Login Register






Anyone in the InfoSec or Cyber Security sector? filter_list
Author
Message
Anyone in the InfoSec or Cyber Security sector? #1
IF you are working towards or already in the IT Security, Cyber Security, or anything related to the field, I would be most grateful if you were to provide any tips pointers that will help me get my foot into the door.

Some things I am working towards are: CompTIA A+, Security+, Network+, then by July I believe I will be ready to take a CEH and CPT bootcamp from InfoSec Institute. I have all of my generals finished to transfer to a major university and I am taking all of the computer science courses required for my lower division major.

Thanks for your time if you have made it this far.

Reply

RE: Anyone in the InfoSec or Cyber Security sector? #2
There is no easy answer. It does depend on the field, but equally it depends on the position.

If I assume you are looking to get on board as a Network Security Analyst, Security+ is a good cert to have. I would also recommend any Cisco certs, as they are invaluable to just about any kind of technical job, especially for networking.

It's less about the degree now days but of coarse degrees and certs are still valuable, just make sure you have plenty of hands on experience.

If there is one thing I would recommend after a decade of IT work, it's that you need some hands on experience. Get a lab going in your bedroom if you have to and break stuff!

Cheers
(This post was last modified: 12-16-2013, 10:25 PM by Cloud_mybb_import25633.)

Reply

RE: Anyone in the InfoSec or Cyber Security sector? #3
Sinfony,

I am working towards a position as a penetration tester hopefully in a small group, I would like to test for vulnerabilities in different organizations. I have an overall understanding of the route that you want to work towards so I can give you my recommendations on that. I would work towards the basics of course such as your CompTIA's (A+, Network+, Security+, Linux+/LPIC-1). It is important that you go out of the norm and complete your Linux certification not only because you will work with Linux distro's once you get the job but the Linux cert can convert into a 3-1. When I passed my CompTIA Linux+ exams I was able to also hold the title/certification of LPIC-1 and the Novell Certified Linux Administrator as well as 2 others from Novell. All you have to do is apply and fill out the paperwork and you are granted those certifications. I highly recommend working towards your EC-Council certifications, although expensive they are very well known and respected in top organizations. If you have any other questions about your job route or certification route, fell free to email me or pm me or I am usually in the IRC chat most of the time.

Reply

RE: Anyone in the InfoSec or Cyber Security sector? #4
InfoSec isn't an easy field to break into. It does depend what type job you want in infosec. Generally speaking get your CISSP Associate(you need work experience for the full thing). CISSP is the standard for any corporate position its needed to get past the HR selection. If you want to go government or work government contracts then CEH is your standard since it meets the ANSI 17024 standard which is a requirement for government work.

That said CEH is very widely considered a joke; google around. CISSP is very corporate based around policies and theories so if that suits you its not necessarily a bad choice.

If you want to get into penetration testing then certs don't matter. OSCP is about the only cert that has any bearing and its not much in the pentesting world but atleast it means you had to do something to get it besides a brain dump. Basically security certifications don't matter in pentesting, but corporate world they can help.

With that out of the way the network related certs and other IT areas are not bad to have they help with indicating that you have foundational understanding.

As for getting your foot in the door there are two major tips anyone in industry would give:

1. Networking: conferences, local security group meetings(citysec, 2600, 2621, local defcon meetings, etc), play and local hackerspace. Basically you want to make friends who do the job you want and have them recommend you for positions inside their own company. If you want to get into pentesting playing CTFs and getting involved with a CTF team is another good choice.

2. Do something. Better than having certs is actually being able to show you've done something. Obviously what you do depends on what you want to get into, blogs are pretty common especially with technical content can look pretty good. Even better is to build something or hack something you can show off. Doesn't need to be amazing but as with a lot of IT fields hiring managers like to see that security is more than just another job for you. Seeing that you practice in your offtime reflects well.

Those two things will bring you above most of the other applicants but you've got to be passionate about working in security to make it in and last.

Reply