* If designing and enforcing rules and policy interests you, turn to page 23.
* If deploying and managing complex technical infrastructure interests you, turn to page 12.
* If being a part of teams that ship products is what gets you up in the morning, turn to page 45.
* If being a part of teams that tear shipping or soon-to-be shipping products to shreds is more your thing, turn to page 34.
Which will you choose? I'll tell you what the page says.
0. Learn to love programming in at least one language. The C Programming Language has the most cachet in application security, but for this step-by-step list, Java or Python or Ruby will do fine.
1. Grab a copy of The Web Application Hacker’s Handbook and The Tangled Web
2. Go to the “previous releases” archive at WordPress.org and grab very old versions of WordPress; install them at EC2.
3. Download OWASP WebScarab or Burp Suite Free Edition, both of which are free, and use them to find bugs in ancient WordPress.
If you are at step 0 now and are immediately looking for a new gig in Chicago, San Francisco, or New York, you can also email me directly and get step 1 for free.
Other people should play this game so I can read the other pages, just like I always used to do when these books came out!
I'd love to be wrong, though. I've been wanting to get my hands on some of their training for a while now.
We don't really look at certification or training stuff in candidates (except as a weak signal that someone is seriously interested in doing security, but that's something that's easy to convince us of verbally too), but our recruiting process definitely wants you to be comfortable with code. I think we're similar to a lot of other firms.