I wouldn't automatically discount someone who put the OSCP on their resume, like I would the CISSP, CEH, and Security+. Any experience, even non-pentesting, would probably trump it though.
I wouldn't automatically discount someone who put the OSCP on their resume, like I would the CISSP, CEH, and Security+. Any experience, even non-pentesting, would probably trump it though.
Avoid certification.
I started MicroCorruption and RE flummoxes me. I keep coming back to it because I can tell how weak I am and it has pissed me off for 2 years. Even in OSCP i get bent out of shape on my insufficiency there and never focus on other stuff.
I don't want to be a Metasploit jockey. Where to from here? Online CS courses in C and ASM work my way up? I don't have a degree in it.
You don't have to do RE to be in software security. There's virtually no assembly-level RE in web application security, and very little of it in mobile security. Both of those specialties are more lucrative than RE, a specialty where maybe the top 10% go to high-status RE and exploit dev careers, and the other 90% go to low-status malware analysis and SOC jobs.
My advice is to pick a technology stack you really like and get comfortable with it at a nuts and bolts level, and then build security expertise on top of that. Maybe that's iOS and Swift, or maybe it's web and Django, or maybe it's distributed databases. Pick something, get good, and then be a security expert for that thing.
IMO that should be avoid current certification. Avoiding all certification for all eternity would imply that training decent pentesters/hackers is something that cannot be done in a controlled methodical way. Which would be a setback for the entire infosec industry, IMO, because I do think that such a thing (infosec is not a special snowflake) is possible.
I think OSCP is actually a big step in the right direction. The harder challenges in their training network force you (and encourage you) to deeply investigate the underlying security issue. That part of the training actually focuses on the underlying conditioning that you need to become a good pentester, as shown by their slogan 'try harder'.
It's the same thing that armies the world over do. The army also realized that knowing everything there's to know about tactics and how to operate a weapon is not enough, soldiers also need to be aggressive and need to be conditioned to be able to effectively engage an enemy. So there's training designed to increase a soldier's willingness to fire upon enemies when ordered to.
The same goes a bit for this training, where underlying simple technical guidance is provided at the start of the training, and later a trainee is left to themselves and pushed to investigate on their own, something that I'd recognize as one of the cornerstones of a successful hacker.
Still, I'd also avoid hiring a person for a technical position if all they can show is a CISM/CISP/w\e
I do like the ones that offer memory corruption/exploitation challenges, but those are few and far between.
Why? Is that something that can hurt your abilities, or your employment prospects?
As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications (the former is usually where all of the really interesting work is done). So wasting time on a certification that won't help you is putting you behind people that don't waste their time with certifications.
> Certification in a field such as vulnerability research
OSCP is basically tool-based network pen testing with a bit of outdated websec and buffer overflows thrown into the mix. It's not "vulnerability research" in any meaningful sense of the word. They have some other certs (OSCE) that might purport to target that domain, but idk much about them.
> As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications
So apparently OSCP won't get you a job at Matasano - but they're not the only game in town, and a lot of other security shops with less name recognition and lower standards do in fact use the OSCP as a positive signal.
No, it won't be l33t but it will be a job that they can use to transition to those fancy schmancy companies whose founders are HN regulars.
So in that sense, they do care about OSCP.
Here: https://rhinosecuritylabs.com/company/ lists OCSP and CISSP and a bunch of other certs. So I guess they care about that.
Now, how about you name the pentesting firm that does not list any certs.
How about if they just had a job in Vb.net form a year and then worked other languages for five years.
I guess it's a very fine difference.
A lot of good employers know this, and put zero weight on certa. Or as tptacek mentioned, possibly even consider it a bad thing. If I see a CV with CEH, I go in with an open mind but aware it's probably going to go poorly. I'd rather see someone who bought a stack of books, wrote some vulnerable code to attack, asked for advice from people; demonstrated they could throw themselves in and make it up as they go along.
Rather avoid certification if you just want to have 20 lines on your resume to look like a ninja and brag. I'm a hiring manager in infosec, and same deal if you brag about certs I start to tune out.
So how do you get through HR wall? Padding CV with keywords is a common way to get an interview. I'm an embedded system engineer looking to move closer to IT security, so how do I get there without experience and certifications as virtually all jobs require one, another or both (except junior positions, but I'm too old to start from the very bottom)? I do learn a lot on my spare time, but you still need to get a chance to demonstrate your skills, which is impossible if your CV is discarded as "requirements are not met" (a.k.a not enough keywords on CV match the ones in job description).
A decent company will have your future colleagues heavily involved in the hiring process, and they'll know how to chat to you about security.
This elitism is not helpful. There are finite employers in the world, and many of them do screen based on keywords. That's reality. Applicants who are entering the job market might not always have the luxury of disregarding n% (where n most likely > 75) of their potential employers based on stuff like "oh well any real company wouldn't screen my resume..."
But chances are if someone is browsing HN they're at least genuinely engaged enough to do better than that. You're advocating for people to shoot for average, I'm suggesting to not settle.
From my perspective, I'm advocating that people don't inadvertently shoot themselves in the foot. They might not yet be qualified to work at Matasano or [insert top tier security shop here] : not everyone is.
Assuming someone isn't (yet) qualified to work with their dream employer, what do you suggest they do? "Don't settle" in that scenario sounds a lot like "be unemployed". I'm straight up saying it's better to build up skills at a job - even if that job isn't their endgame.
But I think in this case, the issue might be that rather than one job being the first step to the other, we're talking about two totally distinct tracks. If a company is sufficiently shoddy and certification-happy, it's possible that they don't even provide meaningful experience for someone seeking the top-tier options. You might be better served by hardening systems at some general software job than getting an entry-level security job and blindly throwing Nessus at client's systems.
Of course, but you still have to get to them first as no sane company makes their engineers to do 1st round CV screening (especially for publicly announced positions where tens or hundreds of CVs are applied). From my personal experience, technical interview with an engineer is usually only on 2nd/3rd round, so we are back to square 1. Yes, I know the best positions are filled through networking and recommendations, but that's not an option when you live outside of tech bubbles.