think another path is required that probably starts at VUSec.
FYI, VUSec is the systems security department at the Vrije Universiteit Amsterdam.
Btw, I'm for hire as a junior pentester or junior reverse engineer.
As someone who’s gone deep down the rabbit hole of trying to learn this stuff, I’ll give this advice. Focus on learning computer science, computer architecture and networks as a foundation.
Learning all this technology without understanding the fundamentals is a waste of time.
Most certs are overrated. They don’t actually test your understanding that well. The people who care a lot about certs are people who you probably don’t want to work with. They’re just a way for the IT guys who run the cert programs to make extra cash. By all means, if your company is willing to pay for cert training get it but don’t waste too much time studying for them.
Absolutely echo this. You need to really start with the basics, and focus on understanding (i.e. asking yourself) *how* and *why* everything works and happens.
In order to find vulnerabilities, you need to understand how a system works, and how all the parts that lead up to it work. You'll ultimately want to understand how $high_level_language ends up as bytecode that executes on the CPU, and if/how you can modify/manipulate that. And a bit about the underlying hardware and electronics never does any harm for some rowhammer type attacks.
If you want to defend and secure a system, you need to understand it, and all its dependencies, and the assumptions it makes. You'll want to understand the hardware, and how it's secured etc.
For networked systems, get a really good understanding of TCP, UDP and IP. Learn how firewalls work.
The aim is to get to a point where you know the fundamentals and how things work to the point there's no "magic" in how the computer works - you know enough to explain a PC from reset vector through to UEFI, bootloader, OS load, software load, network exchanges, etc. And similar for an IP network - you want to know everything about subnets, how VLANs work, how tagging works, how 802.1x works, how WiFi works, etc. And this is just the start!
You'll struggle to secure something you don't understand - this is why $bigcompany can't secure their basic IT network - those responsible didn't understand the basic principles, or how the moving parts worked (either on their own or as part of the bigger system), and it ends up compromised by someone who does understand those principles.
Certs are not vital, but OSCP is well known and highly regarded.
I haven't heard of any of the rest, beyond CEH (the "joke"), and OSCE (just next-level OSCP).
A lot of people do get OSCP (for it's perceived value) and CEH (as a box-ticking exercise), and the former is of definite benefit, but I wouldn't call any of them necessities.
The roadmap seems more of a completionists reference rather than anything else.
All that said, they do seem to know what they're talking about (particularly The CEH joke)
As someone who has done hiring for various cyber security roles I can tell you that I only look at degrees and certs when the role is more junior and I get more excited seeing someone with a personal tech blog than any degree/cert. After junior roles I will usually simply have a conversation with the applicant and ask them what they have worked on in the field, the conversations tend to feel very natural when the person is legit with their knowledge level.
Haven't commented in an extremely long time but I'm popping into voice my opinion here on two specific certs in that list: eJPT and eCPPT
Those certs are for self study only, the applicable value for them in the hiring process is non existent. No one knows who they are or what they do. Used to be a huge advocate of those certs until I actually bought them, then I immediately regretted it. It's been a few years now but I had an awful time with the latter; buggy, filled with errors, typos, non working software. Back then at least, you had to spend hours fiddling with with the settings just to get it to work at a base level. The eJPT itself is extremely basic, it's just using like 5-10 basic techniques to retrieve a few flags worth of info. Really didn't like how the modules were set up. The main resources are powerpoint slides to cover all the text info, then you may have a few minute video occasionally that explains 1 topic barely. The labs would come with lab guides that were all but useless. The authors are Italian so typos and grammatical errors are rampant.
Curiously enough back when I bought them, they sold their courses individually and they were insanely expensive. Looking at them now, it seems they went away from that and now offer a one for all subscription of 2k/year. The eCPPT alone cost me almost that back much when :/
Since then it seems the company has kind of given up. They used to be pretty active on social media trying to advertise themselves, now they barely ever post. It's like they've given up and are just maintaining the content they have until the ship sinks.
If you can get your company to pay for the subscription, go for it. If for nothing else, just the collection of powerpoints and curated information. Other than that, I'd stay away.
The article focuses exclusively on the technical side. No, certifications are not required. Sure, they will get your resume higher on the list.
Security is much more than simply breaking stuff. You need to understand the fundamentals, CIA triad, risk, misunderstandings that arise from the fundamentals, issues that generally arise with security due to the context etc. Debunk also some common myths around security. Fundamentals can land you in tables that technical skills won't. It is one thing to land bugs and another to be able to sit in a meeting with a guy from engineering and reason with his team and reach an agreement. Generally, working with non-security folks is hard and knowing the fundamentals helps. This also requires soft skills. Know your limits and be honest about them. Also, it is good to listen to people and their concerns. Generally, soft skills are super important in security because in most cases your opening statement is going to be one of the following:
- I found some bugs that I want to discuss with you.
- You did X which violated that policy and it rang an alarm in SOC.
- We have this issue and I came up with this plan to build this to address it.
Being able to calm the other side is crucial or you risk derailing the conversation. Also, being able to write code helps a lot. As a matter of fact, I forced team-members to work for other teams for two months. Not only they brought skills back, my team now had an understanding of their work and potential pain points.
Being able to understand the pain of the other side and also come up with solutions (incl. writing code)
If I started again, I'd do the following:
1) Understand the fundamentals and the limitations
2) Build stuff. It helps relate with people.
3) Break stuff. It's fun and useful to understand what went wrong.
4) Have a broad knowledge but focus on specific fields. Some people like defending, some people like attacking, some like building stuff.
5) As every job, it has its laundry list and boring tasks that people need to make. Yes, Excel spreadsheets are a thing in infosec.
6) Don't focus too much on certifications.
Edit: Saw this[3] comment. That comment reminded me of something. We've had, time and time, candidates with certificates that could do exploit stuff but couldn't use SSH. One of my first hiring questions was "How do you use SSH" and "How do you delete files from the terminal". I wasn't sure whether this guy was making fun of me or my resume sucked. Apparently, the guy was fed up with people not knowing to use a system that he started asking such questions regardless if you had a Ph.D. in Computer Science.
[3] https://news.ycombinator.com/reply?id=25814333&goto=item%3Fi...
Certs are not that important to people in the industry, but they are important to HR.
As a beginner who wants to get into infosec, very very often a cert or two is the difference between the resume being thrown out or getting an interview.
As an experienced security professional with years of experience, a cert is literally never the reason you do or do not get an interview.
I have mentored 4 people into security within the last 3 years, 3 from IT and one from general sales (of golf carts), and my advice is always the same to them all.
1. Start the networking game immediately. If I was to guess, I would say 2/4 or 3/4 infosec hires are because the new hire knows someone on the infosec team before applying. Find your local infosec meet ups, (They still meet virtually, and soon in person again). Start going to local infosec conferences (look into bsides), and look for community hosted events. Infosec is full of nut jobs who think its a good time to spend hundreds of hours hosting a CTF for no freakin reason other than it is fun. Go to these, get to know the local infosec community.
2. While doing #1, Start Getting a general understanding of all areas of IT. Know what helpdesk does, what windows admins do, what nix admins do, what developers do, what network admins do, and of course what security analyst/engineers do. Develop the skills necessary so that you could confidently do the entry level job of the IT vertical.
3. While Doing #1 and #2 Focus heavily on identifying what aspect of security you want. Like all IT verticals, once you get into it, there are a million specializations, identify if you want to go Offensive, or Defensive. If you are into Risk and Compliance, SOC analyst, Solutions Engineer, pretesting, red team, exploit development, the list goes on and on and on. For the most part, identifying Offensive or Defensive will be enough. There are probably 5 Defensive Infosec jobs for every 1 offensive job. And there is plenty of opportunity to switch to 'the other team' during your career. And just because you are defensive doesnt mean you will NEVER do any offensive work, you will dabble in it weekly/monthly, you just will be like 90% focused on defense. And for those reasons I usually recommend people trying to get into infosec to try and land a defensive infosec role for their first infosec job, even if they know they ultimately want to go offensive.
4. Pick up at least one cert focused on either offensive or defensive infosec (depending on what you want). I specifically recommend OSCP for offensive, and I recommend Sec+ for defense. This is not to develop skills, but for those other 1/4 or 2/4 hires that are not placed by networking. The reality of our world is that Certs get you past the HR filter. These certs are specifically for landing you interviews, no amount of certs will help you perform well in an interview, and if you only do certs for training, you will 100% fail every single interview. Getting a cert almost always increases the number of interviews to places where you do not know someone.
5. While doing #1 and #4, and after #2, #3, focus in on what you find interesting about infosec. Try to become an expert on that area. Not only should you learn about that area, you should learn about every technology that supports that area. If you think webapp security is interesting, learn every single piece of technology that is even peripheral to webapp (A lot of stuff). Security is a mindset, not a skill set. The knowledge a nix admin has and the security engineer have are similar, the difference is mindset and priority.
Once you are working on #5, you should start applying full force. You 100% can apply while you still know absolutely nothing, but odds are against you, but still dont let an opportunity pass you up. The first infosec job is the hardest one to get.
I have hired numerous folks in building out a very successful security team. None had certificates, and I didn't even ask. It is better to study deep technical topics rather than to study for certs, e.g., decompilation, how to do SSRF, how to audit AWS, how to get developers to build secure code.
First rule of 'Cyber Security': never use the phrase 'Cyber Security' in any serious discussion on hacking. If I was going to hire-on a computer security professional. The first question I would ask is, how many machines have you owned?
Alright so lots of people are saying certs aren’t worth it here. But as someone desperately trying to pivot from software development (5 year exp) to anything security related (which I find far more interesting), how are you supposed to do that without certs? I’ve done CTF events and performed well, I’ve done HTB for well over a year at this point, and the only time I’ve ever heard back from a company regarding an (offense) security position was basically just to see if I could be persuaded to do software development for their company instead. It’s extremely frustrating.
The annoying truth is that offensive security roles, despite being the "sexy" face of security, are in much less demand compared to defensive security roles. There are some very prestigious pentesting or research shops that pay a lot for highly-skilled offensive security professionals, but they are rare. The average company treats offensive security as an entry-level position meant to attract newbies to security with the "sexy hacker role" before pushing them into more in-demand positions like application security. For context, many of the large companies I consult for have ~5 people max on their red teams, while having 100+ on the rest of their security teams (the "blue" teams). There just relatively aren't that many offensive security positions available.
If you really want to do security, then my advice is to either look at some dedicated security consulting shops that do penetration testing (and be prepared to take a pay cut), or alternatively use your software development experience to pivot into an application security role. From there, you might find it easier to get involved with some offensive security efforts through that.
If you're doing well at CTFs and HTB and similar, I guess you are now at the point where you should start to look at networking. Clearly given world circumstances right now, in-person networking events are not likely to be happening, but it's likely that there's a local community in your area with security people.
They might still be doing virtual events, having some speakers etc. Get yourself known. I have been able to get junior people straight out of college/university into roles by getting them into the "networks". There's a worldwide shortage of security people, caused partly by the inability of the people who need them to efficiently hire them (other causes include wanting top-level skills for bottom level pay, and blaming lack of people for their own lack of willingness to pay).
The more you get known in your local security community, the better. After a while, perhaps they'll be interested in a talk from you about something as well - it gets you seen and known, and it's much easier to break into security when you're known.
> Chances are most of the people you talk to are hiring or know people who are hiring.
Definitely this. And if they like you, and their company isn't hiring, they might even be able to get them to hire you. Good and enthusiastic security people are hard to come by, so you take the ones you can get, if times are good and you think you might need more soon!
And even if they aren't hiring, chances are they will be able to make a personal introduction to someone who is hiring - at least in the local networks I've been involved in, there's more demand than there is supply, so people are generally pretty willing to help you make connections with the right people. And at the back of their mind, they will also be thinking how they can always go to you in future to get out of their current place(!)
Do you have a MS? If you were interested in government cybersecurity work, you could do something like SFS (https://www.sfs.opm.gov/) and get a MS with a pretty much guaranteed gov't job at the end of it. It's also a good program if you want to get working for FFRDC's.
edit: They also give a ~$25k-$35k stipend plus tuition, security certs, books, etc. It's a pretty solid deal IMO.
People saying certs aren't worth it are only looking at half the picture. EVERYONE knows most certs suck, and the few that are good are drowned out by the volume of half ass shitty certs that are just money grabs.
But certs are an unfortunate necessity in a world where fresh college graduates without a days worth of experience in IT or Security are pre-filtering resumes. Certs ARE worth it, to get past HR. I always tell everyone who wants to get into security that the first infosec job is the hardest to get, and for that, you need to play the HR game, and that means a couple certs. You need to sit down in front of the hiring manager for an interview to get the job, your hiring manager will know your cert means nothing, almost guaranteed he never even asks you about any of them.
Your resume means everything to get in front of the manager, then your resume means jack shit to the manager. It is stupid, but is the world we live in.
You can get hired into infosec without the certs though, and that's know the hiring manager or know someone on the team you are applying for. Hiring managers can tell HR "I want to interview Joe Somebody, he said he will apply this week", and in security, id say more than 50% of the hires are indeed that. So to do this, go to the local professional meetups that meet monthly, go out for beers with the people, go to the local conferences and make friends with many people already in the industry, maybe do a talk at the meetups or local conference. Then when a position opens up at a place where there is someone you know, you now can get an interview.
But you really should be doing both at once. Most competent developers or IT people can pass Sec+ blindfolded, you most certainly do not have to take the class, at MOST skim the study guide book once, and your almost guaranteed to pass. It is a joke, everyone in the industry knows it, yet if you could dramatically increase your chances of getting an interview while you are taking the time to develop those relationships, what idiot wouldn't?
I've heard this a lot before and I'm sure its true in a lot of cases.
But I've been in security over a decade, and have hired at smaller boutique pentest companies, and multi billion dollar companies. In all cases, the CVs/resumes come straight to us, they never go via HR.
I can sympathize with the comment, and know for a fact it's true in a lot of fields, including ones it shouldn't be done in due to similar skills niches.
Despite this, as you say, I've usually seen CVs/resumes come straight to the hiring team - the first thing an effective security lead does ensure there's no pre-screening on CVs, as they want to see the "unconventional" CVs as much as the conventional ones.
There's also companies that actively have their techies go out and fly the flag, post on the /r/netsec or HN hiring thread, and give a point of contact straight to a personal or team mailbox.
I don't have any certs (apart from malformed X509 files..) so I can't speak of their effectiveness. What has worked for me is having a strong presence in open source. I just show people one of my projects like [1] and nobody asks about certs or education, ever. I spend most of my free time on these projects so cultivating a sizeable project might not be a suitable route for anyone who has a life outside of computers, though having some kind of publicly available utility where a prospective employer can check out your coding style and skills is probably a decent way to stand out amidst a sea of applicants.
58 comments
[ 3.3 ms ] story [ 123 ms ] threadShit this is what’s kept me from leaving software. If that’s true, maybe I should try security, I’ve done some security adjacent stuff, but mostly implementing software for compliance purposes.
It seems like being a highly paid security engineer requires a lot more commitment than being a highly paid software engineer.
[1] https://zerodium.com/program.html
Unless your plan is to go it your own, and either start your own business or go black hat, OSCP is indeed good advice.
I'm wondering if OSCP is an "easy resume filter" in a time of online job applications being easier than ever before, rather than something they have a business need for, as their clients demand it?
The reality is that OSCP is very hands on focused in training and examination. For the most part, based in real world skills and tools. Certs like CEH, Sec+ do jack shit for real world application, and focus you into memorizing things. At least passing the OSCP means you are competent in at least the basic tool set usage and application in an lab environment, which is more than most can say. Sure, you can be a competent pen tester without it, many are. but when you are staring down 100 resumes, where people spend more time making their resumes look good than they spend on polishing their skills, OSCP actually does its job in creating a known baseline of skills better than most other certs. (What certs are supposed to do)
Rarely have I seen clients care about the pen tester having OSCP. It has always been the employer that has cared.
Pursuit of certification is not good advice.
Long term, you're better off being a developer and getting into security that way. Plus you're going to learn to program as a pentester anyway. The job market and day-to-day and salary is also much better. It is hilarious how necessary/important security is but pentesters seem to get low salaries and have high barriers to entry.
I remember the relief washing over me on the first morning of the bootcamp when there were questions such as "what's a shell" and "What's Linux?".
100% of the people on the bootcamp passed.
This is terrible advice. You don't need lots of BS certs to get into security.
The only cert here worth doing is OSCP, and even that has lost respect/value in recent years to rampant cheating and answer sharing.
FWIW, IMO, the best form of proof is showing how hard you can pwn boxes :)
Most of the top tier people that I know in cyber security are not certified professionals, but rather people that have deep knowledge in their area of expertise with the ability to apply security knowledge to it.
The list of certifications is bad because:
- it only focuses on offensive security work, which is a small part of the actual field (there is the entire blue side as an example)
- it focuses heavily on the software side of the house which is once again not the entire field (more than a few places have been popped due to infrastructure misconfigurations and issues)
- it ignores many common enterprise environments that use things like Active Directory, Otka, EUA, SSO, etc. These are things that you will encounter and must know how to work with or secure if you are a generalist in the field (if you're specialized you may never touch these things at all).
In short, this is good if you want to be a consultant doing generic penetration testing but not much more than that. They may also serve as HR checkboxes for recruiters that do not understand the job requirements.
You don't need certifications at all to do well in the sector - people are still judged on their merits (and previous gigs), as there's a broad recognition, by those who are any good at least, that certifications are very prescriptive and don't signal quality. I have none, nobody has ever asked about them.
The recent scandal around some large security companies sharing cheat-sheets and answers to certification exams [0] shows one reason people don't trust certifications.
Some "customers" will want certifications, generally those that have no clue about cyber security, and who therefore have no clue what they want. You might find it hard to break into those kinds of roles in the first instance without some kind of certification, however once you've got some experience and track record, you tend to find they go away.
[0] https://www.theregister.com/2020/08/14/crest_investigates_nc...
In fact, this article is very narrowly focused on penetration testing-type roles. There are a whole host of other security roles that require all kinds of different skillsets which aren't even mentioned here.
If you do want a penetration testing role, I don't see anything wrong with this roadmap other than the fact that it over-emphasizes the need for certs. Like all other types of roles, some hiring managers might be part of the "certification chaser" crowd and might require certs for candidates, but IME most don't care and someone not having a cert has never stopped me from hiring them, and quite frankly if someone does have certs it doesn't make me any more inclined to hire them.
Not working there but have a friend that does and looked around a bit myself.
My experience:
- 3 university courses from VUSec (e.g. how to do Rowhammer via JavaScript? How to analyze a binary? How to do a XSRF, XSS or SQLi? <-- is stuff I learned there)
- Hack The Box full-time for 2 months, most difficult machine I pwned was PlayerTwo (making a working heap exploit by poisoning the t-cache).
My friend also did OSCP after that and he rated it between easy to medium level compared to Hack The Box. However, you did need to be faster at finding the easy to medium exploits compared to Hack The Box (since OSCP is time-based and Hack The Box isn't). The levels of Hack The Box are: easy, medium, hard and insane. IMO, this is a false characterization, since the levels are more like:
Easy: metasploit vulnerability
Medium: some payload vulnerability
Hard: harder to find the vulnerabilities, but most vulnerabilties are of level "medium", mixed in with some binary stuff that's quite easy to do (if you know binary, because if you don't, you're gonna cry with how hard it is. I suspect most people don't know how to do it, but VUSec prepped me well for that)
Insane: medium web level vulnerabilities (same as hard), but the binary stuff becomes a lot harder, also mixed in with C vulnerabilities (e.g. heap exploit).
That's it for the education side, now for the work side.
-----
My insight is, there are two types of companies:
- Tech companies (they don't care about things like OSCP)
- Traditional companies (they care a lot about things like OSCP)
The job ads that I saw for tech companies, or tech-related companies (e.g. Airbus [1]) were quite deep. Most of them require deep C/C++ skills with binary stuff and less on the web side.
The job ads that I saw for traditional companies were more web-based, had no clue about binary/low level stuff and terms like OSCP were mentioned quite often but not always.
My friend now works at a traditional company. He noticed a few things that the article doesn't touch (I skimmed it, I might be wrong).
- The level that he needs is at most medium hack the box level (technically)
- The level of social skills that he needs is quite high, because you're always telling some IT team that they didn't secure their shit properly
- The level of political skills that he needs is quite high as well, because not only do you deal with the IT team, you also deal with all the managers relevant to it
So yea, that's what I know. So the resources that this article gave were quite good for getting a job at a traditional company as a pentester, because it's more or less what my friend did. However, if you want to work at Google or something, I think another path is required that probably starts at VUSec.
FYI, VUSec is the systems security department at the Vrije Universiteit Amsterdam.
Btw, I'm for hire as a junior pentester or junior reverse engineer.
Learning all this technology without understanding the fundamentals is a waste of time.
Most certs are overrated. They don’t actually test your understanding that well. The people who care a lot about certs are people who you probably don’t want to work with. They’re just a way for the IT guys who run the cert programs to make extra cash. By all means, if your company is willing to pay for cert training get it but don’t waste too much time studying for them.
In order to find vulnerabilities, you need to understand how a system works, and how all the parts that lead up to it work. You'll ultimately want to understand how $high_level_language ends up as bytecode that executes on the CPU, and if/how you can modify/manipulate that. And a bit about the underlying hardware and electronics never does any harm for some rowhammer type attacks.
If you want to defend and secure a system, you need to understand it, and all its dependencies, and the assumptions it makes. You'll want to understand the hardware, and how it's secured etc.
For networked systems, get a really good understanding of TCP, UDP and IP. Learn how firewalls work.
The aim is to get to a point where you know the fundamentals and how things work to the point there's no "magic" in how the computer works - you know enough to explain a PC from reset vector through to UEFI, bootloader, OS load, software load, network exchanges, etc. And similar for an IP network - you want to know everything about subnets, how VLANs work, how tagging works, how 802.1x works, how WiFi works, etc. And this is just the start!
You'll struggle to secure something you don't understand - this is why $bigcompany can't secure their basic IT network - those responsible didn't understand the basic principles, or how the moving parts worked (either on their own or as part of the bigger system), and it ends up compromised by someone who does understand those principles.
I haven't heard of any of the rest, beyond CEH (the "joke"), and OSCE (just next-level OSCP).
A lot of people do get OSCP (for it's perceived value) and CEH (as a box-ticking exercise), and the former is of definite benefit, but I wouldn't call any of them necessities.
The roadmap seems more of a completionists reference rather than anything else.
All that said, they do seem to know what they're talking about (particularly The CEH joke)
Those certs are for self study only, the applicable value for them in the hiring process is non existent. No one knows who they are or what they do. Used to be a huge advocate of those certs until I actually bought them, then I immediately regretted it. It's been a few years now but I had an awful time with the latter; buggy, filled with errors, typos, non working software. Back then at least, you had to spend hours fiddling with with the settings just to get it to work at a base level. The eJPT itself is extremely basic, it's just using like 5-10 basic techniques to retrieve a few flags worth of info. Really didn't like how the modules were set up. The main resources are powerpoint slides to cover all the text info, then you may have a few minute video occasionally that explains 1 topic barely. The labs would come with lab guides that were all but useless. The authors are Italian so typos and grammatical errors are rampant.
Curiously enough back when I bought them, they sold their courses individually and they were insanely expensive. Looking at them now, it seems they went away from that and now offer a one for all subscription of 2k/year. The eCPPT alone cost me almost that back much when :/
Since then it seems the company has kind of given up. They used to be pretty active on social media trying to advertise themselves, now they barely ever post. It's like they've given up and are just maintaining the content they have until the ship sinks.
If you can get your company to pay for the subscription, go for it. If for nothing else, just the collection of powerpoints and curated information. Other than that, I'd stay away.
Security is much more than simply breaking stuff. You need to understand the fundamentals, CIA triad, risk, misunderstandings that arise from the fundamentals, issues that generally arise with security due to the context etc. Debunk also some common myths around security. Fundamentals can land you in tables that technical skills won't. It is one thing to land bugs and another to be able to sit in a meeting with a guy from engineering and reason with his team and reach an agreement. Generally, working with non-security folks is hard and knowing the fundamentals helps. This also requires soft skills. Know your limits and be honest about them. Also, it is good to listen to people and their concerns. Generally, soft skills are super important in security because in most cases your opening statement is going to be one of the following: - I found some bugs that I want to discuss with you. - You did X which violated that policy and it rang an alarm in SOC. - We have this issue and I came up with this plan to build this to address it. Being able to calm the other side is crucial or you risk derailing the conversation. Also, being able to write code helps a lot. As a matter of fact, I forced team-members to work for other teams for two months. Not only they brought skills back, my team now had an understanding of their work and potential pain points.
Being able to understand the pain of the other side and also come up with solutions (incl. writing code) If I started again, I'd do the following: 1) Understand the fundamentals and the limitations 2) Build stuff. It helps relate with people. 3) Break stuff. It's fun and useful to understand what went wrong. 4) Have a broad knowledge but focus on specific fields. Some people like defending, some people like attacking, some like building stuff. 5) As every job, it has its laundry list and boring tasks that people need to make. Yes, Excel spreadsheets are a thing in infosec. 6) Don't focus too much on certifications.
Worthy reads [1] https://www.freecodecamp.org/news/so-you-want-to-work-in-sec...
[2] https://lcamtuf.blogspot.com/2016/08/so-you-want-to-work-in-...
Edit: Saw this[3] comment. That comment reminded me of something. We've had, time and time, candidates with certificates that could do exploit stuff but couldn't use SSH. One of my first hiring questions was "How do you use SSH" and "How do you delete files from the terminal". I wasn't sure whether this guy was making fun of me or my resume sucked. Apparently, the guy was fed up with people not knowing to use a system that he started asking such questions regardless if you had a Ph.D. in Computer Science. [3] https://news.ycombinator.com/reply?id=25814333&goto=item%3Fi...
I have mentored 4 people into security within the last 3 years, 3 from IT and one from general sales (of golf carts), and my advice is always the same to them all. 1. Start the networking game immediately. If I was to guess, I would say 2/4 or 3/4 infosec hires are because the new hire knows someone on the infosec team before applying. Find your local infosec meet ups, (They still meet virtually, and soon in person again). Start going to local infosec conferences (look into bsides), and look for community hosted events. Infosec is full of nut jobs who think its a good time to spend hundreds of hours hosting a CTF for no freakin reason other than it is fun. Go to these, get to know the local infosec community.
2. While doing #1, Start Getting a general understanding of all areas of IT. Know what helpdesk does, what windows admins do, what nix admins do, what developers do, what network admins do, and of course what security analyst/engineers do. Develop the skills necessary so that you could confidently do the entry level job of the IT vertical.
3. While Doing #1 and #2 Focus heavily on identifying what aspect of security you want. Like all IT verticals, once you get into it, there are a million specializations, identify if you want to go Offensive, or Defensive. If you are into Risk and Compliance, SOC analyst, Solutions Engineer, pretesting, red team, exploit development, the list goes on and on and on. For the most part, identifying Offensive or Defensive will be enough. There are probably 5 Defensive Infosec jobs for every 1 offensive job. And there is plenty of opportunity to switch to 'the other team' during your career. And just because you are defensive doesnt mean you will NEVER do any offensive work, you will dabble in it weekly/monthly, you just will be like 90% focused on defense. And for those reasons I usually recommend people trying to get into infosec to try and land a defensive infosec role for their first infosec job, even if they know they ultimately want to go offensive.
4. Pick up at least one cert focused on either offensive or defensive infosec (depending on what you want). I specifically recommend OSCP for offensive, and I recommend Sec+ for defense. This is not to develop skills, but for those other 1/4 or 2/4 hires that are not placed by networking. The reality of our world is that Certs get you past the HR filter. These certs are specifically for landing you interviews, no amount of certs will help you perform well in an interview, and if you only do certs for training, you will 100% fail every single interview. Getting a cert almost always increases the number of interviews to places where you do not know someone.
5. While doing #1 and #4, and after #2, #3, focus in on what you find interesting about infosec. Try to become an expert on that area. Not only should you learn about that area, you should learn about every technology that supports that area. If you think webapp security is interesting, learn every single piece of technology that is even peripheral to webapp (A lot of stuff). Security is a mindset, not a skill set. The knowledge a nix admin has and the security engineer have are similar, the difference is mindset and priority.
Once you are working on #5, you should start applying full force. You 100% can apply while you still know absolutely nothing, but odds are against you, but still dont let an opportunity pass you up. The first infosec job is the hardest one to get.
If you really want to do security, then my advice is to either look at some dedicated security consulting shops that do penetration testing (and be prepared to take a pay cut), or alternatively use your software development experience to pivot into an application security role. From there, you might find it easier to get involved with some offensive security efforts through that.
They might still be doing virtual events, having some speakers etc. Get yourself known. I have been able to get junior people straight out of college/university into roles by getting them into the "networks". There's a worldwide shortage of security people, caused partly by the inability of the people who need them to efficiently hire them (other causes include wanting top-level skills for bottom level pay, and blaming lack of people for their own lack of willingness to pay).
The more you get known in your local security community, the better. After a while, perhaps they'll be interested in a talk from you about something as well - it gets you seen and known, and it's much easier to break into security when you're known.
Go to your local security meetups, network, meet people. Chances are most of the people you talk to are hiring or know people who are hiring.
Get yourself a blog, write about your security research, write about your experiences with CTFs.
Showing that you care about security enough to do it in your own time is worth more than any cert.
Definitely this. And if they like you, and their company isn't hiring, they might even be able to get them to hire you. Good and enthusiastic security people are hard to come by, so you take the ones you can get, if times are good and you think you might need more soon!
And even if they aren't hiring, chances are they will be able to make a personal introduction to someone who is hiring - at least in the local networks I've been involved in, there's more demand than there is supply, so people are generally pretty willing to help you make connections with the right people. And at the back of their mind, they will also be thinking how they can always go to you in future to get out of their current place(!)
edit: They also give a ~$25k-$35k stipend plus tuition, security certs, books, etc. It's a pretty solid deal IMO.
But certs are an unfortunate necessity in a world where fresh college graduates without a days worth of experience in IT or Security are pre-filtering resumes. Certs ARE worth it, to get past HR. I always tell everyone who wants to get into security that the first infosec job is the hardest to get, and for that, you need to play the HR game, and that means a couple certs. You need to sit down in front of the hiring manager for an interview to get the job, your hiring manager will know your cert means nothing, almost guaranteed he never even asks you about any of them.
Your resume means everything to get in front of the manager, then your resume means jack shit to the manager. It is stupid, but is the world we live in.
You can get hired into infosec without the certs though, and that's know the hiring manager or know someone on the team you are applying for. Hiring managers can tell HR "I want to interview Joe Somebody, he said he will apply this week", and in security, id say more than 50% of the hires are indeed that. So to do this, go to the local professional meetups that meet monthly, go out for beers with the people, go to the local conferences and make friends with many people already in the industry, maybe do a talk at the meetups or local conference. Then when a position opens up at a place where there is someone you know, you now can get an interview.
But you really should be doing both at once. Most competent developers or IT people can pass Sec+ blindfolded, you most certainly do not have to take the class, at MOST skim the study guide book once, and your almost guaranteed to pass. It is a joke, everyone in the industry knows it, yet if you could dramatically increase your chances of getting an interview while you are taking the time to develop those relationships, what idiot wouldn't?
But I've been in security over a decade, and have hired at smaller boutique pentest companies, and multi billion dollar companies. In all cases, the CVs/resumes come straight to us, they never go via HR.
Despite this, as you say, I've usually seen CVs/resumes come straight to the hiring team - the first thing an effective security lead does ensure there's no pre-screening on CVs, as they want to see the "unconventional" CVs as much as the conventional ones.
There's also companies that actively have their techies go out and fly the flag, post on the /r/netsec or HN hiring thread, and give a point of contact straight to a personal or team mailbox.
[1] https://github.com/guidovranken/cryptofuzz