Introducing Chronicle, a new Alphabet business dedicated to cybersecurity
medium.com
medium.com
Can anyone here speak to the "there's already a huge talent shortage" part of this article? Specifically, security is a field I'd love to work in, but I honestly don't see a ton of job postings and I'm unsure as to how one might transition from say a role as a full-stack web developer into a security job.
For example, here's are some things I've been doing as I'm considering a move into a security-focused role:
- Following the industry (podcasts ala Sans mainly)
- Reading books on hacking (currently "The Shellcoder's Handbook")
- Reviewing my comp sci basics (x86 assembly + reading K&R "The C Programming Language")
- Dabbling in some hacking exercises (https://ropemporium.com and https://canyouhack.us/)
Mainly asking because I see statements like the above regarding the shortage of security talent all the time, yet I can't find a lot of guidance either for exactly how one can get started in this field.
[edit]: List formatting
You'll often find people that have experience running automated scans, filling up compliance paperwork, setting up firewalls and SIEM tools, etc. but don't know how to deal with source code or mitigation. At the other end of the spectrum, there's a small number of people who can review code and write tools, exploits, etc. but hate the bureaucratic work. In the middle, which is the kind of person that a startup or small company would want to hire, there is an even tinier number of candidates.
The kinds of things you are doing sound great. Perhaps try to participate in bug bounties, too. One reason you don't see a ton of job postings is that many companies don't know yet they need them. :-) Also, a lot of recruiting might just happen through word-of-mouth or in an outbound fashion. In my limited interactions, I found that the security community can sometimes work like a club or a society, more than in other tech circles.
actually I have noticed this and so we are spinning up a security consulting practice in 2018 looking to address this gap (staffed with experienced developers or former developers). Time will tell if this is a workable approach..
Because once you learn enough of the stuff you start to realize its all bullshit. Compliance (hipaa hitech, pci, sox) and most industry standard practices (antivirus, firewalling) are lipstick on a pig. Very often you have to chose between being secure or standard compliant (for example running antivirus can be a big security hole, or give false sense of security).
Hypothetically, if you have solid experience as a full stack web developer then I would suggest finding a way to pivot off that expertise (web application security, infrastructure, etc) rather than diving into the Shellcoders Handbook, x86, and K&R, which are going to be more tailored towards reverse engineering and vulnerability research.
> if you have solid experience as a full stack web developer then I would suggest finding a way to pivot off that expertise (web application security, infrastructure, etc) rather than diving into the Shellcoders Handbook, x86, and K&R, which are going to be more tailored towards reverse engineering and vulnerability research.
I've been focusing on those areas because they are what legitimately fascinate me. I enjoy web dev, but I'm finding my passion (as indicated by what I like to research and learn about in my free time) is low-level stuff: operating systems, C programming and associated vulnerabilities, assembly language, etc.
The interaction between software and hardware has always fascinated me (1997 when we got our fist computer: How does this hunk of plastic and silicon do that??), and I feel like that's where I want to go long-term.
https://news.ycombinator.com/item?id=16057016
Note that I describe the sorts of skills we seek. (you don't need to have them all) The word "security" doesn't appear because that isn't too interesting or useful. Lots of good people come from an embedded RTOS background. Somebody who just runs a port scanner would not have the right skills.
Second of all, are you looking in the right places, online or physically? On reddit, try /r/netsec or /r/reverseengineering or similar. Be willing to consider the southeastern states.
Making yourself look good to hire is mainly about showing that you have the skills. We hired somebody who had a great story about hacking an overly-fancy parking meter to run code from the tokens. We hired another person who got invited to talk at a conference about hacking a router. Solving some of the DEFCON CTF challenges would look good; they are considered difficult. Contributing to a project like Wine or Qemu or MAME would look good, particularly if you deal with something undocumented.
Is there a reason why security is a focus there?
But if I'd seen that job posting I would have assumed it was some kind of embedded Linux driver development, not a security job.
Florida is the wrong side of the Atlantic for me, but I'll be reading job descriptions more carefully from now on...
Ask HN: How can I learn computer security?
If you are serious about security try to get a job in a security consultancy that does penetration testing, APT and that sort of stuff. They often hire people at a junior level too and build them up. I've seen quite a few people progressing from basic level to advanced using this approach.
One reason for the talent shortage is that security work is to a large degree about keeping up with enormous amounts of information on attack types. If you stop drinking from the firehose for even a few months you're going to miss new types of attacks and new information. And there are precious few systems that help reduce the impact of vulnerabilities... there are some but it's still an area dominated by trivia-like knowledge (I don't mean it's trivial but rather, that there are a lot of "just facts" that you have to know and cannot easily learn or derive on your own).
Ultimately the industries approach to security is not sustainable. We need to systematically move away from insecure infrastructures. Unfortunately nobody wants to do that. First thing that'd have to go - the use of web apps for UI.
Perhaps X is taking on less radical projects than I imagined. Would love to hear others' viewpoints on this as well, though.
1) It's not a part of core enterprise GSuite / GCP offerings.
2) It's announced on Medium, and not on usual Alphabet channels.
https://blog.x.company/graduation-day-introducing-chronicle-...
Hope just use for branding and not try to directly monetize.
disclosure: I have no affiliation with either one but wonder why Google/Alphabet would be _that_ late to the party and offer nothing that isn't already out there. yawn
If you're in a large enterprise you can easily be generating hundreds of thousands of events per second (both in terms of network actions and system events) and you need something to make that manageable and able to generate alerts so that your Incident Response team can respond to actual problems.
No idea really, since all the articles about Chronicle are really vague, but it reads more like a Threat Intelligence Platform + a Threat Analytics Platform.
Sure, that was in vogue at times and some people wasted a lot of money but that over-summarization doesn’t give you an accurate understanding of what actually happened.
Hiring private security or bodyguards is not considered unethical or illegal. Installing alarm systems is not unethical. Am I misunderstanding this?
Google already sells consulting to cloud customers, this seems perfectly natural and I'm not sure how you avoid it.
Quite the opposite, that's how most consulting & professional service companies do business.
Cloud services & security consulting are complimentary.
Conflict of interest would be if Google was doing the hacking and the securing.
I don't think any of them claim sole ownership of the word 'Chronicle', but I'd imagine there will be some "this will be too confusing" back-and-forth.