Skip Navigation
Mentorship Monday - Discussions for career and learning!
  • I wouldn't worry about certs to start, especially not OSCP. Since you are in the software/dev space, I would consider security roles in the AppSec or CloudSec space as places to jump first. For that, consider going through PortSwigger's web security academy (free) training online to learn more about web vulns, their impact, how to mitigate, etc... If you want a cert, consider one from a cloud vendor and apply to jobs that use that vendor. If you can do even basic scripting, understand app-related vulns and use a few appsec tools then you should be an easy hire for a lot of places. (That said, I've been hearing the market for infosec is atrocious right now).

  • Mentorship Monday - Discussions for career and learning!

    Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

    0
    What are You Working on Wednesday

    Weekly thread to discuss whatever you’re working on, big or small, at work or in your free time.

    6
    Mentorship Monday - Discussions for career and learning!

    Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

    3
    Off-Topic Friday

    Wanna chat about something non-infosec amongst those of us who frequent /c/cybersecurity? Here’s your chance! (Keep things civil & respectful please)

    3
    What are You Working on Wednesday

    Weekly thread to discuss whatever you’re working on, big or small, at work or in your free time.

    3
    Mentorship Monday - Discussions for career and learning!
  • Never been in the QA world myself, but as someone who has spent a fair bit of time in AppSec, I've encountered Selenium the most. 🤷‍♂️

  • Mentorship Monday - Discussions for career and learning!

    Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

    0
    Off-Topic Friday

    Wanna chat about something non-infosec amongst those of us who frequent /c/cybersecurity? Here’s your chance! (Keep things civil & respectful please)

    0
    Mentorship Monday - Discussions for career and learning!
  • When you say "transferrable in QA" do you mean, languages useful for QA folks that transfer out? I'd argue any/all of them would be for appsec folks.

  • Mentorship Monday - Discussions for career and learning!

    Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

    5
    Mentorship Monday - Discussions for career and learning!
  • Not a bug bounty hunter myself, but it seems like one of those things that you just have to jump into and start trying to do. So many bounties seem to be pretty low-hanging fruit type of stuff. The payouts might be either LOW or non-paid, just recognition type stuff, but seeing an accepted bounty submission come back does a lot for your confidence. It's like CTFs in a way. Getting into CTFs seems intimidating at first, but then when you go actually do one and you have some level of success, it starts to feel a bit more approachable, you get more XP and you do better the next time.

    You could also check this out https://www.bugbountyhunter.com/zseano/ and anything/everything from https://portswigger.net as that team is the best I know in terms of cutting-edge web app research.

  • Off-Topic Friday

    Wanna chat about something non-infosec amongst those of us who frequent /c/cybersecurity? Here’s your chance! (Keep things civil & respectful please)

    0
    What are You Working on Wednesday

    Weekly thread to discuss whatever you’re working on, big or small, at work or in your free time.

    6
    Mentorship Monday - Discussions for career and learning!
  • That's a loaded question 😅. One that can be answered in a few different ways... From a technical perspective, "infosec" is a relatively vast field comprised of a lot of sub-disciplines, so from a tooling and procedural perspective, it varies from job to job. Some would argue a lot of what we do is just theater, and for many orgs and many "pros", this may very well be true. At the root of it all though, you could say our job is to ensure the Confidentiality, Integrity and Availability (classic CIA triad) of data/systems, keeping in mind the balance/tradeoffs between security needs and business requirements. To do so, we employ a variety of tactics, techniques, tools, methodologies, frameworks, etc... Another way to boil down what security folks do is in the lens of "risk". Most business and IT decisions in general come down to risk-based decision making and security is no different. Security teams should understand the risk introduced by the threat landscape coupled with the respective data, attack surface, business assets, etc... to help inform the business how to reduce security risk to acceptable levels.

    Hopefully this answer isn't too vague and non-answer-ey!

  • Mentorship Monday - Discussions for career and learning!

    Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

    5
    Mentorship Monday - Discussions for career and learning!
  • Titles in the security world are kinda a mess. Generally I just look for "-security engineer" titles. So in this case you would probably find "Cloud Security Engineer" or something. Look for security engineer roles that have anything cloud-related in the job req and you are probably on to something.

  • What are You Working on Wednesday

    Weekly thread to discuss whatever you’re working on, big or small, at work or in your free time.

    0
    Mentorship Monday - Discussions for career and learning!
  • Hard to say, especially in this market. But, if you have some coding chops (from DevOps experience) or you have some knowledge of native cloud security tooling (from a Cloud role), then you would definitely have a leg up in getting a security engineer or netsec role (consider that a lot of modern “networks” are largely cloud networks).

  • Mentorship Monday - Discussions for career and learning!

    Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

    5
    Off-Topic Friday

    Wanna chat about something non-infosec amongst those of us who frequent /c/cybersecurity? Here’s your chance! (Keep things civil & respectful please)

    0
    Off-Topic Friday
  • I'd wager most people do. But you certainly hear about all the people who spend their free time doin more cyberz. I am definitely guilty of this a lot of the time. But I've been working harder to disconnect more. Being a parent helps with this as it's pretty mandatory.

  • Mentorship Monday - Discussions for career and learning!

    Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

    7
    Off-Topic Friday

    Wanna chat about something non-infosec amongst those of us who frequent /c/cybersecurity? Here’s your chance! (Keep things civil & respectful please)

    2
    What are You Working on Wednesday

    Weekly thread to discuss whatever you’re working on, big or small, at work or in your free time.

    2
    Mentorship Monday - Discussions for career and learning!

    Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

    0
    Mentorship Monday - Discussions for career and learning!
  • I wrote a bit about the pitfall(s) of "Certification Paths" - https://shellsharks.com/notes/2023/11/14/stop-worrying-about-certification-paths.

    This is coming from someone who has A LOT of certs, and I've learned over this time that it's just not the right way to think about progressing career-wise. You can read more though about certs and some thoughts on what you could take here too https://shellsharks.com/training-retrospective#what-certification-or-training-should-i-take.

  • Mentorship Monday - Discussions for career and learning!
  • Never heard of 'em. I'd say most of those things, while not necessarily "scams", are probably not worth the time you would put into them. That said, if you have free time and they pay, then it is what it is. If you go down that path, make sure to report back!

  • What are You Working on Wednesday

    Weekly thread to discuss whatever you’re working on, big or small, at work or in your free time.

    2
    Mentorship Monday - Discussions for career and learning!

    Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

    6
    Off-Topic Friday
  • Greed. Capitalism. AI speculation. Other stuff ...

  • Mentorship Monday - Discussions for career and learning!
  • Big consulting firms (e.g. Accenture) and the like. Government jobs too if you're close to where those are. Outside that, it's very random which companies have such openings. The bigger the company the more likely it would have a higher diversity of roles and seniority openings.

  • Off-Topic Friday
  • Omg. I too have developed an "affinity" for coffee as of late. Have been thinking of cutting back. There's always tomorrow right?

  • What are You Working on Wednesday
  • I'm a KubeNoob so gotta give you props regardless 😅

  • What are You Working on Wednesday
  • Y'all doin' cool stuff. Rust, K8s, GH automation - 💪 @CodeGameEat@lemmy.world @MigratingtoLemmy@lemmy.world @thadah@lemmy.world

  • Mentorship Monday - Discussions for career and learning!
  • I always recommend Wild West Hack'n Fest. Cool location and the con is pretty good.

  • shellsharks shellsharks @infosec.pub

    Infosec researcher | writes @ https://shellsharks.com

    Mastodon: @shellsharks@infosec.exchange

    Posts 165
    Comments 184
    Moderates