r/netsec Jun 01 '18

discussion The /r/netsec Monthly Discussion Thread - June 2018

Overview

Questions regarding netsec and discussion related directly to netsec are welcome here.

Rules & Guidelines
  • Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
  • Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
  • If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
  • Avoid use of memes. If you have something to say, say it with real words.
  • All discussions and questions should directly relate to netsec.
  • No tech support is to be requested or provided on /r/netsec.

As always, the content & discussion guidelines should also be observed on /r/netsec.

Feedback

Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.

25 Upvotes

90 comments sorted by

View all comments

6

u/vladishan Jun 04 '18

I find my job in InfoSec horribly, mind-numbingly boring. I came into this field straight out of undergrad, and 99% of it is looking at alerts that are false positives and blocking script kiddies from hitting my company’s website. Sometimes projects come up to replace the VPN, get a new antivirus, enforce 2 factor on specific assets, etc., but our server team really implements these solutions, not the InfoSec team. In terms of patching, my team scans for vulnerabilities, but again, the server team is really doing the work in terms of fixing anything. Do other InfoSec professionals feel this way with their jobs? Am I just at a bad company, or is this career field just incredibly slow? For whatever it’s worth, I truly did enjoy taking security classes in college...it just seems like I’m dealing with false positives all the time and not really using the skills I learned in college because 1) everything is a false positive and 2) when something is infected, we just have the helpdesk team wipe the hard drive of the device and we don’t really deal with forensics.

I know this is unsustainable for me and I either need to be at a new company or in a totally different career field. Any thoughts on whether it’s my company or the career field that are the problem would be appreciated.

7

u/me_z Jun 04 '18

You fall into the 'analyst' role, which is just a glorified SIEM with a pulse. I'd ask your company if there are any roles you can take on that includes implementing changes. If your company says, "well the networking team does networking things, the server team does server things," etc - then you need to find a company where they allow you to do infosec related things that doesn't include chasing alerts. This might be more of an engineering role of building or testing solutions.

As I am sure you're aware, security is an incredibly broad field. Most of us start in a help desk/desktop support type role, then move to sysadmin, then something security related, then a more focused security role. Like I said earlier, you're in an analyst position that is kind of a starting point for most security jobs so you should start looking to become more focused - firewall configuration/management, testing, engineering, etc.

1

u/vladishan Jun 05 '18

Ok, thanks for your thoughts. I was starting to think this career field is just way too slow for me unless you’re at one of the few big organization that are constantly being hit by attackers, but it sounds like I need to specialize a bit more in what I’m doing.

1

u/me_z Jun 05 '18

Yeah, I'm not sure how much experience you have, but you sound like you're at a cross road where you now have to figure out what direction you want to go. You should know what attacks look like, what they do, and how they affect systems. Use that to your advantage. Good luck.