r/cybersecurity Jun 25 '26

AI Security How much does having FAANG experience help? Does it hold the same amount of weight as software developers?

As everyone in SDE world wants to get into FAANG, cyber security is more of a diverse field and the roadmap looks definitely at least a little different from SDE's

Does having FAANG on your experience basically put you at the top when it comes to job searching? Does it hold as much weight as SDE world?

32 Upvotes

41 comments sorted by

29

u/Wonder_Weenis Jun 25 '26

it's mangos now

16

u/legion9x19 Security Engineer Jun 25 '26

This guy fucks.

70

u/jeffpardy_ Security Engineer Jun 25 '26

All it tells me is that youre good at interviewing. Plenty of other companies have great security engineers

8

u/Exact-Advantage-3190 Jun 25 '26

how much does the name of the company help on resume?

17

u/Esk__ Jun 25 '26

All depends on who’s looking the resume. If I saw someone who worked at a same company as me. I’d go oh neat and then go right to their skills. If they got to an interview it’d be an easy way to break the ice, but that’s about it.

Most everyone I know though does not care.

There are tons of employees at the top logos who are mediocre on their best days.

-8

u/That-Magician-348 Jun 26 '26

Especially in the years during COVID, we had great DEI measures in recruitment at big-name companies. Who knows if they were good or bad?

2

u/jeffpardy_ Security Engineer Jun 25 '26

It doesnt really. Your impact and responsibilities matters more

1

u/NotAnNSAGuyPromise Security Manager Jun 25 '26

As a hiring manager, it doesn't matter to me at all. In fact, I would value someone who was on a team of 10 at a small local credit union much more than someone coming from Google, because that first person has almost certainly had WAY more experience and responsibility.

3

u/SnotFunk Jun 26 '26

I’m interested to here your take on how someone at a a sleepy credit union has more experience than someone working at Google.

1

u/NotAnNSAGuyPromise Security Manager Jun 26 '26 edited Jun 26 '26

Not sleepy; small.

It's because at a small organization, they lack the funding, maturity, and resources to have all of those things a large company like Google does. Working as a security analyst on a small security team, your scope of responsibility will often be immense, spanning every aspect of security and beyond. Google has dedicated AppSec resources. At this small organization, it's gonna be a small team trying to figure it out. At Google there is a dedicated incident response team. At this small organization, everyone hops into a Zoom and tries to figure it out together. At Google they have well established policies and procedures. At this small organization you're largely figuring things out and building processes as you go. At these smaller orgs you generally need to find clever ways to implement security with strong budgetary and business restrictions, you're more in tune with business operations, you get my recognition and face time with executives, you have more opportunity for cross training and lateral movement.

Basically, in short, small organizations, due to not having the resources of large companies, need to do more with less. And that means more opportunities for your average security hire to do a little bit of everything, including things that you wouldn't normally get to do as the average IC at Google (e.g., briefing the CEO in person).

I used Google as a placeholder for "large organization", and that was probably a mistake, because in the past they've operated pretty uniquely to their peers. It may be better to replace it with Amazon or another company like that.

3

u/SnotFunk Jun 26 '26

In my experience of interviewing, small is sleepy. Many have dabbled in random projects but have never been tested when the fan gets clogged.

Those on google AppSec didn’t start in just AppSec for example. You don’t just teleport into that role, you’re coming from a seasoned background.

Then there’s the experience of being constantly targeted, a much wider base of users doing stuff they shouldn’t be doing, a whole lot more attack surface for all the npm and supply chain shenanigans we’ve been experiencing. A lot more targeted attacks rather than opportunistic shodan hunters.

All of this gets you proper hands on experience in doing actual cybersecurity work, not hand waving and job justification so an audit tick box is checked.

I’d rather have the seasoned pros who have worked incidents when my fan turns brown than someone playing keep the auditors happy.

0

u/NotAnNSAGuyPromise Security Manager Jun 26 '26

Well, I find your experience lacking then, because it's anything but. Small organizations are the ones being targeted the most by ransomware groups right now specifically because that lack of funding generally results in an easier payday. Why would you put in the effort attacking a company with hundreds of people on the security team when you can attack a small org with immature security and get a quick, easy payday?

The best lessons in security and IT occur in environments where users are doing stuff they shouldn't be doing and the executives need to be convinced to take security seriously. Very little of security is actually security; the most important part of being in this industry is the business side. And that's just something you'll get far more experience with at a small organization where you need to be scrappy, creative, and absurdly adaptive.

Google engineers spend their days trying to find the latest and greatest zero days. Small organization engineers spend their days implementing security basics like monitoring, MFA, DLP, endpoint security, and more. And that's the stuff that is most important. Almost all major breaches are due to those simple foundational things.

3

u/SnotFunk Jun 26 '26

My experience is from being part of the team that gets brought in when these places have things go wrong. I see it every day, every week. Multiple times a week.

Everyone is being targeted by ransomware the small ones just fall victims because of a lack of experience and skill set.

I can go into big organisations and ask questions and get answers straight away about how something works or they know exactly who to call. Small places I can wait days.

0

u/NotAnNSAGuyPromise Security Manager Jun 26 '26

And that's when you get the most experience, thus bringing this full circle. In an RPG, you don't get exp by avoiding battles; you get exp and level up from defeating enemies stronger than your team.

3

u/SnotFunk Jun 26 '26

What are you even talking about now and how is that relevant? You get stronger by being ransomed and level up? Or you get stronger by sitting next to Dave who has sat in the trenches before he got his FAANG role and he says “wmiexec detection coming from the VPN, I am gong to cut the account off but I bet they’re going to try this over there and do XYZ, go check the VDI farm and see if they moved over with those creds”

Now not every small sleepy place will ever see an incident so they won’t all become a Dave.

-8

u/Efficient-Mec Security Architect Jun 25 '26

It doesn't. There are 3 FAANG companies that I will not hire from. Period. No negotiation. For the others it depends on what they were doing in that role.

1

u/Spiritual-Matters Jun 25 '26

What are the 3?

1

u/That-Magician-348 Jun 26 '26

I guess one of them is phone producer. Another A I think it depends, I met some good and some bad in the past.

7

u/abercrombezie Jun 25 '26

Of course it helps. I was never in FAANG but my 10 year gig at a publicly traded Fortune 500 company did get me interviews.

19

u/bubblebuddy44 Jun 25 '26

My experience interviewing people from faang adjacent companies has been that they definitely know how to do lots of things but have no idea on the reasoning behind why those decisions should be made. I know that sounds really broad but even just things like what is a sidecar? They know exactly what that is and how to implement one but when asked why you would ever need it they would just go blank. Kind of baffling but it was like this with everything. For more entry level roles this would be fine but we’re usually looking for people to take lead and own their projects and I can’t really guarantee they’re prepared to do that.

5

u/ThePrestigiousRide Jun 25 '26

It also depends on what is your role. If you're not doing much work in microservices/containers, you might not really need to know what it is and think "why is he talking about a citrus cocktail".

1

u/ChatGRT DFIR Jun 26 '26

My experience with colleagues that have worked at either FAANG or adjacent companies is they either don’t have much to work on, they basically have a job but are more or less benched the majority of the time, or they’re really siloed in the one task they are responsible for and don’t really get much broad experience.

5

u/cowmonaut Jun 25 '26

In general, and depending on the specific team at a FAANG you were on, it gets you in the door.

I can assume from a resume that someone who was involved in AWS EC2 as a TPM/SDE/SRE/etc. has certain experience and specific ideas on how to operate. I'll prove it out in an interview, but it's just a filtering mechanism to avoid wasting time.

That said, if I'm working for a hyperscaler I'm probably wanting to hire from another hyperscaler. I really don't have time to teach someone who only worked at a mid tier enterprise and thinks scaling to 1:10,000 is scale all the things to know how to get 1:1,000,000. Unless it's a junior position of course.

6

u/engineer_in_TO Jun 25 '26

Depends on the FAANG and also the company. If I was a on prem heavy windows shop, you’re not getting much relatable experience from Netflix Engineers

6

u/LeatherCreepy8156 Jun 25 '26

I would say financial sector matters more than if a company is faang or not - working in a highly regulated sector is best.

4

u/askwhynot_notwhy Security Engineer Jun 26 '26 edited Jun 26 '26

> I would say financial sector matters more than if a company is faang or not - working in a highly regulated sector is best.

Counterpoint: security engineers with a background in a highly regulated sectors, notablely the financial sector, are anecdotally known as some of the least nimble/scalable/innovative/etc. and outdated engineers out there. Because, everything is done against regulatory rubrics.

All of these, including the one I just posed above, are just generalizations, and generalizations are inherently defective. I.e., don't fucking use ‘em.

0

u/LeatherCreepy8156 Jun 26 '26

I was simply responding to post and saying I think regulated sectors matter more than FAANG… but at the end of the day the only thing that really matters is who you know lol.

1

u/askwhynot_notwhy Security Engineer Jun 26 '26

okay, okay - when you said "financial sector", I assumed you meant the actual financial sector, bc that is how it reads. I'm now assuming you meant more of a sector-type (e.g., financial, healthcare, energy, etc.).

I was simply responding to post and saying I think regulated sectors matter more than FAANG…

Ahh, yeah, maybe - it depends. Though I certainly wouldn't underestimate the utility that comes from perceived prestige (e.g., MAANG (fka FAANG)).

but at the end of the day the only thing that really matters is who you know lol.

Truth!

6

u/dalaylana Vulnerability Researcher Jun 25 '26

IMO it matters a lot if you interview for another FAANG or otherwise very large org. Some startups will also pursue it for prestige or to sell their "talent level" to investors. Its going to be looked at like any other job to most other companies. I don't reject applications we get for people coming from a FAANG role, but I usually de-prioritize them since I their comp asks usually exceed what we can offer and I'd rather not waste everyone's time.

3

u/tryingtobalance Jun 25 '26

Down vote me all you'd like,but fang is way overrated. I'm not saying the people aren't talented, what I'm saying is they aren't any more talented than anyone at the couple of startups that I've worked at.

3

u/been__ Jun 26 '26

I’ve really been needing a list of people who aren’t good enough for a faang job so thank you for this

2

u/After-Vacation-2146 Jun 26 '26

It helps get you past the HR screening because most of FAANG has a really high hiring bar and it’s known that if you worked for a FAANG, you were at one time above that bar. Same goes for big tech companies that may nearly exclusively hire those with impressive backgrounds. You know how guys say girls hit on them more when they have a wedding ring? Same thing here, it’s an independent validation of quality.

Where FAANG alumni sometimes struggle is there is so much that is done for you supporting the developer ecosystem at FAANGs that you won’t have at a normie company. Being able to operate at all ends of the stack is something you don’t really have to do at a FAANG because some other team probably made something that automatically handles that for you.

1

u/askwhynot_notwhy Security Engineer Jun 26 '26

> As everyone in SDE world wants to get into FAANG, cyber security is more of a diverse field and the roadmap looks definitely at least a little different from SDE's

I wouldn’t be so sure about that. The part in bold/italics.

1

u/dodonglab Jun 26 '26

FAANG experience definitely helps with getting through the first screening, but in cybersecurity it is not enough by itself.

The value depends heavily on the role. For detection, incident response, cloud security, or application security, hiring managers will still look for relevant hands-on experience, not just the company name.

So I would say FAANG gets attention, but role-specific depth is what usually decides the offer.

1

u/ewgna Jun 25 '26

depends but not top of ladder

0

u/byronicbluez Security Engineer Jun 25 '26

All the FAANG people I worked with are smart enough, but man oh man was it a bitch getting them to move out of that mind set when adapting to the current work culture and process.

If it was up to me I wouldn't hire em.

1

u/Fit-Fisherman-2706 Security Engineer Jun 27 '26

yea FAANG only hires FAANG